This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

High CPU usage, Ping.exe, browsers redirect, [Closed]

109 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Jeff,
I want to let you know that I wont have access to the infected computer until Thursday evening. I hope you could keep this thread open while I'm gone. Thx

Here is the combofix file that you requested:
ComboFix 11-12-12.02 - Deano-Casino 12/13/2011 9:40.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.330 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\G4E7R0u.com_"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-13 to 2011-12-13 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-09 22:28 . 2011-12-09 22:30 79872 —-a-w- c:\windows\system32\G4E7R0u.com_
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 07:47 . 2011-11-18 07:48 ——– d—–w- c:\documents and settings\All Users\Application Data\3B35B
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
2011-11-16 15:39 . 2011-11-16 15:39 ——– d—–w- c:\documents and settings\All Users\Application Data\F3A9
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 00:00 . 2011-12-13 00:00 1557928 —-a-w- C:\tdsskiller1.zip
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\All Users\Application Data\3B35B —-
.
2011-11-18 07:48 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\3B35B\{B031773F-6F0E-4BB2-8C0E-D1D8DEB3851B}.swf
.
—- Directory of c:\documents and settings\All Users\Application Data\F3A9 —-
.
2011-11-16 15:39 . 2010-12-14 15:02 3957 —-a-w- c:\documents and settings\All Users\Application Data\F3A9\{F62FF99B-E3A0-4F9D-A0C8-604391F13C25}.swf
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-12_18.09.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-13 16:20 . 2011-12-13 16:20 16384 c:\windows\Temp\Perflib_Perfdata_444.dat
+ 2011-01-07 22:39 . 2011-01-07 22:39 51024 c:\windows\system32\vcomp100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80208 c:\windows\system32\mfcm100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43344 c:\windows\system32\mfc100kor.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43856 c:\windows\system32\mfc100jpn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 63824 c:\windows\system32\mfc100esn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 55120 c:\windows\system32\mfc100enu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100deu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100cht.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100chs.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100chs.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 768848 c:\windows\system32\msvcr100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 421200 c:\windows\system32\msvcp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 137544 c:\windows\system32\atl100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4342600 c:\windows\system32\mfc100.dll
+ 2011-12-13 16:30 . 2011-12-13 16:30 2186240 c:\windows\Installer\aa899.msi
+ 2011-01-08 03:10 . 2011-01-08 03:10 3991040 c:\windows\Installer\33ccf61.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-10-25 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-09 c:\windows\Tasks\At10.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At12.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At14.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-10 c:\windows\Tasks\At16.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At18.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At2.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At20.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At22.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At24.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At26.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At28.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At30.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At32.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-12 c:\windows\Tasks\At34.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At36.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At38.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At4.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At40.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At42.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At44.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At46.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\At48.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At6.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-09 c:\windows\Tasks\At8.job
- c:\windows\system32\G4E7R0u.com_ [2011-12-09 22:30]
.
2011-12-13 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-13 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-13 09:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(1080)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-13 10:04:38
ComboFix-quarantined-files.txt 2011-12-13 17:04
ComboFix2.txt 2011-12-12 18:15
ComboFix3.txt 2011-12-07 03:34
ComboFix4.txt 2011-12-05 02:19
ComboFix5.txt 2011-12-13 16:33
.
Pre-Run: 34,073,661,440 bytes free
Post-Run: 34,060,410,880 bytes free
.
- - End Of File - - 93B8F0F9C53E6852CC6FE3AFF7D6CAC3
Hi Wicked Kitt_E,

Thanks for letting me know. I will be sure to keep this open. :)
———-

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    AtJob::
    
    File::
    c:\windows\system32\G4E7R0u.com_
    
    Folder::
    c:\documents and settings\All Users\Application Data\3B35B
    c:\documents and settings\All Users\Application Data\F3A9
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff,

Thanks for keeping the thread open.

Here is the results of the combofix:

ComboFix 11-12-16.01 - Deano-Casino 12/16/2011 10:09:23.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.549 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
FILE ::
"c:\windows\system32\G4E7R0u.com_"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\3B35B
c:\documents and settings\All Users\Application Data\3B35B\{B031773F-6F0E-4BB2-8C0E-D1D8DEB3851B}.swf
c:\documents and settings\All Users\Application Data\F3A9
c:\documents and settings\All Users\Application Data\F3A9\{F62FF99B-E3A0-4F9D-A0C8-604391F13C25}.swf
.
.
((((((((((((((((((((((((( Files Created from 2011-11-16 to 2011-12-16 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
2011-11-18 06:52 . 2011-11-18 06:52 ——– d—–w- C:\LB Photo Realism x256 6.9.2
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 00:00 . 2011-12-13 00:00 1557928 —-a-w- C:\tdsskiller1.zip
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-12_18.09.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-16 15:50 . 2011-12-16 15:50 16384 c:\windows\Temp\Perflib_Perfdata_61c.dat
- 2010-03-18 16:15 . 2010-03-18 16:15 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80720 c:\windows\system32\mfcm100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 60752 c:\windows\system32\mfc100rus.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43344 c:\windows\system32\mfc100kor.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43856 c:\windows\system32\mfc100jpn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 62288 c:\windows\system32\mfc100ita.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100fra.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 63824 c:\windows\system32\mfc100esn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 55120 c:\windows\system32\mfc100enu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100cht.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100chs.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100chs.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 768848 c:\windows\system32\msvcr100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 421200 c:\windows\system32\msvcp100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 421200 c:\windows\system32\msvcp100.dll
+ 2011-07-11 08:14 . 2011-07-11 08:14 295248 c:\windows\system32\drivers\avgtdix.sys
+ 2011-01-07 22:39 . 2011-01-07 22:39 137544 c:\windows\system32\atl100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4342600 c:\windows\system32\mfc100.dll
+ 2011-12-14 22:52 . 2011-12-14 22:52 4683264 c:\windows\Installer\e38a8.msi
+ 2011-12-13 16:30 . 2011-12-13 16:30 2186240 c:\windows\Installer\aa899.msi
+ 2011-01-08 03:10 . 2011-01-08 03:10 3991040 c:\windows\Installer\33ccf61.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-16 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-16 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-13 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-16 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-16 10:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
Completion time: 2011-12-16 10:32:52
ComboFix-quarantined-files.txt 2011-12-16 17:32
ComboFix2.txt 2011-12-13 17:04
ComboFix3.txt 2011-12-12 18:15
ComboFix4.txt 2011-12-07 03:34
ComboFix5.txt 2011-12-16 17:03
.
Pre-Run: 33,523,433,472 bytes free
Post-Run: 33,785,970,688 bytes free
.
- - End Of File - - 59145770F4BC8D899860C75183F928E9
Hi Jeff, here are the results of Malwarebytes and ESET online scan: Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8381 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 12/16/2011 1:21:53 PM mbam-log-2011-12-16 (13-21-53).txt Scan type: Quick scan Objects scanned: 297847 Time elapsed: 21 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\deano-casino\my documents\downloads\setupplaysushi(1).exe (PUP.PlaySushi) -> Quarantined and deleted successfully. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 # version=7 # firefox.exe=1.9.1.5 # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=fdd6117eec3c704cb230fa81aa69f6ff # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-11-22 06:45:33 # local_time=2009-11-22 11:45:33 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 3441714 3441714 0 0 # compatibility_mode=1024 16777175 100 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=256247 # found=0 # cleaned=0 # scan_time=11118 ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fdd6117eec3c704cb230fa81aa69f6ff # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-06 01:15:41 # local_time=2011-12-05 06:15:41 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 67641306 67641306 0 0 # compatibility_mode=1032 16777193 100 95 2450738 65317753 0 0 # compatibility_mode=8192 67108863 100 0 63309358 63309358 0 0 # scanned=391903 # found=426 # cleaned=0 # scan_time=30132 C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971 a variant of Win32/Kryptik.VZH trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Desktop\pcrepairclinic.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\122.tmp Win32/Olmarik.AWO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\124.tmp Win32/Olmarik.AWO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\14C.tmp probably a variant of Win32/Kryptik.WAW trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\14D.tmp probably a variant of Win32/Kryptik.WAW trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe probably a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe Win32/InstallCore application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml Win32/DownloadAdmin.A.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe a variant of Win32/Kryptik.VZH trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c Java/TrojanDownloader.OpenStream.NCA trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe a variant of Win32/Adware.HotBar.H application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe a variant of Win32/Adware.HotBar.H application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe a variant of Win32/Adware.HotBar.H application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe Win32/Adware.ErrorRepair application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe a variant of Win32/Adware.Gamevance.AT application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa a variant of Win32/Kryptik.WFA trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f a variant of Win32/Kryptik.WDH trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573 Win32/Spy.SpyEye.CA trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72 a variant of Win32/Kryptik.WEI trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3 a variant of Java/Agent.DM trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\zugo.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png Win32/TrojanDownloader.Tracur.I trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg Win32/BHO.NZK trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg Win32/TrojanDownloader.Tracur.I trojan (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabVideoConverter\Uninstall\Uninstall.exe Win32/InstallCore application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\PlaySushi\psuninst.exe a variant of Win32/Adware.Gamevance.BE application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\HookDllOE.dll probably a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\WhiteSmokeRegistration.exe a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\WSEnrichment.exe probably a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\html\english\dictClientDic\index.html HTML/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\html\english\dictClientDic\translator.html HTML/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\B2E9.tmp.vir probably a variant of Win32/Kryptik.WAW trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\KeyboardBackupManager.dll.vir Win32/TrojanDownloader.Tracur.I trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\ExplorerWin32.dll.vir a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll.vir a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe.vir probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSA.exe.vir probably a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAAX.dll.vir a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAHook.dll.vir a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteUninstaller.exe.vir a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch.F application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IEOVR.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3TPINST.DLL.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3UNPAT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\00276091.exe.vir a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToOLbar32.dll.vir a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\0.15040859031063447.exe.vir a variant of Win32/Kryptik.WDX trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\0.6344036376832972.exe.vir a variant of Win32/Kryptik.WDX trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\0.9150836843586603.exe.vir a variant of Win32/Kryptik.WDH trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\0.949885126871846.exe.vir Win32/Spy.SpyEye.CA trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507561.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507569.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513743.exe a variant of Win32/Adware.OpenInstall application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513750.exe a variant of Win32/Adware.Gamevance.BE application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513751.exe Win32/DownloadAdmin.A.Gen application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513752.exe probably a variant of Win32/Adware.LRYETGT application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513754.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518769.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518770.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518771.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518772.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518773.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518774.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518775.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520752.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520753.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520754.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520755.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520756.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520757.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520758.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521736.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524743.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525748.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525749.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525750.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525751.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525752.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525753.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525754.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526743.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527735.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527736.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530795.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530796.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530797.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530798.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530799.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530800.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530801.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530818.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530819.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530820.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530821.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530822.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530823.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530824.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532770.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532771.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532772.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532773.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532774.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532775.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532789.dll a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532791.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533763.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533790.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533791.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533792.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533793.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533794.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533795.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0534763.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535763.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535782.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535783.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535784.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535785.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535786.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535787.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535828.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535843.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535844.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535845.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535846.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535847.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535848.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535849.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0536828.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537828.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537841.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537842.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537843.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537844.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537845.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537846.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0538828.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539828.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539845.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539865.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539866.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539867.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539868.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539869.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539870.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540845.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540857.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540858.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540859.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540860.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540861.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540862.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540896.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540935.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540936.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540937.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540938.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540939.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540940.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540941.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0541896.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0541914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0542914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0543914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0544914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545959.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545960.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545961.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545962.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545963.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545964.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545965.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546914.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546940.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546953.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546954.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546955.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546956.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546957.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546958.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546959.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0547940.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0548940.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549940.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549967.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0549985.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0550985.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0551985.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0552001.exe probably a variant of Win32/Kryptik.WAW trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0552985.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553024.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553062.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553063.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553064.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553065.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553066.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553067.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553068.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553076.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554076.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554086.exe a variant of Win32/Kryptik.WDW trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554087.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554088.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554089.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554090.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554091.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554092.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554093.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555076.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555118.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555119.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555120.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555121.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555122.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555123.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556076.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556106.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556107.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556108.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556109.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556110.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556111.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556150.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556205.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556219.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556220.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556221.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556222.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556223.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556224.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556225.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0557205.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0557218.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0558218.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0559218.sys a variant of Win32/Rootkit.Kryptik.FF trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562259.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562260.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562261.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562262.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562263.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562264.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562265.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562502.exe a variant of Win32/Kryptik.VZH trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562542.lnk LNK/URL.B trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562626.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562627.exe Win32/InstallCore application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562629.exe Win32/InstallCore application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562635.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562636.dll Win32/TrojanDownloader.Tracur.I trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562638.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562642.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562646.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562661.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562668.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562669.dll a variant of Win32/Kryptik.UXS trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562676.exe probably a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562677.dll a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562680.dll a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562681.exe a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562682.dll probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562692.dll probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562694.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562695.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562696.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562697.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562698.DLL Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562699.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562700.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562701.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562702.SCR Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562703.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562704.DLL Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562705.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562706.EXE Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562707.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562709.DLL Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562710.DLL Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562713.DLL Win32/Toolbar.MyWebSearch.F application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562714.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562715.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562716.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562718.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562719.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562721.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562722.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562723.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562724.EXE Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562725.EXE Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562726.DLL Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562727.DLL a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562728.DLL Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562729.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562730.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562731.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562732.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562733.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562734.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562735.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562736.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562737.exe a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562746.dll Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562750.dll a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562751.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562754.exe a variant of Win32/Kryptik.WDX trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562755.exe a variant of Win32/Kryptik.WDX trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562756.exe a variant of Win32/Kryptik.WDH trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562757.exe Win32/Spy.SpyEye.CA trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562760.scr Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562902.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562910.dll a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562912.exe probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=fdd6117eec3c704cb230fa81aa69f6ff # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-17 04:06:32 # local_time=2011-12-16 09:06:32 (-0700, US Mountain Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 68605217 68605217 0 0 # compatibility_mode=1024 16777191 100 0 4504581 4504581 0 0 # compatibility_mode=8192 67108863 100 0 64273269 64273269 0 0 # scanned=399998 # found=355 # cleaned=0 # scan_time=26885 C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Desktop\pcrepairclinic.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe probably a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe a variant of Win32/InstallCore.E application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml Win32/DownloadAdmin.A.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c Java/TrojanDownloader.OpenStream.NCA trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe Win32/Adware.ErrorRepair application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\68e32803-209d3400 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\33\3002e1-16a76483 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\7\133e75c7-203bc6b7 multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\45\45a86cad-501d0a03 a variant of Java/Exploit.CVE-2011-3544.C trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3 a variant of Java/Agent.DM trojan (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe probably a variant of Win32/Adware.ERSKVQT application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\zugo.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe multiple threats (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe a variant of Win32/InstallCore.D application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabVideoConverter\VideoConverter.exe a variant of Win32/InstallCore.A application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\FoxTabVideoConverter\Uninstall\Uninstall.exe a variant of Win32/InstallCore.E application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\PlaySushi\psuninst.exe a variant of Win32/Adware.Gamevance.BE application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\HookDllOE.dll probably a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\WhiteSmokeRegistration.exe a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\WSEnrichment.exe probably a variant of Win32/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\html\english\dictClientDic\index.html HTML/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\WhiteSmoke\html\english\dictClientDic\translator.html HTML/WhiteSmoke application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Program Files\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\gn7nuhve.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DA00D550-BB91-4A26-AAE5-9172D626CAAE}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Tarma Installer\{DE3B7BF9-0770-4104-BC0B-B1CCCCE2F053}\_Setupx.dll.vir a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\sj03k314.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest.vir Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Documents and Settings\The Crew\Application Data\Mozilla\Firefox\Profiles\f40a6q8j.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar.vir JS/Agent.NDO trojan (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarApp.dll.vir a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarEng.dll.vir Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarsrv.exe.vir probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\BabylonToolbarTlbr.dll.vir Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\BabylonToolbar\BabylonToolbar\1.4.35.10\bh\BabylonToolbar.dll.vir Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSA.exe.vir probably a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAAX.dll.vir a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteSAHook.dll.vir a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\ClickPotatoLiteUninstaller.exe.vir a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\ClickPotatoLite\bin\10.0.728.0\firefox\extensions\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\plugins\npclntax_ClickPotatoLiteSA.dll.vir probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch.F application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IEOVR.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3TPINST.DLL.vir Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3UNPAT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSMLBTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSUABTN.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\Cache\00276091.exe.vir a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\Search Toolbar\SearchToolbar.dll.vir Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToOLbar32.dll.vir a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507561.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP287\A0507569.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513743.exe a variant of Win32/Adware.OpenInstall application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513750.exe a variant of Win32/Adware.Gamevance.BE application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513751.exe Win32/DownloadAdmin.A.Gen application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513752.exe probably a variant of Win32/Adware.LRYETGT application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0513754.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518769.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518770.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518771.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518772.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518773.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518774.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0518775.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520752.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520753.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520754.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520755.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520756.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520757.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0520758.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521736.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0521742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0524743.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525748.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525749.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525750.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525751.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525752.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525753.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0525754.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526742.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0526743.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527735.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527736.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527737.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527738.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527739.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527740.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0527741.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530795.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530796.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530797.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530798.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530799.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530800.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP290\A0530801.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530818.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530819.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530820.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530821.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530822.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530823.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP291\A0530824.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532770.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532771.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532772.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532773.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532774.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532775.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532789.dll a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0532791.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533790.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533791.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533792.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533793.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533794.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0533795.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535782.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535783.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535784.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535785.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535786.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535787.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535843.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535844.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535845.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535846.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535847.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535848.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0535849.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537841.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537842.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537843.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537844.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537845.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0537846.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539865.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539866.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539867.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539868.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539869.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0539870.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540857.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540858.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540859.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540860.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540861.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540862.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540935.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540936.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540937.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540938.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540939.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540940.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0540941.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545959.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545960.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545961.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545962.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545963.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545964.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0545965.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546953.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546954.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546955.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546956.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546957.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546958.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0546959.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553062.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553063.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553064.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553065.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553066.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553067.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0553068.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554087.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554088.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554089.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554090.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554091.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554092.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0554093.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555118.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555119.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555120.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555121.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555122.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP294\A0555123.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556106.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556107.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556108.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556109.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556110.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556111.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556219.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556220.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556221.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556222.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556223.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556224.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0556225.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562259.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562260.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562261.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562262.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562263.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562264.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP296\A0562265.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562542.lnk LNK/URL.B trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562626.exe a variant of Win32/SoftonicDownloader.A application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562627.exe a variant of Win32/InstallCore.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562629.exe a variant of Win32/InstallCore.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562635.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562638.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562642.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562646.dll a variant of Win32/Adware.Yontoo.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562661.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562668.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562676.exe probably a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562677.dll a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562680.dll a variant of Win32/Adware.180Solutions application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562681.exe a variant of Win32/Adware.HotBar.E application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562682.dll probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562692.dll probably a variant of Win32/Adware.HotBar.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562694.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562695.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562696.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562697.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562698.DLL Win32/Toolbar.MyWebSearch.B application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562699.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562700.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562701.DLL Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562702.SCR Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562703.DLL Win32/Toolbar.MyWebSearch.G application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562704.DLL Win32/Toolbar.MyWebSearch.D application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562705.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562706.EXE Win32/Adware.FunWeb application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562707.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562709.DLL Win32/Toolbar.MyWebSearch.H application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562710.DLL Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562713.DLL Win32/Toolbar.MyWebSearch.F application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562714.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562715.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562716.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562718.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562719.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562721.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562722.DLL Win32/Toolbar.MyWebSearch.P application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562723.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562724.EXE Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562725.EXE Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562726.DLL Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562727.DLL a variant of Win32/Toolbar.MyWebSearch.I application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562728.DLL Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562729.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562730.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562731.DLL Win32/Toolbar.MyWebSearch.J application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562732.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562733.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562734.EXE Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562735.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562736.DLL Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562737.exe a variant of Win32/Toolbar.MyWebSearch.K application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562746.dll Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562750.dll a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562751.exe a variant of Win32/Toolbar.Zugo application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562760.scr Win32/Toolbar.MyWebSearch application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562902.manifest Win32/TrojanDownloader.Tracur.F trojan (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562910.dll a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562911.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562912.exe probably a variant of Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562913.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I C:\System Volume Information\_restore{97D5533D-9886-4376-9D9F-104DD3439735}\RP297\A0562914.dll Win32/Toolbar.Babylon application (unable to clean) 00000000000000000000000000000000 I
Hi Wicked Kitt_E,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    File::
    C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest 
    C:\Documents and Settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar 
    C:\Documents and Settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971	
    C:\Documents and Settings\DEADA275\Desktop\pcrepairclinic.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\122.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\124.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\14C.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\14D.tmp	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml	
    C:\Documents and Settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe	a 
    C:\Documents and Settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe	
    C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9	
    C:\Documents and Settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe	
    C:\Documents and Settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe	
    C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest 
    C:\Documents and Settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573	
    C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72	
    C:\Documents and Settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe	
    C:\Documents and Settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe	
    C:\Documents and Settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe	
    C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt	
    C:\Documents and Settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini	
    C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest 
    C:\Documents and Settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar	
    C:\Documents and Settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3	
    C:\Documents and Settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\zugo.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg	
    C:\Documents and Settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg	
    C:\Program Files\FoxTabFLVPlayer\FLVPlayer.exe	
    C:\Program Files\FoxTabFLVPlayer\Uninstall\Uninstall.exe	
    C:\Program Files\FoxTabVideoConverter\VideoConverter.exe	
    C:\Program Files\FoxTabVideoConverter\Uninstall\Uninstall.exe	
    C:\Program Files\PlaySushi\psuninst.exe	
    C:\Program Files\Uniblue\SpeedUpMyPC\Launcher.exe	
    C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe	
    C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe	
    C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe	
    C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe	
    C:\Program Files\WhiteSmoke\HookDllOE.dll	
    C:\Program Files\WhiteSmoke\WhiteSmokeRegistration.exe	
    C:\Program Files\WhiteSmoke\WSEnrichment.exe	
    C:\Program Files\WhiteSmoke\html\english\dictClientDic\index.html	
    C:\Program Files\WhiteSmoke\html\english\dictClientDic\translator.html	
    C:\Program Files\Windows Live\Messenger\msimg32.dll	
    C:\Program Files\Windows Live\Messenger\riched20.dll
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Hi Jeff,

Here is the combofix log:

ComboFix 11-12-18.01 - Deano-Casino 12/18/2011 14:39:27.8.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.560 [GMT -7:00]
Running from: C:\ComboFix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\documents and settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\DEADA275\Application Data\Mozilla\Firefox\Profiles\l56b8n5z.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\DEADA275\Application Data\Sun\Java\Deployment\cache\6.0\1\4f8c7441-5be7e971"
"c:\documents and settings\DEADA275\Desktop\pcrepairclinic.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\122.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\124.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\14C.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\14D.tmp"
"c:\documents and settings\DEADA275\Local Settings\Temp\F0516A30-BAB0-7891-A724-A8C64FCEF821\MyBabylonTB.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\ICReinstall\Facemoods.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\ICReinstall\VideoConverterSetup.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\is-ILLAJ.tmp\getinstalls-silentinstaller.exe"
"c:\documents and settings\DEADA275\Local Settings\Temp\nsi81.tmp\__localxml.xml"
"c:\documents and settings\DEADA275\Local Settings\Temp\nsi81.tmp\2\tr-tightrope-sntb.exe a"
"c:\documents and settings\DEADA275\Local Settings\Temp\YontooSetup-Silent.exe"
"c:\documents and settings\DEADA275\Local Settings\Temporary Internet Files\Content.IE5\GGUYR5LI\file[1].exe"
"c:\documents and settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\0\6add3540-183377f9"
"c:\documents and settings\Deano-Casino\Application Data\Sun\Java\Deployment\cache\6.0\27\578d041b-504b640c"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(2).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller(3).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\ClickPotatoInstaller.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\FixCleanerSetup.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\MyFunCards(1).exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\MyFunCards.exe"
"c:\documents and settings\Deano-Casino\My Documents\Downloads\SetupPlaySushi(1).exe"
"c:\documents and settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\MommyDearest\Application Data\Mozilla\Firefox\Profiles\d0mk2i09.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\16\773490-73c0e6aa"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\18\7624352-152f6a7f"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\39\2e1c1fe7-35707573"
"c:\documents and settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\114fc934-2a0f1d72"
"c:\documents and settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\enemies-names.txt"
"c:\documents and settings\The Crew.DEAM\Application Data\A5D0C6F9CF9CA6969D3E693DC87C3BAF\local.ini"
"c:\documents and settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome.manifest"
"c:\documents and settings\The Crew.DEAM\Application Data\Mozilla\Firefox\Profiles\lynhlbe0.default\extensions\{2182a29e-d489-49c7-ad81-213e27bcb6ab}\chrome\xulcache.jar"
"c:\documents and settings\The Crew.DEAM\Application Data\Sun\Java\Deployment\cache\6.0\6\2eff00c6-751446b3"
"c:\documents and settings\The Crew.DEAM\Desktop\WhiteSmokeInstaller_9386.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Application Data\Google\GoogleUpdate\Googleup.dll"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_HC2Setup_exe.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\ICReinstall\cnet_SetupImgBurn_2_5_5_0_exe.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\is271270771\WhiteSmokeTrial.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf1.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf2.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf3.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nsc29.tmp\tzdworf4.png"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\001.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\002.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\nssCF.tmp\003.jgg"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\thpm4588730036398929620.tmp"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\thpm512581307115453428.tmp"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\YontooSetup-Silent.exe"
"c:\documents and settings\The Crew.DEAM\Local Settings\Temp\zugo.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\FlvPlayerSetup.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\Softonic-Downloader33501.exe"
"c:\documents and settings\The Crew\My Documents\Downloads\SoftonicDownloader_for_sevenvg-rc-windows-7-theme.exe"
"c:\program files\FoxTabFLVPlayer\FLVPlayer.exe"
"c:\program files\FoxTabFLVPlayer\Uninstall\Uninstall.exe"
"c:\program files\FoxTabVideoConverter\Uninstall\Uninstall.exe"
"c:\program files\FoxTabVideoConverter\VideoConverter.exe"
"c:\program files\PlaySushi\psuninst.exe"
"c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe"
"c:\program files\Uniblue\SpeedUpMyPC\sp_move_serial.exe"
"c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe"
"c:\program files\Uniblue\SpeedUpMyPC\spnotifier.exe"
"c:\program files\Uniblue\SpeedUpMyPC\sump.exe"
"c:\program files\WhiteSmoke\HookDllOE.dll"
"c:\program files\WhiteSmoke\html\english\dictClientDic\index.html"
"c:\program files\WhiteSmoke\html\english\dictClientDic\translator.html"
"c:\program files\WhiteSmoke\WhiteSmokeRegistration.exe"
"c:\program files\WhiteSmoke\WSEnrichment.exe"
"c:\program files\Windows Live\Messenger\msimg32.dll"
"c:\program files\Windows Live\Messenger\riched20.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Deano-Casino\Application Data\Toolbar4
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-12 05:42 . 2011-12-12 05:44 ——– d—–w- c:\documents and settings\Administrator\.minecraft
2011-12-07 06:12 . 2011-12-07 06:12 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59 . 2011-12-07 06:18 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2011-12-07 04:15 . 2011-12-07 04:15 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\The Crew\Application Data\AVG2012
2011-12-07 04:12 . 2011-12-07 04:12 ——– d—–w- c:\documents and settings\Deano-Casino\Application Data\AVG2012
2011-12-01 20:45 . 2011-12-01 20:45 ——– d—–w- C:\tdsskiller
2011-11-23 17:57 . 2011-11-23 17:58 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-11-22 12:19 . 2011-11-22 12:19 ——– d—–w- C:\found.000
2011-11-19 23:45 . 2011-11-19 23:45 ——– d—–w- c:\program files\inKline Global
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\Yontoo Layers
2011-11-19 23:40 . 2011-11-20 00:01 ——– d—–w- c:\program files\FoxTabVideoConverter
2011-11-19 22:15 . 2011-11-19 22:15 ——– d—–w- c:\program files\Emerge Desktop
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 00:00 . 2011-12-13 00:00 1557928 —-a-w- C:\tdsskiller1.zip
2011-12-01 12:48 . 2008-04-14 12:00 52480 —-a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-01 04:44 . 2011-12-01 20:45 1547774 —-a-w- C:\tdsskiller.zip
2011-10-25 08:07 . 2011-10-08 02:26 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-10 14:22 . 2009-10-07 00:45 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 13:23 . 2010-12-08 11:12 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 13:21 . 2010-08-03 22:23 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2008-04-14 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2008-04-14 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2008-04-14 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-23 22:02 . 2011-05-19 20:14 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 17:05 . 2011-03-29 21:07 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot_2011-12-12_18.09.02 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-18 18:52 . 2011-12-18 18:52 16384 c:\windows\Temp\Perflib_Perfdata_624.dat
- 2010-03-18 16:15 . 2010-03-18 16:15 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 51024 c:\windows\system32\vcomp100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80720 c:\windows\system32\mfcm100u.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80720 c:\windows\system32\mfcm100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 80208 c:\windows\system32\mfcm100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 60752 c:\windows\system32\mfc100rus.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 60752 c:\windows\system32\mfc100rus.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43344 c:\windows\system32\mfc100kor.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43344 c:\windows\system32\mfc100kor.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 43856 c:\windows\system32\mfc100jpn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 43856 c:\windows\system32\mfc100jpn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 62288 c:\windows\system32\mfc100ita.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 62288 c:\windows\system32\mfc100ita.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100fra.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100fra.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 63824 c:\windows\system32\mfc100esn.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 63824 c:\windows\system32\mfc100esn.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 55120 c:\windows\system32\mfc100enu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 55120 c:\windows\system32\mfc100enu.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 64336 c:\windows\system32\mfc100deu.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100cht.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100cht.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 36176 c:\windows\system32\mfc100chs.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 36176 c:\windows\system32\mfc100chs.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 768848 c:\windows\system32\msvcr100.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 421200 c:\windows\system32\msvcp100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 421200 c:\windows\system32\msvcp100.dll
+ 2011-07-11 08:14 . 2011-07-11 08:14 295248 c:\windows\system32\drivers\avgtdix.sys
+ 2011-01-07 22:39 . 2011-01-07 22:39 137544 c:\windows\system32\atl100.dll
- 2010-03-18 16:15 . 2010-03-18 16:15 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4368720 c:\windows\system32\mfc100u.dll
+ 2011-01-07 22:39 . 2011-01-07 22:39 4342600 c:\windows\system32\mfc100.dll
+ 2011-12-14 22:52 . 2011-12-14 22:52 4683264 c:\windows\Installer\e38a8.msi
+ 2011-12-13 16:30 . 2011-12-13 16:30 2186240 c:\windows\Installer\aa899.msi
+ 2011-01-08 03:10 . 2011-01-08 03:10 3991040 c:\windows\Installer\33ccf61.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd}]
2009-11-07 08:07 297808 —-a-w- c:\windows\system32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2011-12-07 04:15 1451336 —-a-w- c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2011-03-23 15:12 931696 —-a-w- c:\program files\kikin\ie_kikin.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2011-07-22 23:53 787744 —-a-w- c:\program files\Yontoo Layers\YontooIEClient.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\8.0.0.40\AVG Secure Search_toolbar.dll" [2011-12-07 1451336]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2011-06-08 822456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"P17Helper"="P17.dll" [2005-05-04 64512]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-04-08 13891176]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2011-12-07 218464]
.
c:\documents and settings\The Crew\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
Styler.lnk - c:\documents and settings\The Crew\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe [2011-6-16 15086]
.
c:\documents and settings\Deano-Casino\Start Menu\Programs\Startup\AutorunsDisabled
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\AutorunsDisabled
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [N/A]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [N/A]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Fliptoast.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Fliptoast.lnk
backup=c:\windows\pss\Fliptoast.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Philips GoGear VIBE Device Manager.lnk]
backup=c:\windows\pss\Philips GoGear VIBE Device Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Desktop]
2011-04-12 07:14 4613624 —-a-w- c:\program files\4shared Desktop\desktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4shared Update]
2011-04-12 07:14 608760 —-a-w- c:\program files\4shared Desktop\checkUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvIcon]
2008-04-13 12:39 49152 —-a-w- c:\program files\Vista Drive Icon\DrvIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
2008-04-14 12:00 44032 —-a-w- c:\windows\ime\imkr6_1\imekrmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iMesh]
2011-06-01 19:19 21880240 —-a-w- c:\program files\iMesh Applications\iMesh\iMesh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 —-a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
2011-10-08 21:31 366024 —-a-w- c:\program files\IncrediMail\Bin\IncMail.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-07-30 17:41 2363392 —-a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2011-02-24 09:57 1753192 —-a-w- c:\program files\NVIDIA Corporation\nView\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ocs_SM]
2011-09-13 04:59 106496 —-a-w- c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 —-a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-02-17 17:14 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedUpMyPC]
2011-05-24 00:27 67960 —-a-w- c:\program files\Uniblue\SpeedUpMyPC\Launcher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
2010-04-29 16:38 1652736 —-a-r- c:\program files\AWS\WeatherBug\Weather.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SeaPort"=2 (0x2)
"RichVideo"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"SearchAnonymizer"=2 (0x2)
"sdCoreService"=3 (0x3)
"sdAuxService"=3 (0x3)
"NMIndexingService"=3 (0x3)
"LightScribeService"=2 (0x2)
"Bonjour Service"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Electronic Arts\\Dead Space\\Dead Space.exe"=
"c:\\Program Files\\Boxee\\BOXEE.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 Beta 5\\firefox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\Mozilla Firefox 3.6 RC 1\\firefox.exe"=
"c:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"=
"c:\\Program Files\\Lighthouse Interactive\\T34vsTiger\\TvsT.exe"=
"c:\\Program Files\\Ubisoft\\IL-2 Sturmovik Forgotten Battles\\il2.exe"=
"c:\\Program Files\\Lead Pursuit\\Battlefield Operations\\FalconAF.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\TroubleShooter.exe"=
"c:\\Program Files\\AdventureQuest Worlds Toolbar\\ToolbarUpdate.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\brink\\brink.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\ava\\REACTOR.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Program Files\\Steam\\steamapps\\azcrew\\half-life\\hl.exe"=
"c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"c:\\Steam\\steamapps\\common\\call of duty black ops\\BlackOpsMP.exe"=
"c:\\Steam\\steamapps\\azcrew\\half-life source\\hl2.exe"=
"c:\\Program Files\\iBryte\\playbryte\\ibrytedesktop.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"c:\\Documents and Settings\\The Crew.DEAM\\Local Settings\\Temp\\incredimail_install.exe"=
"c:\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\Bohemia Interactive\\ArmA 2\\arma2.exe"=
"c:\\Program Files\\Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Steam\\steamapps\\azcrew\\garrysmod\\hl2.exe"=
"c:\\Steam\\steamapps\\common\\killingfloor\\System\\KillingFloor.exe"=
"c:\\Steam\\steamapps\\common\\fallout new vegas\\FalloutNVLauncher.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 3:48 AM 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/20/2009 9:23 AM 28552]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/12/2009 9:05 AM 206256]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 4:12 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [4/27/2011 10:33 PM 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe [12/6/2011 9:15 PM 246624]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [8/3/2010 3:23 PM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [8/3/2010 3:23 PM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [8/3/2010 3:23 PM 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [12/11/2009 9:37 AM 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [10/7/2009 9:39 AM 457312]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/11/2009 11:30 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [12/8/2009 3:29 PM 47360]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [5/1/2007 4:11 PM 132232]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2/3/2009 7:41 AM 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2/3/2009 7:41 AM 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [10/8/2009 12:39 PM 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys –> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?]
S4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/12/2009 9:05 AM 348824]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\DEADA275\Application Data\OCS\SM\SearchAnonymizerHelper.exe [9/12/2011 9:59 PM 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\AutorunsDisabled\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-07-30 17:39 451872 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-18 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2011-04-02 00:24]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-11 18:29]
.
2011-09-26 c:\windows\Tasks\Norton Security Scan for Deano-Casino.job
- c:\progra~1\NORTON~2\Engine\351~1.6\Nss.exe [2011-07-16 11:19]
.
2011-12-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-12-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1659004503-1177238915-1008.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47]
.
2011-09-26 c:\windows\Tasks\SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC\spmonitor.exe [2011-08-18 00:27]
.
2011-12-18 c:\windows\Tasks\User_Feed_Synchronization-{D81FAA29-1225-43D0-9C2B-A4B5A9C8A97D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bigseekpro.com/pivotstickfigure/{5D7E9955-3C04-4B2E-BE43-C161637CC061}
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\documents and settings\Deano-Casino\Application Data\Mozilla\Firefox\Profiles\5rlgdvec.default\
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7Bd8b798bc-6ae6-4a18-90fc-15f2bf54a416%7D&mid=27ee163b2f4cb34ac3e1da2365327ceb-06ce4fc639803a2e3563922518183d8e94088cb9&ds=AVG&v=8.0.0.40&lang=en&pr=fr&d=2011-12-06%2021%3A15%3A09&sap=ku&q=
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-18 15:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1060284298-1659004503-1177238915-1003\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"datasecu"=hex:31,e4,75,d6,9b,a1,3f,18,f1,28,20,5c,9e,f8,f2,f7,43,3a,5e,af,c0,
98,ad,90,f4,d9,c1,fd,4d,93,dc,2d,41,a7,a0,33,b3,7d,0e,42,26,9e,e5,12,e7,4a,\
"rkeysecu"=hex:b2,95,bd,3c,85,4b,48,d5,56,4b,32,96,d0,df,b0,b6
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3448)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-18 15:05:48
ComboFix-quarantined-files.txt 2011-12-18 22:05
ComboFix2.txt 2011-12-16 17:32
ComboFix3.txt 2011-12-13 17:04
ComboFix4.txt 2011-12-12 18:15
ComboFix5.txt 2011-12-18 21:33
.
Pre-Run: 33,411,014,656 bytes free
Post-Run: 33,592,217,600 bytes free
.
- - End Of File - - 3FB716B7580579B73BBC7488B0F8C5A4
Hi Jeff, The system is running slow at times. The system would lock up while surfing with firefox. There is a window that pops up about closing firefox high memory usage. Also get a blue screen, Watchdog,sys (0x8E). I had to reboot 4 times today because the system locked up while surfing. But so far since I ran that combofix I had to reboot once. The only main complaint this evening is that firefox high mem usage. I will change out the AVG like you suggest. I will use tomorrow to make the AVG change and see how it runs.
Hi Jeff, :( Well things are not looking to good. It seemed to be working fine o.k. on one profile yesterday but then I switched to another profile this morning and I'm getting the bing redirect, no shortcuts work(rundll32.exe error, and 'open with') Also I cant get the virus scan to work/run, click on the the actual icon for the virus scan and a link(c:\programfiles\avg……) would pop up in firefox and a window pops up asking to save the file. boo-hoo
Hi Jeff,

Heres the DDS files:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 10:26:54.67 on Wed 12/21/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_30
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.545 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\AVG\AVG2012\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
C:\Program Files\AVG\AVG2012\avgnsx.exe
C:\Program Files\AVG\AVG2012\avgemcx.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\The Crew.DEAM\My Documents\Downloads\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://home.sweetim.com/?st=1&barid={AD1F486C-ED81-11E0-BA01-001EE5EA8467}
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: AutorunsDisabled - No File
BHO: IEPlugin Class: {11222041-111b-46e3-bd29-efb2449479b1} - c:\progra~1\arcsoft\mediac~1\intern~1\ARCURL~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll
BHO: PlayBryte BHO: {61e0ef7a-9bc0-45ea-9b2f-f3e9f02692bd} - mscoree.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.22\AVG Secure Search_toolbar.dll
BHO: DCA BHO: {b49699fc-1665-4414-a1cb-c4a2a4a13eec} - c:\program files\common files\freecause\dca\dca-bho.dll
BHO: WeCareReminder Class: {d824f0de-3d60-4f57-9eb1-66033ecd8abb} - c:\documents and settings\all users\application data\wecarereminder\IEHelperv2.5.0.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: kikin Plugin: {e601996f-e400-41ca-804b-cd6373a7eee2} - c:\program files\kikin\ie_kikin.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SMTTB2009 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\hypercam toolbar\tbcore3.dll
BHO: Yontoo Layers: {fd72061e-9fde-484d-a58a-0bab4151cad8} - c:\program files\yontoo layers\YontooIEClient.dll
TB: StylerToolBar: {d2f8f919-690b-4ea2-9fa7-a203d1e04f75} - c:\program files\styler\tb\StylerTB.dll
TB: QT TabBar: {d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - mscoree.dll
TB: QT Tab Standard Buttons: {d2bf470e-ed1c-487f-a666-2bd8835eb6ce} - mscoree.dll
TB: AVG Security Toolbar: {95b7759c-8c7f-4bf1-b163-73684a933233} - c:\program files\avg secure search\9.0.0.22\AVG Secure Search_toolbar.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {3385E2D6-567B-4FC6-8F0F-D7A8C6E6118C} - No File
TB: {338B4DFE-2E2C-4338-9E41-E176D497299E} - No File
TB: {90EEE664-34B1-422A-A782-779AF65CDF6D} - No File
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
TB: {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No File
TB: {9565115D-C7D6-46D3-BD63-B67B481A4368} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [KeyboardBackupManager] rundll32.exe "c:\documents and settings\all users\application data\KeyboardBackupManager.dll",DllRegisterServer
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [vProt] "c:\program files\avg secure search\vprot.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoru~1\hpphot~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
IE: &Download All using 4shared Desktop - c:\program files\4shared desktop\down_all.htm
IE: &Download using 4shared Desktop - c:\program files\4shared desktop\down_link.htm
IE: &Search - http://edits.mywebsearch.com/toolbaredits/…mp;n=2011050817
IE: Search the Web - c:\program files\sweetim\toolbars\internet explorer\resources\menuext.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
LSP: mswsock.dll
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://utilities.pcpitstop.com/Nirvana/controls/PCPitStop.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.0.cab
DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} - hxxps://www.microsoft.com/resources/virtuallabs/ActiveX/VMRCActiveXClient1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
DPF: {62789780-B744-11D0-986B-00609731A21D} - hxxp://gis.pima.gov/mapguide/viewer/ver65/mgaxctrl.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259477377359
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} -
DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15101/CTSUEng.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1259477481812
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll
DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://ccfiles.creative.com/Web/softwareupdate/su/ocx/15109/CTPID.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstop2.dll
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\9.0.1\ViProtocol.dll
Notify: AutorunsDisabled - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\thecre~1.dea\applic~1\mozilla\firefox\profiles\lynhlbe0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2418376&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - PageRage Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=Z160&install_date=20110918
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZUxdm593YYUS&ptb=yFNr5NpMFZ7vV0qkXYavEQ&ind=2011050817&ptnrS=ZUxdm593YYUS&si=&n=77de3341&psa=&st=kwd&searchfor=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\5.0.61118.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\np_gp.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeploytk.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nppdf32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin4.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin5.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin6.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npqtplugin7.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
—- FIREFOX POLICIES —-
FF - user.js: extentions.y2layers.installId - c93232af-db61-4f01-82c2-a32792b08e1f
FF - user.js: extentions.y2layers.defaultEnableAppsList - PageRage,PageRageGlobal,Buzzdock,BuzzdockTease,PageRage,PageRageGlobal,
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 32592]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-11-20 28552]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 230608]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 40016]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-9-15 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 74480]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-14 54752]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-4-27 2218600]
R2 vToolbarUpdater;vToolbarUpdater;c:\program files\common files\avg secure search\vtoolbarupdater\9.0.1\ToolbarUpdater.exe [2011-12-18 869216]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 16720]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [2009-12-11 28160]
R3 N3AB;N3AB Wireless Network Adapter Service;c:\windows\system32\drivers\N3AB.sys [2009-10-7 457312]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2010-2-18 551680]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-10-11 133104]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-10-11 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?]
S3 SaiH075C;SaiH075C;c:\windows\system32\drivers\SaiH075C.sys [2007-5-1 132232]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 7408]
S3 silabenm;RIGblaster Plug & Play Serial Port Enumerator Driver;c:\windows\system32\drivers\silabenm.sys [2009-2-3 17920]
S3 silabser;RIGblaster Plug & Play Driver;c:\windows\system32\drivers\silabser.sys [2009-2-3 60544]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-10-8 94992]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\vboxnetflt.sys –> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
S4 cpuz132;cpuz132; [x]
S4 SearchAnonymizer;SearchAnonymizer;c:\documents and settings\deada275\application data\ocs\sm\SearchAnonymizerHelper.exe [2011-9-12 40960]
.
=============== File Associations ===============
.
.exe=Ipt
.
=============== Created Last 30 ================
.
2011-12-21 16:07:29 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll
2011-12-21 16:07:29 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll
2011-12-21 16:07:29 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll
2011-12-21 16:07:29 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll
2011-12-20 20:16:45 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-12-19 00:39:20 ——– d—–w- c:\windows\system32\cache
2011-12-19 00:39:18 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG Secure Search
2011-12-15 19:02:48 ——– d—–w- c:\docume~1\thecre~1.dea\applic~1\AVG Secure Search
2011-12-13 00:00:42 ——– d—–w- C:\tdsskiller1
2011-12-12 16:35:33 4343835 ——r- C:\ComboFix.exe
2011-12-07 06:12:26 ——– d—–w- C:\76eb605531d17f49d13974016cf124
2011-12-07 05:59:13 ——– d—–w- c:\windows\SxsCaPendDel
2011-12-07 04:15:14 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2011-12-07 04:15:05 ——– d—–w- c:\program files\common files\AVG Secure Search
2011-12-07 04:15:03 ——– d—–w- c:\program files\AVG Secure Search
2011-12-07 04:12:38 ——– d—–w- c:\docume~1\thecre~1.dea\applic~1\AVG2012
2011-12-01 21:40:04 208896 —-a-w- c:\windows\MBR.exe
2011-12-01 20:45:35 ——– d—–w- C:\tdsskiller
2011-11-22 12:19:10 ——– d—–w- C:\found.000
.
==================== Find3M ====================
.
2011-12-20 20:11:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25:32 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-10 10:27:10 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-11-04 19:20:51 916992 —-a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 —-a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-25 08:07:23 0 —-a-w- c:\windows\system32\ConduitEngine.tmp
2011-10-18 11:13:22 186880 —-a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 10:28:17.25 ===============

Attachments:

Hi Wicked Kitt_E,

Same as the other. Seems that ZeroAccess is on here as well. :(
————

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-
Hi Jeff, I tried to run the GMER and a blue screen appeared, "Driver_IRQL_NOT_Less_or_Equal Atapi.sys (0xD1). I tried again and got the same blue screen. I rebooted the system and it hung on the XP Splash screen for a while and everything is loading really slow. Should I try GMER again?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI