This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware/Spyware infecting everything

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My brother recently plugged in his flashdrive which he uses on his work computer into my PC. Within seconds my computer was infected with 2 new processes :pullhair: -

Zeazem.Exe and Videos.exe

Now, I cant use any flashdrives because they become automatically infected and eventually stop working, and most of my stuff stored is hidden even though I choose the "Show hidden files or folders" option. I have very sensitive information on my computer and I'm really worried about what could potentially happen guys.

Here's my hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:51:19 PM, on 2/14/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\Db5d\services.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\WINDOWS\Db5d\lsass.exe
C:\Documents and Settings\USER\zeazem.exe
C:\Documents and Settings\USER\Application Data\csrss.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\STacSV.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.soccernet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\Db5d\lsass.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (file missing)
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [000] C:\WINDOWS\Db5d\services.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Edukeziwakecof] rundll32.exe "C:\WINDOWS\odenur70.dll",Startup
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [zeazem] C:\Documents and Settings\USER\zeazem.exe
O4 - HKCU\..\Run: [000] C:\Documents and Settings\USER\Application Data\csrss.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Microsoft Startup Controller.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5447EEA-9B4F-49DD-821F-4BECE6DCBC54}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe

–
End of file - 7299 bytes


I've tried using Spybot S&D, but it doesn't recognize any threats/infected files, and I'm currently trying Malwarebytes'. I know that Videos.Exe isn't evident in the logfile I posted, but its there alright. Every now and then it appears in my running system processes.

Also, is there anyway I can fix the flashdrives that have now been rendered useless? I've tried reformatting them - it doesn't work.

Any help would be most appreciated.

Thank you.
Hello compaq_hater and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Before we do any fixing I would also like to see the results of an ARK scan. As for the USB sticks, if they are infected and formatting them does not remove the malware, I would get rid of them.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans come back and let me know.
Hi JonTom, Thanks for the assistance. As requested, here are the log files: DDS (Ver_10-10-31.01) - NTFSx86 Run by [removed] at 18:22:00.62 on Mon 02/14/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.501.204 [GMT -4:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\sttray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Documents and Settings\USER\Start Menu\Programs\Startup\Microsoft Startup Controller.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\mqtgsvc.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\WgaTray.exe C:\Documents and Settings\USER\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.soccernet.com/ uDefault_Page_URL = hxxp://www.msn.com mWinlogon: Shell=explorer.exe c:\windows\db5d\lsass.exe BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Edukeziwakecof] rundll32.exe "c:\windows\odenur70.dll",Startup uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [zeazem] c:\documents and settings\user\zeazem.exe uRun: [000] c:\documents and settings\user\application data\csrss.exe mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [SigmatelSysTrayApp] sttray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [000] c:\windows\db5d\services.exe StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\documents and settings\user\start menu\programs\startup\Microsoft Startup Controller.exe StartupFolder: c:\docume~1\user\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe uPolicies-explorer: DisallowRun = 1 (0x1) uPolicies-disallowrun: 1 = command.com uPolicies-disallowrun: 2 = avgcc.exe uPolicies-disallowrun: 3 = egui.exe uPolicies-disallowrun: 4 = avgw.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab TCP: {C5447EEA-9B4F-49DD-821F-4BECE6DCBC54} = 208.67.222.222,208.67.220.220 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\mm7j4emy.default\ FF - prefs.js: browser.startup.homepage - hxxp://soccernet.com FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified ============= SERVICES / DRIVERS =============== R3 ip100xp;IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [2008-6-30 26752] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-1-23 38224] =============== Created Last 30 ================ 2011-02-14 22:22:00 2746 —-a-w- c:\windows\erebelisuzog.dll 2011-02-14 19:41:59 2746 —-a-w- c:\windows\elidoruvozerazur.dll 2011-02-14 16:50:25 388096 —-a-r- c:\docume~1\user\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-14 11:08:40 2746 —-a-w- c:\windows\upatefes.dll 2011-02-14 02:40:13 711168 —-a-w- c:\windows\is-4KVT6.exe 2011-02-14 00:51:59 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-02-14 00:51:59 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2011-02-14 00:29:28 ——– d-sh–w- c:\windows\Db5d 2011-02-14 00:29:18 57344 –sh–r- c:\documents and settings\user\zeazem.exe 2011-02-14 00:28:00 2746 —-a-w- c:\windows\eqadifemeyu.dll 2011-02-13 20:05:10 2746 —-a-w- c:\windows\idodirotaniqeri.dll 2011-02-13 13:42:43 2746 —-a-w- c:\windows\ekanaxix.dll 2011-02-12 03:42:24 2746 —-a-w- c:\windows\agogihajileso.dll 2011-02-11 22:21:20 2746 —-a-w- c:\windows\iqadifemeyudafa.dll 2011-02-11 02:24:12 2746 —-a-w- c:\windows\aqetidal.dll 2011-02-10 11:02:22 2746 —-a-w- c:\windows\ubulisuzogerut.dll 2011-02-10 02:05:56 2746 —-a-w- c:\windows\iyadalumihudusi.dll 2011-02-09 23:58:59 2746 —-a-w- c:\windows\efocuqewofehoc.dll 2011-02-09 14:12:41 2746 —-a-w- c:\windows\uzejokilomini.dll 2011-02-09 02:03:19 2746 —-a-w- c:\windows\ohaniqeribecidu.dll 2011-02-08 14:16:12 2746 —-a-w- c:\windows\awayeyogomu.dll 2011-02-08 01:49:05 2746 —-a-w- c:\windows\ivubevami.dll 2011-02-07 21:33:54 2746 —-a-w- c:\windows\ohewerec.dll 2011-02-07 15:27:42 2746 —-a-w- c:\windows\akuqapejucohotu.dll 2011-02-07 00:17:35 2746 —-a-w- c:\windows\ebojodohujeh.dll 2011-02-06 21:01:26 2746 —-a-w- c:\windows\ozelugoqoralo.dll 2011-02-06 04:45:55 2746 —-a-w- c:\windows\ujovaqeg.dll 2011-02-06 03:06:11 2746 —-a-w- c:\windows\ulovowiyel.dll 2011-02-05 20:54:22 2746 —-a-w- c:\windows\ixazezocoh.dll 2011-02-05 17:53:36 2746 —-a-w- c:\windows\atidumos.dll 2011-02-05 11:59:28 2746 —-a-w- c:\windows\isaxuyiru.dll 2011-02-05 01:40:20 2746 —-a-w- c:\windows\elagologiw.dll 2011-02-04 19:38:41 2746 —-a-w- c:\windows\apaloput.dll 2011-02-04 01:53:17 2746 —-a-w- c:\windows\umanodijip.dll 2011-02-03 23:20:15 2746 —-a-w- c:\windows\ibulejac.dll 2011-02-02 22:49:58 2746 —-a-w- c:\windows\irojihan.dll 2011-02-02 03:25:13 2746 —-a-w- c:\windows\ejequkiv.dll 2011-02-01 14:57:36 2746 —-a-w- c:\windows\ewiqerofiboqa.dll 2011-02-01 01:46:50 2746 —-a-w- c:\windows\ilozobif.dll 2011-01-31 21:43:34 2746 —-a-w- c:\windows\uzidepig.dll 2011-01-31 15:40:38 2746 —-a-w- c:\windows\ipaganisapam.dll 2011-01-30 22:47:41 2746 —-a-w- c:\windows\ecigefim.dll 2011-01-30 05:30:06 2746 —-a-w- c:\windows\onegozuxecu.dll 2011-01-29 21:58:11 2746 —-a-w- c:\windows\erubosuyeganowet.dll 2011-01-29 15:01:27 2746 —-a-w- c:\windows\uyonodijipatax.dll 2011-01-28 17:45:36 2746 —-a-w- c:\windows\enodevacuq.dll 2011-01-28 03:43:14 2746 —-a-w- c:\windows\uzujovapu.dll 2011-01-27 21:52:05 2746 —-a-w- c:\windows\ukaxibugojud.dll 2011-01-27 19:47:23 2746 —-a-w- c:\windows\ahuvurij.dll 2011-01-27 01:10:41 2746 —-a-w- c:\windows\eloxedakoko.dll 2011-01-26 14:02:38 2746 —-a-w- c:\windows\irazozaw.dll 2011-01-26 01:39:38 2746 —-a-w- c:\windows\uyofiqem.dll 2011-01-25 21:32:11 2746 —-a-w- c:\windows\usidajugaborovom.dll 2011-01-25 13:30:18 2746 —-a-w- c:\windows\ikuqusiwoj.dll 2011-01-24 23:53:09 2746 —-a-w- c:\windows\uqinigowe.dll 2011-01-24 21:15:25 2746 —-a-w- c:\windows\ahikimup.dll 2011-01-24 15:18:32 2746 —-a-w- c:\windows\evanubililahacaf.dll 2011-01-23 17:06:21 2746 —-a-w- c:\windows\emevekegubix.dll 2011-01-23 05:08:33 2746 —-a-w- c:\windows\ojucanuveruq.dll 2011-01-22 22:52:34 2746 —-a-w- c:\windows\omedujodivoduke.dll 2011-01-22 16:51:38 2746 —-a-w- c:\windows\iqupiqiyonoxuxab.dll 2011-01-22 04:17:10 2746 —-a-w- c:\windows\aguyiqop.dll 2011-01-21 13:37:26 2746 —-a-w- c:\windows\alegagimo.dll 2011-01-20 22:49:21 2746 —-a-w- c:\windows\oyogeteyojomucet.dll 2011-01-20 05:39:09 2746 —-a-w- c:\windows\abewejoguxa.dll 2011-01-20 02:48:34 2746 —-a-w- c:\windows\ebaxevoyohovoj.dll 2011-01-19 19:22:06 2746 —-a-w- c:\windows\iwiwajurija.dll 2011-01-19 04:01:32 2746 —-a-w- c:\windows\uxogovagif.dll 2011-01-18 16:22:47 2746 —-a-w- c:\windows\obiwubix.dll 2011-01-18 05:02:47 2746 —-a-w- c:\windows\efopekamos.dll 2011-01-18 02:03:33 2746 —-a-w- c:\windows\uqomehigat.dll 2011-01-17 23:54:14 2746 —-a-w- c:\windows\aqocoruwuya.dll 2011-01-17 16:19:02 2746 —-a-w- c:\windows\inogekajomowap.dll 2011-01-17 03:30:20 2746 —-a-w- c:\windows\uxugivajiy.dll 2011-01-16 23:02:44 2746 —-a-w- c:\windows\agovinuyozewahat.dll 2011-01-16 03:51:56 2746 —-a-w- c:\windows\iheradiyub.dll 2011-01-15 22:34:27 2746 —-a-w- c:\windows\initijokilo.dll ==================== Find3M ==================== 2011-01-15 14:49:07 2746 —-a-w- c:\windows\afuhasafoxo.dll 2011-01-15 02:54:51 2746 —-a-w- c:\windows\ohanidopumam.dll 2011-01-15 00:21:33 2746 —-a-w- c:\windows\evajurij.dll 2011-01-14 05:32:27 2746 —-a-w- c:\windows\alerohilonora.dll 2011-01-14 03:04:10 2746 —-a-w- c:\windows\abegologiw.dll 2011-01-13 17:09:05 2746 —-a-w- c:\windows\ogupepac.dll 2011-01-13 02:39:37 2746 —-a-w- c:\windows\ulaxeyuvasa.dll 2011-01-12 20:03:38 2746 —-a-w- c:\windows\evoxijum.dll 2011-01-12 02:29:09 2746 —-a-w- c:\windows\ezahodopuvonej.dll 2011-01-11 17:16:40 2746 —-a-w- c:\windows\adoxayugupiditem.dll 2011-01-10 20:19:05 2746 —-a-w- c:\windows\ocekolak.dll 2011-01-10 03:27:25 2746 —-a-w- c:\windows\emuleqayisa.dll 2011-01-09 22:30:17 2746 —-a-w- c:\windows\ucunagog.dll 2011-01-09 15:12:43 2746 —-a-w- c:\windows\onupucusezejoh.dll 2011-01-09 03:56:17 2746 —-a-w- c:\windows\azaxanim.dll 2011-01-09 02:02:51 2746 —-a-w- c:\windows\efivacas.dll 2011-01-08 19:48:59 2746 —-a-w- c:\windows\okaruvupo.dll 2011-01-08 04:57:24 2746 —-a-w- c:\windows\ufinezuduqiya.dll 2011-01-07 14:21:55 2746 —-a-w- c:\windows\uluwoxut.dll 2011-01-06 17:00:13 2746 —-a-w- c:\windows\oqocubuwo.dll 2011-01-06 03:59:22 2746 —-a-w- c:\windows\inidepig.dll 2011-01-05 22:13:40 2746 —-a-w- c:\windows\ivanewunoz.dll 2011-01-05 19:35:30 2746 —-a-w- c:\windows\ayatobabuyutomo.dll 2011-01-05 16:55:22 2746 —-a-w- c:\windows\azamikagoxu.dll 2011-01-05 00:05:46 2746 —-a-w- c:\windows\itoqafotoce.dll 2011-01-04 18:23:18 2746 —-a-w- c:\windows\awelihoc.dll 2011-01-04 04:30:40 2746 —-a-w- c:\windows\ivonocesofih.dll 2011-01-04 00:40:37 2746 —-a-w- c:\windows\ilutapimo.dll 2011-01-03 04:26:05 2746 —-a-w- c:\windows\avimoyesicogot.dll 2011-01-02 23:37:22 2746 —-a-w- c:\windows\uqejulow.dll 2011-01-02 22:32:43 2746 —-a-w- c:\windows\uhigevusu.dll 2011-01-02 14:21:43 2746 —-a-w- c:\windows\evupeteroqaxacod.dll 2011-01-02 01:59:50 2746 —-a-w- c:\windows\aheqisal.dll 2011-01-01 15:44:30 2746 —-a-w- c:\windows\ojevehulato.dll 2011-01-01 04:23:24 2746 —-a-w- c:\windows\uyokozehu.dll 2010-12-31 03:03:03 2746 —-a-w- c:\windows\afemohagiqinic.dll 2010-12-31 02:15:13 2746 —-a-w- c:\windows\onuviyifani.dll 2010-12-30 18:19:25 2746 —-a-w- c:\windows\ufiyohupofuyipi.dll 2010-12-30 02:59:24 2746 —-a-w- c:\windows\orexavigam.dll 2010-12-28 22:35:18 2746 —-a-w- c:\windows\ububiweyifeg.dll 2010-12-28 17:26:03 2746 —-a-w- c:\windows\iyebupicericoxep.dll 2010-12-27 23:00:18 2746 —-a-w- c:\windows\iqeteroqax.dll 2010-12-27 14:36:56 2746 —-a-w- c:\windows\agebewahazuyos.dll 2010-12-27 03:07:02 2746 —-a-w- c:\windows\uveyamuzageyabe.dll 2010-12-26 22:48:36 2746 —-a-w- c:\windows\ulevabuyudikug.dll 2010-12-26 21:39:07 2746 —-a-w- c:\windows\aterereweril.dll 2010-12-26 06:06:13 2746 —-a-w- c:\windows\ufejuxapivehadaj.dll 2010-12-25 22:57:25 2746 —-a-w- c:\windows\agepiqiyonoxuxab.dll 2010-12-25 00:12:59 2746 —-a-w- c:\windows\asepalirikijir.dll 2010-12-24 04:13:25 2746 —-a-w- c:\windows\evuleyocozof.dll 2010-12-23 23:36:57 2746 —-a-w- c:\windows\uzaxanimifixejo.dll 2010-12-22 16:16:53 2746 —-a-w- c:\windows\uzidehibe.dll 2010-12-22 01:20:39 2746 —-a-w- c:\windows\ezisuras.dll 2010-12-21 13:34:28 2746 —-a-w- c:\windows\oqeguxaboko.dll 2010-12-21 02:23:13 2746 —-a-w- c:\windows\aguxojux.dll 2010-12-20 14:50:25 2746 —-a-w- c:\windows\ejoguheyekit.dll 2010-12-20 02:40:24 2746 —-a-w- c:\windows\uwabupov.dll 2010-12-19 04:36:12 2746 —-a-w- c:\windows\enafapit.dll 2010-12-18 20:57:24 2746 —-a-w- c:\windows\evuxaxeda.dll 2010-12-18 13:17:26 2746 —-a-w- c:\windows\ebelirikijiraz.dll 2010-12-17 02:14:46 2746 —-a-w- c:\windows\udovowiyelukig.dll 2010-12-16 20:55:13 2746 —-a-w- c:\windows\onobetog.dll 2010-12-16 12:25:00 2746 —-a-w- c:\windows\uheradiy.dll 2010-12-16 10:09:34 2746 —-a-w- c:\windows\iveyaxukow.dll 2010-12-16 02:24:31 2746 —-a-w- c:\windows\inaxozuvovepur.dll 2010-12-15 23:31:17 2746 —-a-w- c:\windows\adaxoyenevud.dll 2010-12-15 19:25:10 2746 —-a-w- c:\windows\ecerefub.dll 2010-12-15 17:08:17 2746 —-a-w- c:\windows\uwavateb.dll 2010-12-15 14:20:30 2746 —-a-w- c:\windows\abolupuf.dll 2010-12-15 03:35:30 2746 —-a-w- c:\windows\aquxorig.dll 2010-12-15 00:09:54 2746 —-a-w- c:\windows\obiwateb.dll 2010-12-14 21:36:34 2746 —-a-w- c:\windows\odoxesab.dll 2010-12-14 18:28:26 2746 —-a-w- c:\windows\atefonut.dll 2010-12-14 15:20:37 2746 —-a-w- c:\windows\ujazezoc.dll 2010-12-14 03:25:26 2746 —-a-w- c:\windows\uqisuxom.dll 2010-12-13 02:09:46 2746 —-a-w- c:\windows\opuvupilidar.dll 2010-12-12 23:02:22 2746 —-a-w- c:\windows\ojatucigenoguq.dll 2010-12-12 20:29:15 2746 —-a-w- c:\windows\ehowamikuxiyay.dll 2010-12-12 16:53:03 2746 —-a-w- c:\windows\ipuhakucadic.dll 2010-12-12 14:18:03 2746 —-a-w- c:\windows\okexoxiw.dll 2010-12-12 03:56:14 2746 —-a-w- c:\windows\aqoneniq.dll 2010-12-11 21:07:18 2746 —-a-w- c:\windows\ilapijaferoc.dll 2010-12-11 18:09:16 2746 —-a-w- c:\windows\amodinigowe.dll 2010-12-11 15:44:42 2746 —-a-w- c:\windows\ajasiquy.dll 2010-12-11 15:00:28 2746 —-a-w- c:\windows\apuqepijo.dll 2010-12-11 04:07:35 2746 —-a-w- c:\windows\enuxecab.dll 2010-12-10 21:34:07 2746 —-a-w- c:\windows\anovaqegayuxoxot.dll 2010-12-10 20:32:11 2746 —-a-w- c:\windows\ipufivufepov.dll 2010-12-10 16:29:48 2746 —-a-w- c:\windows\ohowofehocozis.dll 2010-12-10 14:02:23 2746 —-a-w- c:\windows\egumopajeboyorad.dll 2010-12-10 04:32:38 2746 —-a-w- c:\windows\imoxuqot.dll 2010-12-10 01:28:29 2746 —-a-w- c:\windows\icozuvif.dll 2010-12-09 22:02:19 2746 —-a-w- c:\windows\egacukexugu.dll 2010-12-09 18:33:40 2746 —-a-w- c:\windows\etodelubem.dll 2010-12-09 16:15:23 2746 —-a-w- c:\windows\ayahegucobojeb.dll 2010-12-09 06:28:48 2746 —-a-w- c:\windows\onadahig.dll 2010-12-08 22:14:58 2746 —-a-w- c:\windows\azidehibewava.dll 2010-12-08 20:33:23 2746 —-a-w- c:\windows\idareweh.dll 2010-12-08 04:13:51 2746 —-a-w- c:\windows\uxenubililah.dll 2010-12-08 00:56:56 2746 —-a-w- c:\windows\oricaliroquq.dll 2008-11-29 19:49:24 152064 –sh–w- c:\windows\db5d\services.exe ============= FINISH: 18:23:19.64 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-10-31.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/7/2005 11:24:05 AM System Uptime: 2/14/2011 6:19:30 PM (0 hours ago) Motherboard: Intel Corporation | | D946GZIS Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 37 GiB total, 6.012 GiB free. D: is CDROM () E: is Removable ==== Disabled Device Manager Items ============= Class GUID: Description: Ethernet Controller Device ID: PCI\VEN_8086&DEV_1094&SUBSYS_00018086&REV_01\4&1E46F438&0&40F0 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_8086&DEV_1094&SUBSYS_00018086&REV_01\4&1E46F438&0&40F0 Service: Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia 5130c-2 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia 5130c-2 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd ==== System Restore Points =================== RP168: 11/17/2010 12:23:38 AM - System Checkpoint RP169: 11/19/2010 7:55:55 PM - System Checkpoint RP170: 11/22/2010 11:04:43 PM - System Checkpoint RP171: 12/19/2010 12:43:15 AM - System Checkpoint RP172: 12/23/2010 11:43:05 PM - System Checkpoint RP173: 12/30/2010 11:28:28 PM - System Checkpoint RP174: 1/1/2011 12:55:40 AM - System Checkpoint RP175: 1/4/2011 12:30:15 AM - System Checkpoint RP176: 1/6/2011 12:30:21 PM - System Checkpoint RP177: 1/7/2011 11:51:53 PM - System Checkpoint RP178: 1/9/2011 12:43:39 AM - System Checkpoint RP179: 1/13/2011 11:36:45 PM - System Checkpoint RP180: 1/15/2011 6:39:54 PM - System Checkpoint RP181: 1/22/2011 12:44:27 AM - System Checkpoint RP182: 1/24/2011 7:29:09 PM - System Checkpoint RP183: 1/25/2011 11:20:09 PM - System Checkpoint RP184: 1/28/2011 12:05:43 AM - System Checkpoint RP185: 1/30/2011 12:49:29 AM - System Checkpoint RP186: 2/2/2011 10:28:00 PM - System Checkpoint RP187: 2/7/2011 11:22:29 AM - System Checkpoint RP188: 2/9/2011 12:09:24 AM - System Checkpoint RP189: 2/13/2011 9:26:22 PM - System Checkpoint RP190: 2/14/2011 12:50:16 PM - Installed HiJackThis RP191: 2/14/2011 6:11:56 PM - Removed Symantec AntiVirus Client ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 Apple Application Support Apple Software Update Broadcom 440x 10/100 Integrated Controller BufferChm CCleaner (remove only) CD/DVD-ROM Generator 1.20 D2400 D2400_Help DeviceDiscovery DeviceManagementQFolder dj_sf_ProductContext dj_sf_software dj_sf_software_req DriverSetup DVD Decrypter (Remove Only) ERUNT 1.1j FLV Player High Definition Audio Driver Package - KB888111 HiJackThis HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) HP Deskjet Printer Driver Software 9.0 HP Imaging Device Functions 9.0 Image Resizer Powertoy for Windows XP Imation Disk Manager V a Service Intel® Graphics Media Accelerator Driver IsoBuster 2.2 Java Auto Updater Java™ 6 Update 2 Java™ 6 Update 21 LimeWire 5.4.8 LiveUpdate 1.7 (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2003 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Outlook Web Access S/MIME Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.7 Mozilla Firefox (3.6.13) MSN Toolbar MSVC80_x86_v2 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK Nero PhotoShow Express Nero Suite Nokia Connectivity Cable Driver Nokia PC Suite oggcodecs 0.71.0946 PanoStandAlone PartyPokerNet PC Connectivity Solution Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926247) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939373) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942830) Security Update for Windows XP (KB942831) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Segoe UI Shockwave SigmaTel Audio SIW version 2010.07.14 SopCast 3.0.3 Status Toolbox TrayApp UnloadSupport Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) Veetle TV 0.9.14 WebFldrs XP WebReg Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WinZip ==== Event Viewer Messages From Past Week ======== 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-1 is not functioning. 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-0 is not functioning. 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port LPT1 is not functioning. 2/7/2011 9:49:57 PM, error: NAVAP [20] - 2/14/2011 2:35:02 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. 2/13/2011 9:31:21 PM, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 2/13/2011 9:31:11 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. ==== End Of File =========================== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-10-31.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/7/2005 11:24:05 AM System Uptime: 2/14/2011 6:19:30 PM (0 hours ago) Motherboard: Intel Corporation | | D946GZIS Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 37 GiB total, 6.012 GiB free. D: is CDROM () E: is Removable ==== Disabled Device Manager Items ============= Class GUID: Description: Ethernet Controller Device ID: PCI\VEN_8086&DEV_1094&SUBSYS_00018086&REV_01\4&1E46F438&0&40F0 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_8086&DEV_1094&SUBSYS_00018086&REV_01\4&1E46F438&0&40F0 Service: Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia 5130c-2 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia 5130c-2 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd ==== System Restore Points =================== RP168: 11/17/2010 12:23:38 AM - System Checkpoint RP169: 11/19/2010 7:55:55 PM - System Checkpoint RP170: 11/22/2010 11:04:43 PM - System Checkpoint RP171: 12/19/2010 12:43:15 AM - System Checkpoint RP172: 12/23/2010 11:43:05 PM - System Checkpoint RP173: 12/30/2010 11:28:28 PM - System Checkpoint RP174: 1/1/2011 12:55:40 AM - System Checkpoint RP175: 1/4/2011 12:30:15 AM - System Checkpoint RP176: 1/6/2011 12:30:21 PM - System Checkpoint RP177: 1/7/2011 11:51:53 PM - System Checkpoint RP178: 1/9/2011 12:43:39 AM - System Checkpoint RP179: 1/13/2011 11:36:45 PM - System Checkpoint RP180: 1/15/2011 6:39:54 PM - System Checkpoint RP181: 1/22/2011 12:44:27 AM - System Checkpoint RP182: 1/24/2011 7:29:09 PM - System Checkpoint RP183: 1/25/2011 11:20:09 PM - System Checkpoint RP184: 1/28/2011 12:05:43 AM - System Checkpoint RP185: 1/30/2011 12:49:29 AM - System Checkpoint RP186: 2/2/2011 10:28:00 PM - System Checkpoint RP187: 2/7/2011 11:22:29 AM - System Checkpoint RP188: 2/9/2011 12:09:24 AM - System Checkpoint RP189: 2/13/2011 9:26:22 PM - System Checkpoint RP190: 2/14/2011 12:50:16 PM - Installed HiJackThis RP191: 2/14/2011 6:11:56 PM - Removed Symantec AntiVirus Client ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 Apple Application Support Apple Software Update Broadcom 440x 10/100 Integrated Controller BufferChm CCleaner (remove only) CD/DVD-ROM Generator 1.20 D2400 D2400_Help DeviceDiscovery DeviceManagementQFolder dj_sf_ProductContext dj_sf_software dj_sf_software_req DriverSetup DVD Decrypter (Remove Only) ERUNT 1.1j FLV Player High Definition Audio Driver Package - KB888111 HiJackThis HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) HP Deskjet Printer Driver Software 9.0 HP Imaging Device Functions 9.0 Image Resizer Powertoy for Windows XP Imation Disk Manager V a Service Intel® Graphics Media Accelerator Driver IsoBuster 2.2 Java Auto Updater Java™ 6 Update 2 Java™ 6 Update 21 LimeWire 5.4.8 LiveUpdate 1.7 (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2003 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Outlook Web Access S/MIME Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.7 Mozilla Firefox (3.6.13) MSN Toolbar MSVC80_x86_v2 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK Nero PhotoShow Express Nero Suite Nokia Connectivity Cable Driver Nokia PC Suite oggcodecs 0.71.0946 PanoStandAlone PartyPokerNet PC Connectivity Solution Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926247) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939373) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942830) Security Update for Windows XP (KB942831) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Segoe UI Shockwave SigmaTel Audio SIW version 2010.07.14 SopCast 3.0.3 Status Toolbox TrayApp UnloadSupport Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) Veetle TV 0.9.14 WebFldrs XP WebReg Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WinZip ==== Event Viewer Messages From Past Week ======== 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-1 is not functioning. 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-0 is not functioning. 2/8/2011 9:32:23 PM, error: RemoteAccess [20013] - The communication device attached to port LPT1 is not functioning. 2/7/2011 9:49:57 PM, error: NAVAP [20] - 2/14/2011 2:35:02 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. 2/13/2011 9:31:21 PM, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 2/13/2011 9:31:11 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. ==== End Of File =========================== Please, let me know if I did it correctly.
Hello compaq_hater

Please, let me know if I did it correctly.

Was GMER able to complete its scan? If the scan ran without problems, please post the log that was created.

If you had trouble getting GMER to complete (which can happen from time to time) please try the following:


  • GMER


    • If you are having trouble getting GMER to complete a scan, please run it again, but this time uncheck everything EXCEPT "Sections" and "C:\".
    • If GMER does not produce a log please try running it from Safe Mode.

    • How to use the F8 method to Start Your Computer in Safe Mode

    • Restart your computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
    • Use the arrow keys to select the Safe mode menu item.
    • Press Enter.

    • If GMER in safe mode does not work, please try Rootkit Unhooker:

  • Rootkit Unhooker


    • Please Download Rootkit Unhooker and Save it to your desktop.
    • Now double-click on RKUnhookerLE.exe to run it.
    • Click the Report tab, then click Scan.
    • Check (Tick) Drivers, Stealth. Uncheck the rest, then Click OK.
    • Wait till the scanner has finished and then click File, Save Report.
    • Save the report somewhere where you can find it. Click Close.

    Copy the entire contents of the report and paste it in your next reply here.

    Note: You may get the following warning, just click OK and continue.

    "Rootkit Unhooker has detected a parasite inside itself!
    It is recommended to remove parasite, okay?"


    Please provide the GMER/Rootkit Unhooker log in your next reply. If you are still having trouble, come back and let me know :)
Hi again JonTom,

could've sworn I posted the Gmer log.

Here it is:

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-14 20:15:34
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 ST340823A rev.3.39
Running: gmer.exe; Driver: C:\DOCUME~1\USER\LOCALS~1\Temp\kwxoqpoc.sys


—- User code sections - GMER 1.0.15 —-

ÒuÛŠëÔÿÿÿÿservicesentry point in "ÒuÛŠëÔÿÿÿÿservicesentry point in "" section [0x00436FD4] C:\WINDOWS\Db5d\services.exe[400] C:\WINDOWS\Db5d\services.exe entry point in "ÒuÛŠëÔÿÿÿÿservicesentry point in "" section [0x00436FD4]
ÒuÛŠëÔÿÿÿÿservicesunknown last code section [0x00421000, 0x25000, 0xE00000E0] C:\WINDOWS\Db5d\services.exe[400] C:\WINDOWS\Db5d\services.exe unknown last code section [0x00421000, 0x25000, 0xE00000E0]
ÒuÛŠëÔÿÿÿÿcsrss.exentry point in "ÒuÛŠëÔÿÿÿÿcsrss.exentry point in "" section [0x00436FD4] C:\Documents and Settings\USER\Application Data\csrss.exe[648] C:\Documents and Settings\USER\Application Data\csrss.exe entry point in "ÒuÛŠëÔÿÿÿÿcsrss.exentry point in "" section [0x00436FD4]
ÒuÛŠëÔÿÿÿÿcsrss.exunknown last code section [0x00421000, 0x25000, 0xE00000E0] C:\Documents and Settings\USER\Application Data\csrss.exe[648] C:\Documents and Settings\USER\Application Data\csrss.exe unknown last code section [0x00421000, 0x25000, 0xE00000E0]

—- EOF - GMER 1.0.15 —-

Sorry about that. Hope thats what you were looking for.

Just an additional note, my Local Disk has become loaded with numerous bogus folders and, every time I start my computer, an MSDOS box pops up with a zeazem.exe prompt.

Thanks.
Hello compaq_hater

could've sworn I posted the Gmer log

:) No problem.

Please do the following:

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Hi JonTom,

As requested, here is the Combofix logfile:

ComboFix 11-02-15.01 - USER 02/15/2011 16:57:27.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.501.200 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\abgtmgh.exe
C:\agharrh.exe
C:\aguulrb.exe
C:\aieotob.exe
C:\aoeitgh.exe
C:\aphmesb.exe
C:\aptbbre.exe
C:\argmsur.exe
C:\argrpma.exe
C:\arushlg.exe
C:\asrlhcl.exe
C:\atactgp.exe
C:\ateeour.exe
C:\atmuioc.exe
C:\auratop.exe
C:\baugibu.exe
C:\bbbopag.exe
C:\bcguaia.exe
C:\bclohhi.exe
C:\bgruscb.exe
C:\bmbsesa.exe
C:\bpbrtlp.exe
C:\bsmbetr.exe
C:\bteltha.exe
C:\btmelhm.exe
c:\documents and settings\USER\Application Data\csrss.exe
c:\documents and settings\USER\Local Settings\carbon.exe
c:\documents and settings\USER\RavMonLog
c:\documents and settings\USER\Start Menu\Programs\Startup\Microsoft Startup Controller.exe
c:\documents and settings\USER\zeazem.exe
C:\hapepcm.exe
C:\hbeccta.exe
C:\hbeicar.exe
C:\hcsuiga.exe
C:\heishbm.exe
C:\hhaioso.exe
C:\hlrhbem.exe
C:\hlslite.exe
C:\hobuhpr.exe
C:\hoirbtm.exe
C:\homrpsl.exe
C:\htritru.exe
C:\hupiipt.exe
C:\iohlrsl.exe
C:\leibpph.exe
C:\lreoomb.exe
C:\macuimo.exe
C:\mahtaau.exe
C:\mbthrir.exe
C:\mcclstg.exe
C:\megellm.exe
C:\mguuahr.exe
C:\mhouibb.exe
C:\mllsalm.exe
C:\mrgegcs.exe
C:\mtehubo.exe
C:\new folder.exe
C:\pbauhog.exe
C:\pcoibei.exe
C:\pgmahbb.exe
C:\phthseh.exe
C:\poegcgr.exe
C:\popgtbg.exe
C:\prbcaie.exe
c:\program files\Internet Explorer\ws2help.dll
c:\program files\Windows Media Player\ws2help.dll
C:\pslogui.exe
C:\tchcrec.exe
C:\tcsiutl.exe
C:\tcupspe.exe
C:\teeicic.exe
C:\teorrgc.exe
C:\tgucump.exe
C:\thaambu.exe
C:\tihgirl.exe
C:\toehcir.exe
C:\tplshat.exe
C:\tpuspmi.exe
C:\tricmlp.exe
C:\tseemst.exe
C:\tuctthe.exe
C:\tuogohl.exe
C:\ulalgte.exe
C:\ulastre.exe
C:\USER's Files.exe
C:\VIDEOS.exe
c:\windows\awayeyogomu.dll
c:\windows\Db5d\lsass.exe
c:\windows\Db5d\services.exe
c:\windows\idareweh.dll
c:\windows\obiwateb.dll
c:\windows\odenur70.dll
c:\windows\ohewerec.dll
c:\windows\system32\AutoRun.inf
c:\windows\system32\TrulyAmazing.scr

—– File Replicators —–

C:\abgtmgh.exe
C:\agharrh.exe
C:\aguulrb.exe
C:\aieotob.exe
C:\aoeitgh.exe
C:\aphmesb.exe
C:\aptbbre.exe
C:\argmsur.exe
C:\argrpma.exe
C:\arushlg.exe
C:\asrlhcl.exe
C:\atactgp.exe
C:\ateeour.exe
C:\atmuioc.exe
C:\auratop.exe
C:\baugibu.exe
C:\bbbopag.exe
C:\bcguaia.exe
C:\bclohhi.exe
C:\bgruscb.exe
C:\bmbsesa.exe
C:\bpbrtlp.exe
C:\bsmbetr.exe
C:\bteltha.exe
C:\btmelhm.exe
c:\documents and settings\USER\Application Data\csrss.exe
c:\documents and settings\USER\Local Settings\carbon.exe
c:\documents and settings\USER\Start Menu\Programs\Startup\Microsoft Startup Controller.exe
C:\hapepcm.exe
C:\hbeccta.exe
C:\hbeicar.exe
C:\hcsuiga.exe
C:\heishbm.exe
C:\hhaioso.exe
C:\hlrhbem.exe
C:\hlslite.exe
C:\hobuhpr.exe
C:\hoirbtm.exe
C:\homrpsl.exe
C:\htritru.exe
C:\hupiipt.exe
C:\icsrsgi.exe
C:\iohlrsl.exe
C:\leibpph.exe
C:\lreoomb.exe
C:\macuimo.exe
C:\mahtaau.exe
C:\mbthrir.exe
C:\mcclstg.exe
C:\megellm.exe
C:\mguuahr.exe
C:\mhouibb.exe
C:\mllsalm.exe
C:\mrgegcs.exe
C:\mtehubo.exe
C:\pbauhog.exe
C:\pcoibei.exe
C:\pgmahbb.exe
C:\phthseh.exe
C:\poegcgr.exe
C:\popgtbg.exe
C:\prbcaie.exe
C:\pslogui.exe
C:\tchcrec.exe
C:\tcsiutl.exe
C:\tcupspe.exe
C:\teeicic.exe
C:\teorrgc.exe
C:\tgucump.exe
C:\thaambu.exe
C:\tihgirl.exe
C:\toehcir.exe
C:\tplshat.exe
C:\tpuspmi.exe
C:\tricmlp.exe
C:\tseemst.exe
C:\tuctthe.exe
C:\tuogohl.exe
C:\ulalgte.exe
C:\ulastre.exe
c:\windows\agrsmdel.exe
c:\windows\Db5d\lsass.exe
c:\windows\system32\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0012\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0016\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0017\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0018\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0019\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0020\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0021\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0022\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0023\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0024\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0025\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0026\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0027\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0028\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0029\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0030\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0031\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0032\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0034\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0035\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0036\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0037\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0038\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0039\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0040\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0041\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0042\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0043\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0044\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0045\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0046\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0047\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0048\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0049\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0050\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0051\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0052\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0053\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0054\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0055\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0056\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0057\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0058\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0059\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0060\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0061\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0062\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0063\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0064\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0065\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0066\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0067\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0068\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0069\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0070\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0071\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0072\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0073\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0074\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0075\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0076\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0077\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0078\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0079\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0080\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0081\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0082\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0083\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0084\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0085\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0086\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0087\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0088\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0089\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0090\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0091\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0092\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0093\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0094\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0095\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0096\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0097\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0098\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0099\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0100\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0101\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0102\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0103\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0104\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0105\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0106\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0107\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0109\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0110\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0111\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0112\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0113\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0114\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0115\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0116\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0117\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0118\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0119\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0120\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0121\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0122\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0123\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0124\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0125\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0126\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0127\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0128\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0129\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0130\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0131\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0132\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0133\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0134\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0135\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0136\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0137\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0138\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0139\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0140\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0141\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0142\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0143\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0144\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0145\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0146\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0147\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0148\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0149\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0150\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0151\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0152\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0153\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0154\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0155\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0156\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0157\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0158\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0159\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0160\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0161\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0162\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0163\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0164\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0165\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0166\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0167\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0168\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0169\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0170\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0171\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0172\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0173\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0174\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0175\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0176\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0177\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0178\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0179\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0180\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0181\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0182\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0183\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0184\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0185\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0186\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0187\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0188\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0189\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0190\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0191\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0192\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0193\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0194\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0195\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0196\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0197\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0198\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0199\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0200\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0201\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0202\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0203\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0204\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0205\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0206\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0207\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0208\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0209\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0210\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0211\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0212\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0213\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0214\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0215\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0216\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0217\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0218\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0219\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0220\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0221\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0222\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0223\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0224\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0225\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0226\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0227\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0228\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0229\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0230\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0231\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0232\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0233\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0234\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0235\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0236\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0237\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0238\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0239\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0240\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0241\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0242\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0243\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0244\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0245\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0246\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0247\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0248\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0249\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0250\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0251\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0252\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0253\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0254\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0255\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0256\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0257\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0258\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0259\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0260\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0261\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0262\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0263\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0264\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0265\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0266\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0267\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0268\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0269\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0270\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0271\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0272\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0273\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0274\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0275\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0276\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0277\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0278\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0279\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0280\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0281\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0282\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0283\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0284\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0285\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0286\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0287\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0288\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0289\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0290\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0291\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0292\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0293\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0294\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0295\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0296\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0297\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0298\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0299\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0301\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0302\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0303\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0304\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0305\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0306\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0307\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0308\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0309\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0310\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0311\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0312\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0313\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0314\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0315\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0316\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0317\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0318\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0319\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0320\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0321\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0322\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0323\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0324\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0325\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0326\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0327\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0328\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0329\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0330\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0331\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0332\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0333\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0334\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0335\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0336\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0337\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0338\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0339\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0340\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0341\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0342\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0343\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0344\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0345\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0346\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0347\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0348\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0349\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0350\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0351\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0352\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0353\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0354\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0355\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0356\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0357\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0358\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0359\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0360\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0361\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0362\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0363\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0364\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0365\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0366\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0367\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0368\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0369\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0370\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0371\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0372\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0373\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0374\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0375\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0376\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0377\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0378\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0379\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0380\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0381\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0382\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0383\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0384\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0385\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0387\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0388\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0389\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0390\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0391\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0392\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0393\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0394\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0396\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0397\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0398\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0399\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0400\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0401\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0402\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0403\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0404\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0405\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0406\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0407\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0408\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0409\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0410\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0411\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0412\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0413\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0414\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0415\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0416\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0417\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0418\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0419\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0420\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0421\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0422\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0423\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0424\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0425\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0426\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0427\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0428\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0429\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0430\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0431\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0432\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0433\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0434\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0435\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0436\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0437\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0438\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0439\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0440\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0441\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0442\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0443\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0444\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0445\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0446\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0447\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0448\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0449\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0450\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0451\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0452\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0453\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0454\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0455\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0456\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0457\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0458\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0459\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0460\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0461\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0462\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0463\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0464\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0465\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0466\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0467\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0468\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0469\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0470\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0471\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0472\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0473\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0474\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0475\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0476\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0477\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0478\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0479\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0480\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0481\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0482\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0483\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0484\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0485\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0486\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0487\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0488\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0489\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0490\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0491\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0492\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0493\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0494\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0495\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0496\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0497\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0498\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0499\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0500\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0501\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0502\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0503\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0504\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0505\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0506\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0507\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0508\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0509\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0510\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0511\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0512\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0513\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0514\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0515\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0516\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0517\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0518\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0519\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0520\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0521\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0522\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0523\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0524\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0525\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0526\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0527\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0528\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0529\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0530\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0531\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0532\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0533\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0534\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0535\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0536\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0537\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0538\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0539\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0540\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0541\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0542\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0543\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0544\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0545\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0546\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0547\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0548\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0549\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0550\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0551\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0552\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0553\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0554\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0555\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0556\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0557\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0558\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0559\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0560\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0561\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0562\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0563\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0564\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0565\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0566\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0567\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0568\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0569\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0570\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0571\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0572\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0573\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0574\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0575\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0576\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0577\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0578\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0579\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0580\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0581\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0582\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0583\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0584\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0585\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0586\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0587\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0588\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0589\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0590\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0591\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0592\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0593\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0594\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0595\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0596\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0597\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0598\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0599\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0600\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0601\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0602\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0603\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0604\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0605\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0606\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0607\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0608\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0609\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0610\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0611\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0612\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0613\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0614\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0615\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0616\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0617\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0618\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0619\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0620\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0621\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0622\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0623\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0624\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0625\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0626\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0627\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0628\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0629\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0630\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0631\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0632\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0633\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0634\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0635\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0636\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0637\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0638\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0639\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0640\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0641\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0642\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0643\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0644\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0645\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0646\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0647\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0648\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0649\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0650\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0651\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0652\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0653\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0654\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0655\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0656\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0657\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0658\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0659\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0660\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0661\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0662\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0663\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0664\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0665\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0666\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0667\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0668\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0669\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0670\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0671\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0672\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0673\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0674\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0675\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0676\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0677\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0678\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0679\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0680\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0681\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0682\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0683\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0684\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0685\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0686\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0687\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0688\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0689\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0690\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0691\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0692\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0693\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0694\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0695\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0696\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0697\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0698\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0699\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0701\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0702\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0703\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0704\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0705\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0706\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0707\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0708\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0709\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0710\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0711\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0712\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0713\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0714\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0715\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0716\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0717\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0718\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0719\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0720\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0721\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0722\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0723\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0724\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0725\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0726\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0727\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0728\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0729\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0730\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0731\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0732\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0733\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0734\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0735\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0736\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0737\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0738\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0739\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0740\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0741\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0742\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0743\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0744\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0745\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0746\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0747\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0748\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0749\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0750\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0751\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0752\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0753\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0754\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0755\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0756\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0757\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0758\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0759\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0760\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0761\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0762\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0763\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0764\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0765\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0766\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0767\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0768\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0769\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0770\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0771\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0772\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0773\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0774\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0775\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0776\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0777\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0778\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0779\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0780\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0781\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0782\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0783\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0784\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0785\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0786\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0787\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0788\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0789\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0790\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0791\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0792\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0793\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0794\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0795\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0796\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0797\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0798\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0799\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0800\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0801\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0802\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0803\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0804\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0805\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0806\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0807\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0808\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0809\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0810\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0812\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0813\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0814\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0815\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0816\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0817\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0818\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0819\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0820\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0821\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0822\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0823\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0824\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0825\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0826\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0827\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0828\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0829\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0830\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0831\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0832\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0833\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0834\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0835\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0836\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0837\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0838\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0839\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0840\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0841\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0842\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0843\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0844\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0845\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0846\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0847\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0848\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0849\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0850\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0851\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0852\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0853\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0854\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0855\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0856\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0857\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0858\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0859\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0860\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0861\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0862\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0863\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0864\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0865\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0866\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0867\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0868\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0869\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0870\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0871\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0872\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0873\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0874\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0875\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0876\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0877\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0878\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0879\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0880\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0881\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0882\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0883\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0884\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0887\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0888\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0889\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0890\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0891\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0892\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0893\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0894\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0895\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0896\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0897\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0898\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0899\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0900\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0901\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0902\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0903\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0904\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0905\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0906\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0907\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0908\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0909\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0910\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0911\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0912\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0913\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0914\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0915\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0916\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0917\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0918\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0919\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0920\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0921\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0922\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0923\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0924\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0925\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0926\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0927\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0928\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0929\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0930\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0931\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0932\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0933\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0934\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0935\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0936\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0937\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0938\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0939\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0940\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0941\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0942\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0943\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0944\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0945\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0946\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0947\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0948\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0949\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0950\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0951\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0952\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0953\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0954\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0955\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0956\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0957\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0958\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0959\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0960\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0961\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0962\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0963\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0964\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0965\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0966\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0967\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0968\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0969\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0970\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0971\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0972\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0973\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0974\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0975\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0976\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0977\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0978\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0979\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0980\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0981\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0982\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0983\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0984\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0985\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0986\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0987\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0988\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0989\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0990\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0991\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0992\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0993\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0994\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0995\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0996\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0997\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0998\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\0999\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1000\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1001\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1002\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1003\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1004\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1005\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1006\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1007\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1008\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1009\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1010\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1011\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1012\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1013\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1014\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1015\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1016\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1017\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1018\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1020\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1021\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1022\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1023\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1024\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1025\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1026\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1027\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1028\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1029\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1030\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1031\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1032\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1033\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1034\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1035\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1036\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1037\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1038\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1039\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1040\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1041\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1042\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1043\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1044\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1045\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1046\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1047\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1048\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1049\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1050\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1051\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1052\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1053\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1054\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1055\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1056\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1057\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1058\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1059\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1060\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1061\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1062\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1063\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1064\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1065\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1066\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1067\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1068\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1069\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1070\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1071\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1072\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1073\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1074\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1075\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1076\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1077\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1078\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1079\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1080\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1081\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1082\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1083\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1084\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1085\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1086\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1087\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1088\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1089\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1090\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1091\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1092\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1093\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1094\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1095\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1096\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1097\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1098\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1099\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1100\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1101\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1102\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1103\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1104\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1105\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1106\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1107\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1108\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1109\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1110\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1111\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1112\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1113\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1114\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1115\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1116\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1117\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1118\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1119\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1120\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1121\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1122\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1123\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1124\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1125\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1126\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1127\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1128\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1129\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1130\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1131\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1132\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1133\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1134\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1135\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1136\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1137\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1138\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1139\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1140\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1141\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1142\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1143\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1144\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1145\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1146\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1147\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1148\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1149\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1150\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1151\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1152\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1153\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1154\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1155\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1156\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1157\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1158\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1159\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1160\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1161\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1162\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1163\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1164\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1165\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1166\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1167\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1168\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1169\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1170\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1171\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1172\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1173\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1174\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1175\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1176\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1177\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1178\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1179\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1180\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1181\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1182\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1183\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1184\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1185\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1186\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1187\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1188\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1189\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1190\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1191\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1192\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1193\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1194\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1195\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1196\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1197\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1198\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1199\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1200\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1201\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1202\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1203\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1204\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1205\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1206\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1207\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1208\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1209\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1210\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1211\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1212\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1213\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1214\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1215\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1216\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1217\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1218\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1219\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1220\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1221\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1222\DriverFiles\agrsmdel.exe
c:\windows\system32\ReinstallBackups\1223\DriverFiles\agrsmdel.exe
.
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected
Restored copy from - c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll

.
((((((((((((((((((((((((( Files Created from 2011-01-15 to 2011-02-15 )))))))))))))))))))))))))))))))
.

2011-02-15 02:20 . 2011-02-15 02:20 ——– d—–w- C:\USMT.TMP
2011-02-15 02:14 . 2011-02-15 02:14 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-02-14 23:07 . 2011-02-14 23:07 2746 —-a-w- c:\windows\oburisub.dll
2011-02-14 22:22 . 2011-02-14 22:22 2746 —-a-w- c:\windows\erebelisuzog.dll
2011-02-14 19:41 . 2011-02-14 19:41 2746 —-a-w- c:\windows\elidoruvozerazur.dll
2011-02-14 16:50 . 2011-02-14 16:50 388096 —-a-r- c:\documents and settings\USER\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-14 11:08 . 2011-02-14 11:08 2746 —-a-w- c:\windows\upatefes.dll
2011-02-14 02:40 . 2011-02-14 02:40 711168 —-a-w- c:\windows\is-4KVT6.exe
2011-02-14 00:51 . 2011-02-14 22:19 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-14 00:51 . 2011-02-14 22:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-02-14 00:28 . 2011-02-14 00:28 2746 —-a-w- c:\windows\eqadifemeyu.dll
2011-02-13 20:05 . 2011-02-13 20:05 2746 —-a-w- c:\windows\idodirotaniqeri.dll
2011-02-13 13:42 . 2011-02-13 13:42 2746 —-a-w- c:\windows\ekanaxix.dll
2011-02-12 03:42 . 2011-02-12 03:42 2746 —-a-w- c:\windows\agogihajileso.dll
2011-02-11 22:21 . 2011-02-11 22:21 2746 —-a-w- c:\windows\iqadifemeyudafa.dll
2011-02-11 02:24 . 2011-02-11 02:24 2746 —-a-w- c:\windows\aqetidal.dll
2011-02-10 11:02 . 2011-02-10 11:02 2746 —-a-w- c:\windows\ubulisuzogerut.dll
2011-02-10 02:05 . 2011-02-10 02:05 2746 —-a-w- c:\windows\iyadalumihudusi.dll
2011-02-09 23:58 . 2011-02-09 23:58 2746 —-a-w- c:\windows\efocuqewofehoc.dll
2011-02-09 14:12 . 2011-02-09 14:12 2746 —-a-w- c:\windows\uzejokilomini.dll
2011-02-09 02:03 . 2011-02-09 02:03 2746 —-a-w- c:\windows\ohaniqeribecidu.dll
2011-02-08 01:49 . 2011-02-08 01:49 2746 —-a-w- c:\windows\ivubevami.dll
2011-02-07 15:27 . 2011-02-07 15:27 2746 —-a-w- c:\windows\akuqapejucohotu.dll
2011-02-07 00:17 . 2011-02-07 00:17 2746 —-a-w- c:\windows\ebojodohujeh.dll
2011-02-06 21:01 . 2011-02-06 21:01 2746 —-a-w- c:\windows\ozelugoqoralo.dll
2011-02-06 04:45 . 2011-02-06 04:45 2746 —-a-w- c:\windows\ujovaqeg.dll
2011-02-06 03:06 . 2011-02-06 03:06 2746 —-a-w- c:\windows\ulovowiyel.dll
2011-02-05 20:54 . 2011-02-05 20:54 2746 —-a-w- c:\windows\ixazezocoh.dll
2011-02-05 17:53 . 2011-02-05 17:53 2746 —-a-w- c:\windows\atidumos.dll
2011-02-05 11:59 . 2011-02-05 11:59 2746 —-a-w- c:\windows\isaxuyiru.dll
2011-02-05 01:40 . 2011-02-05 01:40 2746 —-a-w- c:\windows\elagologiw.dll
2011-02-04 19:38 . 2011-02-04 19:38 2746 —-a-w- c:\windows\apaloput.dll
2011-02-04 01:53 . 2011-02-04 01:53 2746 —-a-w- c:\windows\umanodijip.dll
2011-02-03 23:20 . 2011-02-03 23:20 2746 —-a-w- c:\windows\ibulejac.dll
2011-02-02 22:49 . 2011-02-02 22:49 2746 —-a-w- c:\windows\irojihan.dll
2011-02-02 03:25 . 2011-02-02 03:25 2746 —-a-w- c:\windows\ejequkiv.dll
2011-02-01 14:57 . 2011-02-01 14:57 2746 —-a-w- c:\windows\ewiqerofiboqa.dll
2011-02-01 01:46 . 2011-02-01 01:46 2746 —-a-w- c:\windows\ilozobif.dll
2011-01-31 21:43 . 2011-01-31 21:43 2746 —-a-w- c:\windows\uzidepig.dll
2011-01-31 15:40 . 2011-01-31 15:40 2746 —-a-w- c:\windows\ipaganisapam.dll
2011-01-30 22:47 . 2011-01-30 22:47 2746 —-a-w- c:\windows\ecigefim.dll
2011-01-30 05:30 . 2011-01-30 05:30 2746 —-a-w- c:\windows\onegozuxecu.dll
2011-01-29 21:58 . 2011-01-29 21:58 2746 —-a-w- c:\windows\erubosuyeganowet.dll
2011-01-29 15:01 . 2011-01-29 15:01 2746 —-a-w- c:\windows\uyonodijipatax.dll
2011-01-28 17:45 . 2011-01-28 17:45 2746 —-a-w- c:\windows\enodevacuq.dll
2011-01-28 03:43 . 2011-01-28 03:43 2746 —-a-w- c:\windows\uzujovapu.dll
2011-01-27 21:52 . 2011-01-27 21:52 2746 —-a-w- c:\windows\ukaxibugojud.dll
2011-01-27 19:47 . 2011-01-27 19:47 2746 —-a-w- c:\windows\ahuvurij.dll
2011-01-27 01:10 . 2011-01-27 01:10 2746 —-a-w- c:\windows\eloxedakoko.dll
2011-01-26 14:02 . 2011-01-26 14:02 2746 —-a-w- c:\windows\irazozaw.dll
2011-01-26 01:39 . 2011-01-26 01:39 2746 —-a-w- c:\windows\uyofiqem.dll
2011-01-25 21:32 . 2011-01-25 21:32 2746 —-a-w- c:\windows\usidajugaborovom.dll
2011-01-25 13:30 . 2011-01-25 13:30 2746 —-a-w- c:\windows\ikuqusiwoj.dll
2011-01-24 23:53 . 2011-01-24 23:53 2746 —-a-w- c:\windows\uqinigowe.dll
2011-01-24 21:15 . 2011-01-24 21:15 2746 —-a-w- c:\windows\ahikimup.dll
2011-01-24 15:18 . 2011-01-24 15:18 2746 —-a-w- c:\windows\evanubililahacaf.dll
2011-01-23 17:06 . 2011-01-23 17:06 2746 —-a-w- c:\windows\emevekegubix.dll
2011-01-23 05:08 . 2011-01-23 05:08 2746 —-a-w- c:\windows\ojucanuveruq.dll
2011-01-22 22:52 . 2011-01-22 22:52 2746 —-a-w- c:\windows\omedujodivoduke.dll
2011-01-22 16:51 . 2011-01-22 16:51 2746 —-a-w- c:\windows\iqupiqiyonoxuxab.dll
2011-01-22 04:17 . 2011-01-22 04:17 2746 —-a-w- c:\windows\aguyiqop.dll
2011-01-21 13:37 . 2011-01-21 13:37 2746 —-a-w- c:\windows\alegagimo.dll
2011-01-20 22:49 . 2011-02-03 01:54 2746 —-a-w- c:\windows\oyogeteyojomucet.dll
2011-01-20 05:39 . 2011-01-20 05:39 2746 —-a-w- c:\windows\abewejoguxa.dll
2011-01-20 02:48 . 2011-01-20 02:48 2746 —-a-w- c:\windows\ebaxevoyohovoj.dll
2011-01-19 19:22 . 2011-01-19 19:22 2746 —-a-w- c:\windows\iwiwajurija.dll
2011-01-19 04:01 . 2011-01-19 04:01 2746 —-a-w- c:\windows\uxogovagif.dll
2011-01-18 16:22 . 2011-01-18 16:22 2746 —-a-w- c:\windows\obiwubix.dll
2011-01-18 05:02 . 2011-01-18 05:02 2746 —-a-w- c:\windows\efopekamos.dll
2011-01-18 02:03 . 2011-01-18 02:03 2746 —-a-w- c:\windows\uqomehigat.dll
2011-01-17 23:54 . 2011-01-17 23:54 2746 —-a-w- c:\windows\aqocoruwuya.dll
2011-01-17 16:19 . 2011-01-17 16:19 2746 —-a-w- c:\windows\inogekajomowap.dll
2011-01-17 03:30 . 2011-01-17 03:30 2746 —-a-w- c:\windows\uxugivajiy.dll
2011-01-16 23:02 . 2011-01-16 23:02 2746 —-a-w- c:\windows\agovinuyozewahat.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2007-07-06 177152]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 282624]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-06-23 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\USER\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 14:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 14:57 1451520 —-a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
2004-11-12 01:50 212992 —-a-w- c:\progra~1\Nero\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 08:00 132496 —-a-w- c:\program files\Java\jre1.6.0_02\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R3 ip100xp;IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [6/30/2008 3:31 PM 26752]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/23/2009 6:54 PM 38224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.soccernet.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {C5447EEA-9B4F-49DD-821F-4BECE6DCBC54} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\USER\Application Data\Mozilla\Firefox\Profiles\mm7j4emy.default\
FF - prefs.js: browser.startup.homepage - hxxp://soccernet.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-Edukeziwakecof - c:\windows\odenur70.dll
HKCU-Run-zeazem - c:\documents and settings\USER\zeazem.exe
AddRemove-Imation Disk Manager V a Service - c:\docume~1\USER\LOCALS~1\Temp\Imation Disk Manager V a.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-15 17:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3572)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\program files\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\program files\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_eng.nlr
c:\program files\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\msdtc.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\snmp.exe
c:\windows\system32\STacSV.exe
c:\windows\system32\mqsvc.exe
c:\windows\system32\mqtgsvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\WgaTray.exe
c:\windows\sttray.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Completion time: 2011-02-15 17:16:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-15 21:16

Pre-Run: 6,431,678,464 bytes free
Post-Run: 6,390,042,624 bytes free

- - End Of File - - 8FC2C8D91ECFD6AF81A6A5DCB591B1F0


The first time I ran the program, the computer restarted and I got a message regarding a problem with odenur70.dll.

Was also wondering if there was anyway to repair the USB flash drives that have been corrupted?
Hello compaq_hater

Thank you for the log.

Was also wondering if there was anyway to repair the USB flash drives that have been corrupted?

Good question. If you have tried reformatting them without success I am not sure. For the moment, please do not use them at all as you run the risk of spreading the infection (we will try and deal with them later).

You appear to have no real-time antivirus installed and have not yet upgraded to XP SP3. Support for SP2 ran out a few months ago now. Please refrain from connecting to the internet except to download the required tools and to post the logs back here. Once you system is clean we will get an AV on board and get you updated.

Please work your way through the following steps:

  • P2P Programs:


    • P2P programs are a major source of Malware infections.
    • From your log I see you have LimeWire 5.4.8. We do not pass judgment on file-sharing, however we must inform you that engaging in this activity and having this kind of software installed on your system will always make you more susceptible to Malware infections.
    • The use of P2P programs may be contributing to your current situation, and you would certainly be doing yourself a favour by removing them.
    • If you wish to keep the program(s), please do not use them until your computer is cleaned.
    • Information regarding the risk of using these programs can be found from here and here.
    • It is strongly recommend that you uninstall any P2P programs you have on your system.
    • To do this, Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • A list of currently installed programs will be displayed.
    • Find the "LimeWire 5.4.8" program, click on it once and then click on the "Remove" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.


      PLEASE NOTE:
    • Even if you are using a P2P program that is deemed safe, it is only the program that is safe. Any files that you receive using a "safe" P2P program may be infected with Malware. The malware writers use P2P file-sharing as a major conduit to spread infected files.

  • Please make all files and folders Visible:


    • Click "Start" Go to My Computer-> Tools-> Folder Options-> View tab:
    • Choose to "Show hidden files and folders".
    • Uncheck the "Hide protected operating system files" and the "Hide extensions for known file types" boxes.
    • Close the window with "OK".

  • Please scan the following files


    • Please go to VirusTotal


    • On the page you'll find a "Browse" button.
    • Click on the Browse button.
    • In the Choose File to Upload window which opens, copy and paste this into the File Name box.


    c:\windows\is-4KVT6.exe


    • Next, click the Open button.
    • Then click the "Send File" button just below.
    • This will scan the file. Please be patient.
    • If you get a message saying File has already been analyzed: click Reanalyze file now.
    • Once scanned, copy and paste the link to the results page in your next reply.
    • Please repeat this procedure for the following files:


    c:\windows\system32\inetsrv\inetinfo.exe

    Please post the links to the scan results in your next reply.
Hello compaq_hater

Thank you for the scan links.

  • Please work through the following steps


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    File::
    c:\windows\oburisub.dll
    c:\windows\erebelisuzog.dll
    c:\windows\elidoruvozerazur.dll
    c:\windows\upatefes.dll
    c:\windows\eqadifemeyu.dll
    c:\windows\idodirotaniqeri.dll
    c:\windows\ekanaxix.dll
    c:\windows\agogihajileso.dll
    c:\windows\iqadifemeyudafa.dll
    c:\windows\aqetidal.dll
    c:\windows\ubulisuzogerut.dll
    c:\windows\iyadalumihudusi.dll
    c:\windows\efocuqewofehoc.dll
    c:\windows\uzejokilomini.dll
    c:\windows\ohaniqeribecidu.dll
    c:\windows\ivubevami.dll
    c:\windows\akuqapejucohotu.dll
    c:\windows\ebojodohujeh.dll
    c:\windows\ozelugoqoralo.dll
    c:\windows\ujovaqeg.dll
    c:\windows\ulovowiyel.dll
    c:\windows\ixazezocoh.dll
    c:\windows\atidumos.dll
    c:\windows\isaxuyiru.dll
    c:\windows\elagologiw.dll
    c:\windows\apaloput.dll
    c:\windows\umanodijip.dll
    c:\windows\ibulejac.dll
    c:\windows\irojihan.dll
    c:\windows\ejequkiv.dll
    c:\windows\ewiqerofiboqa.dll
    c:\windows\ilozobif.dll
    c:\windows\uzidepig.dll
    c:\windows\ipaganisapam.dll
    c:\windows\ecigefim.dll
    c:\windows\onegozuxecu.dll
    c:\windows\erubosuyeganowet.dll
    c:\windows\uyonodijipatax.dll
    c:\windows\enodevacuq.dll
    c:\windows\uzujovapu.dll
    c:\windows\ukaxibugojud.dll
    c:\windows\ahuvurij.dll
    c:\windows\eloxedakoko.dll
    c:\windows\irazozaw.dll
    c:\windows\uyofiqem.dll
    c:\windows\usidajugaborovom.dll
    c:\windows\ikuqusiwoj.dll
    c:\windows\uqinigowe.dll
    c:\windows\ahikimup.dll
    c:\windows\evanubililahacaf.dll
    c:\windows\emevekegubix.dll
    c:\windows\ojucanuveruq.dll
    c:\windows\omedujodivoduke.dll
    c:\windows\iqupiqiyonoxuxab.dll
    c:\windows\aguyiqop.dll
    c:\windows\alegagimo.dll
    c:\windows\oyogeteyojomucet.dll
    c:\windows\abewejoguxa.dll
    c:\windows\ebaxevoyohovoj.dll
    c:\windows\iwiwajurija.dll
    c:\windows\uxogovagif.dll
    c:\windows\obiwubix.dll
    c:\windows\efopekamos.dll
    c:\windows\uqomehigat.dll
    c:\windows\aqocoruwuya.dll
    c:\windows\inogekajomowap.dll
    c:\windows\uxugivajiy.dll
    c:\windows\agovinuyozewahat.dll

    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Hi

Here is the log:

ComboFix 11-02-15.01 - USER 02/15/2011 20:12:09.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.501.284 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\USER\Desktop\CFScript.txt

FILE ::
"c:\windows\abewejoguxa.dll"
"c:\windows\agogihajileso.dll"
"c:\windows\agovinuyozewahat.dll"
"c:\windows\aguyiqop.dll"
"c:\windows\ahikimup.dll"
"c:\windows\ahuvurij.dll"
"c:\windows\akuqapejucohotu.dll"
"c:\windows\alegagimo.dll"
"c:\windows\apaloput.dll"
"c:\windows\aqetidal.dll"
"c:\windows\aqocoruwuya.dll"
"c:\windows\atidumos.dll"
"c:\windows\ebaxevoyohovoj.dll"
"c:\windows\ebojodohujeh.dll"
"c:\windows\ecigefim.dll"
"c:\windows\efocuqewofehoc.dll"
"c:\windows\efopekamos.dll"
"c:\windows\ejequkiv.dll"
"c:\windows\ekanaxix.dll"
"c:\windows\elagologiw.dll"
"c:\windows\elidoruvozerazur.dll"
"c:\windows\eloxedakoko.dll"
"c:\windows\emevekegubix.dll"
"c:\windows\enodevacuq.dll"
"c:\windows\eqadifemeyu.dll"
"c:\windows\erebelisuzog.dll"
"c:\windows\erubosuyeganowet.dll"
"c:\windows\evanubililahacaf.dll"
"c:\windows\ewiqerofiboqa.dll"
"c:\windows\ibulejac.dll"
"c:\windows\idodirotaniqeri.dll"
"c:\windows\ikuqusiwoj.dll"
"c:\windows\ilozobif.dll"
"c:\windows\inogekajomowap.dll"
"c:\windows\ipaganisapam.dll"
"c:\windows\iqadifemeyudafa.dll"
"c:\windows\iqupiqiyonoxuxab.dll"
"c:\windows\irazozaw.dll"
"c:\windows\irojihan.dll"
"c:\windows\isaxuyiru.dll"
"c:\windows\ivubevami.dll"
"c:\windows\iwiwajurija.dll"
"c:\windows\ixazezocoh.dll"
"c:\windows\iyadalumihudusi.dll"
"c:\windows\obiwubix.dll"
"c:\windows\oburisub.dll"
"c:\windows\ohaniqeribecidu.dll"
"c:\windows\ojucanuveruq.dll"
"c:\windows\omedujodivoduke.dll"
"c:\windows\onegozuxecu.dll"
"c:\windows\oyogeteyojomucet.dll"
"c:\windows\ozelugoqoralo.dll"
"c:\windows\ubulisuzogerut.dll"
"c:\windows\ujovaqeg.dll"
"c:\windows\ukaxibugojud.dll"
"c:\windows\ulovowiyel.dll"
"c:\windows\umanodijip.dll"
"c:\windows\upatefes.dll"
"c:\windows\uqinigowe.dll"
"c:\windows\uqomehigat.dll"
"c:\windows\usidajugaborovom.dll"
"c:\windows\uxogovagif.dll"
"c:\windows\uxugivajiy.dll"
"c:\windows\uyofiqem.dll"
"c:\windows\uyonodijipatax.dll"
"c:\windows\uzejokilomini.dll"
"c:\windows\uzidepig.dll"
"c:\windows\uzujovapu.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\abewejoguxa.dll
c:\windows\agogihajileso.dll
c:\windows\agovinuyozewahat.dll
c:\windows\aguyiqop.dll
c:\windows\ahikimup.dll
c:\windows\ahuvurij.dll
c:\windows\akuqapejucohotu.dll
c:\windows\alegagimo.dll
c:\windows\apaloput.dll
c:\windows\aqetidal.dll
c:\windows\aqocoruwuya.dll
c:\windows\atidumos.dll
c:\windows\ebaxevoyohovoj.dll
c:\windows\ebojodohujeh.dll
c:\windows\ecigefim.dll
c:\windows\efocuqewofehoc.dll
c:\windows\efopekamos.dll
c:\windows\ejequkiv.dll
c:\windows\ekanaxix.dll
c:\windows\elagologiw.dll
c:\windows\elidoruvozerazur.dll
c:\windows\eloxedakoko.dll
c:\windows\emevekegubix.dll
c:\windows\enodevacuq.dll
c:\windows\eqadifemeyu.dll
c:\windows\erebelisuzog.dll
c:\windows\erubosuyeganowet.dll
c:\windows\evanubililahacaf.dll
c:\windows\ewiqerofiboqa.dll
c:\windows\ibulejac.dll
c:\windows\idodirotaniqeri.dll
c:\windows\ikuqusiwoj.dll
c:\windows\ilozobif.dll
c:\windows\inogekajomowap.dll
c:\windows\ipaganisapam.dll
c:\windows\iqadifemeyudafa.dll
c:\windows\iqupiqiyonoxuxab.dll
c:\windows\irazozaw.dll
c:\windows\irojihan.dll
c:\windows\isaxuyiru.dll
c:\windows\ivubevami.dll
c:\windows\iwiwajurija.dll
c:\windows\ixazezocoh.dll
c:\windows\iyadalumihudusi.dll
c:\windows\obiwubix.dll
c:\windows\oburisub.dll
c:\windows\ohaniqeribecidu.dll
c:\windows\ojucanuveruq.dll
c:\windows\omedujodivoduke.dll
c:\windows\onegozuxecu.dll
c:\windows\oyogeteyojomucet.dll
c:\windows\ozelugoqoralo.dll
c:\windows\ubulisuzogerut.dll
c:\windows\ujovaqeg.dll
c:\windows\ukaxibugojud.dll
c:\windows\ulovowiyel.dll
c:\windows\umanodijip.dll
c:\windows\upatefes.dll
c:\windows\uqinigowe.dll
c:\windows\uqomehigat.dll
c:\windows\usidajugaborovom.dll
c:\windows\uxogovagif.dll
c:\windows\uxugivajiy.dll
c:\windows\uyofiqem.dll
c:\windows\uyonodijipatax.dll
c:\windows\uzejokilomini.dll
c:\windows\uzidepig.dll
c:\windows\uzujovapu.dll

.
((((((((((((((((((((((((( Files Created from 2011-01-16 to 2011-02-16 )))))))))))))))))))))))))))))))
.

2011-02-15 02:20 . 2011-02-15 02:20 ——– d—–w- C:\USMT.TMP
2011-02-15 02:14 . 2011-02-15 02:14 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2011-02-14 16:50 . 2011-02-14 16:50 388096 —-a-r- c:\documents and settings\USER\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-14 02:40 . 2011-02-14 02:40 711168 —-a-w- c:\windows\is-4KVT6.exe
2011-02-14 00:51 . 2011-02-14 22:19 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-14 00:51 . 2011-02-14 22:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-11-11 1451520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsmqIntCert"="mqrt.dll" [2007-07-06 177152]
"SigmatelSysTrayApp"="sttray.exe" [2006-05-26 282624]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-06-23 86016]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

c:\documents and settings\USER\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 14:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray]
2009-11-11 14:57 1451520 —-a-w- c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
2004-11-12 01:50 212992 —-a-w- c:\progra~1\Nero\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-07-12 08:00 132496 —-a-w- c:\program files\Java\jre1.6.0_02\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R3 ip100xp;IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [6/30/2008 3:31 PM 26752]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [1/23/2009 6:54 PM 38224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.soccernet.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {C5447EEA-9B4F-49DD-821F-4BECE6DCBC54} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\USER\Application Data\Mozilla\Firefox\Profiles\mm7j4emy.default\
FF - prefs.js: browser.startup.homepage - hxxp://soccernet.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-15 20:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(532)
c:\windows\system32\igfxdev.dll
.
Completion time: 2011-02-15 20:22:19
ComboFix-quarantined-files.txt 2011-02-16 00:22
ComboFix2.txt 2011-02-15 21:16

Pre-Run: 6,454,448,128 bytes free
Post-Run: 6,443,450,368 bytes free

- - End Of File - - 0E2D4CAD37A2A491AE9F480B663BC609
Hello compaq_hater

Thanks for the log. Please work your way through the following steps:

  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please un-install Java™ 6 Update 2


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "Java™ 6 Update 2" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note: You will need to use Internet Explorer for this scan.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM log and the ESET log in your next reply :)
Hi again, Here are the logs you requested. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5769 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 2/15/2011 10:06:27 PM mbam-log-2011-02-15 (22-06-27).txt Scan type: Quick scan Objects scanned: 145888 Time elapsed: 5 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ________________________________________________________________________________ _________________________________________________________________________________ ___ C:\Qoobox\Quarantine\C\WINDOWS\odenur70.dll.vir a variant of Win32/Kryptik.GSL trojan C:\Qoobox\Quarantine\C\WINDOWS\Db5d\services.exe.vir Win32/VB.NQK worm C:\Qoobox\Quarantine\C\WINDOWS\system32\TrulyAmazing.scr.vir Win32/VB.NQK worm C:\Qoobox\Quarantine\Replicators\6BD30C107EEFBBB4457A63110EEE5DE9 Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP189\A0111783.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP189\A0111784.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0112002.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117228.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117229.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117230.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117231.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117232.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117233.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117234.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117235.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117236.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117237.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117238.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117239.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117240.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117241.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117242.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117243.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117244.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117245.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117246.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117247.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117248.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117249.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117250.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117251.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117252.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117253.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117254.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117255.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117256.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117257.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117258.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117259.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117260.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117261.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117262.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117263.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117264.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117265.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117266.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117267.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117268.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117269.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117270.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117271.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117272.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117273.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117274.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117275.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117276.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117277.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117278.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117279.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117280.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117281.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117282.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117283.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117284.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117285.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117286.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117294.exe Win32/VB.NQK worm C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117297.dll a variant of Win32/Kryptik.GSL trojan C:\System Volume Information\_restore{C16F5B8D-93B7-419F-8EEF-F18E25F913F6}\RP191\A0117300.scr Win32/VB.NQK worm
Hello compaq_hater

Thank you for the logs.

The items detected by ESET will be taken care of in the steps below:

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Security programs


    • I cannot see a real-time antivirus installed on your machine.
    • You are strongly advised to install an AV. Using your computer without one is just asking for trouble.
    • I have provided links to three trusted programs (just choose one).




    • For a free Firewall try one of the following:
    • Comodo Personal Firewall
    • NOTE: If you use a Third Party AnitiVirus, make sure you uncheck the option to install Comodo AntiVirus when you install Comodo Firewall.



    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.

    Once you have completed the above steps, update your AV program and perform a system scan.

    Please post a new DDS log in your next reply and let me know how the machine is running now :)
Hi JonTom, here are the logs you requested: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-10-31.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/7/2005 11:24:05 AM System Uptime: 2/16/2011 9:53:52 AM (5 hours ago) Motherboard: Intel Corporation | | D946GZIS Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz Processor: Intel® Pentium® 4 CPU 3.00GHz | | 2997/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 37 GiB total, 6.603 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: Description: Ethernet Controller Device ID: PCI\VEN_8086&DEV;_1094&SUBSYS;_00018086&REV;_01\4&1E46F438&0&40F0 Manufacturer: Name: Ethernet Controller PNP Device ID: PCI\VEN_8086&DEV;_1094&SUBSYS;_00018086&REV;_01\4&1E46F438&0&40F0 Service: Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia 5130c-2 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia 5130c-2 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd ==== System Restore Points =================== No restore point in system. ==== Installed Programs ====================== Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 Apple Application Support Apple Software Update avast! Free Antivirus Broadcom 440x 10/100 Integrated Controller BufferChm CCleaner (remove only) CD/DVD-ROM Generator 1.20 D2400 D2400_Help DeviceDiscovery DeviceManagementQFolder dj_sf_ProductContext dj_sf_software dj_sf_software_req DriverSetup DVD Decrypter (Remove Only) ERUNT 1.1j ESET Online Scanner v3 FLV Player High Definition Audio Driver Package - KB888111 HiJackThis HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) HP Deskjet Printer Driver Software 9.0 HP Imaging Device Functions 9.0 Image Resizer Powertoy for Windows XP Intel® Graphics Media Accelerator Driver IsoBuster 2.2 Java Auto Updater Java™ 6 Update 24 LiveUpdate 1.7 (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Encarta Encyclopedia Standard 2003 Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Outlook Web Access S/MIME Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.7 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox (3.6.13) MSN Toolbar MSVC80_x86_v2 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK Nero PhotoShow Express Nero Suite Nokia Connectivity Cable Driver Nokia PC Suite oggcodecs 0.71.0946 PanoStandAlone PartyPokerNet PC Connectivity Solution Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917537) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926247) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939373) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942830) Security Update for Windows XP (KB942831) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Segoe UI Shockwave SigmaTel Audio SIW version 2010.07.14 SopCast 3.0.3 Status Toolbox TrayApp UnloadSupport Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) Veetle TV 0.9.14 WebFldrs XP WebReg Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.4) Windows Driver Package - Nokia Modem (10/05/2009 4.2) Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0) Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) Windows Internet Explorer 8 Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WinZip ==== Event Viewer Messages From Past Week ======== 2/14/2011 7:09:06 AM, error: NAVAP [20] - 2/14/2011 6:24:46 PM, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period. 2/14/2011 2:35:02 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Dnscache service. 2/14/2011 10:18:55 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service ServiceLayer with arguments "" in order to run the server: {ACF50018-41F8-476D-85FD-CD953DAE4A49} 2/14/2011 10:15:13 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The World Wide Web Publishing service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The Simple Mail Transfer Protocol (SMTP) service depends on the IIS Admin service which failed to start because of the following error: The dependency service or group failed to start. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The Message Queuing Triggers service depends on the Message Queuing service which failed to start because of the following error: The dependency service or group failed to start. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The Message Queuing service depends on the Distributed Transaction Coordinator service which failed to start because of the following error: The dependency service or group failed to start. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 2/14/2011 10:15:13 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 2/14/2011 10:15:09 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 2/14/2011 10:14:36 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 2/14/2011 10:14:33 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 2/13/2011 9:41:23 PM, error: Disk [11] - The driver detected a controller error on \Device\Harddisk0\D. 2/13/2011 9:41:23 PM, error: atapi [5] - A parity error was detected on \Device\Ide\IdePort0. 2/12/2011 12:54:03 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-1 is not functioning. 2/12/2011 12:54:03 PM, error: RemoteAccess [20013] - The communication device attached to port VPN3-0 is not functioning. 2/12/2011 12:54:03 PM, error: RemoteAccess [20013] - The communication device attached to port LPT1 is not functioning. ==== End Of File =========================== DDS (Ver_10-10-31.01) - NTFSx86 Run by [removed] at 14:12:36.26 on Wed 02/16/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.501.63 [GMT -4:00] AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\mqsvc.exe C:\WINDOWS\sttray.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\mqtgsvc.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\WgaTray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\hh.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Documents and Settings\USER\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.soccernet.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll EB: &Discuss;: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [MsmqIntCert] regsvr32 /s mqrt.dll mRun: [SigmatelSysTrayApp] sttray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui StartupFolder: c:\docume~1\user\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\user\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: E&xport; to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {F4430FE8-2638-42e5-B849-800749B94EED} - c:\program files\partygaming.net\partypokernet\RunPF.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab TCP: {C5447EEA-9B4F-49DD-821F-4BECE6DCBC54} = 208.67.222.222,208.67.220.220 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\mm7j4emy.default\ FF - prefs.js: browser.startup.homepage - hxxp://soccernet.com FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\veetle\player\npvlc.dll FF - plugin: c:\program files\veetle\plugins\npVeetle.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-2-16 294608] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-2-16 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2011-2-16 40384] R3 ip100xp;IC Plus IP100 10/100 Fast Ethernet Adapter NT Driver;c:\windows\system32\drivers\ipfnd51.sys [2008-6-30 26752] =============== Created Last 30 ================ 2011-02-16 14:06:16 38848 —-a-w- c:\windows\avastSS.scr 2011-02-16 14:05:53 ——– d—–w- c:\docume~1\alluse~1\applic~1\Alwil Software 2011-02-16 02:15:10 ——– d—–w- c:\program files\ESET 2011-02-15 19:11:21 ——– d-sha-r- C:\cmdcons 2011-02-15 02:20:10 ——– d—–w- C:\USMT.TMP 2011-02-14 16:50:25 388096 —-a-r- c:\docume~1\user\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-14 02:40:13 711168 —-a-w- c:\windows\is-4KVT6.exe 2011-02-14 00:51:59 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-02-14 00:51:59 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy ==================== Find3M ==================== 2011-02-03 01:40:23 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-02 23:19:39 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-01-16 03:51:56 2746 —-a-w- c:\windows\iheradiyub.dll 2011-01-15 22:34:27 2746 —-a-w- c:\windows\initijokilo.dll 2011-01-15 14:49:07 2746 —-a-w- c:\windows\afuhasafoxo.dll 2011-01-15 02:54:51 2746 —-a-w- c:\windows\ohanidopumam.dll 2011-01-15 00:21:33 2746 —-a-w- c:\windows\evajurij.dll 2011-01-14 05:32:27 2746 —-a-w- c:\windows\alerohilonora.dll 2011-01-14 03:04:10 2746 —-a-w- c:\windows\abegologiw.dll 2011-01-13 17:09:05 2746 —-a-w- c:\windows\ogupepac.dll 2011-01-13 02:39:37 2746 —-a-w- c:\windows\ulaxeyuvasa.dll 2011-01-12 20:03:38 2746 —-a-w- c:\windows\evoxijum.dll 2011-01-12 02:29:09 2746 —-a-w- c:\windows\ezahodopuvonej.dll 2011-01-11 17:16:40 2746 —-a-w- c:\windows\adoxayugupiditem.dll 2011-01-10 20:19:05 2746 —-a-w- c:\windows\ocekolak.dll 2011-01-10 03:27:25 2746 —-a-w- c:\windows\emuleqayisa.dll 2011-01-09 22:30:17 2746 —-a-w- c:\windows\ucunagog.dll 2011-01-09 15:12:43 2746 —-a-w- c:\windows\onupucusezejoh.dll 2011-01-09 03:56:17 2746 —-a-w- c:\windows\azaxanim.dll 2011-01-09 02:02:51 2746 —-a-w- c:\windows\efivacas.dll 2011-01-08 19:48:59 2746 —-a-w- c:\windows\okaruvupo.dll 2011-01-08 04:57:24 2746 —-a-w- c:\windows\ufinezuduqiya.dll 2011-01-07 14:21:55 2746 —-a-w- c:\windows\uluwoxut.dll 2011-01-06 17:00:13 2746 —-a-w- c:\windows\oqocubuwo.dll 2011-01-06 03:59:22 2746 —-a-w- c:\windows\inidepig.dll 2011-01-05 22:13:40 2746 —-a-w- c:\windows\ivanewunoz.dll 2011-01-05 19:35:30 2746 —-a-w- c:\windows\ayatobabuyutomo.dll 2011-01-05 16:55:22 2746 —-a-w- c:\windows\azamikagoxu.dll 2011-01-05 00:05:46 2746 —-a-w- c:\windows\itoqafotoce.dll 2011-01-04 18:23:18 2746 —-a-w- c:\windows\awelihoc.dll 2011-01-04 04:30:40 2746 —-a-w- c:\windows\ivonocesofih.dll 2011-01-04 00:40:37 2746 —-a-w- c:\windows\ilutapimo.dll 2011-01-03 04:26:05 2746 —-a-w- c:\windows\avimoyesicogot.dll 2011-01-02 23:37:22 2746 —-a-w- c:\windows\uqejulow.dll 2011-01-02 22:32:43 2746 —-a-w- c:\windows\uhigevusu.dll 2011-01-02 14:21:43 2746 —-a-w- c:\windows\evupeteroqaxacod.dll 2011-01-02 01:59:50 2746 —-a-w- c:\windows\aheqisal.dll 2011-01-01 15:44:30 2746 —-a-w- c:\windows\ojevehulato.dll 2011-01-01 04:23:24 2746 —-a-w- c:\windows\uyokozehu.dll 2010-12-31 03:03:03 2746 —-a-w- c:\windows\afemohagiqinic.dll 2010-12-31 02:15:13 2746 —-a-w- c:\windows\onuviyifani.dll 2010-12-30 18:19:25 2746 —-a-w- c:\windows\ufiyohupofuyipi.dll 2010-12-30 02:59:24 2746 —-a-w- c:\windows\orexavigam.dll 2010-12-28 22:35:18 2746 —-a-w- c:\windows\ububiweyifeg.dll 2010-12-28 17:26:03 2746 —-a-w- c:\windows\iyebupicericoxep.dll 2010-12-27 23:00:18 2746 —-a-w- c:\windows\iqeteroqax.dll 2010-12-27 14:36:56 2746 —-a-w- c:\windows\agebewahazuyos.dll 2010-12-27 03:07:02 2746 —-a-w- c:\windows\uveyamuzageyabe.dll 2010-12-26 22:48:36 2746 —-a-w- c:\windows\ulevabuyudikug.dll 2010-12-26 21:39:07 2746 —-a-w- c:\windows\aterereweril.dll 2010-12-26 06:06:13 2746 —-a-w- c:\windows\ufejuxapivehadaj.dll 2010-12-25 22:57:25 2746 —-a-w- c:\windows\agepiqiyonoxuxab.dll 2010-12-25 00:12:59 2746 —-a-w- c:\windows\asepalirikijir.dll 2010-12-24 04:13:25 2746 —-a-w- c:\windows\evuleyocozof.dll 2010-12-23 23:36:57 2746 —-a-w- c:\windows\uzaxanimifixejo.dll 2010-12-22 16:16:53 2746 —-a-w- c:\windows\uzidehibe.dll 2010-12-22 01:20:39 2746 —-a-w- c:\windows\ezisuras.dll 2010-12-21 13:34:28 2746 —-a-w- c:\windows\oqeguxaboko.dll 2010-12-21 02:23:13 2746 —-a-w- c:\windows\aguxojux.dll 2010-12-20 14:50:25 2746 —-a-w- c:\windows\ejoguheyekit.dll 2010-12-20 02:40:24 2746 —-a-w- c:\windows\uwabupov.dll 2010-12-19 04:36:12 2746 —-a-w- c:\windows\enafapit.dll 2010-12-18 20:57:24 2746 —-a-w- c:\windows\evuxaxeda.dll 2010-12-18 13:17:26 2746 —-a-w- c:\windows\ebelirikijiraz.dll 2010-12-17 02:14:46 2746 —-a-w- c:\windows\udovowiyelukig.dll 2010-12-16 20:55:13 2746 —-a-w- c:\windows\onobetog.dll 2010-12-16 12:25:00 2746 —-a-w- c:\windows\uheradiy.dll 2010-12-16 10:09:34 2746 —-a-w- c:\windows\iveyaxukow.dll 2010-12-16 02:24:31 2746 —-a-w- c:\windows\inaxozuvovepur.dll 2010-12-15 23:31:17 2746 —-a-w- c:\windows\adaxoyenevud.dll 2010-12-15 19:25:10 2746 —-a-w- c:\windows\ecerefub.dll 2010-12-15 17:08:17 2746 —-a-w- c:\windows\uwavateb.dll 2010-12-15 14:20:30 2746 —-a-w- c:\windows\abolupuf.dll 2010-12-15 03:35:30 2746 —-a-w- c:\windows\aquxorig.dll 2010-12-14 21:36:34 2746 —-a-w- c:\windows\odoxesab.dll 2010-12-14 18:28:26 2746 —-a-w- c:\windows\atefonut.dll 2010-12-14 15:20:37 2746 —-a-w- c:\windows\ujazezoc.dll 2010-12-14 03:25:26 2746 —-a-w- c:\windows\uqisuxom.dll 2010-12-13 02:09:46 2746 —-a-w- c:\windows\opuvupilidar.dll 2010-12-12 23:02:22 2746 —-a-w- c:\windows\ojatucigenoguq.dll 2010-12-12 20:29:15 2746 —-a-w- c:\windows\ehowamikuxiyay.dll 2010-12-12 16:53:03 2746 —-a-w- c:\windows\ipuhakucadic.dll 2010-12-12 14:18:03 2746 —-a-w- c:\windows\okexoxiw.dll 2010-12-12 03:56:14 2746 —-a-w- c:\windows\aqoneniq.dll 2010-12-11 21:07:18 2746 —-a-w- c:\windows\ilapijaferoc.dll 2010-12-11 18:09:16 2746 —-a-w- c:\windows\amodinigowe.dll 2010-12-11 15:44:42 2746 —-a-w- c:\windows\ajasiquy.dll 2010-12-11 15:00:28 2746 —-a-w- c:\windows\apuqepijo.dll 2010-12-11 04:07:35 2746 —-a-w- c:\windows\enuxecab.dll 2010-12-10 21:34:07 2746 —-a-w- c:\windows\anovaqegayuxoxot.dll 2010-12-10 20:32:11 2746 —-a-w- c:\windows\ipufivufepov.dll 2010-12-10 16:29:48 2746 —-a-w- c:\windows\ohowofehocozis.dll 2010-12-10 14:02:23 2746 —-a-w- c:\windows\egumopajeboyorad.dll 2010-12-10 04:32:38 2746 —-a-w- c:\windows\imoxuqot.dll 2010-12-10 01:28:29 2746 —-a-w- c:\windows\icozuvif.dll 2010-12-09 22:02:19 2746 —-a-w- c:\windows\egacukexugu.dll 2010-12-09 18:33:40 2746 —-a-w- c:\windows\etodelubem.dll 2010-12-09 16:15:23 2746 —-a-w- c:\windows\ayahegucobojeb.dll 2010-12-09 06:28:48 2746 —-a-w- c:\windows\onadahig.dll 2010-12-08 22:14:58 2746 —-a-w- c:\windows\azidehibewava.dll ============= FINISH: 14:15:09.56 =============== The machine is running pretty well again. :) I'm guessing we're almost done?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI