This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Malware Bytes periodically sends me a message that says it blocked acc

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few days ago I did a malware bytes scan which resulted in an overflow of trojans being detected in my users-appdata-temp folder and now I am periodically getting an update in my icon tray that says that malware bytes has blocked access to a potentially malicious website: 219.152.26.163. Type:outgoing, Port 47705, and process uttorent.exe.

When I ran OTL only OTL.txt popped up after the scan but extras.txt didn't pop up.

Here is the OTL.txt log:

OTL logfile created on: 9/22/2013 8:00:37 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul.Paul-PC\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 51.87% Memory free
5.92 Gb Paging File | 4.35 Gb Available in Paging File | 73.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 120.70 Gb Free Space | 55.32% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Paul.Paul-PC\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe (Spigot, Inc.)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\libcef.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll ()
MOD - C:\Program Files\Common Files\Adobe\CEPServiceManager4\zlib1.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\Apache2.4.4\bin\httpd.exe (Apache Software Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Paul\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130922.002\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130922.002\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\Windows\System32\drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (O2MDGRDR) – C:\Windows\System32\drivers\o2mdg.sys (O2Micro )
DRV - (O2SDGRDR) – C:\Windows\System32\drivers\o2sdg.sys (O2Micro )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{3A434D2D-EFE9-4239-836B-6EFFC9FE9581}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{5033EE8D-A640-41CA-9012-7AFD6DF2C83F}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2786678

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=714647&fr;=spigot-yhp-ie
IE - HKCU\..\SearchScopes,DefaultScope = {19CE7FE4-BED6-4C79-9A4D-37D8D1AA91E9}
IE - HKCU\..\SearchScopes\{19CE7FE4-BED6-4C79-9A4D-37D8D1AA91E9}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc;=12&type;=714647"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130917
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:[removed]
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=714647&p;="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom14.xpi [2012/03/20 20:52:52 | 000,102,505 | —- | M] ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/19 08:28:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/19 08:28:04 | 000,000,000 | —D | M]

[2013/05/02 19:14:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2013/09/22 18:16:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions
[2013/09/18 19:32:47 | 000,000,000 | —D | M] (WOT) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/09/22 18:16:30 | 000,534,729 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/07/30 20:39:55 | 000,824,302 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/08/06 19:18:55 | 000,000,915 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\searchplugins\yahoo.xml
[2013/09/19 08:28:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/19 08:28:10 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll

O1 HOSTS File: ([2013/09/07 22:16:12 | 000,000,054 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SearchProtection] C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE (Spigot, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Users\Paul.Paul-PC\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B82892F4-0671-4942-BCB8-BCB5812C3AE4}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2013/09/21 20:24:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:22:49 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\AppData\Roaming\Malwarebytes
[2013/09/19 08:28:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 22:20:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WampServer
[2013/09/07 22:15:27 | 000,000,000 | —D | C] – C:\wamp
[2013/09/07 21:41:52 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Desktop\php-5.5.3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/22 19:29:22 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/22 19:29:22 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/22 19:22:12 | 000,000,372 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2013/09/22 19:20:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/22 19:20:18 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2013/09/22 18:18:05 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/21 20:55:45 | 000,726,092 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/21 20:24:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:23:18 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/19 21:18:06 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/09/19 21:18:06 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/17 01:01:56 | 000,108,254 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/09/15 12:57:33 | 003,868,360 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/09/13 21:49:22 | 000,001,456 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/09/05 14:56:33 | 000,066,389 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.pdf
[2013/09/05 14:56:17 | 000,073,594 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.rtf
[2013/08/30 19:36:21 | 000,140,137 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png
[2013/08/29 14:27:10 | 000,001,919 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\New Text Document.html
[2013/08/24 21:59:48 | 023,003,252 | —- | M] () – C:\Users\Paul.Paul-PC\Documents\vlc-2.0.8-win32.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/21 20:55:45 | 000,726,092 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/17 01:01:52 | 000,108,254 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/08/30 19:36:20 | 000,140,137 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png
[2013/08/24 21:59:36 | 023,003,252 | —- | C] () – C:\Users\Paul.Paul-PC\Documents\vlc-2.0.8-win32.exe
[2013/08/19 03:47:33 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe PNG Format CC Prefs
[2013/08/14 23:49:58 | 000,000,054 | —- | C] () – C:\Users\Paul.Paul-PC\.gitconfig
[2013/07/06 19:22:16 | 000,001,456 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/07/06 18:55:57 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe BMP Format CC Prefs

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll\system32\wbem\wbemess.dll
"ThreadingModel" = Apartment

========== LOP Check ==========

[2013/08/19 04:23:11 | 000,000,000 | —D | M] – C:\Users\Paul.Paul-PC\AppData\Roaming\FileZilla
[2013/08/15 02:10:19 | 000,000,000 | —D | M] – C:\Users\Paul.Paul-PC\AppData\Roaming\GitHub
[2013/07/04 20:55:10 | 000,000,000 | —D | M] – C:\Users\Paul.Paul-PC\AppData\Roaming\PDAppFlex
[2013/08/06 18:56:43 | 000,000,000 | —D | M] – C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection
[2013/09/22 19:54:35 | 000,000,000 | —D | M] – C:\Users\Paul.Paul-PC\AppData\Roaming\uTorrent

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\PolicyDefinitions\en-US\Explorer.adml
[2009/07/13 22:07:10 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\x86_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_22d6d5b5cba907ce\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\PolicyDefinitions\Explorer.admx
[2009/06/10 17:34:46 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\x86_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_1590ffd752297581\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_525b5180f3f95373\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_51a3a583dafd0cef\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\erdnt\cache\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_05c8dd40d4f56065\explorer.exe.mui

< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/09/22 19:57:23 | 000,075,672 | —- | M] () MD5=4B434D69D2B7544FF0F56145A342C33B – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf

< MD5 for: EXPLORER.ZIP >
[2006/03/07 00:48:08 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_b12560b1c817cfde\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20795_none_b3c5cc459f4108f2\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\erdnt\cache\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_b1148f09c82553c5\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_b19f2c1ee1420ce6\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_b119907bc820d278\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_b346f9b4861b55c2\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_b12660fbc816e935\iexplore.exe
[2011/12/16 04:03:08 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=38668C6CADABC9487C683FADD3D165D0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16930_none_b378134285f73a44\iexplore.exe
[2011/08/20 00:35:15 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=41FE5E37EFE0B587A688BA0E4FA41288 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16869_none_b360a432860774ff\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16700_none_b3987f3a85deec23\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16671_none_b34dce2a8616cbea\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_b1a52ddae13ca4f0\iexplore.exe
[2011/04/22 15:29:16 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=64EFAF916C4009F1B84153D0BB491FB0 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16800_none_b398812085dee94a\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20831_none_b402ac8b9f13f917\iexplore.exe
[2011/06/21 01:25:30 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=6BB506124872ACDFAC5BD912CA1334CE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20992_none_b3c2cf339f43b73b\iexplore.exe
[2011/11/05 00:38:00 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=8ED7C19AEFA3673AADB0D6864B03FBCE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16912_none_b38fb3ae85e53510\iexplore.exe
[2012/03/21 02:16:35 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20861_none_b3e23cc79f2c4cea\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_b1276145c816028c\iexplore.exe
[2011/06/21 01:37:00 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=A3AB0A260049BE22AB52E302D9220A92 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16839_none_b38113f685ef212c\iexplore.exe
[2011/11/05 00:39:45 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=A8A14CD0CB499B80412F75D53996AE29 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21085_none_b3d0781f9f391a91\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16722_none_b384dff685ed56b3\iexplore.exe
[2011/02/24 01:45:11 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=AB2BB40A5FE49AD236791AC22BD08869 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20908_none_b42a203b9ef553cc\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_b1a12cb2e1403f94\iexplore.exe
[2011/12/16 05:19:51 | 000,673,048 | —- | M] (Microsoft Corporation) MD5=C53E41F92B19EC97D987F968403BEC49 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21108_none_b429fa439ef58435\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_b5780d7c8309d95c\iexplore.exe
[2011/02/24 01:32:52 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C6697A46554E36541E81182B258A19D6 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16766_none_b35da16e860a2bd3\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_b1955c7ce149422e\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_b1a22cfce13f58eb\iexplore.exe
[2011/04/22 15:11:29 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=F94877A94996B3C12BB31AD722840457 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.20949_none_b3ffe0d59f14dce7\iexplore.exe
[2011/08/20 00:32:44 | 000,673,024 | —- | M] (Microsoft Corporation) MD5=FA623BE79902A7B49FF4F21117B63C83 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.21033_none_b40487279f125c2e\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/03/21 02:16:36 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/03/21 02:16:36 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_aae2948effb95a30\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_acf38f2bbdc896a9\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_af24a2f3bab71a43\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\System32\drivers\etc\services
[2009/06/10 17:39:37 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\services

< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/09/05 10:04:00 | 000,559,090 | —- | M] () MD5=8ADD48E413D05BF2E7AEC00173DDFABC – C:\Program Files\Adobe\Reader 11.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\erdnt\cache\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\System32\en-US\services.exe.mui
[2009/07/13 22:03:06 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=0DA5F221169DEB5AC3A22465CD6F0281 – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_69d39d3a8748c332\services.exe.mui

< MD5 for: SERVICES.H >
[2013/06/23 15:44:20 | 000,001,124 | —- | M] () MD5=3E3742C81D3173F4469F85050E4C5AAD – C:\wamp\bin\mysql\mysql5.6.12\include\mysql\services.h

< MD5 for: SERVICES.LNK >
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:41:45 | 000,001,288 | —- | M] () MD5=021B1B178776500E54560EDCFFE0EE21 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2009/06/10 17:26:14 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.mof

< MD5 for: SERVICES.MSC >
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\System32\wdi\perftrack\Services.ptxml
[2009/07/13 16:20:01 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\PolicyDefinitions\en-US\WinLogon.adml
[2009/07/13 22:05:00 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_94da67ab3e358f3a\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\PolicyDefinitions\WinLogon.admx
[2009/06/10 17:43:18 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\x86_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_7ae3b2e5da95d117\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\erdnt\cache\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\System32\en-US\winlogon.exe.mui
[2010/11/20 08:12:53 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=65C2C2EE8F334EE07F66876551DE1827 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_ccfffb7662588b45\winlogon.exe.mui
[2009/07/13 22:05:28 | 000,022,528 | —- | M] (Microsoft Corporation) MD5=DB61D28A59DEE68F77811B291D83AD1B – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_cacee7ae656a07ab\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-DEDDC9B6.PF >
[2013/09/20 17:05:40 | 000,037,670 | —- | M] () MD5=6FAD04798581194B037941FE106CEFDF – C:\Windows\Prefetch\WINLOGON.EXE-DEDDC9B6.pf

< MD5 for: WINLOGON.MFL >
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\System32\wbem\en-US\winlogon.mfl
[2009/07/13 22:09:40 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_2891397980a26140\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\System32\wbem\winlogon.mof
[2009/07/13 16:37:34 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_800f1ff3d73b72d9\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2009/06/10 17:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/06/10 17:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2009/11/29 22:55:23 | 000,002,569 | RH– | M] () – C:\dell.sdr
[2012/02/11 18:12:56 | 000,067,646 | —- | M] () – C:\google_chrome.ico
[2012/02/11 18:20:10 | 000,067,646 | —- | M] () – C:\happy_jack_o_lantern.ico
[2013/09/22 19:20:18 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2010/08/02 23:12:02 | 000,000,696 | -H– | M] () – C:\IPH.PH
[2013/09/22 19:20:30 | 3180,285,952 | -HS- | M] () – C:\pagefile.sys
[2012/06/22 23:52:53 | 000,000,000 | —- | M] () – C:\t17k.2
[2012/12/21 00:05:57 | 000,000,000 | —- | M] () – C:\t1ak.2
[2011/06/20 20:55:32 | 000,000,000 | —- | M] () – C:\t1b8.2
[2012/10/04 20:23:17 | 000,000,000 | —- | M] () – C:\t1bk.2
[2012/11/20 21:43:16 | 000,000,000 | —- | M] () – C:\t1c8.2
[2013/07/18 00:15:24 | 000,000,000 | —- | M] () – C:\t1cc.2
[2013/03/06 21:47:58 | 000,000,000 | —- | M] () – C:\t1ck.2
[2013/07/15 20:55:43 | 000,000,000 | —- | M] () – C:\t1ds.2
[2012/10/02 20:52:14 | 000,000,000 | —- | M] () – C:\t1fc.1
[2012/10/02 20:52:15 | 000,000,000 | —- | M] () – C:\t1fc.2

< %systemroot%\Fonts\*.com >
[2009/07/14 00:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 17:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/13 21:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 08:21:36 | 000,030,208 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 00:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is OS
Volume Serial Number is BA18-6D3D
Directory of C:\
07/14/2009 12:53 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:53 AM All Users [C:\ProgramData]
07/14/2009 12:53 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:53 AM Application Data [C:\ProgramData]
07/14/2009 12:53 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:53 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:53 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:53 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:53 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:53 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:53 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:53 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:53 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:53 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:53 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:53 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:53 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:53 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:53 AM My Music [C:\Users\Default\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Edward
12/16/2009 12:20 AM Application Data [C:\Users\Edward\AppData\Roaming]
12/16/2009 12:20 AM Cookies [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Cookies]
12/16/2009 12:20 AM Local Settings [C:\Users\Edward\AppData\Local]
12/16/2009 12:20 AM My Documents [C:\Users\Edward\Documents]
12/16/2009 12:20 AM NetHood [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/16/2009 12:20 AM PrintHood [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/16/2009 12:20 AM Recent [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Recent]
12/16/2009 12:20 AM SendTo [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\SendTo]
12/16/2009 12:20 AM Start Menu [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Start Menu]
12/16/2009 12:20 AM Templates [C:\Users\Edward\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Edward\AppData\Local
12/16/2009 12:20 AM Application Data [C:\Users\Edward\AppData\Local]
12/16/2009 12:20 AM History [C:\Users\Edward\AppData\Local\Microsoft\Windows\History]
12/16/2009 12:20 AM Temporary Internet Files [C:\Users\Edward\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Edward\Documents
12/16/2009 12:20 AM My Music [C:\Users\Edward\Music]
12/16/2009 12:20 AM My Pictures [C:\Users\Edward\Pictures]
12/16/2009 12:20 AM My Videos [C:\Users\Edward\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Guest
03/23/2010 11:30 PM Application Data [C:\Users\Guest\AppData\Roaming]
03/23/2010 11:30 PM Cookies [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Cookies]
03/23/2010 11:30 PM Local Settings [C:\Users\Guest\AppData\Local]
03/23/2010 11:30 PM My Documents [C:\Users\Guest\Documents]
03/23/2010 11:30 PM NetHood [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/23/2010 11:30 PM PrintHood [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/23/2010 11:30 PM Recent [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Recent]
03/23/2010 11:30 PM SendTo [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\SendTo]
03/23/2010 11:30 PM Start Menu [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu]
03/23/2010 11:30 PM Templates [C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Guest\AppData\Local
03/23/2010 11:30 PM Application Data [C:\Users\Guest\AppData\Local]
03/23/2010 11:30 PM History [C:\Users\Guest\AppData\Local\Microsoft\Windows\History]
03/23/2010 11:30 PM Temporary Internet Files [C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Guest\Documents
03/23/2010 11:30 PM My Music [C:\Users\Guest\Music]
03/23/2010 11:30 PM My Pictures [C:\Users\Guest\Pictures]
03/23/2010 11:30 PM My Videos [C:\Users\Guest\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Paul
12/16/2009 12:25 AM Application Data [C:\Users\Paul\AppData\Roaming]
12/16/2009 12:25 AM Cookies [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Cookies]
12/16/2009 12:25 AM Local Settings [C:\Users\Paul\AppData\Local]
12/16/2009 12:25 AM My Documents [C:\Users\Paul\Documents]
12/16/2009 12:25 AM NetHood [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/16/2009 12:25 AM PrintHood [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/16/2009 12:25 AM Recent [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Recent]
12/16/2009 12:25 AM SendTo [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\SendTo]
12/16/2009 12:25 AM Start Menu [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Start Menu]
12/16/2009 12:25 AM Templates [C:\Users\Paul\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Paul\AppData\Local
12/16/2009 12:25 AM Application Data [C:\Users\Paul\AppData\Local]
12/16/2009 12:25 AM History [C:\Users\Paul\AppData\Local\Microsoft\Windows\History]
12/16/2009 12:25 AM Temporary Internet Files [C:\Users\Paul\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Paul\Documents
12/16/2009 12:25 AM My Music [C:\Users\Paul\Music]
12/16/2009 12:25 AM My Pictures [C:\Users\Paul\Pictures]
12/16/2009 12:25 AM My Videos [C:\Users\Paul\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Paul.Paul-PC
04/29/2013 09:19 PM Application Data [C:\Users\Paul.Paul-PC\AppData\Roaming]
04/29/2013 09:19 PM Cookies [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Cookies]
04/29/2013 09:19 PM Local Settings [C:\Users\Paul.Paul-PC\AppData\Local]
04/29/2013 09:19 PM My Documents [C:\Users\Paul.Paul-PC\Documents]
04/29/2013 09:19 PM NetHood [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/29/2013 09:19 PM PrintHood [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/29/2013 09:19 PM Recent [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Recent]
04/29/2013 09:19 PM SendTo [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\SendTo]
04/29/2013 09:19 PM Start Menu [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Start Menu]
04/29/2013 09:19 PM Templates [C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Paul.Paul-PC\AppData\Local
04/29/2013 09:19 PM Application Data [C:\Users\Paul.Paul-PC\AppData\Local]
04/29/2013 09:19 PM History [C:\Users\Paul.Paul-PC\AppData\Local\Microsoft\Windows\History]
04/29/2013 09:19 PM Temporary Internet Files [C:\Users\Paul.Paul-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Paul.Paul-PC\Documents
04/29/2013 09:19 PM My Music [C:\Users\Paul.Paul-PC\Music]
04/29/2013 09:19 PM My Pictures [C:\Users\Paul.Paul-PC\Pictures]
04/29/2013 09:19 PM My Videos [C:\Users\Paul.Paul-PC\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:53 AM My Music [C:\Users\Public\Music]
07/14/2009 12:53 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:53 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
11/29/2009 09:06 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
11/29/2009 09:06 PM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
11/29/2009 09:06 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
11/29/2009 09:06 PM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
11/29/2009 09:06 PM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
102 Dir(s) 129,595,596,800 bytes free

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/04/29 21:21:00 | 000,000,221 | -HS- | M] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2013/09/21 20:24:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-12-05 04:17:55

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:1AE68282

< End of report >


Here is the Hijackthis.log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:32:13 PM, on 9/22/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16455)
Boot mode: Normal

Running processes:
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Windows\OEM13Mon.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\conhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe
C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Paul.Paul-PC\Desktop\OTL.exe
C:\Windows\notepad.exe
C:\Users\Paul.Paul-PC\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=714647&fr;=spigot-yhp-ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
O4 - HKLM\..\Run: [AdobeCEPServiceManager] "C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Paul.Paul-PC\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [SearchProtection] "C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart
O4 - HKUS\S-1-5-21-2674026609-1698660912-1609442580-1003\..\Run: [uTorrent] "C:\Users\Paul.Paul-PC\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED (User '?')
O4 - HKUS\S-1-5-21-2674026609-1698660912-1609442580-1003\..\Run: [SearchProtection] "C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart (User '?')
O4 - HKUS\S-1-5-21-2674026609-1698660912-1609442580-1003\..\Run: [AdobeBridge] (User '?')
O4 - Global Startup: McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: O2FLASH - O2Micro International - C:\Windows\system32\DRIVERS\o2flash.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.4.4\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE

–
End of file - 10985 bytes


Here is the DDS.txt log:

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 20:33:18.74 on Sun 09/22/2013
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.yahoo.com?type=714647&fr;=spigot-yhp-ie
BHO: MSS+ Identifier: {0e8a89ad-95d7-40eb-8d9d-083ef7066a01} - c:\program files\mcafee security scan\3.0.318\McAfeeMSS_IE.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
uRun: [uTorrent] "c:\users\paul.paul-pc\appdata\roaming\utorrent\uTorrent.exe" /MINIMIZED
uRun: [SearchProtection] "c:\users\paul.paul-pc\appdata\roaming\search protection\SearchProtection.EXE" /autostart
uRun: [AdobeBridge]
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [Broadcom Wireless Manager UI] c:\program files\dell\dell wireless wlan card\WLTRAY.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [OEM13Mon.exe] c:\windows\OEM13Mon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [Adobe Creative Cloud] "c:\program files\adobe\adobe creative cloud\acc\Creative Cloud.exe" –showwindow=false –onOSstartup=true
mRun: [AdobeCEPServiceManager] "c:\program files\common files\adobe\cepservicemanager4\CEPServiceManager.exe" -launchedbylogin
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS6ServiceManager] "c:\program files\common files\adobe\cs6servicemanager\CS6ServiceManager.exe" -launchedbylogin
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\3.0.318\SSScheduler.exe
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\paul~1.pa~\appdata\roaming\mozilla\firefox\profiles\ya3lift0.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei;=utf-8&ilc;=12&type;=714647&p;=
FF - plugin: c:\program files\adobe\adobe creative cloud\utils\npAdobeAAMDetect32.dll
FF - plugin: c:\program files\adobe\adobe creative cloud\utils\npAdobeAAMDetect64.dll
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\mcafee security scan\3.0.318\npMcAfeeMSS.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_8_800_168.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2013-09-21 18:22:49 ——– d—–w- c:\users\paul~1.pa~\appdata\roaming\Malwarebytes
2013-09-08 02:15:27 ——– d—–w- C:\wamp
2013-09-05 14:04:02 209272 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll
.
==================== Find3M ====================
.
2013-09-20 01:18:06 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-20 01:18:06 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe
.
============= FINISH: 20:33:56.59 ===============
Hi pmedvins,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

[external image: Posted Image] P2P - (Peer to Peer)

I see you have/had P2P software uTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections and possibly Identity Theft. It likely contributed to your current situation. This page will give you further information.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

I would strongly recommend that you uninstall this now.

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • uTorrent/BitTorrent


=========================

[external image: Posted Image] aswMBR

Download aswMBR.exe and save it to your desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
=========================

[external image: Posted Image] Security Check

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
=========================

[external image: Posted Image] AdwCleaner

Download AdwCleaner to your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
=========================

[external image: Posted Image] Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 & 8 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Under Extra Registry section, select Use SafeList <– important
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
=========================

In your next post please provide the following:
  • aswMBR.txt
  • attachMBR.zip
  • checkup.txt
  • AdwCleaner.txt
  • OTL.txt
  • Extras.txt
  • Any symptoms?
Hi OCD, thanks a lot for helping me out. The scan for aswmbr didn't finish because it kept scanning the infected items in a loop. I clicked save log anyway. I didn't notice any difference with the symtpoms.

Here are the logs:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-26 01:38:50
—————————–
01:38:50.130 OS Version: Windows 6.1.7601 Service Pack 1
01:38:50.130 Number of processors: 2 586 0x170A
01:38:50.134 ComputerName: PAUL-PC UserName: Paul
01:38:51.451 Initialize success
01:39:11.638 AVAST engine defs: 13092501
01:40:56.375 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
01:40:56.377 Disk 0 Vendor: TOSHIBA_ FG00 Size: 238475MB BusType: 3
01:40:56.632 Disk 0 MBR read successfully
01:40:56.634 Disk 0 MBR scan
01:40:56.639 Disk 0 Windows VISTA default MBR code
01:40:56.643 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
01:40:56.654 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 81920
01:40:56.672 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 223434 MB offset 30801920
01:40:56.701 Disk 0 scanning sectors +488395120
01:40:57.052 Disk 0 scanning C:\Windows\system32\drivers
01:41:24.764 Service scanning
01:42:14.970 Service SysPlant C:\Windows\SYSTEM32\Drivers\SysPlant.sys **LOCKED** 32
01:42:16.474 Service Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys **LOCKED** 32
01:42:28.716 Service WPS C:\Windows\system32\drivers\wpsdrvnt.sys **LOCKED** 32
01:42:28.854 Service WpsHelper C:\Windows\system32\drivers\WpsHelper.sys **LOCKED** 32
01:42:30.386 Modules scanning
01:43:15.477 Disk 0 trace - called modules:
01:43:15.517 ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys halmacpi.dll dxgkrnl.sys igdkmd32.sys dxgmms1.sys
01:43:15.527 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x868a2030]
01:43:15.537 3 CLASSPNP.SYS[8b5a359e] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x85e3f028]
01:43:16.660 AVAST engine scan C:\Windows
01:43:34.729 AVAST engine scan C:\Windows\system32
01:50:15.066 AVAST engine scan C:\Windows\system32\drivers
01:51:13.127 AVAST engine scan C:\Users\Paul.Paul-PC
02:00:41.252 File: C:\Users\Paul.Paul-PC\AppData\Local\Mozilla\Firefox\Profiles\ya3lift0.default\safebrowsing **INFECTED** Win32:Malware-gen
02:00:47.257 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH15ED.tmp **INFECTED** Win64:Sirefef-A [Trj]
02:00:47.340 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH1D8B.tmp **INFECTED** Win64:Sirefef-A [Trj]
02:00:47.498 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH57B6.tmp **INFECTED** Win32:Malware-gen
02:00:47.675 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH693E.tmp **INFECTED** Win32:Malware-gen
02:00:47.766 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH7D77.tmp **INFECTED** Win64:Sirefef-A [Trj]
02:00:47.853 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH7DAC.tmp **INFECTED** Win64:Sirefef-A [Trj]
02:00:47.947 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH7FAF.tmp **INFECTED** Win64:Sirefef-A [Trj]
02:00:48.018 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8153.tmp **INFECTED** Win32:Malware-gen
02:00:48.157 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8159.tmp **INFECTED** Win32:Malware-gen
02:00:48.391 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH815B.tmp **INFECTED** Win32:Malware-gen
02:00:48.519 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH815D.tmp **INFECTED** Win32:Malware-gen
02:00:48.750 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8163.tmp **INFECTED** Win32:Malware-gen
02:00:48.868 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH816D.tmp **INFECTED** Win32:Malware-gen
02:00:48.987 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH816E.tmp **INFECTED** Win32:Malware-gen
02:00:49.064 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8172.tmp **INFECTED** Win32:Malware-gen
02:00:49.142 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH817F.tmp **INFECTED** Win32:Malware-gen
02:00:49.263 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8181.tmp **INFECTED** Win32:Malware-gen
02:00:49.338 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8188.tmp **INFECTED** Win32:Malware-gen
02:00:49.479 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH818A.tmp **INFECTED** Win32:Malware-gen
02:00:49.564 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8193.tmp **INFECTED** Win32:Malware-gen
02:00:49.631 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8196.tmp **INFECTED** Win32:Malware-gen
02:00:49.760 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH819C.tmp **INFECTED** Win32:Malware-gen
02:00:49.855 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81BA.tmp **INFECTED** Win32:Malware-gen
02:00:49.980 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81BE.tmp **INFECTED** Win32:Malware-gen
02:00:50.080 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81C6.tmp **INFECTED** Win32:Malware-gen
02:00:50.157 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81CB.tmp **INFECTED** Win32:Malware-gen
02:00:50.382 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81D5.tmp **INFECTED** Win32:Malware-gen
02:00:50.559 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81D8.tmp **INFECTED** Win32:Malware-gen
02:00:50.834 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81DC.tmp **INFECTED** Win32:Malware-gen
02:00:50.927 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81E6.tmp **INFECTED** Win32:Malware-gen
02:00:51.461 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81F.tmp **INFECTED** Win32:Malware-gen
02:00:51.656 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81F6.tmp **INFECTED** Win32:Malware-gen
02:00:51.866 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81FB.tmp **INFECTED** Win32:Malware-gen
02:00:51.953 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81FC.tmp **INFECTED** Win32:Malware-gen
02:00:52.069 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH81FF.tmp **INFECTED** Win32:Malware-gen
02:00:52.143 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8201.tmp **INFECTED** Win32:Malware-gen
02:00:52.211 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8205.tmp **INFECTED** Win32:Malware-gen
02:00:52.288 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8211.tmp **INFECTED** Win32:Malware-gen
02:00:52.383 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8213.tmp **INFECTED** Win32:Malware-gen
02:00:52.500 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8215.tmp **INFECTED** Win32:Malware-gen
02:00:52.574 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8217.tmp **INFECTED** Win32:Malware-gen
02:00:52.639 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8218.tmp **INFECTED** Win32:Malware-gen
02:00:52.830 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH821D.tmp **INFECTED** Win32:Malware-gen
02:00:53.024 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH822.tmp **INFECTED** Win32:Malware-gen
02:00:53.122 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8221.tmp **INFECTED** Win32:Malware-gen
02:00:53.204 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8225.tmp **INFECTED** Win32:Malware-gen
02:00:53.304 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8228.tmp **INFECTED** Win32:Malware-gen
02:00:53.405 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8232.tmp **INFECTED** Win32:Malware-gen
02:00:53.580 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8236.tmp **INFECTED** Win32:Malware-gen
02:00:53.657 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH823F.tmp **INFECTED** Win32:Malware-gen
02:00:53.747 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH824.tmp **INFECTED** Win32:Malware-gen
02:00:53.874 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8249.tmp **INFECTED** Win32:Malware-gen
02:00:53.934 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH824A.tmp **INFECTED** Win32:Malware-gen
02:00:54.018 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH824D.tmp **INFECTED** Win32:Malware-gen
02:00:54.182 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8250.tmp **INFECTED** Win32:Malware-gen
02:00:54.372 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8256.tmp **INFECTED** Win32:Malware-gen
02:00:54.456 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8259.tmp **INFECTED** Win32:Malware-gen
02:00:54.656 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH825C.tmp **INFECTED** Win32:Malware-gen
02:00:54.765 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8261.tmp **INFECTED** Win32:Malware-gen
02:00:54.863 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8262.tmp **INFECTED** Win32:Malware-gen
02:00:54.940 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8263.tmp **INFECTED** Win32:Malware-gen
02:00:55.033 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8271.tmp **INFECTED** Win32:Malware-gen
02:00:55.243 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8274.tmp **INFECTED** Win32:Malware-gen
02:00:55.363 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8278.tmp **INFECTED** Win32:Malware-gen
02:00:55.561 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8279.tmp **INFECTED** Win32:Malware-gen
02:00:55.760 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8285.tmp **INFECTED** Win32:Malware-gen
02:00:55.843 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH828B.tmp **INFECTED** Win32:Malware-gen
02:00:55.957 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8296.tmp **INFECTED** Win32:Malware-gen
02:00:56.041 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH829D.tmp **INFECTED** Win32:Malware-gen
02:00:56.124 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82A5.tmp **INFECTED** Win32:Malware-gen
02:00:56.226 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82A6.tmp **INFECTED** Win32:Malware-gen
02:00:56.299 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82AB.tmp **INFECTED** Win32:Malware-gen
02:00:56.475 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82B0.tmp **INFECTED** Win32:Malware-gen
02:00:56.535 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82B3.tmp **INFECTED** Win32:Malware-gen
02:00:56.626 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82C1.tmp **INFECTED** Win32:Malware-gen
02:00:56.709 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82C3.tmp **INFECTED** Win32:Malware-gen
02:00:56.790 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82C9.tmp **INFECTED** Win32:Malware-gen
02:00:56.910 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82D2.tmp **INFECTED** Win32:Malware-gen
02:00:57.003 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82D3.tmp **INFECTED** Win32:Malware-gen
02:00:57.124 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82D6.tmp **INFECTED** Win32:Malware-gen
02:00:57.605 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82DC.tmp **INFECTED** Win32:Malware-gen
02:00:57.977 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82DE.tmp **INFECTED** Win32:Malware-gen
02:00:58.080 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82E2.tmp **INFECTED** Win32:Malware-gen
02:00:58.245 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82E5.tmp **INFECTED** Win32:Malware-gen
02:00:58.397 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82E8.tmp **INFECTED** Win32:Malware-gen
02:00:58.489 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82EA.tmp **INFECTED** Win32:Malware-gen
02:00:58.568 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82EB.tmp **INFECTED** Win32:Malware-gen
02:00:58.644 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82F3.tmp **INFECTED** Win32:Malware-gen
02:00:58.739 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82FA.tmp **INFECTED** Win32:Malware-gen
02:00:58.846 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH82FC.tmp **INFECTED** Win32:Malware-gen
02:00:58.931 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8300.tmp **INFECTED** Win32:Malware-gen
02:00:59.113 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH830B.tmp **INFECTED** Win32:Malware-gen
02:00:59.218 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH830F.tmp **INFECTED** Win32:Malware-gen
02:00:59.314 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH831.tmp **INFECTED** Win32:Malware-gen
02:00:59.412 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8313.tmp **INFECTED** Win32:Malware-gen
02:00:59.503 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH831C.tmp **INFECTED** Win32:Malware-gen
02:00:59.591 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8321.tmp **INFECTED** Win32:Malware-gen
02:00:59.693 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8325.tmp **INFECTED** Win32:Malware-gen
02:00:59.759 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8328.tmp **INFECTED** Win32:Malware-gen
02:00:59.849 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH832A.tmp **INFECTED** Win32:Malware-gen
02:01:00.019 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8334.tmp **INFECTED** Win32:Malware-gen
02:01:00.094 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH833C.tmp **INFECTED** Win32:Malware-gen
02:01:00.182 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8344.tmp **INFECTED** Win32:Malware-gen
02:01:00.277 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8351.tmp **INFECTED** Win32:Malware-gen
02:01:00.348 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8352.tmp **INFECTED** Win32:Malware-gen
02:01:00.429 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8355.tmp **INFECTED** Win32:Malware-gen
02:01:00.618 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8356.tmp **INFECTED** Win32:Malware-gen
02:01:00.714 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8358.tmp **INFECTED** Win32:Malware-gen
02:01:00.793 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH835F.tmp **INFECTED** Win32:Malware-gen
02:01:00.975 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8362.tmp **INFECTED** Win32:Malware-gen
02:01:01.075 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8370.tmp **INFECTED** Win32:Malware-gen
02:01:01.214 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8372.tmp **INFECTED** Win32:Malware-gen
02:01:01.288 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH837D.tmp **INFECTED** Win32:Malware-gen
02:01:01.367 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH837E.tmp **INFECTED** Win32:Malware-gen
02:01:01.451 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH838.tmp **INFECTED** Win32:Malware-gen
02:01:01.591 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8386.tmp **INFECTED** Win32:Malware-gen
02:01:01.660 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8387.tmp **INFECTED** Win32:Malware-gen
02:01:01.771 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH838C.tmp **INFECTED** Win32:Malware-gen
02:01:01.938 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8391.tmp **INFECTED** Win32:Malware-gen
02:01:02.082 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8394.tmp **INFECTED** Win32:Malware-gen
02:01:02.203 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8397.tmp **INFECTED** Win32:Malware-gen
02:01:02.289 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH839E.tmp **INFECTED** Win32:Malware-gen
02:01:02.452 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83A.tmp **INFECTED** Win32:Malware-gen
02:01:02.555 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83A6.tmp **INFECTED** Win32:Malware-gen
02:01:02.737 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83AA.tmp **INFECTED** Win32:Malware-gen
02:01:02.807 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83AB.tmp **INFECTED** Win32:Malware-gen
02:01:02.937 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83AF.tmp **INFECTED** Win32:Malware-gen
02:01:03.001 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83B.tmp **INFECTED** Win32:Malware-gen
02:01:03.058 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83B0.tmp **INFECTED** Win32:Malware-gen
02:01:03.131 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83B4.tmp **INFECTED** Win32:Malware-gen
02:01:03.211 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83B5.tmp **INFECTED** Win32:Malware-gen
02:01:03.383 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83B9.tmp **INFECTED** Win32:Malware-gen
02:01:03.467 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83BC.tmp **INFECTED** Win32:Malware-gen
02:01:03.542 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83BF.tmp **INFECTED** Win32:Malware-gen
02:01:03.643 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83C9.tmp **INFECTED** Win32:Malware-gen
02:01:03.743 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83CB.tmp **INFECTED** Win32:Malware-gen
02:01:03.825 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83D0.tmp **INFECTED** Win32:Malware-gen
02:01:03.935 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83DC.tmp **INFECTED** Win32:Malware-gen
02:01:04.054 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83EB.tmp **INFECTED** Win32:Malware-gen
02:01:04.118 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83EC.tmp **INFECTED** Win32:Malware-gen
02:01:04.645 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83ED.tmp **INFECTED** Win32:Malware-gen
02:01:04.776 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83F5.tmp **INFECTED** Win32:Malware-gen
02:01:04.854 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83F8.tmp **INFECTED** Win32:Malware-gen
02:01:04.915 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83FB.tmp **INFECTED** Win32:Malware-gen
02:01:04.987 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH83FC.tmp **INFECTED** Win32:Malware-gen
02:01:05.090 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH840.tmp **INFECTED** Win32:Malware-gen
02:01:05.177 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8401.tmp **INFECTED** Win32:Malware-gen
02:01:05.256 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8404.tmp **INFECTED** Win32:Malware-gen
02:01:05.329 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH840A.tmp **INFECTED** Win32:Malware-gen
02:01:05.401 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH840B.tmp **INFECTED** Win32:Malware-gen
02:01:05.574 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8412.tmp **INFECTED** Win32:Malware-gen
02:01:05.675 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH841F.tmp **INFECTED** Win32:Malware-gen
02:01:05.751 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8421.tmp **INFECTED** Win32:Malware-gen
02:01:05.837 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8423.tmp **INFECTED** Win32:Malware-gen
02:01:05.902 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8430.tmp **INFECTED** Win32:Malware-gen
02:01:06.032 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8436.tmp **INFECTED** Win32:Malware-gen
02:01:06.118 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH843D.tmp **INFECTED** Win32:Malware-gen
02:01:06.205 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8445.tmp **INFECTED** Win32:Malware-gen
02:01:06.262 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8447.tmp **INFECTED** Win32:Malware-gen
02:01:06.341 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8448.tmp **INFECTED** Win32:Malware-gen
02:01:06.426 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8450.tmp **INFECTED** Win32:Malware-gen
02:01:06.622 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH845C.tmp **INFECTED** Win32:Malware-gen
02:01:06.728 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH846.tmp **INFECTED** Win32:Malware-gen
02:01:06.829 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8470.tmp **INFECTED** Win32:Malware-gen
02:01:06.987 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8472.tmp **INFECTED** Win32:Malware-gen
02:01:07.139 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8474.tmp **INFECTED** Win32:Malware-gen
02:01:07.247 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8475.tmp **INFECTED** Win32:Malware-gen
02:01:07.371 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8479.tmp **INFECTED** Win32:Malware-gen
02:01:07.463 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH848.tmp **INFECTED** Win32:Malware-gen
02:01:07.567 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8481.tmp **INFECTED** Win32:Malware-gen
02:01:07.684 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8487.tmp **INFECTED** Win32:Malware-gen
02:01:07.793 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8489.tmp **INFECTED** Win32:Malware-gen
02:01:08.002 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8490.tmp **INFECTED** Win32:Malware-gen
02:01:08.092 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8493.tmp **INFECTED** Win32:Malware-gen
02:01:08.196 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8494.tmp **INFECTED** Win32:Malware-gen
02:01:08.315 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8496.tmp **INFECTED** Win32:Malware-gen
02:01:08.583 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH849E.tmp **INFECTED** Win32:Malware-gen
02:01:08.686 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH849F.tmp **INFECTED** Win32:Malware-gen
02:01:08.783 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84A.tmp **INFECTED** Win32:Malware-gen
02:01:08.873 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84A2.tmp **INFECTED** Win32:Malware-gen
02:01:08.990 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84A6.tmp **INFECTED** Win32:Malware-gen
02:01:09.127 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84B3.tmp **INFECTED** Win32:Malware-gen
02:01:09.242 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84BE.tmp **INFECTED** Win32:Malware-gen
02:01:09.438 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84CD.tmp **INFECTED** Win32:Malware-gen
02:01:09.542 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84D7.tmp **INFECTED** Win32:Malware-gen
02:01:09.620 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84E0.tmp **INFECTED** Win32:Malware-gen
02:01:09.850 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84E1.tmp **INFECTED** Win32:Malware-gen
02:01:09.925 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84E4.tmp **INFECTED** Win32:Malware-gen
02:01:10.022 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84F.tmp **INFECTED** Win32:Malware-gen
02:01:10.135 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84F1.tmp **INFECTED** Win32:Malware-gen
02:01:10.254 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH84F5.tmp **INFECTED** Win32:Malware-gen
02:01:10.409 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH850.tmp **INFECTED** Win32:Malware-gen
02:01:10.943 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8500.tmp **INFECTED** Win32:Malware-gen
02:01:11.063 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8507.tmp **INFECTED** Win32:Malware-gen
02:01:11.175 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8529.tmp **INFECTED** Win32:Malware-gen
02:01:11.332 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8537.tmp **INFECTED** Win32:Malware-gen
02:01:11.405 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8546.tmp **INFECTED** Win32:Malware-gen
02:01:11.544 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8556.tmp **INFECTED** Win32:Malware-gen
02:01:11.683 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8558.tmp **INFECTED** Win32:Malware-gen
02:01:11.743 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8578.tmp **INFECTED** Win32:Malware-gen
02:01:11.807 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8588.tmp **INFECTED** Win32:Malware-gen
02:01:11.975 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8594.tmp **INFECTED** Win32:Malware-gen
02:01:12.080 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85A0.tmp **INFECTED** Win32:Malware-gen
02:01:12.169 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85A8.tmp **INFECTED** Win32:Malware-gen
02:01:12.242 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85B0.tmp **INFECTED** Win32:Malware-gen
02:01:12.313 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85B3.tmp **INFECTED** Win32:Malware-gen
02:01:12.465 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85B4.tmp **INFECTED** Win32:Malware-gen
02:01:12.583 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85B6.tmp **INFECTED** Win32:Malware-gen
02:01:12.670 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85BC.tmp **INFECTED** Win32:Malware-gen
02:01:12.734 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85BF.tmp **INFECTED** Win32:Malware-gen
02:01:12.904 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85C5.tmp **INFECTED** Win32:Malware-gen
02:01:12.983 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85C6.tmp **INFECTED** Win32:Malware-gen
02:01:13.044 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85C7.tmp **INFECTED** Win32:Malware-gen
02:01:13.126 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85CA.tmp **INFECTED** Win32:Malware-gen
02:01:13.201 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85CC.tmp **INFECTED** Win32:Malware-gen
02:01:13.291 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85CE.tmp **INFECTED** Win32:Malware-gen
02:01:13.373 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85D8.tmp **INFECTED** Win32:Malware-gen
02:01:13.437 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85DA.tmp **INFECTED** Win32:Malware-gen
02:01:13.511 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85DB.tmp **INFECTED** Win32:Malware-gen
02:01:13.567 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85DD.tmp **INFECTED** Win32:Malware-gen
02:01:13.631 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85E6.tmp **INFECTED** Win32:Malware-gen
02:01:13.697 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85E7.tmp **INFECTED** Win32:Malware-gen
02:01:13.758 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85F4.tmp **INFECTED** Win32:Malware-gen
02:01:13.822 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85F5.tmp **INFECTED** Win32:Malware-gen
02:01:13.896 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85F8.tmp **INFECTED** Win32:Malware-gen
02:01:13.976 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85F9.tmp **INFECTED** Win32:Malware-gen
02:01:14.163 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85FA.tmp **INFECTED** Win32:Malware-gen
02:01:14.240 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85FB.tmp **INFECTED** Win32:Malware-gen
02:01:14.299 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85FD.tmp **INFECTED** Win32:Malware-gen
02:01:14.355 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85FE.tmp **INFECTED** Win32:Malware-gen
02:01:14.426 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH85FF.tmp **INFECTED** Win32:Malware-gen
02:01:14.495 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH860.tmp **INFECTED** Win32:Malware-gen
02:01:14.553 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8601.tmp **INFECTED** Win32:Malware-gen
02:01:14.622 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8607.tmp **INFECTED** Win32:Malware-gen
02:01:14.711 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH860D.tmp **INFECTED** Win32:Malware-gen
02:01:14.771 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH860F.tmp **INFECTED** Win32:Malware-gen
02:01:14.860 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8611.tmp **INFECTED** Win32:Malware-gen
02:01:14.910 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH861D.tmp **INFECTED** Win32:Malware-gen
02:01:15.003 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH861F.tmp **INFECTED** Win32:Malware-gen
02:01:15.077 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH862.tmp **INFECTED** Win32:Malware-gen
02:01:15.268 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8620.tmp **INFECTED** Win32:Malware-gen
02:01:15.335 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8623.tmp **INFECTED** Win32:Malware-gen
02:01:15.407 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8628.tmp **INFECTED** Win32:Malware-gen
02:01:15.454 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH862F.tmp **INFECTED** Win32:Malware-gen
02:01:15.554 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8639.tmp **INFECTED** Win32:Malware-gen
02:01:15.693 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH863C.tmp **INFECTED** Win32:Malware-gen
02:01:15.830 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH863F.tmp **INFECTED** Win32:Malware-gen
02:01:15.909 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH864.tmp **INFECTED** Win32:Malware-gen
02:01:15.992 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8640.tmp **INFECTED** Win32:Malware-gen
02:01:16.070 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8648.tmp **INFECTED** Win32:Malware-gen
02:01:16.125 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH864C.tmp **INFECTED** Win32:Malware-gen
02:01:16.307 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH864D.tmp **INFECTED** Win32:Malware-gen
02:01:16.404 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH865.tmp **INFECTED** Win32:Malware-gen
02:01:18.162 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH866.tmp **INFECTED** Win32:Malware-gen
02:01:18.400 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8662.tmp **INFECTED** Win32:Malware-gen
02:01:18.460 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH866B.tmp **INFECTED** Win32:Malware-gen
02:01:18.603 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH866C.tmp **INFECTED** Win32:Malware-gen
02:01:18.720 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH866F.tmp **INFECTED** Win32:Malware-gen
02:01:18.789 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH867.tmp **INFECTED** Win32:Malware-gen
02:01:18.895 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8674.tmp **INFECTED** Win32:Malware-gen
02:01:18.986 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8677.tmp **INFECTED** Win32:Malware-gen
02:01:19.049 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8678.tmp **INFECTED** Win32:Malware-gen
02:01:19.117 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH867C.tmp **INFECTED** Win32:Malware-gen
02:01:19.259 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH867E.tmp **INFECTED** Win32:Malware-gen
02:01:19.418 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH868A.tmp **INFECTED** Win32:Malware-gen
02:01:19.485 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8693.tmp **INFECTED** Win32:Malware-gen
02:01:19.557 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8696.tmp **INFECTED** Win32:Malware-gen
02:01:19.622 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8698.tmp **INFECTED** Win32:Malware-gen
02:01:19.742 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH869F.tmp **INFECTED** Win32:Malware-gen
02:01:19.794 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86A2.tmp **INFECTED** Win32:Malware-gen
02:01:19.863 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86A6.tmp **INFECTED** Win32:Malware-gen
02:01:19.921 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86A9.tmp **INFECTED** Win32:Malware-gen
02:01:19.971 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86AB.tmp **INFECTED** Win32:Malware-gen
02:01:20.037 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86B.tmp **INFECTED** Win32:Malware-gen
02:01:20.187 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86B0.tmp **INFECTED** Win32:Malware-gen
02:01:20.273 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86B2.tmp **INFECTED** Win32:Malware-gen
02:01:20.471 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86B3.tmp **INFECTED** Win32:Malware-gen
02:01:20.544 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86B9.tmp **INFECTED** Win32:Malware-gen
02:01:20.593 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86BF.tmp **INFECTED** Win32:Malware-gen
02:01:20.656 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86C.tmp **INFECTED** Win32:Malware-gen
02:01:20.732 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86C1.tmp **INFECTED** Win32:Malware-gen
02:01:20.812 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86C8.tmp **INFECTED** Win32:Malware-gen
02:01:20.989 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86CC.tmp **INFECTED** Win32:Malware-gen
02:01:21.072 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86D5.tmp **INFECTED** Win32:Malware-gen
02:01:21.121 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86D8.tmp **INFECTED** Win32:Malware-gen
02:01:21.171 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86DC.tmp **INFECTED** Win32:Malware-gen
02:01:21.245 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86E1.tmp **INFECTED** Win32:Malware-gen
02:01:21.333 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86E3.tmp **INFECTED** Win32:Sirefef-AHF [Trj]
02:01:21.413 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86E8.tmp **INFECTED** Win32:Malware-gen
02:01:21.621 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86EB.tmp **INFECTED** Win32:Malware-gen
02:01:21.685 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86F.tmp **INFECTED** Win32:Malware-gen
02:01:21.747 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86F4.tmp **INFECTED** Win32:Malware-gen
02:01:21.823 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86F7.tmp **INFECTED** Win32:Malware-gen
02:01:21.901 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH86FC.tmp **INFECTED** Win32:Malware-gen
02:01:21.950 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8702.tmp **INFECTED** Win32:Malware-gen
02:01:22.022 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8703.tmp **INFECTED** Win32:Malware-gen
02:01:22.122 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8707.tmp **INFECTED** Win32:Malware-gen
02:01:22.179 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8711.tmp **INFECTED** Win32:Malware-gen
02:01:22.239 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8716.tmp **INFECTED** Win32:Malware-gen
02:01:22.297 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8720.tmp **INFECTED** Win32:Malware-gen
02:01:22.351 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8721.tmp **INFECTED** Win32:Malware-gen
02:01:22.411 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8727.tmp **INFECTED** Win32:Malware-gen
02:01:22.485 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8729.tmp **INFECTED** Win32:Malware-gen
02:01:22.571 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH872E.tmp **INFECTED** Win32:Malware-gen
02:01:22.691 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8739.tmp **INFECTED** Win32:Malware-gen
02:01:22.770 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH873F.tmp **INFECTED** Win32:Malware-gen
02:01:22.839 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8748.tmp **INFECTED** Win32:Malware-gen
02:01:22.926 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8750.tmp **INFECTED** Win32:Malware-gen
02:01:23.013 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8758.tmp **INFECTED** Win32:Malware-gen
02:01:23.071 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8759.tmp **INFECTED** Win32:Malware-gen
02:01:23.137 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH876.tmp **INFECTED** Win32:Malware-gen
02:01:23.225 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8761.tmp **INFECTED** Win32:Malware-gen
02:01:23.291 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8764.tmp **INFECTED** Win32:Malware-gen
02:01:23.376 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8765.tmp **INFECTED** Win32:Malware-gen
02:01:23.461 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8767.tmp **INFECTED** Win32:Malware-gen
02:01:23.557 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH876B.tmp **INFECTED** Win32:Malware-gen
02:01:23.654 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH876C.tmp **INFECTED** Win32:Malware-gen
02:01:23.730 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH876D.tmp **INFECTED** Win32:Malware-gen
02:01:23.812 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH877.tmp **INFECTED** Win32:Malware-gen
02:01:23.992 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8771.tmp **INFECTED** Win32:Malware-gen
02:01:24.053 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8774.tmp **INFECTED** Win32:Malware-gen
02:01:24.117 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8777.tmp **INFECTED** Win32:Malware-gen
02:01:24.205 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH878D.tmp **INFECTED** Win32:Malware-gen
02:01:24.308 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8796.tmp **INFECTED** Win32:Malware-gen
02:01:24.671 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH879F.tmp **INFECTED** Win32:Malware-gen
02:01:24.785 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87A2.tmp **INFECTED** Win32:Malware-gen
02:01:24.878 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87B1.tmp **INFECTED** Win32:Malware-gen
02:01:24.962 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87B5.tmp **INFECTED** Win32:Malware-gen
02:01:26.968 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87B6.tmp **INFECTED** Win32:Malware-gen
02:01:27.047 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87B7.tmp **INFECTED** Win32:Malware-gen
02:01:27.100 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87BF.tmp **INFECTED** Win32:Malware-gen
02:01:27.153 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87C2.tmp **INFECTED** Win32:Malware-gen
02:01:27.216 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87C3.tmp **INFECTED** Win32:Malware-gen
02:01:27.433 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87C5.tmp **INFECTED** Win32:Malware-gen
02:01:27.488 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87D1.tmp **INFECTED** Win32:Malware-gen
02:01:27.573 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87D2.tmp **INFECTED** Win32:Malware-gen
02:01:27.754 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87D5.tmp **INFECTED** Win32:Malware-gen
02:01:27.824 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87D8.tmp **INFECTED** Win32:Malware-gen
02:01:27.962 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87D9.tmp **INFECTED** Win32:Malware-gen
02:01:28.027 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87E1.tmp **INFECTED** Win32:Malware-gen
02:01:28.097 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87ED.tmp **INFECTED** Win32:Malware-gen
02:01:28.164 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87F0.tmp **INFECTED** Win32:Malware-gen
02:01:28.276 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87F4.tmp **INFECTED** Win32:Malware-gen
02:01:28.358 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87F8.tmp **INFECTED** Win32:Sirefef-AHF [Trj]
02:01:28.443 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87F9.tmp **INFECTED** Win32:Malware-gen
02:01:28.529 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH87FA.tmp **INFECTED** Win32:Malware-gen
02:01:28.620 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8803.tmp **INFECTED** Win32:Malware-gen
02:01:28.801 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8807.tmp **INFECTED** Win32:Malware-gen
02:01:28.909 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8809.tmp **INFECTED** Win32:Malware-gen
02:01:28.971 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH880A.tmp **INFECTED** Win32:Malware-gen
02:01:29.034 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH880C.tmp **INFECTED** Win32:Malware-gen
02:01:29.109 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8811.tmp **INFECTED** Win32:Malware-gen
02:01:29.169 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8817.tmp **INFECTED** Win32:Malware-gen
02:01:29.236 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH881C.tmp **INFECTED** Win32:Malware-gen
02:01:29.298 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH881F.tmp **INFECTED** Win32:Malware-gen
02:01:29.374 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8820.tmp **INFECTED** Win32:Malware-gen
02:01:29.462 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8829.tmp **INFECTED** Win32:Malware-gen
02:01:29.615 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH882D.tmp **INFECTED** Win32:Malware-gen
02:01:29.676 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8833.tmp **INFECTED** Win32:Malware-gen
02:01:29.761 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH883C.tmp **INFECTED** Win32:Malware-gen
02:01:29.842 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8845.tmp **INFECTED** Win32:Malware-gen
02:01:29.944 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8848.tmp **INFECTED** Win32:Malware-gen
02:01:30.005 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH884E.tmp **INFECTED** Win32:Malware-gen
02:01:30.052 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH885.tmp **INFECTED** Win32:Malware-gen
02:01:30.129 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8852.tmp **INFECTED** Win32:Malware-gen
02:01:30.238 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8860.tmp **INFECTED** Win32:Malware-gen
02:01:30.434 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8862.tmp **INFECTED** Win32:Malware-gen
02:01:30.536 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8864.tmp **INFECTED** Win32:Malware-gen
02:01:30.621 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8865.tmp **INFECTED** Win32:Malware-gen
02:01:30.722 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH886A.tmp **INFECTED** Win32:Malware-gen
02:01:30.839 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH886F.tmp **INFECTED** Win32:Malware-gen
02:01:30.879 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8871.tmp **INFECTED** Win32:Malware-gen
02:01:32.184 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8875.tmp **INFECTED** Win32:Malware-gen
02:01:32.382 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH887C.tmp **INFECTED** Win32:Malware-gen
02:01:32.500 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH887F.tmp **INFECTED** Win32:Malware-gen
02:01:32.574 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8880.tmp **INFECTED** Win32:Malware-gen
02:01:32.640 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8892.tmp **INFECTED** Win32:Malware-gen
02:01:32.706 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8898.tmp **INFECTED** Win32:Malware-gen
02:01:32.782 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8899.tmp **INFECTED** Win32:Malware-gen
02:01:32.852 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH889E.tmp **INFECTED** Win32:Malware-gen
02:01:32.932 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88A6.tmp **INFECTED** Win32:Malware-gen
02:01:33.039 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88A8.tmp **INFECTED** Win32:Malware-gen
02:01:33.093 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88B0.tmp **INFECTED** Win32:Malware-gen
02:01:33.150 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88B3.tmp **INFECTED** Win32:Malware-gen
02:01:33.389 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88BF.tmp **INFECTED** Win32:Malware-gen
02:01:33.459 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88C.tmp **INFECTED** Win32:Malware-gen
02:01:33.511 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88C3.tmp **INFECTED** Win32:Malware-gen
02:01:33.664 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88C6.tmp **INFECTED** Win32:Malware-gen
02:01:33.750 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88C8.tmp **INFECTED** Win32:Malware-gen
02:01:33.823 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88CA.tmp **INFECTED** Win32:Malware-gen
02:01:33.991 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88CB.tmp **INFECTED** Win32:Malware-gen
02:01:34.044 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88CE.tmp **INFECTED** Win32:Malware-gen
02:01:34.128 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88D.tmp **INFECTED** Win32:Malware-gen
02:01:34.188 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88D7.tmp **INFECTED** Win32:Malware-gen
02:01:34.263 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88DA.tmp **INFECTED** Win32:Malware-gen
02:01:34.340 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88DB.tmp **INFECTED** Win32:Malware-gen
02:01:34.416 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88DC.tmp **INFECTED** Win32:Malware-gen
02:01:34.601 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88DE.tmp **INFECTED** Win32:Malware-gen
02:01:34.677 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88E7.tmp **INFECTED** Win32:Malware-gen
02:01:34.747 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88F3.tmp **INFECTED** Win32:Malware-gen
02:01:34.815 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88F4.tmp **INFECTED** Win32:Malware-gen
02:01:34.959 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88F6.tmp **INFECTED** Win32:Malware-gen
02:01:35.033 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88F9.tmp **INFECTED** Win32:Malware-gen
02:01:35.095 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88FA.tmp **INFECTED** Win32:Malware-gen
02:01:35.162 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH88FF.tmp **INFECTED** Win32:Malware-gen
02:01:35.224 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89.tmp **INFECTED** Win32:Malware-gen
02:01:35.286 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8904.tmp **INFECTED** Win32:Malware-gen
02:01:35.510 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH890E.tmp **INFECTED** Win32:Malware-gen
02:01:35.729 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8910.tmp **INFECTED** Win32:Malware-gen
02:01:35.786 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8913.tmp **INFECTED** Win32:Malware-gen
02:01:35.845 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8918.tmp **INFECTED** Win32:Malware-gen
02:01:35.915 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8919.tmp **INFECTED** Win32:Malware-gen
02:01:35.984 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH891D.tmp **INFECTED** Win32:Malware-gen
02:01:36.070 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8920.tmp **INFECTED** Win32:Malware-gen
02:01:36.127 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8922.tmp **INFECTED** Win32:Malware-gen
02:01:36.185 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8929.tmp **INFECTED** Win32:Malware-gen
02:01:36.241 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH892C.tmp **INFECTED** Win32:Malware-gen
02:01:36.304 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH892E.tmp **INFECTED** Win32:Malware-gen
02:01:36.373 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH893C.tmp **INFECTED** Win32:Malware-gen
02:01:36.502 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH894E.tmp **INFECTED** Win32:Malware-gen
02:01:36.653 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH894F.tmp **INFECTED** Win32:Malware-gen
02:01:36.751 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8957.tmp **INFECTED** Win32:Malware-gen
02:01:36.805 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH895F.tmp **INFECTED** Win32:Malware-gen
02:01:36.894 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8967.tmp **INFECTED** Win32:Malware-gen
02:01:36.993 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8968.tmp **INFECTED** Win32:Malware-gen
02:01:38.626 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH896B.tmp **INFECTED** Win32:Malware-gen
02:01:38.732 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8973.tmp **INFECTED** Win32:Malware-gen
02:01:38.801 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8977.tmp **INFECTED** Win32:Malware-gen
02:01:38.888 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8978.tmp **INFECTED** Win32:Malware-gen
02:01:39.059 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH897A.tmp **INFECTED** Win32:Malware-gen
02:01:39.129 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH897B.tmp **INFECTED** Win32:Malware-gen
02:01:39.276 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH897E.tmp **INFECTED** Win32:Malware-gen
02:01:39.330 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH897F.tmp **INFECTED** Win32:Malware-gen
02:01:39.488 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH898.tmp **INFECTED** Win32:Malware-gen
02:01:39.557 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8987.tmp **INFECTED** Win32:Malware-gen
02:01:39.618 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8988.tmp **INFECTED** Win32:Malware-gen
02:01:39.789 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH898A.tmp **INFECTED** Win32:Malware-gen
02:01:39.910 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8996.tmp **INFECTED** Win32:Malware-gen
02:01:40.110 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH899A.tmp **INFECTED** Win32:Malware-gen
02:01:40.272 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH899D.tmp **INFECTED** Win32:Malware-gen
02:01:40.372 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH899E.tmp **INFECTED** Win32:Malware-gen
02:01:40.476 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH899F.tmp **INFECTED** Win32:Malware-gen
02:01:40.541 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89A1.tmp **INFECTED** Win32:Malware-gen
02:01:40.624 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89A7.tmp **INFECTED** Win32:Malware-gen
02:01:40.688 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89AA.tmp **INFECTED** Win32:Malware-gen
02:01:40.729 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89AE.tmp **INFECTED** Win32:Malware-gen
02:01:40.805 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89B.tmp **INFECTED** Win32:Malware-gen
02:01:40.880 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89B2.tmp **INFECTED** Win32:Malware-gen
02:01:40.937 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89B3.tmp **INFECTED** Win32:Malware-gen
02:01:40.999 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89B9.tmp **INFECTED** Win32:Malware-gen
02:01:41.078 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89BE.tmp **INFECTED** Win32:Malware-gen
02:01:41.154 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89CD.tmp **INFECTED** Win32:Malware-gen
02:01:41.232 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89D.tmp **INFECTED** Win32:Malware-gen
02:01:41.344 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89D1.tmp **INFECTED** Win32:Malware-gen
02:01:41.430 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89D5.tmp **INFECTED** Win32:Malware-gen
02:01:41.583 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89D8.tmp **INFECTED** Win32:Malware-gen
02:01:41.681 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89E5.tmp **INFECTED** Win32:Malware-gen
02:01:41.845 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89E7.tmp **INFECTED** Win32:Malware-gen
02:01:41.959 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89EB.tmp **INFECTED** Win32:Malware-gen
02:01:42.113 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89F.tmp **INFECTED** Win32:Malware-gen
02:01:42.181 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89F3.tmp **INFECTED** Win32:Malware-gen
02:01:42.245 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89F4.tmp **INFECTED** Win32:Malware-gen
02:01:42.306 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH89F5.tmp **INFECTED** Win32:Malware-gen
02:01:42.370 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A04.tmp **INFECTED** Win32:Malware-gen
02:01:42.477 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A07.tmp **INFECTED** Win32:Malware-gen
02:01:42.571 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A0F.tmp **INFECTED** Win32:Malware-gen
02:01:42.640 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A13.tmp **INFECTED** Win32:Malware-gen
02:01:42.713 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A1D.tmp **INFECTED** Win32:Malware-gen
02:01:42.811 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A21.tmp **INFECTED** Win32:Malware-gen
02:01:42.887 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A22.tmp **INFECTED** Win32:Malware-gen
02:01:42.947 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A2E.tmp **INFECTED** Win32:Malware-gen
02:01:43.065 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A33.tmp **INFECTED** Win32:Malware-gen
02:01:43.259 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A35.tmp **INFECTED** Win32:Malware-gen
02:01:43.389 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A3F.tmp **INFECTED** Win32:Malware-gen
02:01:43.448 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A41.tmp **INFECTED** Win32:Malware-gen
02:01:43.556 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A45.tmp **INFECTED** Win32:Malware-gen
02:01:43.687 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A46.tmp **INFECTED** Win32:Malware-gen
02:01:43.872 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A49.tmp **INFECTED** Win32:Malware-gen
02:01:43.962 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A4A.tmp **INFECTED** Win32:Malware-gen
02:01:44.056 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A5.tmp **INFECTED** Win32:Malware-gen
02:01:44.167 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A50.tmp **INFECTED** Win32:Malware-gen
02:01:44.257 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A52.tmp **INFECTED** Win32:Malware-gen
02:01:44.390 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A58.tmp **INFECTED** Win32:Malware-gen
02:01:44.479 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A5A.tmp **INFECTED** Win32:Malware-gen
02:01:44.646 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A5D.tmp **INFECTED** Win32:Malware-gen
02:01:44.804 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A6.tmp **INFECTED** Win32:Malware-gen
02:01:44.924 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A68.tmp **INFECTED** Win32:Malware-gen
02:01:45.015 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A6A.tmp **INFECTED** Win32:Malware-gen
02:01:45.132 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A72.tmp **INFECTED** Win32:Malware-gen
02:01:47.253 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A7B.tmp **INFECTED** Win32:Malware-gen
02:01:47.453 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A7F.tmp **INFECTED** Win32:Malware-gen
02:01:47.532 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A80.tmp **INFECTED** Win32:Malware-gen
02:01:47.716 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A83.tmp **INFECTED** Win32:Malware-gen
02:01:47.861 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A87.tmp **INFECTED** Win32:Malware-gen
02:01:47.954 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A8F.tmp **INFECTED** Win32:Malware-gen
02:01:48.010 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A90.tmp **INFECTED** Win32:Malware-gen
02:01:48.090 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A94.tmp **INFECTED** Win32:Malware-gen
02:01:48.184 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8A98.tmp **INFECTED** Win32:Malware-gen
02:01:48.259 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AA2.tmp **INFECTED** Win32:Malware-gen
02:01:48.327 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AA8.tmp **INFECTED** Win32:Malware-gen
02:01:48.426 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AAD.tmp **INFECTED** Win32:Malware-gen
02:01:48.565 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AAF.tmp **INFECTED** Win32:Malware-gen
02:01:48.632 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AB0.tmp **INFECTED** Win32:Malware-gen
02:01:48.718 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AB3.tmp **INFECTED** Win32:Malware-gen
02:01:48.779 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AB8.tmp **INFECTED** Win32:Malware-gen
02:01:48.863 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AC.tmp **INFECTED** Win32:Malware-gen
02:01:48.925 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AC2.tmp **INFECTED** Win32:Malware-gen
02:01:48.969 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AC5.tmp **INFECTED** Win32:Malware-gen
02:01:49.028 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8ACE.tmp **INFECTED** Win32:Malware-gen
02:01:49.119 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AD.tmp **INFECTED** Win32:Malware-gen
02:01:49.230 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AD1.tmp **INFECTED** Win32:Malware-gen
02:01:49.300 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8ADE.tmp **INFECTED** Win32:Malware-gen
02:01:49.381 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AE7.tmp **INFECTED** Win32:Malware-gen
02:01:49.461 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AEC.tmp **INFECTED** Win32:Malware-gen
02:01:49.524 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AF1.tmp **INFECTED** Win32:Malware-gen
02:01:49.613 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AF6.tmp **INFECTED** Win32:Malware-gen
02:01:49.703 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AF9.tmp **INFECTED** Win32:Malware-gen
02:01:49.799 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8AFD.tmp **INFECTED** Win32:Malware-gen
02:01:49.890 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B0.tmp **INFECTED** Win32:Malware-gen
02:01:50.038 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B03.tmp **INFECTED** Win32:Malware-gen
02:01:50.115 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B0B.tmp **INFECTED** Win32:Malware-gen
02:01:50.200 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B12.tmp **INFECTED** Win32:Malware-gen
02:01:50.272 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B15.tmp **INFECTED** Win32:Malware-gen
02:01:50.379 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B23.tmp **INFECTED** Win32:Malware-gen
02:01:50.487 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B25.tmp **INFECTED** Win32:Malware-gen
02:01:50.629 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B2C.tmp **INFECTED** Win32:Malware-gen
02:01:50.747 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B2F.tmp **INFECTED** Win32:Malware-gen
02:01:50.835 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B31.tmp **INFECTED** Win32:Malware-gen
02:01:50.930 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B36.tmp **INFECTED** Win32:Malware-gen
02:01:51.059 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B3C.tmp **INFECTED** Win32:Malware-gen
02:01:51.162 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B4.tmp **INFECTED** Win32:Malware-gen
02:01:51.233 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B45.tmp **INFECTED** Win32:Malware-gen
02:01:51.298 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B46.tmp **INFECTED** Win32:Malware-gen
02:01:51.443 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B4C.tmp **INFECTED** Win32:Malware-gen
02:01:51.526 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B5.tmp **INFECTED** Win32:Malware-gen
02:01:51.721 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B51.tmp **INFECTED** Win32:Malware-gen
02:01:51.844 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B55.tmp **INFECTED** Win32:Malware-gen
02:01:51.949 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B5C.tmp **INFECTED** Win32:Malware-gen
02:01:52.047 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B5D.tmp **INFECTED** Win32:Malware-gen
02:01:52.118 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B74.tmp **INFECTED** Win32:Malware-gen
02:01:52.197 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B7A.tmp **INFECTED** Win32:Malware-gen
02:01:52.458 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B7D.tmp **INFECTED** Win32:Malware-gen
02:01:52.526 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B8C.tmp **INFECTED** Win32:Malware-gen
02:01:52.594 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B8D.tmp **INFECTED** Win32:Malware-gen
02:01:52.671 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B93.tmp **INFECTED** Win32:Malware-gen
02:01:52.732 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B99.tmp **INFECTED** Win32:Malware-gen
02:01:52.829 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B9A.tmp **INFECTED** Win32:Malware-gen
02:01:52.909 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B9B.tmp **INFECTED** Win32:Malware-gen
02:01:52.985 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8B9C.tmp **INFECTED** Win32:Malware-gen
02:01:53.158 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BA.tmp **INFECTED** Win32:Malware-gen
02:01:53.272 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BA0.tmp **INFECTED** Win32:Malware-gen
02:01:53.476 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BAC.tmp **INFECTED** Win32:Malware-gen
02:01:53.547 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BAF.tmp **INFECTED** Win32:Malware-gen
02:01:53.830 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BB9.tmp **INFECTED** Win32:Malware-gen
02:01:53.988 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BBB.tmp **INFECTED** Win32:Malware-gen
02:01:54.152 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BBF.tmp **INFECTED** Win32:Malware-gen
02:01:54.280 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BC0.tmp **INFECTED** Win32:Malware-gen
02:01:54.403 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BC7.tmp **INFECTED** Win32:Malware-gen
02:01:56.499 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BC8.tmp **INFECTED** Win32:Malware-gen
02:01:56.686 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BCC.tmp **INFECTED** Win32:Malware-gen
02:01:56.787 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BD2.tmp **INFECTED** Win32:Malware-gen
02:01:56.913 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BD5.tmp **INFECTED** Win32:Malware-gen
02:01:57.007 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BD9.tmp **INFECTED** Win32:Malware-gen
02:01:57.129 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BDF.tmp **INFECTED** Win32:Malware-gen
02:01:57.183 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BE0.tmp **INFECTED** Win32:Malware-gen
02:01:57.253 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BE6.tmp **INFECTED** Win32:Malware-gen
02:01:57.349 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BE7.tmp **INFECTED** Win32:Malware-gen
02:01:57.404 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BED.tmp **INFECTED** Win32:Malware-gen
02:01:57.481 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8BFA.tmp **INFECTED** Win32:Malware-gen
02:01:57.574 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C02.tmp **INFECTED** Win32:Malware-gen
02:01:57.666 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C03.tmp **INFECTED** Win32:Malware-gen
02:01:57.745 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C05.tmp **INFECTED** Win32:Malware-gen
02:01:57.936 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C06.tmp **INFECTED** Win32:Malware-gen
02:01:58.030 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C09.tmp **INFECTED** Win32:Malware-gen
02:01:58.082 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C0A.tmp **INFECTED** Win32:Malware-gen
02:01:58.165 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C0B.tmp **INFECTED** Win32:Malware-gen
02:01:58.248 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C0D.tmp **INFECTED** Win32:Malware-gen
02:01:58.360 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C10.tmp **INFECTED** Win32:Malware-gen
02:01:58.564 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C12.tmp **INFECTED** Win32:Malware-gen
02:01:58.655 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C20.tmp **INFECTED** Win32:Malware-gen
02:01:58.741 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C22.tmp **INFECTED** Win32:Malware-gen
02:01:58.847 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C25.tmp **INFECTED** Win32:Malware-gen
02:01:58.940 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C2F.tmp **INFECTED** Win32:Malware-gen
02:01:59.055 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C37.tmp **INFECTED** Win32:Malware-gen
02:01:59.131 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C4C.tmp **INFECTED** Win32:Malware-gen
02:01:59.265 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C53.tmp **INFECTED** Win32:Malware-gen
02:01:59.393 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C54.tmp **INFECTED** Win32:Malware-gen
02:01:59.485 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C55.tmp **INFECTED** Win32:Malware-gen
02:01:59.570 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C5C.tmp **INFECTED** Win32:Malware-gen
02:01:59.654 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C61.tmp **INFECTED** Win32:Malware-gen
02:01:59.736 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C7.tmp **INFECTED** Win32:Malware-gen
02:01:59.874 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C74.tmp **INFECTED** Win32:Malware-gen
02:01:59.969 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C78.tmp **INFECTED** Win32:Malware-gen
02:02:00.048 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C7C.tmp **INFECTED** Win32:Malware-gen
02:02:00.171 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C7D.tmp **INFECTED** Win32:Malware-gen
02:02:00.306 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C84.tmp **INFECTED** Win32:Malware-gen
02:02:00.418 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C87.tmp **INFECTED** Win32:Malware-gen
02:02:00.505 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C8C.tmp **INFECTED** Win32:Malware-gen
02:02:00.588 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C8D.tmp **INFECTED** Win32:Malware-gen
02:02:00.687 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C91.tmp **INFECTED** Win32:Malware-gen
02:02:00.738 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C94.tmp **INFECTED** Win32:Malware-gen
02:02:00.975 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C96.tmp **INFECTED** Win32:Malware-gen
02:02:01.078 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C9C.tmp **INFECTED** Win32:Malware-gen
02:02:01.183 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8C9E.tmp **INFECTED** Win32:Malware-gen
02:02:01.396 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CA3.tmp **INFECTED** Win32:Malware-gen
02:02:01.488 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CAA.tmp **INFECTED** Win32:Malware-gen
02:02:01.563 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CAB.tmp **INFECTED** Win32:Malware-gen
02:02:01.644 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CB3.tmp **INFECTED** Win32:Malware-gen
02:02:01.739 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CBA.tmp **INFECTED** Win32:Malware-gen
02:02:01.884 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CBF.tmp **INFECTED** Win32:Malware-gen
02:02:01.977 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CC.tmp **INFECTED** Win32:Malware-gen
02:02:02.090 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CC0.tmp **INFECTED** Win32:Malware-gen
02:02:02.203 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CC2.tmp **INFECTED** Win32:Malware-gen
02:02:02.279 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CC3.tmp **INFECTED** Win32:Malware-gen
02:02:02.357 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CCB.tmp **INFECTED** Win32:Malware-gen
02:02:02.506 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CD1.tmp **INFECTED** Win32:Malware-gen
02:02:02.618 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CD8.tmp **INFECTED** Win32:Malware-gen
02:02:02.684 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CD9.tmp **INFECTED** Win32:Malware-gen
02:02:02.796 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CDC.tmp **INFECTED** Win32:Malware-gen
02:02:02.958 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CE3.tmp **INFECTED** Win32:Malware-gen
02:02:03.135 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CE7.tmp **INFECTED** Win32:Malware-gen
02:02:03.283 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CE9.tmp **INFECTED** Win32:Malware-gen
02:02:03.540 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CED.tmp **INFECTED** Win32:Malware-gen
02:02:03.677 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CF.tmp **INFECTED** Win32:Malware-gen
02:02:05.551 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CF5.tmp **INFECTED** Win32:Malware-gen
02:02:05.740 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8CFF.tmp **INFECTED** Win32:Malware-gen
02:02:05.961 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D00.tmp **INFECTED** Win32:Malware-gen
02:02:06.027 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D09.tmp **INFECTED** Win32:Malware-gen
02:02:06.101 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D0C.tmp **INFECTED** Win32:Malware-gen
02:02:06.304 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D10.tmp **INFECTED** Win32:Malware-gen
02:02:06.383 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D14.tmp **INFECTED** Win32:Malware-gen
02:02:06.468 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D1C.tmp **INFECTED** Win32:Malware-gen
02:02:06.549 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D1D.tmp **INFECTED** Win32:Malware-gen
02:02:06.620 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D1E.tmp **INFECTED** Win32:Malware-gen
02:02:06.716 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D1F.tmp **INFECTED** Win32:Malware-gen
02:02:06.814 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D22.tmp **INFECTED** Win32:Malware-gen
02:02:06.905 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D26.tmp **INFECTED** Win32:Malware-gen
02:02:06.990 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D27.tmp **INFECTED** Win32:Malware-gen
02:02:07.102 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D28.tmp **INFECTED** Win32:Malware-gen
02:02:07.219 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D2E.tmp **INFECTED** Win32:Malware-gen
02:02:07.325 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D30.tmp **INFECTED** Win32:Malware-gen
02:02:07.418 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D32.tmp **INFECTED** Win32:Malware-gen
02:02:07.492 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D3F.tmp **INFECTED** Win32:Malware-gen
02:02:07.624 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D43.tmp **INFECTED** Win32:Malware-gen
02:02:07.786 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D45.tmp **INFECTED** Win32:Malware-gen
02:02:07.901 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D46.tmp **INFECTED** Win32:Malware-gen
02:02:08.019 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D4B.tmp **INFECTED** Win32:Malware-gen
02:02:08.140 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D54.tmp **INFECTED** Win32:Malware-gen
02:02:08.327 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D7.tmp **INFECTED** Win32:Malware-gen
02:02:08.580 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8D92.tmp **INFECTED** Win32:Malware-gen
02:02:08.844 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DA.tmp **INFECTED** Win32:Malware-gen
02:02:09.074 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DA2.tmp **INFECTED** Win32:Malware-gen
02:02:09.168 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DAF.tmp **INFECTED** Win32:Malware-gen
02:02:09.318 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DB5.tmp **INFECTED** Win32:Malware-gen
02:02:09.425 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DB6.tmp **INFECTED** Win32:Malware-gen
02:02:09.580 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DBD.tmp **INFECTED** Win32:Malware-gen
02:02:09.892 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DBE.tmp **INFECTED** Win32:Malware-gen
02:02:10.369 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DBF.tmp **INFECTED** Win32:Malware-gen
02:02:10.659 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DC.tmp **INFECTED** Win32:Malware-gen
02:02:10.906 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DD4.tmp **INFECTED** Win32:Malware-gen
02:02:11.017 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DD8.tmp **INFECTED** Win32:Malware-gen
02:02:11.126 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DDB.tmp **INFECTED** Win32:Malware-gen
02:02:11.255 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DDD.tmp **INFECTED** Win32:Malware-gen
02:02:11.542 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DDE.tmp **INFECTED** Win32:Malware-gen
02:02:11.736 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DE3.tmp **INFECTED** Win32:Malware-gen
02:02:11.846 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DEB.tmp **INFECTED** Win32:Malware-gen
02:02:12.258 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DEC.tmp **INFECTED** Win32:Malware-gen
02:02:12.399 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DED.tmp **INFECTED** Win32:Malware-gen
02:02:12.835 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DF0.tmp **INFECTED** Win32:Malware-gen
02:02:12.973 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DF2.tmp **INFECTED** Win32:Malware-gen
02:02:13.169 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8DF6.tmp **INFECTED** Win32:Malware-gen
02:02:13.346 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8E.tmp **INFECTED** Win32:Malware-gen
02:02:13.606 File: C:\Users\Paul.Paul-PC\AppData\Local\temp\DWH8E03.tmp **INFECTED** Win32:Malware-gen
02:02:15.528 Disk 0 MBR has been saved successfully to "C:\Users\Paul.Paul-PC\Desktop\MBR.dat"
02:02:15.989 The log file has been saved successfully to "C:\Users\Paul.Paul-PC\Desktop\aswMBR.txt"


Results of screen317's Security Check version 0.99.73
Windows 7 Service Pack 1 x86 (UAC is disabled!)
Internet Explorer 10
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
CCleaner
Java 7 Update 7
Java version out of Date!
Adobe Flash Player 11.8.800.168
Adobe Reader XI
Mozilla Firefox (24.0)
````````Process Check: objlist.exe by Laurent````````
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 3%
````````````````````End of Log``````````````````````


# AdwCleaner v3.005 - Report created 26/09/2013 at 02:22:41
# Updated 22/09/2013 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (32 bits)
# Username : Paul - PAUL-PC
# Running from : C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Trymedia
Folder Deleted : C:\Program Files\fbphotozoom
Folder Deleted : C:\Program Files\Common Files\Software Update Utility
Folder Deleted : C:\Program Files\Common Files\spigot
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnu.xpt
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll
File Deleted : C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.xpt

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2786678
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16455


-\\ Mozilla Firefox v24.0 (en-US)

*************************

AdwCleaner[R0].txt - [2848 octets] - [26/09/2013 02:17:34]
AdwCleaner[S0].txt - [2841 octets] - [26/09/2013 02:22:41]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2901 octets] ##########


OTL logfile created on: 9/26/2013 2:33:04 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul.Paul-PC\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 60.13% Memory free
5.92 Gb Paging File | 4.60 Gb Available in Paging File | 77.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 118.01 Gb Free Space | 54.08% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Paul.Paul-PC\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe (Spigot, Inc.)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\libcef.dll ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll ()
MOD - C:\Program Files\Git\git-cheetah\git_shell_ext.dll ()
MOD - C:\Program Files\Common Files\Adobe\CEPServiceManager4\zlib1.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\Apache2.4.4\bin\httpd.exe (Apache Software Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\Paul\AppData\Local\Temp\catchme.sys File not found
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130925.008\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130925.008\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\Windows\System32\drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (O2MDGRDR) – C:\Windows\System32\drivers\o2mdg.sys (O2Micro )
DRV - (O2SDGRDR) – C:\Windows\System32\drivers\o2sdg.sys (O2Micro )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{3A434D2D-EFE9-4239-836B-6EFFC9FE9581}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{5033EE8D-A640-41CA-9012-7AFD6DF2C83F}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=714647&fr=spigot-yhp-ie
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{19CE7FE4-BED6-4C79-9A4D-37D8D1AA91E9}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=714647"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130917
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:[removed]
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=714647&p="
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom14.xpi
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/19 08:28:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/26 02:22:42 | 000,000,000 | —D | M]

[2013/05/02 19:14:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2013/09/22 18:16:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions
[2013/09/18 19:32:47 | 000,000,000 | —D | M] (WOT) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/09/22 18:16:30 | 000,534,729 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/07/30 20:39:55 | 000,824,302 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/08/06 19:18:55 | 000,000,915 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\searchplugins\yahoo.xml
[2013/09/19 08:28:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/19 08:28:10 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/04/12 17:29:19 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll

O1 HOSTS File: ([2013/09/07 22:16:12 | 000,000,054 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SearchProtection] C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE (Spigot, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B82892F4-0671-4942-BCB8-BCB5812C3AE4}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {4F07DA45-8170-4859-9B5F-037EF2970034} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/26 02:15:51 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/26 00:58:11 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Paul.Paul-PC\Desktop\aswMBR.exe
[2013/09/22 20:26:28 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Paul.Paul-PC\Desktop\HiJackThis.exe
[2013/09/21 20:24:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:22:49 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\AppData\Roaming\Malwarebytes
[2013/09/19 08:28:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 22:20:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WampServer
[2013/09/07 22:15:27 | 000,000,000 | —D | C] – C:\wamp
[2013/09/07 21:41:52 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Desktop\php-5.5.3
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/09/26 02:33:07 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 02:33:07 | 000,014,256 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/26 02:26:01 | 000,000,372 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2013/09/26 02:24:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/26 02:24:19 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2013/09/26 02:18:10 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/26 02:15:21 | 001,042,066 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe
[2013/09/26 02:04:21 | 000,891,144 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\SecurityCheck.exe
[2013/09/26 02:02:15 | 000,000,512 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\MBR.dat
[2013/09/26 00:58:16 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Paul.Paul-PC\Desktop\aswMBR.exe
[2013/09/22 20:32:40 | 000,625,664 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\dds.scr
[2013/09/22 20:26:27 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Paul.Paul-PC\Desktop\HiJackThis.exe
[2013/09/21 20:55:45 | 000,726,092 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/21 20:24:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:23:18 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/19 21:18:06 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/09/19 21:18:06 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/17 01:01:56 | 000,108,254 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/09/15 12:57:33 | 003,868,360 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/09/13 21:49:22 | 000,001,456 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/09/05 14:56:33 | 000,066,389 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.pdf
[2013/09/05 14:56:17 | 000,073,594 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.rtf
[2013/08/30 19:36:21 | 000,140,137 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png
[2013/08/29 14:27:10 | 000,001,919 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\New Text Document.html
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/09/26 02:15:20 | 001,042,066 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe
[2013/09/26 02:04:21 | 000,891,144 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\SecurityCheck.exe
[2013/09/26 02:02:15 | 000,000,512 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\MBR.dat
[2013/09/22 20:32:50 | 000,625,664 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\dds.scr
[2013/09/21 20:55:45 | 000,726,092 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/17 01:01:52 | 000,108,254 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/08/30 19:36:20 | 000,140,137 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png
[2013/08/19 03:47:33 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe PNG Format CC Prefs
[2013/08/14 23:49:58 | 000,000,054 | —- | C] () – C:\Users\Paul.Paul-PC\.gitconfig
[2013/07/06 19:22:16 | 000,001,456 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/07/06 18:55:57 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe BMP Format CC Prefs

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll\system32\wbem\wbemess.dll
"ThreadingModel" = Apartment

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:1AE68282

< End of report >


OTL Extras logfile created on: 9/26/2013 2:33:04 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul.Paul-PC\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.78 Gb Available Physical Memory | 60.13% Memory free
5.92 Gb Paging File | 4.60 Gb Available in Paging File | 77.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 118.01 Gb Free Space | 54.08% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS6\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0294BB2F-6178-459D-8C46-8D1C40D6AD6B}" = rport=445 | protocol=6 | dir=out | app=system |
"{057550CC-1C7E-4C7B-A2F8-3A8DDC978C8C}" = lport=138 | protocol=17 | dir=in | app=system |
"{08E024BB-596A-4DFF-A430-159062EB67CE}" = lport=10243 | protocol=6 | dir=in | app=system |
"{19A5737B-0BEE-43C8-BCD3-3CC714AA4FD3}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{25B9D31D-64EC-44F5-900B-17177C3E5D3C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{295EF879-34FC-4A05-A484-51AA1443280E}" = lport=445 | protocol=6 | dir=in | app=system |
"{2FA65B31-3A9D-4C20-AFC6-469495F0EF44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4084E937-EAAA-47EE-9520-7BE7CE434C09}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{4BF5EB07-06A2-40E2-B5B6-244EF5C49A0F}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{5456EA1E-AF45-48BD-9C96-AB99A6CCF1D9}" = lport=139 | protocol=6 | dir=in | app=system |
"{6364B77A-8796-4078-B3CC-5963A3E70B4F}" = rport=139 | protocol=6 | dir=out | app=system |
"{6EFD3216-D4DB-448C-81DA-E8838C66FFD2}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7C7BD74E-D59D-40F9-8481-A74C4729E9DD}" = rport=138 | protocol=17 | dir=out | app=system |
"{86444BB3-291D-4D31-A046-BB4AA3243C28}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{AF8150A9-8B4A-4262-900E-D368942052B3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BE10AB93-C4A6-464B-BE93-069E778BFF99}" = rport=10243 | protocol=6 | dir=out | app=system |
"{C232D951-55E7-4D04-9346-F88A07FC0B22}" = lport=137 | protocol=17 | dir=in | app=system |
"{C428A183-FD79-40B5-990D-895328F43AC8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{CF0676E6-E2EC-438A-9741-7029DEBD00CE}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F534D21D-02A4-4E48-A237-A3745ED5E6D3}" = rport=137 | protocol=17 | dir=out | app=system |
"{F9C1EEE5-72B7-40C6-BC7C-64E9DF7DEB39}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{003C7A18-60D9-4C89-94D8-DE42C1AA1D76}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{02A4D600-582A-4C14-ADFE-C125CF0CB18F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{0C17B36C-60FB-4BB1-A335-C2EBE1FB63C0}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\cqcweapons\counter-strike\hl.exe |
"{0C37FC6A-45C3-4246-B9BF-769AF169C719}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\cqcweapons\counter-strike\hl.exe |
"{1473D86F-6F04-46A3-9153-CD04272511DC}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{3957575C-7ACA-4AB0-B555-9077CDEDBA56}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe |
"{4849799C-D8E9-4360-8F9A-6B5F2BCC7EA4}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{56D0F97A-5D3C-46D7-962E-78AEBB6734FF}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{56E808A1-BFD0-4B79-B567-B9FA848D697F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{61FB8AD2-C831-45AB-9DFB-D685C3A8300D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{62F27534-2769-4D2F-B42F-E96E62F64F44}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{65901CFC-D156-4C8F-90EA-C26D256CA195}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{68F6992D-6E9D-4F14-88EC-3E0B8BEC7EFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{792347FA-6E18-42DB-A312-3722BC5920DA}" = protocol=17 | dir=in | app=c:\program files\steam\steamapps\cqcweapons\counter-strike\hl.exe |
"{8642AF85-31DC-4BB3-8E9D-1E478C224084}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A5589677-56C4-46C1-A86B-1F0B5425786F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{AB3FBA72-52C3-4476-9A38-230DBE05659B}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BC7833D1-AE4B-4CAB-BDD5-6EA587E5C763}" = protocol=6 | dir=out | app=system |
"{CE504808-152F-4073-8BB9-0F8E7C4D30C6}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D0C84112-3166-45FB-A004-48BF72019D30}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\common\half-life\hl.exe |
"{D3648D1D-2BA3-4973-9B7E-EDC907B6E342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E8715BB0-E132-4617-B344-62E03BFE2C1C}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{E926E57D-011D-4F63-BCC5-FFCFDC28D091}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EEE142F8-8936-4D4C-A080-2FDC773D193A}" = protocol=6 | dir=in | app=c:\program files\steam\steamapps\cqcweapons\counter-strike\hl.exe |
"{EFA98652-B437-42AA-B7D3-EFFD71ED4ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F7DCF881-DB9D-4779-8D1C-CCCBAC7C73FF}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"TCP Query User{36B5CF48-8607-465C-B0A6-6987F524711F}C:\program files\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"TCP Query User{BB9B816B-4D8D-472E-8852-2EBF62006B22}C:\program files\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"UDP Query User{39F2279F-DF48-4C2E-ADC8-168B3784A53F}C:\program files\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files\oovoo\oovoo.exe |
"UDP Query User{AA572A34-D43F-4899-B240-9B291B7296C1}C:\program files\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files\oovoo\oovoo.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Creator Data
"{09760D42-E223-42AD-8C3E-55B47D0DDAC3}" = Roxio Creator DE 10.3
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F6F6876-6334-4977-B5DD-CFC12E193420}" = iTunes
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Creator Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}" = PDF Settings CC
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}" = Adobe Photoshop CC
"{2EFCC193-D915-4CCB-9201-31773A27BC06}" = Symantec Endpoint Protection
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3138EAD3-700B-4A10-B617-B3F8096EE30D}" = Dell Edoc Viewer
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{494367EC-82A9-4C0D-A788-74A967998E8C}" = FXCM Trading Station
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{731B0E4D-F4C7-450C-95B0-E1A3176B1C75}" = Dell Backup and Recovery Manager
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Creator Audio
"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C2690CF-5B74-4F93-8139-7B5644CD6A3B}" = MobileMe Control Panel
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISER_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISER_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISER_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISER_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISER_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.04)
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Creator Copy
"{B6F7DBE7-2FE2-458F-A738-B10832746036}" = Microsoft Reader
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4DDFAA1-EC37-4529-AD5B-A433ADE68662}" = Apple Mobile Device Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EA5D1265-C23C-4410-B722-19314A654B13}" = calibre
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Creator DE 10.3
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"CCleaner" = CCleaner
"Creative OEM013" = Laptop Integrated Webcam Driver (1.01.01.0529)
"Dell Wireless WLAN Card Utility" = Dell Wireless WLAN Card Utility
"ENTERPRISER" = Microsoft Office Enterprise 2007
"Git_is1" = Git version 1.8.3-preview20130601
"HDMI" = Intel® Graphics Media Accelerator Driver
"LiveUpdate" = LiveUpdate 3.3 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"McAfee Security Scan" = McAfee Security Scan Plus
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 24.0 (x86 en-US)" = Mozilla Firefox 24.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Steam App 10" = Counter-Strike
"TVWiz" = Intel® TV Wizard
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 2.0.8
"WampServer 2_is1" = WampServer 2.4
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5f7eb300e2ea4ebf" = GitHub
"FileZilla Client" = FileZilla Client 3.7.3
"Search Protection" = Search Protection

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/26/2013 1:17:58 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec\Symantec
Endpoint Protection\SavUI.exe Event Info: Write Memory Action Taken: Logged Actor
Process: C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe
(PID 792) Time: Thursday, September 26, 2013 1:17:58 AM

Error - 9/26/2013 1:37:10 AM | Computer Name = Paul-PC | Source = Application Error | ID = 1000
Description = Faulting application name: SavUI.exe, version: 11.0.5002.290, time
stamp: 0x4ab2d810 Faulting module name: LDVPCtls.ocx, version: 11.0.5002.290, time
stamp: 0x4ab2e69f Exception code: 0xc0000005 Fault offset: 0x000272a3 Faulting process
id: 0x16f8 Faulting application start time: 0x01ceba77c183d809 Faulting application
path: C:\Program Files\Symantec\Symantec Endpoint Protection\SavUI.exe Faulting
module path: C:\Program Files\Symantec\Symantec Endpoint Protection\LDVPCtls.ocx
Report
Id: afdc8266-266d-11e3-9297-0024e8eb26fd

Error - 9/26/2013 2:01:12 AM | Computer Name = Paul-PC | Source = Application Hang | ID = 1002
Description = The program SavUI.exe version 11.0.5002.290 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 16f8 Start
Time: 01ceba77c183d809 Termination Time: 4 Application Path: C:\Program Files\Symantec\Symantec
Endpoint Protection\SavUI.exe Report Id: f7e3e794-2670-11e3-9297-0024e8eb26fd

Error - 9/26/2013 2:22:40 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec\Symantec
Endpoint Protection\SmcGui.exe Event Info: Terminate Process Action Taken: Logged
Actor
Process: C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe (PID 5520) Time: Thursday,
September 26, 2013 2:22:40 AM

Error - 9/26/2013 2:22:41 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Common Files\Symantec
Shared\ccApp.exe Event Info: Terminate Process Action Taken: Logged Actor Process:
C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe (PID 5520) Time: Thursday, September
26, 2013 2:22:41 AM

Error - 9/26/2013 2:22:41 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec\Symantec
Endpoint Protection\DWHWizrd.exe Event Info: Terminate Process Action Taken: Logged
Actor
Process: C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe (PID 5520) Time: Thursday,
September 26, 2013 2:22:41 AM

Error - 9/26/2013 2:22:42 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec\Symantec
Endpoint Protection\SavUI.exe Event Info: Terminate Process Action Taken: Logged
Actor
Process: C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe (PID 5520) Time: Thursday,
September 26, 2013 2:22:42 AM

Error - 9/26/2013 2:22:43 AM | Computer Name = Paul-PC | Source = Symantec AntiVirus | ID = 16711725
Description = SYMANTEC TAMPER PROTECTION ALERT Target: C:\Program Files\Symantec\Symantec
Endpoint Protection\SmcGui.exe Event Info: Terminate Process Action Taken: Logged
Actor
Process: C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe (PID 5520) Time: Thursday,
September 26, 2013 2:22:43 AM

Error - 9/26/2013 2:26:04 AM | Computer Name = Paul-PC | Source = WinMgmt | ID = 28
Description =

Error - 9/26/2013 2:28:05 AM | Computer Name = Paul-PC | Source = SecurityCenter | ID = 3
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall.

[ Broadcom Wireless LAN Events ]
Error - 6/24/2013 11:18:44 PM | Computer Name = Paul-PC | Source = WLAN-Tray | ID = 0
Description = 23:18:44, Mon, Jun 24, 13 Error - Unable to gain access to user store


Error - 8/28/2013 8:30:05 PM | Computer Name = Paul-PC | Source = WLAN-Tray | ID = 0
Description = 20:30:05, Wed, Aug 28, 13 Error - Unable to gain access to user store


Error - 9/15/2013 12:52:28 PM | Computer Name = Paul-PC | Source = WLAN-Tray | ID = 0
Description = 12:52:28, Sun, Sep 15, 13 Error - Unable to gain access to user store


[ Media Center Events ]
Error - 6/3/2012 8:45:34 PM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 8:45:33 PM - Error connecting to the internet. 8:45:33 PM - Unable
to contact server..

Error - 6/3/2012 11:19:02 PM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 11:19:02 PM - Error connecting to the internet. 11:19:02 PM - Unable
to contact server..

Error - 6/4/2012 1:19:00 AM | Computer Name = Paul-PC | Source = MCUpdate | ID = 0
Description = 1:19:00 AM - Error connecting to the internet. 1:19:00 AM - Unable
to contact server..

[ System Events ]
Error - 9/24/2013 10:01:02 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/24/2013 10:01:02 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/24/2013 10:01:24 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/24/2013 11:16:22 PM | Computer Name = Paul-PC | Source = BROWSER | ID = 8032
Description =

Error - 9/25/2013 8:34:54 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/25/2013 8:34:54 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/25/2013 8:35:11 PM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/26/2013 2:23:59 AM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/26/2013 2:23:59 AM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!

Error - 9/26/2013 2:24:26 AM | Computer Name = Paul-PC | Source = volmgr | ID = 262190
Description = Crash dump initialization failed!


< End of report >

Attachments:

Hi pmedvins,

[external image: Posted Image] TDSSKiller

Please download TDSSKiller.zip - Extract it to your desktop
  • TDSSKiller.exe
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=========================

[external image: Posted Image] ComboFix

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

=========================

In your next post please provide the following:
  • TDSSKiller log
  • Combofix.txt
16:53:02.0169 5720 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 16:53:02.0839 5720 ============================================================ 16:53:02.0839 5720 Current date / time: 2013/09/26 16:53:02.0839 16:53:02.0839 5720 SystemInfo: 16:53:02.0839 5720 16:53:02.0839 5720 OS Version: 6.1.7601 ServicePack: 1.0 16:53:02.0839 5720 Product type: Workstation 16:53:02.0839 5720 ComputerName: PAUL-PC 16:53:02.0839 5720 UserName: Paul 16:53:02.0839 5720 Windows directory: C:\Windows 16:53:02.0839 5720 System windows directory: C:\Windows 16:53:02.0839 5720 Processor architecture: Intel x86 16:53:02.0839 5720 Number of processors: 2 16:53:02.0839 5720 Page size: 0x1000 16:53:02.0839 5720 Boot type: Normal boot 16:53:02.0839 5720 ============================================================ 16:53:03.0479 5720 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 16:53:03.0489 5720 ============================================================ 16:53:03.0489 5720 \Device\Harddisk0\DR0: 16:53:03.0489 5720 MBR partitions: 16:53:03.0489 5720 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x14000, BlocksNum 0x1D4C000 16:53:03.0489 5720 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D60000, BlocksNum 0x1B465170 16:53:03.0489 5720 ============================================================ 16:53:03.0529 5720 C: <-> \Device\Harddisk0\DR0\Partition2 16:53:03.0529 5720 ============================================================ 16:53:03.0529 5720 Initialize success 16:53:03.0529 5720 ============================================================ 16:53:16.0024 5856 ============================================================ 16:53:16.0024 5856 Scan started 16:53:16.0024 5856 Mode: Manual; 16:53:16.0024 5856 ============================================================ 16:53:16.0374 5856 ================ Scan system memory ======================== 16:53:16.0374 5856 System memory - ok 16:53:16.0374 5856 ================ Scan services ============================= 16:53:16.0694 5856 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 16:53:16.0694 5856 1394ohci - ok 16:53:16.0764 5856 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys 16:53:16.0774 5856 ACPI - ok 16:53:16.0834 5856 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 16:53:16.0834 5856 AcpiPmi - ok 16:53:16.0974 5856 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 16:53:16.0974 5856 AdobeARMservice - ok 16:53:17.0054 5856 [ 24A0876D07EF356DCBC1D7A7929354AB ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 16:53:17.0064 5856 AdobeFlashPlayerUpdateSvc - ok 16:53:17.0114 5856 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys 16:53:17.0114 5856 adp94xx - ok 16:53:17.0184 5856 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys 16:53:17.0194 5856 adpahci - ok 16:53:17.0204 5856 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys 16:53:17.0204 5856 adpu320 - ok 16:53:17.0254 5856 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 16:53:17.0254 5856 AeLookupSvc - ok 16:53:17.0324 5856 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys 16:53:17.0334 5856 AFD - ok 16:53:17.0364 5856 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys 16:53:17.0364 5856 agp440 - ok 16:53:17.0414 5856 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys 16:53:17.0424 5856 aic78xx - ok 16:53:17.0484 5856 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe 16:53:17.0484 5856 ALG - ok 16:53:17.0564 5856 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys 16:53:17.0564 5856 aliide - ok 16:53:17.0584 5856 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys 16:53:17.0584 5856 amdagp - ok 16:53:17.0644 5856 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys 16:53:17.0654 5856 amdide - ok 16:53:17.0704 5856 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys 16:53:17.0704 5856 AmdK8 - ok 16:53:17.0714 5856 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys 16:53:17.0714 5856 AmdPPM - ok 16:53:17.0774 5856 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys 16:53:17.0774 5856 amdsata - ok 16:53:17.0784 5856 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys 16:53:17.0794 5856 amdsbs - ok 16:53:17.0814 5856 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys 16:53:17.0814 5856 amdxata - ok 16:53:17.0884 5856 [ D7723A101C5CB4C0FA979E4DDA732EC0 ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys 16:53:17.0884 5856 ApfiltrService - ok 16:53:17.0924 5856 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys 16:53:17.0924 5856 AppID - ok 16:53:17.0964 5856 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll 16:53:17.0964 5856 AppIDSvc - ok 16:53:18.0004 5856 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll 16:53:18.0004 5856 Appinfo - ok 16:53:18.0094 5856 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 16:53:18.0104 5856 Apple Mobile Device - ok 16:53:18.0144 5856 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll 16:53:18.0144 5856 AppMgmt - ok 16:53:18.0184 5856 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys 16:53:18.0194 5856 arc - ok 16:53:18.0194 5856 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys 16:53:18.0204 5856 arcsas - ok 16:53:18.0344 5856 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 16:53:18.0344 5856 aspnet_state - ok 16:53:18.0384 5856 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 16:53:18.0394 5856 AsyncMac - ok 16:53:18.0454 5856 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys 16:53:18.0454 5856 atapi - ok 16:53:18.0524 5856 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 16:53:18.0534 5856 AudioEndpointBuilder - ok 16:53:18.0544 5856 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll 16:53:18.0544 5856 Audiosrv - ok 16:53:18.0634 5856 [ 15ACA2AD17ACECA4814F249783E63AD3 ] avgtp C:\Windows\system32\drivers\avgtpx86.sys 16:53:18.0634 5856 avgtp - ok 16:53:18.0694 5856 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll 16:53:18.0694 5856 AxInstSV - ok 16:53:18.0754 5856 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys 16:53:18.0754 5856 b06bdrv - ok 16:53:18.0784 5856 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 16:53:18.0784 5856 b57nd60x - ok 16:53:18.0834 5856 [ EB4434444E2721D721A8AC8D5D2AD26B ] BCM42RLY C:\Windows\system32\drivers\BCM42RLY.sys 16:53:18.0834 5856 BCM42RLY - ok 16:53:18.0924 5856 [ 5245EBBE39ED9010240C20D21F5A26A9 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl6.sys 16:53:18.0984 5856 BCM43XX - ok 16:53:19.0034 5856 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll 16:53:19.0044 5856 BDESVC - ok 16:53:19.0074 5856 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys 16:53:19.0074 5856 Beep - ok 16:53:19.0144 5856 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll 16:53:19.0144 5856 BFE - ok 16:53:19.0224 5856 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll 16:53:19.0234 5856 BITS - ok 16:53:19.0274 5856 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 16:53:19.0274 5856 blbdrive - ok 16:53:19.0344 5856 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 16:53:19.0344 5856 bowser - ok 16:53:19.0374 5856 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys 16:53:19.0374 5856 BrFiltLo - ok 16:53:19.0384 5856 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys 16:53:19.0384 5856 BrFiltUp - ok 16:53:19.0404 5856 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys 16:53:19.0404 5856 BridgeMP - ok 16:53:19.0454 5856 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll 16:53:19.0464 5856 Browser - ok 16:53:19.0484 5856 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys 16:53:19.0494 5856 Brserid - ok 16:53:19.0494 5856 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 16:53:19.0504 5856 BrSerWdm - ok 16:53:19.0514 5856 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 16:53:19.0514 5856 BrUsbMdm - ok 16:53:19.0524 5856 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 16:53:19.0524 5856 BrUsbSer - ok 16:53:19.0534 5856 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys 16:53:19.0534 5856 BTHMODEM - ok 16:53:19.0594 5856 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll 16:53:19.0594 5856 bthserv - ok 16:53:20.0024 5856 catchme - ok 16:53:20.0114 5856 [ 27D036FB3D22CA8A6662FE960D1A937D ] ccEvtMgr C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 16:53:20.0114 5856 ccEvtMgr - ok 16:53:20.0170 5856 [ 27D036FB3D22CA8A6662FE960D1A937D ] ccSetMgr C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe 16:53:20.0170 5856 ccSetMgr - ok 16:53:20.0311 5856 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 16:53:20.0311 5856 cdfs - ok 16:53:20.0373 5856 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 16:53:20.0389 5856 cdrom - ok 16:53:20.0436 5856 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll 16:53:20.0436 5856 CertPropSvc - ok 16:53:20.0467 5856 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys 16:53:20.0467 5856 circlass - ok 16:53:20.0498 5856 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys 16:53:20.0514 5856 CLFS - ok 16:53:20.0592 5856 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 16:53:20.0592 5856 clr_optimization_v2.0.50727_32 - ok 16:53:20.0685 5856 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 16:53:20.0763 5856 clr_optimization_v4.0.30319_32 - ok 16:53:20.0779 5856 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys 16:53:20.0779 5856 CmBatt - ok 16:53:20.0826 5856 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys 16:53:20.0826 5856 cmdide - ok 16:53:20.0872 5856 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys 16:53:20.0888 5856 CNG - ok 16:53:20.0919 5856 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 16:53:20.0919 5856 Compbatt - ok 16:53:20.0982 5856 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys 16:53:20.0982 5856 CompositeBus - ok 16:53:20.0997 5856 COMSysApp - ok 16:53:21.0028 5856 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys 16:53:21.0044 5856 crcdisk - ok 16:53:21.0091 5856 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll 16:53:21.0091 5856 CryptSvc - ok 16:53:21.0153 5856 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys 16:53:21.0169 5856 CSC - ok 16:53:21.0216 5856 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll 16:53:21.0231 5856 CscService - ok 16:53:21.0262 5856 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll 16:53:21.0278 5856 DcomLaunch - ok 16:53:21.0309 5856 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll 16:53:21.0309 5856 defragsvc - ok 16:53:21.0372 5856 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 16:53:21.0372 5856 DfsC - ok 16:53:21.0450 5856 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll 16:53:21.0450 5856 Dhcp - ok 16:53:21.0481 5856 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys 16:53:21.0481 5856 discache - ok 16:53:21.0543 5856 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys 16:53:21.0543 5856 Disk - ok 16:53:21.0574 5856 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 16:53:21.0574 5856 Dnscache - ok 16:53:21.0652 5856 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll 16:53:21.0652 5856 dot3svc - ok 16:53:21.0715 5856 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll 16:53:21.0715 5856 DPS - ok 16:53:21.0762 5856 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 16:53:21.0762 5856 drmkaud - ok 16:53:21.0824 5856 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 16:53:21.0840 5856 DXGKrnl - ok 16:53:21.0871 5856 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll 16:53:21.0871 5856 EapHost - ok 16:53:21.0996 5856 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys 16:53:22.0058 5856 ebdrv - ok 16:53:22.0105 5856 [ E1E3804F7C59EA3E14637C2A763F65E2 ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 16:53:22.0120 5856 eeCtrl - ok 16:53:22.0152 5856 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe 16:53:22.0152 5856 EFS - ok 16:53:22.0245 5856 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe 16:53:22.0261 5856 ehRecvr - ok 16:53:22.0292 5856 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe 16:53:22.0292 5856 ehSched - ok 16:53:22.0354 5856 [ B83BDCCBACB65BAA9E20888DD0083A16 ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys 16:53:22.0354 5856 ElbyCDIO - ok 16:53:22.0417 5856 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys 16:53:22.0432 5856 elxstor - ok 16:53:22.0510 5856 [ 6D84DFC3B5C5052881BF50470D0C03D1 ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 16:53:22.0526 5856 EraserUtilRebootDrv - ok 16:53:22.0557 5856 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys 16:53:22.0557 5856 ErrDev - ok 16:53:22.0635 5856 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll 16:53:22.0651 5856 EventSystem - ok 16:53:22.0698 5856 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys 16:53:22.0713 5856 exfat - ok 16:53:22.0729 5856 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys 16:53:22.0729 5856 fastfat - ok 16:53:22.0807 5856 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe 16:53:22.0807 5856 Fax - ok 16:53:22.0854 5856 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 16:53:22.0854 5856 fdc - ok 16:53:22.0932 5856 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll 16:53:22.0932 5856 fdPHost - ok 16:53:22.0947 5856 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll 16:53:22.0963 5856 FDResPub - ok 16:53:22.0963 5856 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 16:53:22.0963 5856 FileInfo - ok 16:53:22.0994 5856 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 16:53:22.0994 5856 Filetrace - ok 16:53:23.0025 5856 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 16:53:23.0025 5856 flpydisk - ok 16:53:23.0056 5856 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 16:53:23.0056 5856 FltMgr - ok 16:53:23.0119 5856 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll 16:53:23.0119 5856 FontCache - ok 16:53:23.0181 5856 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 16:53:23.0197 5856 FontCache3.0.0.0 - ok 16:53:23.0212 5856 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 16:53:23.0212 5856 FsDepends - ok 16:53:23.0259 5856 [ B0082808A6856A252F7CDD939892CE50 ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys 16:53:23.0259 5856 fssfltr - ok 16:53:23.0400 5856 [ 28DDEEEC44E988657B732CF404D504CB ] fsssvc C:\Program Files\Windows Live\Family Safety\fsssvc.exe 16:53:23.0431 5856 fsssvc - ok 16:53:23.0462 5856 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 16:53:23.0462 5856 Fs_Rec - ok 16:53:23.0509 5856 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 16:53:23.0524 5856 fvevol - ok 16:53:23.0602 5856 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys 16:53:23.0602 5856 gagp30kx - ok 16:53:23.0649 5856 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 16:53:23.0649 5856 GEARAspiWDM - ok 16:53:23.0696 5856 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll 16:53:23.0712 5856 gpsvc - ok 16:53:23.0743 5856 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 16:53:23.0743 5856 hcw85cir - ok 16:53:23.0805 5856 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys 16:53:23.0805 5856 HDAudBus - ok 16:53:23.0805 5856 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 16:53:23.0821 5856 HidBatt - ok 16:53:23.0821 5856 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys 16:53:23.0821 5856 HidBth - ok 16:53:23.0868 5856 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys 16:53:23.0868 5856 HidIr - ok 16:53:23.0899 5856 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll 16:53:23.0899 5856 hidserv - ok 16:53:23.0961 5856 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 16:53:23.0961 5856 HidUsb - ok 16:53:24.0008 5856 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll 16:53:24.0008 5856 hkmsvc - ok 16:53:24.0055 5856 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll 16:53:24.0070 5856 HomeGroupListener - ok 16:53:24.0102 5856 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 16:53:24.0117 5856 HomeGroupProvider - ok 16:53:24.0164 5856 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 16:53:24.0164 5856 HpSAMD - ok 16:53:24.0226 5856 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys 16:53:24.0242 5856 HTTP - ok 16:53:24.0289 5856 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 16:53:24.0289 5856 hwpolicy - ok 16:53:24.0351 5856 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 16:53:24.0351 5856 i8042prt - ok 16:53:24.0398 5856 [ D483687EACE0C065EE772481A96E05F5 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 16:53:24.0398 5856 iaStor - ok 16:53:24.0476 5856 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 16:53:24.0476 5856 iaStorV - ok 16:53:24.0570 5856 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 16:53:24.0570 5856 idsvc - ok 16:53:24.0819 5856 [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys 16:53:25.0022 5856 igfx - ok 16:53:25.0069 5856 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys 16:53:25.0069 5856 iirsp - ok 16:53:25.0147 5856 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll 16:53:25.0147 5856 IKEEXT - ok 16:53:25.0209 5856 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys 16:53:25.0209 5856 intelide - ok 16:53:25.0256 5856 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 16:53:25.0256 5856 intelppm - ok 16:53:25.0287 5856 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 16:53:25.0287 5856 IPBusEnum - ok 16:53:25.0303 5856 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 16:53:25.0303 5856 IpFilterDriver - ok 16:53:25.0365 5856 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 16:53:25.0381 5856 iphlpsvc - ok 16:53:25.0428 5856 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 16:53:25.0428 5856 IPMIDRV - ok 16:53:25.0459 5856 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys 16:53:25.0474 5856 IPNAT - ok 16:53:25.0521 5856 [ BC0EA61246F8D940FBC5F652D337D6BD ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 16:53:25.0537 5856 iPod Service - ok 16:53:25.0552 5856 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys 16:53:25.0552 5856 IRENUM - ok 16:53:25.0599 5856 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys 16:53:25.0599 5856 isapnp - ok 16:53:25.0646 5856 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 16:53:25.0646 5856 iScsiPrt - ok 16:53:25.0677 5856 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys 16:53:25.0677 5856 kbdclass - ok 16:53:25.0740 5856 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys 16:53:25.0740 5856 kbdhid - ok 16:53:25.0786 5856 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe 16:53:25.0786 5856 KeyIso - ok 16:53:25.0818 5856 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 16:53:25.0833 5856 KSecDD - ok 16:53:25.0880 5856 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 16:53:25.0880 5856 KSecPkg - ok 16:53:25.0927 5856 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll 16:53:25.0927 5856 KtmRm - ok 16:53:25.0974 5856 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll 16:53:25.0974 5856 LanmanServer - ok 16:53:25.0989 5856 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 16:53:26.0005 5856 LanmanWorkstation - ok 16:53:26.0145 5856 [ E34152D03CAAAAA81DD66D803F392522 ] LiveUpdate C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE 16:53:26.0208 5856 LiveUpdate - ok 16:53:26.0254 5856 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 16:53:26.0254 5856 lltdio - ok 16:53:26.0286 5856 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll 16:53:26.0301 5856 lltdsvc - ok 16:53:26.0317 5856 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll 16:53:26.0317 5856 lmhosts - ok 16:53:26.0348 5856 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys 16:53:26.0348 5856 LSI_FC - ok 16:53:26.0364 5856 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys 16:53:26.0364 5856 LSI_SAS - ok 16:53:26.0379 5856 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys 16:53:26.0379 5856 LSI_SAS2 - ok 16:53:26.0379 5856 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys 16:53:26.0395 5856 LSI_SCSI - ok 16:53:26.0426 5856 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys 16:53:26.0426 5856 luafv - ok 16:53:26.0473 5856 [ 4470E3C1E0C3378E4CAB137893C12C3A ] MBAMProtector C:\Windows\system32\drivers\mbam.sys 16:53:26.0488 5856 MBAMProtector - ok 16:53:26.0535 5856 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe 16:53:26.0535 5856 MBAMScheduler - ok 16:53:26.0598 5856 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 16:53:26.0613 5856 MBAMService - ok 16:53:26.0707 5856 [ DDCC236009C707761D60E5C76D639176 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe 16:53:26.0707 5856 McComponentHostService - ok 16:53:26.0738 5856 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 16:53:26.0754 5856 Mcx2Svc - ok 16:53:26.0769 5856 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys 16:53:26.0769 5856 megasas - ok 16:53:26.0800 5856 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys 16:53:26.0800 5856 MegaSR - ok 16:53:26.0910 5856 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe 16:53:26.0910 5856 Microsoft Office Groove Audit Service - ok 16:53:26.0956 5856 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll 16:53:26.0956 5856 MMCSS - ok 16:53:26.0988 5856 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys 16:53:26.0988 5856 Modem - ok 16:53:27.0034 5856 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 16:53:27.0034 5856 monitor - ok 16:53:27.0097 5856 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 16:53:27.0112 5856 mouclass - ok 16:53:27.0128 5856 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 16:53:27.0128 5856 mouhid - ok 16:53:27.0190 5856 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 16:53:27.0190 5856 mountmgr - ok 16:53:27.0268 5856 [ 0329A45C849C9D77901094B8FFE8BBB9 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 16:53:27.0268 5856 MozillaMaintenance - ok 16:53:27.0284 5856 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys 16:53:27.0300 5856 mpio - ok 16:53:27.0331 5856 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 16:53:27.0331 5856 mpsdrv - ok 16:53:27.0409 5856 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll 16:53:27.0424 5856 MpsSvc - ok 16:53:27.0471 5856 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 16:53:27.0471 5856 MRxDAV - ok 16:53:27.0534 5856 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 16:53:27.0549 5856 mrxsmb - ok 16:53:27.0596 5856 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 16:53:27.0596 5856 mrxsmb10 - ok 16:53:27.0643 5856 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 16:53:27.0643 5856 mrxsmb20 - ok 16:53:27.0690 5856 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys 16:53:27.0690 5856 msahci - ok 16:53:27.0752 5856 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys 16:53:27.0752 5856 msdsm - ok 16:53:27.0783 5856 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe 16:53:27.0799 5856 MSDTC - ok 16:53:27.0830 5856 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys 16:53:27.0830 5856 Msfs - ok 16:53:27.0861 5856 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 16:53:27.0861 5856 mshidkmdf - ok 16:53:27.0908 5856 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 16:53:27.0908 5856 msisadrv - ok 16:53:27.0955 5856 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 16:53:27.0970 5856 MSiSCSI - ok 16:53:27.0970 5856 msiserver - ok 16:53:28.0002 5856 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 16:53:28.0017 5856 MSKSSRV - ok 16:53:28.0017 5856 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 16:53:28.0017 5856 MSPCLOCK - ok 16:53:28.0033 5856 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 16:53:28.0033 5856 MSPQM - ok 16:53:28.0048 5856 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 16:53:28.0048 5856 MsRPC - ok 16:53:28.0095 5856 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys 16:53:28.0095 5856 mssmbios - ok 16:53:28.0126 5856 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 16:53:28.0126 5856 MSTEE - ok 16:53:28.0142 5856 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys 16:53:28.0142 5856 MTConfig - ok 16:53:28.0158 5856 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys 16:53:28.0158 5856 Mup - ok 16:53:28.0220 5856 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll 16:53:28.0220 5856 napagent - ok 16:53:28.0267 5856 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 16:53:28.0267 5856 NativeWifiP - ok 16:53:28.0438 5856 [ 81E928EE3751FAF725C87CC17726C05D ] NAVENG C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130925.008\NAVENG.SYS 16:53:28.0470 5856 NAVENG - ok 16:53:28.0532 5856 [ E0C39FA6C76AE8ED53ABF043F35ECDFF ] NAVEX15 C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130925.008\NAVEX15.SYS 16:53:28.0563 5856 NAVEX15 - ok 16:53:28.0641 5856 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys 16:53:28.0641 5856 NDIS - ok 16:53:28.0688 5856 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 16:53:28.0688 5856 NdisCap - ok 16:53:28.0719 5856 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 16:53:28.0719 5856 NdisTapi - ok 16:53:28.0766 5856 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 16:53:28.0766 5856 Ndisuio - ok 16:53:28.0797 5856 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 16:53:28.0813 5856 NdisWan - ok 16:53:28.0844 5856 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 16:53:28.0860 5856 NDProxy - ok 16:53:28.0891 5856 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 16:53:28.0891 5856 NetBIOS - ok 16:53:28.0938 5856 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 16:53:28.0938 5856 NetBT - ok 16:53:28.0953 5856 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe 16:53:28.0953 5856 Netlogon - ok 16:53:29.0000 5856 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll 16:53:29.0000 5856 Netman - ok 16:53:29.0078 5856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 16:53:29.0094 5856 NetMsmqActivator - ok 16:53:29.0109 5856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 16:53:29.0109 5856 NetPipeActivator - ok 16:53:29.0156 5856 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll 16:53:29.0172 5856 netprofm - ok 16:53:29.0218 5856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 16:53:29.0234 5856 NetTcpActivator - ok 16:53:29.0234 5856 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 16:53:29.0234 5856 NetTcpPortSharing - ok 16:53:29.0281 5856 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys 16:53:29.0281 5856 nfrd960 - ok 16:53:29.0328 5856 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\Windows\System32\nlasvc.dll 16:53:29.0328 5856 NlaSvc - ok 16:53:29.0359 5856 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys 16:53:29.0359 5856 Npfs - ok 16:53:29.0390 5856 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll 16:53:29.0390 5856 nsi - ok 16:53:29.0421 5856 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 16:53:29.0421 5856 nsiproxy - ok 16:53:29.0499 5856 [ 0D87503986BB3DFED58E343FE39DDE13 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 16:53:29.0515 5856 Ntfs - ok 16:53:29.0546 5856 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys 16:53:29.0546 5856 Null - ok 16:53:29.0608 5856 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys 16:53:29.0608 5856 nvraid - ok 16:53:29.0624 5856 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys 16:53:29.0624 5856 nvstor - ok 16:53:29.0671 5856 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 16:53:29.0671 5856 nv_agp - ok 16:53:29.0718 5856 [ D955D5DE998DB2476BF0892BE3A96C26 ] O2FLASH C:\Windows\system32\DRIVERS\o2flash.exe 16:53:29.0718 5856 O2FLASH - ok 16:53:29.0749 5856 [ 07AD3CDDF8984F56652CCE6BE8946526 ] O2MDGRDR C:\Windows\system32\DRIVERS\o2mdg.sys 16:53:29.0749 5856 O2MDGRDR - ok 16:53:29.0764 5856 [ 45E4FE55DB8C0549B8CEF1B107F87B70 ] O2SDGRDR C:\Windows\system32\DRIVERS\o2sdg.sys 16:53:29.0780 5856 O2SDGRDR - ok 16:53:29.0858 5856 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE 16:53:29.0874 5856 odserv - ok 16:53:29.0905 5856 [ 86326062A90494BDD79CE383511D7D69 ] OEM13Vfx C:\Windows\system32\DRIVERS\OEM13Vfx.sys 16:53:29.0905 5856 OEM13Vfx - ok 16:53:29.0920 5856 [ 12539B57ED05DE7552403A12B3E0161C ] OEM13Vid C:\Windows\system32\DRIVERS\OEM13Vid.sys 16:53:29.0936 5856 OEM13Vid - ok 16:53:29.0967 5856 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 16:53:29.0983 5856 ohci1394 - ok 16:53:30.0045 5856 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 16:53:30.0045 5856 ose - ok 16:53:30.0092 5856 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 16:53:30.0108 5856 p2pimsvc - ok 16:53:30.0139 5856 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll 16:53:30.0154 5856 p2psvc - ok 16:53:30.0186 5856 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys 16:53:30.0186 5856 Parport - ok 16:53:30.0201 5856 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys 16:53:30.0217 5856 partmgr - ok 16:53:30.0232 5856 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys 16:53:30.0232 5856 Parvdm - ok 16:53:30.0264 5856 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll 16:53:30.0279 5856 PcaSvc - ok 16:53:30.0310 5856 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys 16:53:30.0310 5856 pci - ok 16:53:30.0342 5856 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys 16:53:30.0342 5856 pciide - ok 16:53:30.0388 5856 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys 16:53:30.0388 5856 pcmcia - ok 16:53:30.0435 5856 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys 16:53:30.0435 5856 pcw - ok 16:53:30.0482 5856 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys 16:53:30.0482 5856 PEAUTH - ok 16:53:30.0529 5856 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 16:53:30.0560 5856 PeerDistSvc - ok 16:53:30.0638 5856 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll 16:53:30.0669 5856 pla - ok 16:53:30.0732 5856 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll 16:53:30.0732 5856 PlugPlay - ok 16:53:30.0763 5856 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 16:53:30.0763 5856 PNRPAutoReg - ok 16:53:30.0794 5856 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 16:53:30.0794 5856 PNRPsvc - ok 16:53:30.0856 5856 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 16:53:30.0872 5856 PolicyAgent - ok 16:53:30.0919 5856 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll 16:53:30.0919 5856 Power - ok 16:53:30.0950 5856 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 16:53:30.0950 5856 PptpMiniport - ok 16:53:30.0981 5856 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys 16:53:30.0981 5856 Processor - ok 16:53:31.0028 5856 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll 16:53:31.0044 5856 ProfSvc - ok 16:53:31.0059 5856 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe 16:53:31.0059 5856 ProtectedStorage - ok 16:53:31.0106 5856 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys 16:53:31.0106 5856 Psched - ok 16:53:31.0153 5856 [ 40FEDD328F98245AD201CF5F9F311724 ] PxHelp20 C:\Windows\system32\Drivers\PxHelp20.sys 16:53:31.0153 5856 PxHelp20 - ok 16:53:31.0215 5856 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys 16:53:31.0231 5856 ql2300 - ok 16:53:31.0231 5856 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys 16:53:31.0246 5856 ql40xx - ok 16:53:31.0262 5856 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll 16:53:31.0278 5856 QWAVE - ok 16:53:31.0309 5856 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 16:53:31.0309 5856 QWAVEdrv - ok 16:53:31.0324 5856 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 16:53:31.0340 5856 RasAcd - ok 16:53:31.0371 5856 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 16:53:31.0371 5856 RasAgileVpn - ok 16:53:31.0418 5856 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll 16:53:31.0418 5856 RasAuto - ok 16:53:31.0465 5856 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 16:53:31.0465 5856 Rasl2tp - ok 16:53:31.0496 5856 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll 16:53:31.0512 5856 RasMan - ok 16:53:31.0543 5856 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 16:53:31.0543 5856 RasPppoe - ok 16:53:31.0605 5856 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 16:53:31.0621 5856 RasSstp - ok 16:53:31.0668 5856 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 16:53:31.0668 5856 rdbss - ok 16:53:31.0699 5856 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 16:53:31.0699 5856 rdpbus - ok 16:53:31.0730 5856 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 16:53:31.0730 5856 RDPCDD - ok 16:53:31.0777 5856 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 16:53:31.0777 5856 RDPDR - ok 16:53:31.0808 5856 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 16:53:31.0824 5856 RDPENCDD - ok 16:53:31.0855 5856 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 16:53:31.0855 5856 RDPREFMP - ok 16:53:31.0902 5856 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 16:53:31.0902 5856 RDPWD - ok 16:53:31.0964 5856 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 16:53:31.0964 5856 rdyboost - ok 16:53:32.0011 5856 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll 16:53:32.0011 5856 RemoteAccess - ok 16:53:32.0058 5856 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll 16:53:32.0073 5856 RemoteRegistry - ok 16:53:32.0089 5856 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 16:53:32.0104 5856 RpcEptMapper - ok 16:53:32.0120 5856 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe 16:53:32.0120 5856 RpcLocator - ok 16:53:32.0151 5856 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\System32\rpcss.dll 16:53:32.0167 5856 RpcSs - ok 16:53:32.0214 5856 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 16:53:32.0214 5856 rspndr - ok 16:53:32.0245 5856 [ 06BD46BE6141556125F89DF738333720 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys 16:53:32.0245 5856 RTL8167 - ok 16:53:32.0276 5856 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys 16:53:32.0292 5856 s3cap - ok 16:53:32.0307 5856 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe 16:53:32.0323 5856 SamSs - ok 16:53:32.0370 5856 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 16:53:32.0370 5856 sbp2port - ok 16:53:32.0416 5856 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll 16:53:32.0432 5856 SCardSvr - ok 16:53:32.0448 5856 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 16:53:32.0448 5856 scfilter - ok 16:53:32.0510 5856 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll 16:53:32.0510 5856 Schedule - ok 16:53:32.0557 5856 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll 16:53:32.0557 5856 SCPolicySvc - ok 16:53:32.0604 5856 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll 16:53:32.0604 5856 SDRSVC - ok 16:53:32.0697 5856 [ 16A252022535B680046F6E34E136D378 ] SeaPort C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 16:53:32.0697 5856 SeaPort - ok 16:53:32.0744 5856 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys 16:53:32.0744 5856 secdrv - ok 16:53:32.0775 5856 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll 16:53:32.0791 5856 seclogon - ok 16:53:32.0791 5856 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll 16:53:32.0806 5856 SENS - ok 16:53:32.0838 5856 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll 16:53:32.0838 5856 SensrSvc - ok 16:53:32.0853 5856 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 16:53:32.0853 5856 Serenum - ok 16:53:32.0884 5856 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys 16:53:32.0884 5856 Serial - ok 16:53:32.0916 5856 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys 16:53:32.0916 5856 sermouse - ok 16:53:32.0978 5856 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll 16:53:32.0978 5856 SessionEnv - ok 16:53:33.0025 5856 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 16:53:33.0025 5856 sffdisk - ok 16:53:33.0056 5856 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 16:53:33.0056 5856 sffp_mmc - ok 16:53:33.0056 5856 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 16:53:33.0056 5856 sffp_sd - ok 16:53:33.0103 5856 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys 16:53:33.0103 5856 sfloppy - ok 16:53:33.0165 5856 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll 16:53:33.0181 5856 SharedAccess - ok 16:53:33.0196 5856 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 16:53:33.0212 5856 ShellHWDetection - ok 16:53:33.0243 5856 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys 16:53:33.0259 5856 sisagp - ok 16:53:33.0306 5856 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys 16:53:33.0306 5856 SiSRaid2 - ok 16:53:33.0306 5856 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys 16:53:33.0306 5856 SiSRaid4 - ok 16:53:33.0321 5856 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys 16:53:33.0337 5856 Smb - ok 16:53:33.0430 5856 [ A58C1A086D9C09C6572C948F22CC0E94 ] SmcService C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe 16:53:33.0446 5856 SmcService - ok 16:53:33.0508 5856 [ D2C222441255131E29DE351475F98F6D ] SNAC C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE 16:53:33.0508 5856 SNAC - ok 16:53:33.0571 5856 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 16:53:33.0571 5856 SNMPTRAP - ok 16:53:33.0649 5856 [ E621BB5839CF45FA477F48092EDD2B40 ] SPBBCDrv C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 16:53:33.0649 5856 SPBBCDrv - ok 16:53:33.0680 5856 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys 16:53:33.0696 5856 spldr - ok 16:53:33.0742 5856 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe 16:53:33.0742 5856 Spooler - ok 16:53:33.0867 5856 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe 16:53:33.0898 5856 sppsvc - ok 16:53:33.0945 5856 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll 16:53:33.0945 5856 sppuinotify - ok 16:53:33.0992 5856 [ 2ABF82C8452AB0B9FFC74A2D5DA91989 ] SRTSP C:\Windows\system32\Drivers\SRTSP.SYS 16:53:34.0008 5856 SRTSP - ok 16:53:34.0054 5856 [ E2F9E5887BEA5BD8784D337E06EDA31B ] SRTSPL C:\Windows\system32\Drivers\SRTSPL.SYS 16:53:34.0054 5856 SRTSPL - ok 16:53:34.0101 5856 [ 3B974C158FABD910186F98DF8D3E23F3 ] SRTSPX C:\Windows\system32\Drivers\SRTSPX.SYS 16:53:34.0101 5856 SRTSPX - ok 16:53:34.0148 5856 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys 16:53:34.0164 5856 srv - ok 16:53:34.0179 5856 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 16:53:34.0195 5856 srv2 - ok 16:53:34.0210 5856 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 16:53:34.0210 5856 srvnet - ok 16:53:34.0242 5856 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 16:53:34.0242 5856 SSDPSRV - ok 16:53:34.0257 5856 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll 16:53:34.0273 5856 SstpSvc - ok 16:53:34.0398 5856 [ 329086F957CDFDE026BB6C2DD3B54F56 ] STacSV C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe 16:53:34.0398 5856 STacSV - ok 16:53:34.0444 5856 Steam Client Service - ok 16:53:34.0476 5856 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys 16:53:34.0476 5856 stexstor - ok 16:53:34.0554 5856 [ 61F801547A9F9D630637EEE0440329A6 ] STHDA C:\Windows\system32\DRIVERS\stwrt.sys 16:53:34.0569 5856 STHDA - ok 16:53:34.0616 5856 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll 16:53:34.0616 5856 StiSvc - ok 16:53:34.0647 5856 [ E476C66713C842F58E61A95826ED1D57 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe 16:53:34.0663 5856 stllssvr - ok 16:53:34.0694 5856 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys 16:53:34.0694 5856 storflt - ok 16:53:34.0725 5856 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll 16:53:34.0725 5856 StorSvc - ok 16:53:34.0741 5856 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys 16:53:34.0741 5856 storvsc - ok 16:53:34.0788 5856 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys 16:53:34.0788 5856 swenum - ok 16:53:34.0944 5856 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 16:53:34.0959 5856 SwitchBoard - ok 16:53:34.0990 5856 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll 16:53:35.0006 5856 swprv - ok 16:53:35.0100 5856 [ BA2FB8F8AB24D0279CAA98A4C118150E ] Symantec AntiVirus C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe 16:53:35.0131 5856 Symantec AntiVirus - ok 16:53:35.0178 5856 [ A54FF04BD6E75DC4D8CB6F3E352635E0 ] SymEvent C:\Windows\system32\Drivers\SYMEVENT.SYS 16:53:35.0178 5856 SymEvent - ok 16:53:35.0224 5856 [ 394B2368212114D538316812AF60FDDD ] SYMREDRV C:\Windows\System32\Drivers\SYMREDRV.SYS 16:53:35.0224 5856 SYMREDRV - ok 16:53:35.0256 5856 [ D46676BB414C7531BDFFE637A33F5033 ] SYMTDI C:\Windows\System32\Drivers\SYMTDI.SYS 16:53:35.0256 5856 SYMTDI - ok 16:53:35.0334 5856 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll 16:53:35.0349 5856 SysMain - ok 16:53:35.0396 5856 [ 1295B1DA3E2A2C24C7D176F6E97AFBD1 ] SysPlant C:\Windows\SYSTEM32\Drivers\SysPlant.sys 16:53:35.0396 5856 SysPlant - ok 16:53:35.0443 5856 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll 16:53:35.0443 5856 TabletInputService - ok 16:53:35.0490 5856 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll 16:53:35.0490 5856 TapiSrv - ok 16:53:35.0521 5856 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll 16:53:35.0521 5856 TBS - ok 16:53:35.0599 5856 [ E23A56F843E2AEBBB209D0ACCA73C640 ] Tcpip C:\Windows\system32\drivers\tcpip.sys 16:53:35.0614 5856 Tcpip - ok 16:53:35.0646 5856 [ E23A56F843E2AEBBB209D0ACCA73C640 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 16:53:35.0661 5856 TCPIP6 - ok 16:53:35.0708 5856 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 16:53:35.0708 5856 tcpipreg - ok 16:53:35.0755 5856 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 16:53:35.0755 5856 TDPIPE - ok 16:53:35.0770 5856 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 16:53:35.0786 5856 TDTCP - ok 16:53:35.0833 5856 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 16:53:35.0833 5856 tdx - ok 16:53:35.0895 5856 [ 1DE2E1357552A79F39BFF003A11C533E ] Teefer2 C:\Windows\system32\DRIVERS\teefer2.sys 16:53:35.0895 5856 Teefer2 - ok 16:53:35.0942 5856 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys 16:53:35.0942 5856 TermDD - ok 16:53:35.0989 5856 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll 16:53:36.0004 5856 TermService - ok 16:53:36.0020 5856 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll 16:53:36.0036 5856 Themes - ok 16:53:36.0067 5856 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll 16:53:36.0067 5856 THREADORDER - ok 16:53:36.0067 5856 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll 16:53:36.0082 5856 TrkWks - ok 16:53:36.0129 5856 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 16:53:36.0145 5856 TrustedInstaller - ok 16:53:36.0160 5856 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 16:53:36.0160 5856 tssecsrv - ok 16:53:36.0223 5856 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 16:53:36.0223 5856 TsUsbFlt - ok 16:53:36.0285 5856 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 16:53:36.0285 5856 tunnel - ok 16:53:36.0316 5856 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys 16:53:36.0316 5856 uagp35 - ok 16:53:36.0348 5856 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys 16:53:36.0348 5856 udfs - ok 16:53:36.0394 5856 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe 16:53:36.0394 5856 UI0Detect - ok 16:53:36.0441 5856 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 16:53:36.0441 5856 uliagpkx - ok 16:53:36.0504 5856 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys 16:53:36.0504 5856 umbus - ok 16:53:36.0550 5856 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys 16:53:36.0550 5856 UmPass - ok 16:53:36.0597 5856 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll 16:53:36.0597 5856 UmRdpService - ok 16:53:36.0628 5856 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll 16:53:36.0644 5856 upnphost - ok 16:53:36.0675 5856 [ 73B41F4EAD65F355962168D766AF0F2E ] USBAAPL C:\Windows\system32\Drivers\usbaapl.sys 16:53:36.0675 5856 USBAAPL - ok 16:53:36.0722 5856 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 16:53:36.0722 5856 usbccgp - ok 16:53:36.0753 5856 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys 16:53:36.0753 5856 usbcir - ok 16:53:36.0784 5856 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 16:53:36.0784 5856 usbehci - ok 16:53:36.0847 5856 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 16:53:36.0847 5856 usbhub - ok 16:53:36.0862 5856 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys 16:53:36.0862 5856 usbohci - ok 16:53:36.0909 5856 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 16:53:36.0909 5856 usbprint - ok 16:53:36.0940 5856 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS 16:53:36.0940 5856 USBSTOR - ok 16:53:36.0972 5856 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 16:53:36.0972 5856 usbuhci - ok 16:53:37.0018 5856 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 16:53:37.0018 5856 usbvideo - ok 16:53:37.0050 5856 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll 16:53:37.0065 5856 UxSms - ok 16:53:37.0065 5856 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe 16:53:37.0065 5856 VaultSvc - ok 16:53:37.0128 5856 [ B252DD05C8B1D64239EE8A93C4BC5AD4 ] VClone C:\Windows\system32\DRIVERS\VClone.sys 16:53:37.0128 5856 VClone - ok 16:53:37.0190 5856 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 16:53:37.0190 5856 vdrvroot - ok 16:53:37.0252 5856 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe 16:53:37.0252 5856 vds - ok 16:53:37.0330 5856 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 16:53:37.0330 5856 vga - ok 16:53:37.0362 5856 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys 16:53:37.0362 5856 VgaSave - ok 16:53:37.0408 5856 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 16:53:37.0408 5856 vhdmp - ok 16:53:37.0455 5856 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys 16:53:37.0455 5856 viaagp - ok 16:53:37.0486 5856 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys 16:53:37.0486 5856 ViaC7 - ok 16:53:37.0518 5856 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys 16:53:37.0518 5856 viaide - ok 16:53:37.0564 5856 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys 16:53:37.0564 5856 vmbus - ok 16:53:37.0580 5856 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 16:53:37.0580 5856 VMBusHID - ok 16:53:37.0627 5856 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys 16:53:37.0627 5856 volmgr - ok 16:53:37.0658 5856 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 16:53:37.0658 5856 volmgrx - ok 16:53:37.0720 5856 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys 16:53:37.0720 5856 volsnap - ok 16:53:37.0767 5856 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys 16:53:37.0767 5856 vsmraid - ok 16:53:37.0830 5856 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe 16:53:37.0845 5856 VSS - ok 16:53:37.0970 5856 [ 12EDF8E1E84511E8689483D420CD2B9A ] vToolbarUpdater17.0.1 C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe 16:53:37.0986 5856 vToolbarUpdater17.0.1 - ok 16:53:38.0017 5856 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys 16:53:38.0017 5856 vwifibus - ok 16:53:38.0048 5856 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 16:53:38.0064 5856 vwififlt - ok 16:53:38.0079 5856 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 16:53:38.0079 5856 vwifimp - ok 16:53:38.0126 5856 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll 16:53:38.0142 5856 W32Time - ok 16:53:38.0157 5856 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys 16:53:38.0173 5856 WacomPen - ok 16:53:38.0298 5856 [ A650671AF9A670F678F29FF212B4950C ] wampapache c:\wamp\bin\apache\apache2.4.4\bin\httpd.exe 16:53:38.0298 5856 wampapache - ok 16:53:38.0391 5856 wampmysqld - ok 16:53:38.0422 5856 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 16:53:38.0438 5856 WANARP - ok 16:53:38.0438 5856 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 16:53:38.0438 5856 Wanarpv6 - ok 16:53:38.0532 5856 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 16:53:38.0547 5856 WatAdminSvc - ok 16:53:38.0610 5856 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe 16:53:38.0625 5856 wbengine - ok 16:53:38.0672 5856 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 16:53:38.0672 5856 WbioSrvc - ok 16:53:38.0734 5856 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll 16:53:38.0734 5856 wcncsvc - ok 16:53:38.0766 5856 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 16:53:38.0781 5856 WcsPlugInService - ok 16:53:38.0812 5856 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys 16:53:38.0812 5856 Wd - ok 16:53:38.0844 5856 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 16:53:38.0844 5856 Wdf01000 - ok 16:53:38.0875 5856 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll 16:53:38.0890 5856 WdiServiceHost - ok 16:53:38.0890 5856 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll 16:53:38.0890 5856 WdiSystemHost - ok 16:53:38.0937 5856 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll 16:53:38.0953 5856 WebClient - ok 16:53:38.0968 5856 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll 16:53:38.0968 5856 Wecsvc - ok 16:53:39.0015 5856 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll 16:53:39.0015 5856 wercplsupport - ok 16:53:39.0046 5856 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll 16:53:39.0046 5856 WerSvc - ok 16:53:39.0093 5856 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 16:53:39.0093 5856 WfpLwf - ok 16:53:39.0124 5856 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys 16:53:39.0124 5856 WIMMount - ok 16:53:39.0202 5856 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 16:53:39.0202 5856 WinDefend - ok 16:53:39.0234 5856 WinHttpAutoProxySvc - ok 16:53:39.0280 5856 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 16:53:39.0280 5856 Winmgmt - ok 16:53:39.0358 5856 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll 16:53:39.0390 5856 WinRM - ok 16:53:39.0452 5856 [ A67E5F9A400F3BD1BE3D80613B45F708 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys 16:53:39.0452 5856 WinUsb - ok 16:53:39.0499 5856 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll 16:53:39.0514 5856 Wlansvc - ok 16:53:39.0592 5856 [ 6067ACEF367E79914AF628FA1E9B5330 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe 16:53:39.0608 5856 wlcrasvc - ok 16:53:39.0764 5856 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 16:53:39.0780 5856 wlidsvc - ok 16:53:39.0811 5856 [ 3CBCE0C65CC433121001C1108B511D13 ] wltrysvc C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE 16:53:39.0811 5856 wltrysvc - ok 16:53:39.0842 5856 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys 16:53:39.0842 5856 WmiAcpi - ok 16:53:39.0889 5856 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 16:53:39.0889 5856 wmiApSrv - ok 16:53:39.0998 5856 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 16:53:40.0014 5856 WMPNetworkSvc - ok 16:53:40.0045 5856 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll 16:53:40.0060 5856 WPCSvc - ok 16:53:40.0092 5856 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 16:53:40.0107 5856 WPDBusEnum - ok 16:53:40.0138 5856 [ C1620EBB375D3B02E31FD311C44FEDEB ] WPS C:\Windows\system32\drivers\wpsdrvnt.sys 16:53:40.0138 5856 WPS - ok 16:53:40.0170 5856 [ C306D2037EC147C7C663994F12B87F1E ] WpsHelper C:\Windows\system32\drivers\WpsHelper.sys 16:53:40.0170 5856 WpsHelper - ok 16:53:40.0216 5856 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 16:53:40.0216 5856 ws2ifsl - ok 16:53:40.0279 5856 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll 16:53:40.0294 5856 wscsvc - ok 16:53:40.0294 5856 WSearch - ok 16:53:40.0388 5856 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll 16:53:40.0404 5856 wuauserv - ok 16:53:40.0450 5856 [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 16:53:40.0450 5856 WudfPf - ok 16:53:40.0513 5856 [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 16:53:40.0513 5856 WUDFRd - ok 16:53:40.0560 5856 [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 16:53:40.0575 5856 wudfsvc - ok 16:53:40.0606 5856 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll 16:53:40.0606 5856 WwanSvc - ok 16:53:40.0669 5856 ================ Scan global =============================== 16:53:40.0700 5856 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll 16:53:40.0747 5856 [ 48CB4FDBCAAEAC7BCE2F5941545FF071 ] C:\Windows\system32\winsrv.dll 16:53:40.0762 5856 [ 48CB4FDBCAAEAC7BCE2F5941545FF071 ] C:\Windows\system32\winsrv.dll 16:53:40.0794 5856 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll 16:53:40.0840 5856 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe 16:53:40.0840 5856 [Global] - ok 16:53:40.0840 5856 ================ Scan MBR ================================== 16:53:40.0856 5856 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 16:53:41.0152 5856 \Device\Harddisk0\DR0 - ok 16:53:41.0152 5856 ================ Scan VBR ================================== 16:53:41.0168 5856 [ 5AA220E48CCA85716B5747DE0D795F16 ] \Device\Harddisk0\DR0\Partition1 16:53:41.0168 5856 \Device\Harddisk0\DR0\Partition1 - ok 16:53:41.0184 5856 [ CDDC31D79C774A89F99BFFE58B1DDACD ] \Device\Harddisk0\DR0\Partition2 16:53:41.0184 5856 \Device\Harddisk0\DR0\Partition2 - ok 16:53:41.0184 5856 ============================================================ 16:53:41.0184 5856 Scan finished 16:53:41.0184 5856 ============================================================ 16:53:41.0199 5660 Detected object count: 0 16:53:41.0199 5660 Actual detected object count: 0 16:55:22.0818 5888 Deinitialize success ComboFix 13-09-26.03 - Paul 09/26/2013 17:42:36.5.2 - x86 Running from: c:\users\[removed]\Desktop\ComboFix.exe * Created a new restore point . . ((((((((((((((((((((((((( Files Created from 2013-08-26 to 2013-09-26 ))))))))))))))))))))))))))))))) . . 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\TEMP\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\Public\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\Paul\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\Guest\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\Edward\AppData\Local\temp 2013-09-26 21:51 . 2013-09-26 21:51 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-09-26 07:09 . 2013-09-26 07:09 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Local\WinZip 2013-09-26 07:09 . 2013-09-26 07:09 ——– d—–w- c:\programdata\WinZip 2013-09-26 07:08 . 2013-09-26 07:08 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar 2013-09-26 07:08 . 2013-09-26 07:08 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-09-26 07:08 . 2013-09-26 07:08 ——– d—–w- c:\programdata\AVG SafeGuard toolbar 2013-09-26 07:08 . 2013-09-26 07:08 ——– d—–w- c:\program files\Common Files\AVG Secure Search 2013-09-26 07:08 . 2013-09-26 07:08 ——– d—–w- c:\program files\AVG SafeGuard toolbar 2013-09-26 06:15 . 2013-09-26 06:22 ——– d—–w- C:\AdwCleaner 2013-09-21 18:22 . 2013-09-21 18:22 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Roaming\Malwarebytes 2013-09-15 16:52 . 2013-09-15 16:52 ——– d—–w- c:\users\TEMP.Paul-PC 2013-09-08 02:15 . 2013-09-08 02:21 ——– d—–w- C:\wamp 2013-09-05 14:04 . 2013-09-05 14:04 209272 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-20 01:18 . 2012-05-17 04:36 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-09-20 01:18 . 2011-12-30 17:09 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}] 2013-09-26 07:08 3353624 —-a-w- c:\program files\AVG SafeGuard toolbar\17.0.0.7\AVG SafeGuard toolbar_toolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\17.0.0.7\AVG SafeGuard toolbar_toolbar.dll" [2013-09-26 3353624] . [HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}] [HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1] [HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SearchProtection"="c:\users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" [2013-09-03 832360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-29 217088] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-15 458844] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 170520] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2013-03-10 88984] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984] "Adobe Creative Cloud"="c:\program files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-08-08 2236816] "AdobeCEPServiceManager"="c:\program files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" [2013-03-13 1039248] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] "vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2013-09-26 2404376] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216] R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-07 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-09-26 37664] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] S2 vToolbarUpdater17.0.1;vToolbarUpdater17.0.1;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe [2013-09-26 1734680] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-08-27 108120] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdg.sys [2009-05-22 58528] S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdg.sys [2009-05-07 41504] S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [2007-03-05 7424] S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [2008-05-28 235840] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-12-19 249888] . . — Other Services/Drivers In Memory — . *NewlyCreated* - 15543434 *Deregistered* - 15543434 . Contents of the 'Scheduled Tasks' folder . 2013-09-26 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 01:18] . 2013-09-26 c:\windows\Tasks\AWC Startup.job - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-02-02 20:33] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.yahoo.com?type=714647&fr=spigot-yhp-ie IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.1 Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1\ViProtocol.dll FF - ProfilePath - c:\users\Paul.Paul-PC\AppData\Roaming\Mozilla\Firefox\Profiles\ya3lift0.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com?cid={204F4A45-F957-45EF-9C25-7310E1E10F89}&mid=f7c1f7316cb443d5ac2aa2bef13e1c6b-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=hk018&coid=avgtbdishk&pr=sa&d=&v=17.0.0.7&pid=safeguard&sg=32&sap=hp FF - prefs.js: keyword.URL - FF - ExtSQL: 2013-09-26 03:08; avg@toolbar; c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7 . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2013-09-26 17:52:48 ComboFix-quarantined-files.txt 2013-09-26 21:52 ComboFix2.txt 2013-09-26 21:31 . Pre-Run: 133,695,094,784 bytes free Post-Run: 133,642,514,432 bytes free . - - End Of File - - 04973360A934FFC125E7C31B69F840CE 5C616939100B85E558DA92B899A0FC36
Hi pmedvins,

[external image: Posted Image] Malwarebytes Anti-Rootkit
  • Download Malwarebytes Anti-Rootkit
  • Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
  • Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
  • Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
  • Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
  • After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
  • Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
  • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
[external image: Posted Image]
  • Please click by the introduction screen on the Next button to continue.
[external image: Posted Image]
  • Next you will see the Update Database screen.
  • Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.
[external image: Posted Image]
  • When the update has finished, click on the Next button.
[external image: Posted Image]
  • Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
  • Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.
[external image: Posted Image]
  • When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
  • Make sure everything is selected and that the option to create a restore point is checked.
  • Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
  • Click on Yes button to restart your computer.
  • There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
  • The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
    • For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
  • The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.
=========================

[external image: Posted Image] ComboFix Script

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the code-box below into it:

ClearJavaCache::

Folder::
c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar
c:\programdata\AVG SafeGuard toolbar
c:\program files\Common Files\AVG Secure Search
c:\program files\AVG SafeGuard toolbar

Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"=-
[-HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[-HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[-HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vProt"=-

Driver::
vToolbarUpdater17.0.1

DDS::
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1\ViProtocol.dll

FireFox::
FF - prefs.js: browser.search.selectedEngine - AVG Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com?cid={204F4A45-F957-45EF-9C25-7310E1E10F89}&mid=f7c1f7316cb443d5ac2aa2bef13e1c6b-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=hk018&coid=avgtbdishk&pr=sa&d=&v=17.0.0.7&pid=safeguard&sg=32&sap=hp
FF - ExtSQL: 2013-09-26 03:08; avg@toolbar; c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7

Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]


Referring to the picture above, drag CFScript into ComboFix.exe

When finished, please post the C:\ComboFix.txt for further review.

=========================

In your next post please provide the following:
  • system-log.txt
  • Combofix.txt
————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 3180285952, free: 1562705920 ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 3180285952, free: 1562476544 Downloaded database version: v2013.09.27.08 Downloaded database version: v2013.09.23.01 Initializing… ====================== ———— Kernel report ———— 09/27/2013 20:56:34 ———— Loaded modules ———– \SystemRoot\system32\ntkrnlpa.exe \SystemRoot\system32\halmacpi.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\vmbus.sys \SystemRoot\system32\drivers\winhv.sys \SystemRoot\system32\DRIVERS\iaStor.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\PxHelp20.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\drivers\vmstorfl.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\disk.sys \SystemRoot\system32\DRIVERS\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\System32\Drivers\SRTSP.SYS \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130926.004\NAVEX15.SYS \??\C:\Windows\system32\Drivers\SYMEVENT.SYS \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130926.004\NAVENG.SYS \SystemRoot\System32\Drivers\SRTSPX.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \??\C:\Windows\system32\drivers\avgtpx86.sys \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \??\C:\Windows\system32\drivers\wpsdrvnt.sys \SystemRoot\System32\Drivers\SYMTDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\ws2ifsl.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\drivers\termdd.sys \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\drivers\mssmbios.sys \SystemRoot\System32\Drivers\ElbyCDIO.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\igdkmd32.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\drivers\HDAudBus.sys \SystemRoot\system32\DRIVERS\Rt86win7.sys \SystemRoot\system32\DRIVERS\bcmwl6.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\drivers\1394ohci.sys \SystemRoot\system32\DRIVERS\o2sdg.sys \SystemRoot\system32\DRIVERS\SCSIPORT.SYS \SystemRoot\system32\DRIVERS\o2mdg.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\drivers\i8042prt.sys \SystemRoot\system32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\drivers\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\DRIVERS\VClone.sys \SystemRoot\system32\DRIVERS\teefer2.sys \SystemRoot\system32\drivers\swenum.sys \SystemRoot\system32\drivers\ks.sys \SystemRoot\system32\drivers\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\stwrt.sys \SystemRoot\system32\DRIVERS\portcls.sys \SystemRoot\system32\DRIVERS\drmk.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\system32\DRIVERS\hidusb.sys \SystemRoot\system32\DRIVERS\HIDCLASS.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\system32\DRIVERS\OEM13Vid.sys \SystemRoot\system32\DRIVERS\OEM13Vfx.sys \SystemRoot\system32\DRIVERS\cdfs.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\System32\ATMFD.DLL \SystemRoot\system32\drivers\luafv.sys \??\C:\Windows\system32\drivers\mbam.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\DRIVERS\vwifimp.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \??\C:\Windows\system32\drivers\WpsHelper.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\System32\drivers\ipnat.sys \SystemRoot\system32\drivers\BCM42RLY.sys \SystemRoot\System32\Drivers\SYMREDRV.SYS \SystemRoot\System32\Drivers\fastfat.SYS \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\msctf.dll \Windows\System32\sechost.dll \Windows\System32\rpcrt4.dll \Windows\System32\advapi32.dll \Windows\System32\Wldap32.dll \Windows\System32\msvcrt.dll \Windows\System32\urlmon.dll \Windows\System32\psapi.dll \Windows\System32\normaliz.dll \Windows\System32\iertutil.dll \Windows\System32\nsi.dll \Windows\System32\usp10.dll \Windows\System32\shell32.dll \Windows\System32\ole32.dll \Windows\System32\imm32.dll \Windows\System32\imagehlp.dll \Windows\System32\lpk.dll \Windows\System32\wininet.dll \Windows\System32\difxapi.dll \Windows\System32\ws2_32.dll \Windows\System32\clbcatq.dll \Windows\System32\user32.dll \Windows\System32\comdlg32.dll \Windows\System32\shlwapi.dll \Windows\System32\setupapi.dll \Windows\System32\gdi32.dll \Windows\System32\oleaut32.dll \Windows\System32\kernel32.dll \Windows\System32\crypt32.dll \Windows\System32\wintrust.dll \Windows\System32\comctl32.dll \Windows\System32\cfgmgr32.dll \Windows\System32\devobj.dll \Windows\System32\KernelBase.dll \Windows\System32\msasn1.dll ———– End ———– Done! <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff868a57c8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IAAStorageDevice-1\ Lower Device Object: 0xffffffff85e5f028 Lower Device Driver Name: \Driver\iaStor\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff868a57c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffff868a5400, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xffffffff868a57c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff85e5f028, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\ ———— End ———- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: F638964D Partition information: Partition 0 type is Other (0xde) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 80262 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 81920 Numsec = 30720000 Partition file system is NTFS Partition is bootable Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 30801920 Numsec = 457593200 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 250059350016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)… Done! Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh121d.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1661.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1a38.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1ac5.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1b90.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1bce.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1c2c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1c5a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1e0f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1f66.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1f76.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh206f.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh208f.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh209e.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh20ec.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh213a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2169.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2263.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2511.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh26e5.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2762.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh28f7.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2df7.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2e16.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2f3f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3028.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh31ae.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh320.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh33.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3363.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh33ff.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh345c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh34f9.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh35c4.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh35e3.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh367f.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh373a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3759.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3862.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3872.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh38c0.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3a56.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3bc.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3e7a.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3e99.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3f74.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh41b5.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh455d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh456c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4712.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh48d6.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4c21.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4cec.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4d68.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4e24.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5055.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5074.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5075.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5277.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh52d5.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5371.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh53fd.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh55a2.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh592b.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5a15.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5af0.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5d7f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5e88.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh60ba.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6194.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh61c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6387.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh652c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh65c8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6626.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh66b2.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh67cb.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6838.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6858.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6b25.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6cea.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6d66.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6e12.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f1b.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f88.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7552.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh75c0.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh764.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh764c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7765.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh785e.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh78ac.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh79d5.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7a42.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7b2.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7c83.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7ce1.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7d8c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7ffc.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh825d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh82ab.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8308.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8375.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8450.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh84dd.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh84e.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8672.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8930.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh89c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8ab.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8b33.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8cf7.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8d45.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8df1.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8f0a.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8ff4.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh91b8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9206.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh928.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh93da.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9467.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9495.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh94d4.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9551.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh957.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh964a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9aad.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9e27.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9ee2.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9f4f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha00a.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha49c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha4da.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha5a5.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha6ed.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha75a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha7a8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha825.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha96d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha9da.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha9f.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac4a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac78.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaca7.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhad14.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhadfe.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaf65.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb271.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb5eb.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb86a.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbb28.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc31.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc7f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc9f.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbe92.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbf6c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbff9.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc0c3.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc0f2.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc121.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc17e.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc1bd.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc314.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc3ee.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc41d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc5b3.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc67e.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc729.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc82.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc8a0.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc9a9.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcb10.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcc38.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhce6a.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd1e.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd3c7.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd434.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd887.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd8f4.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd904.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd971.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd991.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd9b0.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhda3c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdb36.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdbe1.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdc9d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdebe.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdf1c.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdfc8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe073.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe6aa.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhec84.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhee39.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhef52.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhef90.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0c8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0d8.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf164.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf193.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf3c5.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf470.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf4be.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf4dd.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf52c.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf6d1.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfa59.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb53.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfdc.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfe6e.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfe9d.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh42ce.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5e69.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6108.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8116.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha097.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcbeb.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1346.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh24d3.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2f10.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe3be.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb92.tmp –> [Rootkit.Zaccess] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3cc6.tmp –> [Trojan.Dropper.BCMiner] Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd1f.tmp –> [Trojan.Dropper.BCMiner] Scan finished Creating System Restore point… Cleaning up… Executing an action fixdamage.exe… Success! Queuing an action fixdamage.exe Removal scheduling successful. System shutdown needed. System shutdown occurred ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_81920_i.mbam… Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam… Removal finished ————————————— Malwarebytes Anti-Rootkit BETA 1.07.0.1005 © Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x86 Account is Administrative Internet Explorer version: 9.0.8112.16421 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.194000 GHz Memory total: 3180285952, free: 1820463104 ======================================= ComboFix 13-09-26.03 - Paul 09/27/2013 23:24:58.6.2 - x86 Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\Paul.Paul-PC\Desktop\CFScript.txt * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\program files\AVG SafeGuard toolbar c:\program files\AVG SafeGuard toolbar\17.0.0.7\AVG SafeGuard toolbar_toolbar.dll c:\program files\AVG SafeGuard toolbar\17.0.0.9\AVG SafeGuard toolbar_toolbar.dll c:\program files\AVG SafeGuard toolbar\about.gif c:\program files\AVG SafeGuard toolbar\active-threats18.gif c:\program files\AVG SafeGuard toolbar\AVG SafeGuard toolbar c:\program files\AVG SafeGuard toolbar\avgMozXPCOM.js c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\bg_close.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\bg_expand.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\bg_tooltip.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\bg_tracking.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\bull4x4.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\divider.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\innerBG_gradient.gif c:\program files\AVG SafeGuard toolbar\Chrome\content\icons\loader.gif c:\program files\AVG SafeGuard toolbar\ChromeRes\AVG SafeGuard toolbar\nt28.html c:\program files\AVG SafeGuard toolbar\ChromeRes\AVG Secure Search\nt28.html c:\program files\AVG SafeGuard toolbar\ChromeRes\nt.html c:\program files\AVG SafeGuard toolbar\ChromeRes\nt28.html c:\program files\AVG SafeGuard toolbar\ChromeRes\nt28.js c:\program files\AVG SafeGuard toolbar\CleanHistory.gif c:\program files\AVG SafeGuard toolbar\configuration.xml c:\program files\AVG SafeGuard toolbar\current.gif c:\program files\AVG SafeGuard toolbar\currently-safe18.gif c:\program files\AVG SafeGuard toolbar\data.zip c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\all.css c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\btn-ok2.gif c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\downBtn.png c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\DSPDlg_IE.html c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\logo2.png c:\program files\AVG SafeGuard toolbar\DSPDlg_IE\upBtn.png c:\program files\AVG SafeGuard toolbar\EnableHelperRes\EEImageHandler.html c:\program files\AVG SafeGuard toolbar\EnableHelperRes\Images\box_ie.png c:\program files\AVG SafeGuard toolbar\EULA.gif c:\program files\AVG SafeGuard toolbar\Eula.txt c:\program files\AVG SafeGuard toolbar\favicon.ico c:\program files\AVG SafeGuard toolbar\feedback.gif c:\program files\AVG SafeGuard toolbar\FireFoxSearchXml.tmp c:\program files\AVG SafeGuard toolbar\help.gif c:\program files\AVG SafeGuard toolbar\icon18.gif c:\program files\AVG SafeGuard toolbar\labs.gif c:\program files\AVG SafeGuard toolbar\Licenses\CPOL license.txt c:\program files\AVG SafeGuard toolbar\Licenses\Encoding_decoding_base64.txt c:\program files\AVG SafeGuard toolbar\Licenses\hmac.txt c:\program files\AVG SafeGuard toolbar\Licenses\LICENSE-bsdiff.txt c:\program files\AVG SafeGuard toolbar\Licenses\LICENSE-bzip.txt c:\program files\AVG SafeGuard toolbar\Licenses\LICENSE-JasonCpp.txt c:\program files\AVG SafeGuard toolbar\Licenses\LICENSE-MPL-NPAPI.txt c:\program files\AVG SafeGuard toolbar\Licenses\LICENSE-sparsehash.txt c:\program files\AVG SafeGuard toolbar\Licenses\Log4CPlus.txt c:\program files\AVG SafeGuard toolbar\Licenses\PassthruApp.txt c:\program files\AVG SafeGuard toolbar\lip.exe c:\program files\AVG SafeGuard toolbar\PostInstall.exe c:\program files\AVG SafeGuard toolbar\PostInstaller.ini c:\program files\AVG SafeGuard toolbar\privacy.gif c:\program files\AVG SafeGuard toolbar\remote_configuration.xml c:\program files\AVG SafeGuard toolbar\search.gif c:\program files\AVG SafeGuard toolbar\setup.bmp c:\program files\AVG SafeGuard toolbar\surf-with-caution18.gif c:\program files\AVG SafeGuard toolbar\Uninstall.exe c:\program files\AVG SafeGuard toolbar\uninstall.gif c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\cp-bg.png c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\cp_logo.png c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\downBtn.png c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\loader.gif c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\uninstall-bg.png c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Images\uninstall\upBtn.png c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\jquery-1.5.1.min.js c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\jquery-1.8.1.min.js c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\JQueyExtensions.js c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\uninstall_cp.css c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Uninstall_cp.html c:\program files\AVG SafeGuard toolbar\UninstallRes\ClientPackage\Uninstall_cp_step2.html c:\program files\AVG SafeGuard toolbar\updating18.gif c:\program files\AVG SafeGuard toolbar\vprot.exe c:\program files\Common Files\AVG Secure Search c:\program files\Common Files\AVG Secure Search\DNTInstaller\17.0.1\avgdttbx.dll c:\program files\Common Files\AVG Secure Search\DriverInstaller\17.0.1\DriverInstaller.exe c:\program files\Common Files\AVG Secure Search\InstalledProducts.ini c:\program files\Common Files\AVG Secure Search\RewardsInstaller\17.0.1\AVGRewardsWorker.cfg c:\program files\Common Files\AVG Secure Search\RewardsInstaller\17.0.1\AVGRewardsWorker.dll c:\program files\Common Files\AVG Secure Search\RewardsInstaller\17.0.1\helper.dll c:\program files\Common Files\AVG Secure Search\ScriptHelperInstaller\17.0.1\ScriptHelper.exe c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.1\npsitesafety.dll c:\program files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.1\SiteSafety.dll c:\program files\Common Files\AVG Secure Search\ToolBandTlb\17.0.1\toolband c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\17.0.1\ViProtocol.dll c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\log4cplusU.dll c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\loggingserver.exe c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\ToolbarUpdater.exe c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.1\UpdaterConfig.ini c:\programdata\AVG SafeGuard toolbar c:\programdata\AVG SafeGuard toolbar\ChromeExt\17.0.0.7\avg.crx c:\programdata\AVG SafeGuard toolbar\ChromeExt\17.0.0.9\avg.crx c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\chrome.manifest c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\chrome\avg.jar c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\components\avg-dnt-policy.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\components\nci.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\components\toolbarhomeApi.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\icon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\install.rdf c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\locale\en-US\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\locale\en-US\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\avg-dnt-adapter.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\avg.xml c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\avg.xul c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\avgJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\Bindings.xml c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\configuration.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\configuration_0.css c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\HistoryCleaner.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\IOJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\af\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\af\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\cs\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\cs\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\da\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\da\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\de\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\de\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\el\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\el\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\en\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\en\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\es-es\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\es-es\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\es\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\es\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\fi\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\fi\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\fr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\fr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\hi\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\hi\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\hu\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\hu\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\id\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\id\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\it\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\it\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ja\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ja\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ko\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ko\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ms\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ms\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\nb\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\nb\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\nl\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\nl\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pl\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pl\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pt-br\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pt-br\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pt\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\pt\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ro\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ro\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ru\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\ru\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sk\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sk\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sv\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\sv\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\th\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\th\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\tr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\tr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\zh-cn\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\zh-cn\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\zh-tw\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\locale\zh-tw\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\passwordbox.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\Preferences.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\propertiesJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\about.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\active-threats18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\ajax-loader.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\CleanHistory.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\close.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\current.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\currently-safe18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\dnt.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\EULA.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\Facebook.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\feedback.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\feedicon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\help.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\icon-1G.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\icon-1R.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\icon_search.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\icon18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\information-24.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\labs.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\loader.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\privacy.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\questionmarkIcon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\search.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\surf-with-caution18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\uninstall.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\updating18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.7\modules\skin\window-close.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\chrome.manifest c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\chrome\avg.jar c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\components\avg-dnt-policy.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\components\nci.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\components\toolbarhomeApi.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\icon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\install.rdf c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\locale\en-US\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\locale\en-US\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\avg-dnt-adapter.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\avg.xml c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\avg.xul c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\avgJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\Bindings.xml c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\configuration.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\configuration_0.css c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\HistoryCleaner.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\IOJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\af\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\af\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\cs\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\cs\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\da\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\da\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\de\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\de\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\el\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\el\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\en\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\en\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\es-es\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\es-es\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\es\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\es\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\fi\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\fi\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\fr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\fr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\hi\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\hi\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\hu\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\hu\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\id\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\id\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\it\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\it\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ja\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ja\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ko\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ko\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ms\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ms\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\nb\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\nb\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\nl\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\nl\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pl\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pl\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pt-br\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pt-br\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pt\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\pt\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ro\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ro\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ru\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\ru\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sk\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sk\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sv\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\sv\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\th\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\th\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\tr\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\tr\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\zh-cn\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\zh-cn\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\zh-tw\global.dtd c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\locale\zh-tw\global.properties c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\passwordbox.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\Preferences.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\propertiesJsm.js c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\about.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\active-threats18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\ajax-loader.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\CleanHistory.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\close.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\current.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\currently-safe18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\dnt.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\EULA.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\Facebook.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\feedback.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\feedicon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\help.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\icon-1G.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\icon-1R.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\icon_search.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\icon18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\information-24.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\labs.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\loader.gif c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\privacy.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\questionmarkIcon.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\search.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\surf-with-caution18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\uninstall.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\updating18.png c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9\modules\skin\window-close.png c:\programdata\AVG SafeGuard toolbar\Logger\logger.properties c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar\DNT\dt.dat c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar\SiteSafety\l_2013_09_26_12_08_49.db c:\users\Paul.Paul-PC\AppData\Local\AVG SafeGuard toolbar\SiteSafety\l_2013_09_27_02_13_37.db . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . ——-\Service_vToolbarUpdater17.0.1 . . ((((((((((((((((((((((((( Files Created from 2013-08-28 to 2013-09-28 ))))))))))))))))))))))))))))))) . . 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\TEMP\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\Public\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\Paul\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\Guest\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\Edward\AppData\Local\temp 2013-09-28 03:38 . 2013-09-28 03:38 ——– d—–w- c:\users\Default\AppData\Local\temp 2013-09-28 03:06 . 2013-09-28 03:06 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Local\VirtualStore 2013-09-26 07:09 . 2013-09-26 07:09 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Local\WinZip 2013-09-26 07:09 . 2013-09-26 07:09 ——– d—–w- c:\programdata\WinZip 2013-09-26 07:08 . 2013-09-26 07:08 37664 —-a-w- c:\windows\system32\drivers\avgtpx86.sys 2013-09-26 06:15 . 2013-09-26 06:22 ——– d—–w- C:\AdwCleaner 2013-09-21 18:22 . 2013-09-21 18:22 ——– d—–w- c:\users\Paul.Paul-PC\AppData\Roaming\Malwarebytes 2013-09-15 16:52 . 2013-09-15 16:52 ——– d—–w- c:\users\TEMP.Paul-PC 2013-09-08 02:15 . 2013-09-08 02:21 ——– d—–w- C:\wamp 2013-09-05 14:04 . 2013-09-05 14:04 209272 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-09-20 01:18 . 2012-05-17 04:36 692616 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2013-09-20 01:18 . 2011-12-30 17:09 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco1] @="{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}" [HKEY_CLASSES_ROOT\CLSID\{AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco2] @="{853B7E05-C47D-4985-909A-D0DC5C6D7303}" [HKEY_CLASSES_ROOT\CLSID\{853B7E05-C47D-4985-909A-D0DC5C6D7303}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ AccExtIco3] @="{42D38F2E-98E9-4382-B546-E24E4D6D04BB}" [HKEY_CLASSES_ROOT\CLSID\{42D38F2E-98E9-4382-B546-E24E4D6D04BB}] 2013-08-01 02:36 2601328 —-a-w- c:\program files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SearchProtection"="c:\users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" [2013-09-03 832360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2009-06-29 217088] "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-15 458844] "Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-07-17 4562944] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520] "OEM13Mon.exe"="c:\windows\OEM13Mon.exe" [2008-01-07 36864] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2009-07-09 115560] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 136216] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 171032] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 170520] "APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2013-03-10 88984] "AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-06-13 472984] "Adobe Creative Cloud"="c:\program files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2013-08-08 2236816] "AdobeCEPServiceManager"="c:\program files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe" [2013-03-13 1039248] "SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096] "AdobeCS6ServiceManager"="c:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr] @="Service" . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus] @="Service" . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2013-04-04 701512] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.0.318\McCHSvc.exe [2013-02-05 235216] R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-07 1343400] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040] S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx86.sys [2013-09-26 37664] S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-04-04 418376] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2013-08-27 108120] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-04-04 22856] S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdg.sys [2009-05-22 58528] S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdg.sys [2009-05-07 41504] S3 OEM13Vfx;Creative Camera OEM013 Video VFX Driver;c:\windows\system32\DRIVERS\OEM13Vfx.sys [2007-03-05 7424] S3 OEM13Vid;Creative Camera OEM013 Driver;c:\windows\system32\DRIVERS\OEM13Vid.sys [2008-05-28 235840] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-12-19 249888] . . Contents of the 'Scheduled Tasks' folder . 2013-09-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-17 01:18] . 2013-09-28 c:\windows\Tasks\AWC Startup.job - c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-02-02 20:33] . . ——- Supplementary Scan ——- . uStart Page = hxxp://search.yahoo.com?type=714647&fr=spigot-yhp-ie IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.1 FF - ProfilePath - c:\users\Paul.Paul-PC\AppData\Roaming\Mozilla\Firefox\Profiles\ya3lift0.default\ FF - prefs.js: browser.search.selectedEngine - AVG Secure Search FF - prefs.js: browser.startup.homepage - hxxp://mysearch.avg.com?cid={204F4A45-F957-45EF-9C25-7310E1E10F89}&mid=f7c1f7316cb443d5ac2aa2bef13e1c6b-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=hk018&coid=avgtbdishk&pr=sa&d=&v=17.0.0.9&pid=safeguard&sg=0&sap=hp FF - prefs.js: keyword.URL - FF - ExtSQL: 2013-09-26 03:08; avg@toolbar; c:\programdata\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9 . - - - - ORPHANS REMOVED - - - - . AddRemove-AVG SafeGuard toolbar - c:\program files\AVG SafeGuard toolbar\UNINSTALL.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\STacSV.exe c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe c:\program files\Common Files\Symantec Shared\ccSvcHst.exe c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\program files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE c:\program files\Dell\Dell Wireless WLAN Card\bcmwltry.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\windows\system32\DRIVERS\o2flash.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\system32\taskhost.exe c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe c:\windows\system32\conhost.exe c:\windows\system32\DllHost.exe c:\windows\system32\sppsvc.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2013-09-27 23:46:21 - machine was rebooted ComboFix-quarantined-files.txt 2013-09-28 03:46 ComboFix2.txt 2013-09-26 21:52 ComboFix3.txt 2013-09-26 21:31 . Pre-Run: 132,641,546,240 bytes free Post-Run: 132,485,074,944 bytes free . - - End Of File - - 5D8CD89CE67E128125664CCFA9DDB8D3 5C616939100B85E558DA92B899A0FC36
Hi pmedvins,

[external image: Posted Image] Run OTL.exe

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Commands
    [purity]
    [createrestorepoint]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
=========================

[external image: Posted Image] Re-run Malwarebytes Anti-Rootkit

=========================

In your next post please provide the following:
  • Fresh OTL.txt
  • New system-log.txt
  • How is the computer running?
Hi OCD, everything is running roughly the same way that is has been.

Here are the logs:

OTL logfile created on: 9/28/2013 9:55:37 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Paul.Paul-PC\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.96 Gb Total Physical Memory | 1.74 Gb Available Physical Memory | 58.81% Memory free
5.92 Gb Paging File | 4.71 Gb Available in Paging File | 79.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 218.20 Gb Total Space | 123.64 Gb Free Space | 56.66% Space Free | Partition Type: NTFS
Drive D: | 45.65 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Paul.Paul-PC\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe (Spigot, Inc.)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
PRC - C:\Program Files\Dell\Dell Wireless WLAN Card\BCMWLTRY.EXE (Dell Inc.)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
PRC - C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
PRC - C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\HEX\libcef.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x86.dll ()
MOD - C:\Program Files\Adobe\Adobe Creative Cloud\CoreSync\CCInvokeAAM.dll ()
MOD - C:\Program Files\Common Files\Adobe\CEPServiceManager4\zlib1.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\03cfab5534482e8fc313ead6edc19100\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\413288993ff690e8251d2dbe32bee01f\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dd758ac0bf7358ac6e4720610fcc63c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\187d7c66735c533de851c76384f86912\mscorlib.ni.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlrmt.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.6.12\bin\mysqld.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\Apache2.4.4\bin\httpd.exe (Apache Software Foundation)
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (Symantec AntiVirus) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (SmcService) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (wltrysvc) – C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE ()
SRV - (STacSV) – C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_5f120bca41bba11b\stacsv.exe (IDT, Inc.)
SRV - (StorSvc) – C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (O2FLASH) – C:\Windows\System32\drivers\o2flash.exe (O2Micro International)


========== Driver Services (SafeList) ==========

DRV - (catchme) – C:\Users\PAUL~1.PA~\AppData\Local\Temp\catchme.sys File not found
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130927.018\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20130927.018\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MBAMProtector) – C:\Windows\System32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (WpsHelper) – C:\Windows\System32\drivers\wpshelper.sys (Symantec Corporation)
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SysPlant) – C:\Windows\System32\drivers\SysPlant.sys (Symantec Corporation)
DRV - (WPS) – C:\Windows\System32\drivers\WPSDRVnt.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (BCM42RLY) – C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (STHDA) – C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (Teefer2) – C:\Windows\System32\drivers\Teefer2.sys (Symantec Corporation)
DRV - (O2MDGRDR) – C:\Windows\System32\drivers\o2mdg.sys (O2Micro )
DRV - (O2SDGRDR) – C:\Windows\System32\drivers\o2sdg.sys (O2Micro )
DRV - (ApfiltrService) – C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (OEM13Vid) – C:\Windows\System32\drivers\OEM13Vid.sys (Creative Technology Ltd.)
DRV - (OEM13Vfx) – C:\Windows\System32\drivers\OEM13Vfx.sys (EyePower Games Pte. Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{3A434D2D-EFE9-4239-836B-6EFFC9FE9581}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{5033EE8D-A640-41CA-9012-7AFD6DF2C83F}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.yahoo.com?type=714647&fr=spigot-yhp-ie
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{19CE7FE4-BED6-4C79-9A4D-37D8D1AA91E9}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://mysearch.avg.com/search?cid={204F4A…mp;d=2013-09-26 03:08:46&v=17.0.0.9&pid=safeguard&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=714647"
FF - prefs.js..browser.startup.homepage: "http://mysearch.avg.com?cid={204F4A45-F957-45EF-9C25-7310E1E10F89}&mid=f7c1f7316cb443d5ac2aa2bef13e1c6b-b602d594afd2b0b327e07a06f36ca6a7e42546d0&lang=en&ds=hk018&coid=avgtbdishk&pr=sa&d=&v=[removed]&pid=safeguard&sg=0&sap=hp"
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:[removed]
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130924
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - prefs.js..keyword.URL: ""
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\17.0.1\\npsitesafety.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.40.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\fbphotozoom\fbphotozoom14.xpi
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG SafeGuard toolbar\FireFoxExt\17.0.0.9
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/09/19 08:28:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/09/28 16:56:59 | 000,000,000 | —D | M]

[2013/05/02 19:14:52 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2013/09/27 17:12:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions
[2013/09/27 17:12:37 | 000,000,000 | —D | M] (WOT) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\Firefox\Profiles\ya3lift0.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/09/22 18:16:30 | 000,534,729 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/07/30 20:39:55 | 000,824,302 | —- | M] () (No name found) – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/09/27 23:08:42 | 000,003,745 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\searchplugins\safeguard-secure-search.xml
[2013/08/06 19:18:55 | 000,000,915 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Roaming\mozilla\firefox\profiles\ya3lift0.default\searchplugins\yahoo.xml
[2013/09/19 08:28:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/09/19 08:28:10 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll
[2013/09/27 17:13:37 | 000,003,745 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\safeguard-secure-search.xml

O1 HOSTS File: ([2013/09/27 23:41:32 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [OEM13Mon.exe] C:\Windows\OEM13Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [SearchProtection] C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE (Spigot, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B82892F4-0671-4942-BCB8-BCB5812C3AE4}: DhcpNameServer = 10.0.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/28 21:44:38 | 000,000,000 | —D | C] – C:\_OTL
[2013/09/28 17:02:05 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Citrix
[2013/09/28 16:57:47 | 000,000,000 | —D | C] – C:\ProgramData\Oracle
[2013/09/28 16:57:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/09/28 16:57:33 | 000,264,616 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/09/28 16:57:21 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/09/28 16:57:21 | 000,175,016 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/09/28 16:57:21 | 000,094,632 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/09/28 16:57:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2013/09/27 23:46:25 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/09/27 23:41:34 | 000,000,000 | —D | C] – C:\$RECYCLE.BIN
[2013/09/27 23:06:20 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\AppData\Local\VirtualStore
[2013/09/27 20:54:15 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Desktop\mbar
[2013/09/27 20:50:27 | 012,907,592 | —- | C] (Malwarebytes Corp.) – C:\Users\Paul.Paul-PC\Desktop\mbar-1.07.0.1005.exe
[2013/09/26 17:10:54 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/09/26 17:10:54 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/09/26 17:10:54 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/09/26 17:10:42 | 000,000,000 | —D | C] – C:\Qoobox
[2013/09/26 16:55:03 | 005,129,766 | R— | C] (Swearware) – C:\Users\Paul.Paul-PC\Desktop\ComboFix.exe
[2013/09/26 03:09:57 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\AppData\Local\WinZip
[2013/09/26 03:09:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
[2013/09/26 03:09:16 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Documents\Add-in Express
[2013/09/26 03:09:08 | 000,000,000 | —D | C] – C:\ProgramData\WinZip
[2013/09/26 03:09:06 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2013/09/26 03:08:45 | 000,037,664 | —- | C] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/09/26 02:15:51 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/22 20:26:28 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Paul.Paul-PC\Desktop\HiJackThis.exe
[2013/09/21 20:24:36 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:22:49 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\AppData\Roaming\Malwarebytes
[2013/09/19 08:28:02 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/09/07 22:20:52 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WampServer
[2013/09/07 22:15:27 | 000,000,000 | —D | C] – C:\wamp
[2013/09/07 21:41:52 | 000,000,000 | —D | C] – C:\Users\Paul.Paul-PC\Desktop\php-5.5.3

========== Files - Modified Within 30 Days ==========

[2013/09/28 21:56:59 | 000,014,256 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/28 21:56:59 | 000,014,256 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/28 21:49:59 | 000,000,372 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2013/09/28 21:49:40 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/28 21:49:19 | 2385,211,392 | -HS- | M] () – C:\hiberfil.sys
[2013/09/28 21:18:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/28 17:02:10 | 000,000,081 | —- | M] () – C:\Users\Paul.Paul-PC\CTX.DAT
[2013/09/28 16:57:13 | 000,094,632 | —- | M] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/09/28 16:57:11 | 000,264,616 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaws.exe
[2013/09/28 16:57:11 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/09/28 16:57:11 | 000,175,016 | —- | M] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/09/28 16:57:10 | 000,868,264 | —- | M] (Oracle Corporation) – C:\Windows\System32\npDeployJava1.dll
[2013/09/28 16:57:10 | 000,790,440 | —- | M] (Oracle Corporation) – C:\Windows\System32\deployJava1.dll
[2013/09/27 23:41:32 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/09/27 20:50:31 | 012,907,592 | —- | M] (Malwarebytes Corp.) – C:\Users\Paul.Paul-PC\Desktop\mbar-1.07.0.1005.exe
[2013/09/26 16:55:07 | 005,129,766 | R— | M] (Swearware) – C:\Users\Paul.Paul-PC\Desktop\ComboFix.exe
[2013/09/26 03:10:28 | 000,000,606 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\MBR.zip
[2013/09/26 03:09:34 | 000,002,283 | —- | M] () – C:\Users\Public\Desktop\WinZip.lnk
[2013/09/26 03:08:51 | 000,003,746 | —- | M] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2013/09/26 03:08:31 | 000,037,664 | —- | M] (AVG Technologies) – C:\Windows\System32\drivers\avgtpx86.sys
[2013/09/26 03:03:15 | 000,000,555 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\MBR.rar
[2013/09/26 02:15:21 | 001,042,066 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe
[2013/09/26 02:02:15 | 000,000,512 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\MBR.dat
[2013/09/22 20:26:27 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Paul.Paul-PC\Desktop\HiJackThis.exe
[2013/09/21 20:55:45 | 000,726,092 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/21 20:24:35 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Paul.Paul-PC\Desktop\OTL.exe
[2013/09/21 14:23:18 | 000,001,073 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/19 21:18:06 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2013/09/19 21:18:06 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/09/17 01:01:56 | 000,108,254 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/09/15 12:57:33 | 003,868,360 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/09/13 21:49:22 | 000,001,456 | —- | M] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/09/05 14:56:33 | 000,066,389 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.pdf
[2013/09/05 14:56:17 | 000,073,594 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\OfficialResume1.rtf
[2013/08/30 19:36:21 | 000,140,137 | —- | M] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png

========== Files Created - No Company Name ==========

[2013/09/28 17:02:10 | 000,000,081 | —- | C] () – C:\Users\Paul.Paul-PC\CTX.DAT
[2013/09/26 17:10:54 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/09/26 17:10:54 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/09/26 17:10:54 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/09/26 17:10:54 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/09/26 17:10:54 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/09/26 03:10:28 | 000,000,606 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\MBR.zip
[2013/09/26 03:09:34 | 000,002,283 | —- | C] () – C:\Users\Public\Desktop\WinZip.lnk
[2013/09/26 03:08:36 | 000,003,746 | —- | C] () – C:\Program Files\Mozilla Firefoxsafeguard-secure-search.xml
[2013/09/26 03:03:15 | 000,000,555 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\MBR.rar
[2013/09/26 02:15:20 | 001,042,066 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\AdwCleaner.exe
[2013/09/26 02:02:15 | 000,000,512 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\MBR.dat
[2013/09/21 20:55:45 | 000,726,092 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Untitled.png
[2013/09/17 01:01:52 | 000,108,254 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\Crystal Reports Viewer.pdf
[2013/08/30 19:36:20 | 000,140,137 | —- | C] () – C:\Users\Paul.Paul-PC\Desktop\wordpress.png
[2013/08/19 03:47:33 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe PNG Format CC Prefs
[2013/08/14 23:49:58 | 000,000,054 | —- | C] () – C:\Users\Paul.Paul-PC\.gitconfig
[2013/07/06 19:22:16 | 000,001,456 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/07/06 18:55:57 | 000,000,132 | —- | C] () – C:\Users\Paul.Paul-PC\AppData\Roaming\Adobe BMP Format CC Prefs

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll\system32\wbem\wbemess.dll
"ThreadingModel" = Apartment

========== Alternate Data Streams ==========

@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:1AE68282

< End of report >


—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.194000 GHz
Memory total: 3180285952, free: 1562705920

=======================================


—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.194000 GHz
Memory total: 3180285952, free: 1562476544

Downloaded database version: v2013.09.27.08
Downloaded database version: v2013.09.23.01
Initializing…
======================
———— Kernel report ————
09/27/2013 20:56:34
———— Loaded modules ———–
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHelp20.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\SRTSP.SYS
\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130926.004\NAVEX15.SYS
\??\C:\Windows\system32\Drivers\SYMEVENT.SYS
\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130926.004\NAVENG.SYS
\SystemRoot\System32\Drivers\SRTSPX.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\Windows\system32\drivers\avgtpx86.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\??\C:\Windows\system32\drivers\wpsdrvnt.sys
\SystemRoot\System32\Drivers\SYMTDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\Drivers\ElbyCDIO.sys
\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd32.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt86win7.sys
\SystemRoot\system32\DRIVERS\bcmwl6.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\DRIVERS\o2sdg.sys
\SystemRoot\system32\DRIVERS\SCSIPORT.SYS
\SystemRoot\system32\DRIVERS\o2mdg.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\VClone.sys
\SystemRoot\system32\DRIVERS\teefer2.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\stwrt.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\OEM13Vid.sys
\SystemRoot\system32\DRIVERS\OEM13Vfx.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\??\C:\Windows\system32\drivers\WpsHelper.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\drivers\ipnat.sys
\SystemRoot\system32\drivers\BCM42RLY.sys
\SystemRoot\System32\Drivers\SYMREDRV.SYS
\SystemRoot\System32\Drivers\fastfat.SYS
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\msctf.dll
\Windows\System32\sechost.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\advapi32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\msvcrt.dll
\Windows\System32\urlmon.dll
\Windows\System32\psapi.dll
\Windows\System32\normaliz.dll
\Windows\System32\iertutil.dll
\Windows\System32\nsi.dll
\Windows\System32\usp10.dll
\Windows\System32\shell32.dll
\Windows\System32\ole32.dll
\Windows\System32\imm32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\lpk.dll
\Windows\System32\wininet.dll
\Windows\System32\difxapi.dll
\Windows\System32\ws2_32.dll
\Windows\System32\clbcatq.dll
\Windows\System32\user32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\shlwapi.dll
\Windows\System32\setupapi.dll
\Windows\System32\gdi32.dll
\Windows\System32\oleaut32.dll
\Windows\System32\kernel32.dll
\Windows\System32\crypt32.dll
\Windows\System32\wintrust.dll
\Windows\System32\comctl32.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\KernelBase.dll
\Windows\System32\msasn1.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff868a57c8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xffffffff85e5f028
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff868a57c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff868a5400, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff868a57c8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff85e5f028, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: F638964D

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 80262

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 81920 Numsec = 30720000
Partition file system is NTFS
Partition is bootable

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 30801920 Numsec = 457593200

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)…
Done!
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh121d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1661.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1a38.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1ac5.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1b90.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1bce.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1c2c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1c5a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1e0f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1f66.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1f76.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh206f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh208f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh209e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh20ec.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh213a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2169.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2263.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2511.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh26e5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2762.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh28f7.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2df7.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2e16.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2f3f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3028.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh31ae.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh320.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh33.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3363.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh33ff.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh345c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh34f9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh35c4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh35e3.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh367f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh373a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3759.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3862.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3872.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh38c0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3a56.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3bc.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3e7a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3e99.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3f74.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh41b5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh455d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh456c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4712.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh48d6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4c21.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4cec.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4d68.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4e24.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5055.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5074.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5075.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5277.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh52d5.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5371.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh53fd.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh55a2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh592b.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5a15.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5af0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5d7f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5e88.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh60ba.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6194.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh61c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6387.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh652c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh65c8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6626.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh66b2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh67cb.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6838.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6858.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6b25.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6cea.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6d66.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6e12.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f1b.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f88.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7552.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh75c0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh764.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh764c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7765.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh785e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh78ac.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh79d5.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7a42.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7b2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7c83.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7ce1.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7d8c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7ffc.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh825d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh82ab.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8308.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8375.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8450.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh84dd.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh84e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8672.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8930.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh89c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8ab.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8b33.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8cf7.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8d45.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8df1.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8f0a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8ff4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh91b8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9206.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh928.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh93da.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9467.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9495.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh94d4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9551.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh957.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh964a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9aad.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9e27.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9ee2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9f4f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha00a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha49c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha4da.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha5a5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha6ed.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha75a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha7a8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha825.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha96d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha9da.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha9f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac4a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac78.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaca7.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhad14.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhadfe.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaf65.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb271.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb5eb.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb86a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbb28.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc31.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc7f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbc9f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbe92.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbf6c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbff9.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc0c3.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc0f2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc121.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc17e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc1bd.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc314.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc3ee.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc41d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc5b3.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc67e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc729.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc82.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc8a0.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc9a9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcb10.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcc38.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhce6a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd1e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd3c7.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd434.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd887.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd8f4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd904.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd971.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd991.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd9b0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhda3c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdb36.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdbe1.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdc9d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdebe.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdf1c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdfc8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe073.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe6aa.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhec84.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhee39.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhef52.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhef90.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0c8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0d8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf164.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf193.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf3c5.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf470.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf4be.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf4dd.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf52c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf6d1.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfa59.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb53.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfdc.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfe6e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfe9d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh42ce.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5e69.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6108.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8116.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha097.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcbeb.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1346.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh24d3.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2f10.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe3be.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb92.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3cc6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd1f.tmp –> [Trojan.Dropper.BCMiner]
Scan finished
Creating System Restore point…
Cleaning up…
Executing an action fixdamage.exe…
Success!
Queuing an action fixdamage.exe
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam…
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_81920_i.mbam…
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam…
Removal finished
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.194000 GHz
Memory total: 3180285952, free: 1820463104

=======================================
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.194000 GHz
Memory total: 3180285952, free: 1635725312

Downloaded database version: v2013.09.28.01
Downloaded database version: v2013.09.28.02
Downloaded database version: v2013.09.28.03
Downloaded database version: v2013.09.28.04
Downloaded database version: v2013.09.28.05
Downloaded database version: v2013.09.28.06
Downloaded database version: v2013.09.28.07
Downloaded database version: v2013.09.28.08
Downloaded database version: v2013.09.28.09
Downloaded database version: v2013.09.28.10
Downloaded database version: v2013.09.28.11
Downloaded database version: v2013.09.28.12
Downloaded database version: v2013.09.29.01
Initializing…
======================
———— Kernel report ————
09/28/2013 22:16:15
———— Loaded modules ———–
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\DRIVERS\compbatt.sys
\SystemRoot\system32\DRIVERS\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\vmbus.sys
\SystemRoot\system32\drivers\winhv.sys
\SystemRoot\system32\DRIVERS\iaStor.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\PxHelp20.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\System32\Drivers\SRTSP.SYS
\??\C:\Windows\system32\Drivers\SYMEVENT.SYS
\SystemRoot\System32\Drivers\SRTSPX.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\??\C:\Windows\system32\drivers\avgtpx86.sys
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\??\C:\Windows\system32\drivers\wpsdrvnt.sys
\SystemRoot\System32\Drivers\SYMTDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\System32\Drivers\ElbyCDIO.sys
\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\igdkmd32.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\usbuhci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\Rt86win7.sys
\SystemRoot\system32\DRIVERS\bcmwl6.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\drivers\1394ohci.sys
\SystemRoot\system32\DRIVERS\o2sdg.sys
\SystemRoot\system32\DRIVERS\SCSIPORT.SYS
\SystemRoot\system32\DRIVERS\o2mdg.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\drivers\i8042prt.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\Apfiltr.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\DRIVERS\VClone.sys
\SystemRoot\system32\DRIVERS\teefer2.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\DRIVERS\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\stwrt.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\OEM13Vid.sys
\SystemRoot\system32\DRIVERS\OEM13Vfx.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Windows\system32\drivers\mbam.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\drivers\HTTP.sys
\??\C:\Windows\system32\drivers\WpsHelper.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\System32\drivers\ipnat.sys
\SystemRoot\system32\drivers\BCM42RLY.sys
\SystemRoot\System32\Drivers\SYMREDRV.SYS
\SystemRoot\System32\Drivers\fastfat.SYS
\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130928.006\NAVEX15.SYS
\??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20130928.006\NAVENG.SYS
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\wininet.dll
\Windows\System32\sechost.dll
\Windows\System32\setupapi.dll
\Windows\System32\Wldap32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\user32.dll
\Windows\System32\gdi32.dll
\Windows\System32\difxapi.dll
\Windows\System32\usp10.dll
\Windows\System32\msvcrt.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\comdlg32.dll
\Windows\System32\nsi.dll
\Windows\System32\imagehlp.dll
\Windows\System32\iertutil.dll
\Windows\System32\oleaut32.dll
\Windows\System32\psapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\normaliz.dll
\Windows\System32\msctf.dll
\Windows\System32\urlmon.dll
\Windows\System32\lpk.dll
\Windows\System32\clbcatq.dll
\Windows\System32\shlwapi.dll
\Windows\System32\shell32.dll
\Windows\System32\ole32.dll
\Windows\System32\kernel32.dll
\Windows\System32\imm32.dll
\Windows\System32\wintrust.dll
\Windows\System32\comctl32.dll
\Windows\System32\crypt32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\devobj.dll
\Windows\System32\msasn1.dll
———– End ———–
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff868a2248
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\Ide\IAAStorageDevice-1\
Lower Device Object: 0xffffffff85e3f028
Lower Device Driver Name: \Driver\iaStor\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff868a2248, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
——— Disk Stack ——
DevicePointer: 0xffffffff868a3d10, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff868a2248, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff85e3f028, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\
———— End ———-
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers…
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0…
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: F638964D

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63 Numsec = 80262

Partition 1 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 81920 Numsec = 30720000
Partition file system is NTFS
Partition is bootable

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 30801920 Numsec = 457593200

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0

Disk Size: 250059350016 bytes
Sector size: 512 bytes

Scanning physical sectors of unpartitioned space on drive 0 (1-62-488377168-488397168)…
Done!
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1046.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh10f1.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh115e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh128.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1303.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1332.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1342.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh13de.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh14d8.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh14e7.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1525.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1535.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1554.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1583.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh167.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh186.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh187.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1880.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh19e6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1cd3.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1d21.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1ee6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1fdf.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh205c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh224f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh228d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh23f4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2413.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhedc8.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhef6d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhefe.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0b4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf0e4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf269.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf2b7.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf3d0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf43d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf611.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf6b.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf769.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf872.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhf90e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfa.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfad2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb11.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfb6e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfc39.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfd04.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfd90.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f18.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6f27.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7187.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7271.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh731d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh73a9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh73d8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7474.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh750.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh76a6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7713.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh780c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7e73.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7e92.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7f7c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh7fc9.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8085.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8121.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhad20.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhad7e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhae58.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaef4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaf61.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb08a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb099.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb27d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb309.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb3f3.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb625.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb6c1.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb71e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb77c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb8b4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhb970.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbb4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbbb0.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbd27.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbe9e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbfd5.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3cf0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3d10.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3ddb.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3f60.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3fbe.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh40e6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh40f6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4106.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4308.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh43c4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4450.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh44ad.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh452a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh471e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4865.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4940.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh49eb.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4a68.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4b14.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4cb9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4db2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh4fe4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5003.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh50dd.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh510c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5225.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5254.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh53bb.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5495.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5512.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh56f5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhceb4.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcf5f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcf9e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcfb.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd114.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd172.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd29a.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd46e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd577.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd5d5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd604.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd807.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd8a3.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhd8c2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdb61.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdb9f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdc2b.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh24a0.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3c06.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5743.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh815f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh92bd.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac94.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhbfe5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdeab.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhebf.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhfed8.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh934a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9378.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh93b7.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh94cf.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh953d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh955c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh95d9.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh95e9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh96b4.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh96f2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh975f.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9887.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9914.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9962.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9b16.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9b45.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9e90.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9f0c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9f3b.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh9ff7.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha083.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha0a2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha322.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha4d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha563.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha5ef.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha7c3.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha802.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwha959.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaaa.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhaab0.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac93.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5753.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5937.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5946.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5947.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5a8e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5afb.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5b0b.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5bd6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5c14.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5d2d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5db9.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5e74.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh5f30.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6049.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh60a6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh643e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6661.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6670.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6892.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh68d0.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh695d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6b31.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6b50.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6b9e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6d05.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6d33.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6d34.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh6eb9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh24fd.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2700.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2710.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh275e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh276d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh277d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh29af.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2af6.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2bb2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2c7d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2cba.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2cda.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2cea.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2d18.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh2d47.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh313d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh31f8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3311.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh34d6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh35cf.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh367b.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh37f1.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3a61.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3a80.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3b0d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhffc2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc12d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc15b.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc20.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc226.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc36e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc3ac.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc6c8.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc86d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc87c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc8e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhca03.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhca50.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcb0c.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhcc25.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhccc1.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh817e.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh818e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh81cd.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8334.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8343.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8507.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh869d.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8767.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh879.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8871.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8aa2.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8b00.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8b3e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8c96.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh8e6.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh900f.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh90ca.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdf5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe050.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe234.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe2ef.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe30e.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe32d.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe35c.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe418.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe4d3.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe521.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe60a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe6d5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe88a.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe8c9.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe964.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe994.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe9c2.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwheadb.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhebd5.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh1e69.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhdd54.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhe476.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh3756.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh53ac.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh67b8.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwh77de.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac.tmp –> [Rootkit.Zaccess]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhac37.tmp –> [Trojan.Dropper.BCMiner]
Infected: c:\Users\Paul.Paul-PC\AppData\Local\temp\dwhc561.tmp –> [Rootkit.Zaccess]
Scan finished
Creating System Restore point…
Cleaning up…
Executing an action fixdamage.exe…
Success!
Queuing an action fixdamage.exe
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam…
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_81920_i.mbam…
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam…
Removal finished
—————————————
Malwarebytes Anti-Rootkit BETA 1.07.0.1005

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x86

Account is Administrative

Internet Explorer version: 9.0.8112.16421

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.194000 GHz
Memory total: 3180285952, free: 1564901376

=======================================
Hi pmedvins,

everything is running roughly the same way that is has been.

I work on a few threads at a time. With that in mind, in future posts could you give a little more detail about how the computer is performing. This will help me in diagnosing the problem quicker.

=========================

[external image: Posted Image] Empty Temp Folder
  • Close all open applications.
  • Click the Start button.
  • In the Search programs and files box, enter Disk Cleanup and press Enter.
  • Locate Disk Cleanup in the list and double-click to open. Wait for the window to open.
  • Select (check) these choices.

    • Downloaded Program Files
    • Temporary Internet Files
    • Offline webpages
    • Recycle Bin
    • Temporary files
    • Thumbnails
    Note: Setup Log Files and System error memory dump files should be left un-checked.
  • Click OK. Click Delete Files.
  • The window will close when done.
=========================

[external image: Posted Image] Farbar Recovery Scan Tool

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • FRST.txt
  • Additions.txt
Everything is running on my computer at a normal place but I'm still worried about these trojans. After I click scan on frst.exe it would stop a minute after and an error message would pop up that says Line 17533 Error:Error in expression and the program would immediately shut down. I tried running it multiple times and the same thing always happened. I downloaded the correct 32 bit version and tried it with and without my antivirus programs enabled.
Hi pmedvins,

Delete the copy of FRST you previously downloaded.

=========================

[external image: Posted Image] rkill

Print out these instructions as we may need to close every window that is open later in the fix.

It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Right click and select "Run as Administrator"
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe
Do not reboot your computer after running rkill as the malware programs will start again.

=========================

[external image: Posted Image] Re-download Farbar Recovery Scan Tool it should of been saved to your desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Right click and select "Run as Administrator" to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply
=========================

In your next post please provide the following:
  • FRST.txt
  • Additions.txt
I ran rkill.exe. I then re-downloaded frst.exe and ran it off my flash drive.The same thing happened where the scan would stop after a minute and it would say Error:Error in expression. I don't have a problem with downloading files.

Here is my rkill.exe log just incase:

Rkill 2.6.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/30/2013 10:53:53 PM in x86 mode.
Windows Version: Windows 7 Professional Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* No malware processes found to kill.

Checking Registry for malware related settings:

* No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* Windows Defender Disabled

[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001

Checking Windows Service Integrity:

* Windows Defender (WinDefend) is not Running.
Startup Type set to: Manual

Searching for Missing Digital Signatures:

* No issues found.

Checking HOSTS File:

* HOSTS file entries found:

127.0.0.1 localhost

Program finished at: 09/30/2013 10:55:08 PM
Execution time: 0 hours(s), 1 minute(s), and 15 seconds(s)
Hi pmedvins,

[external image: Posted Image] Show Hidden Files & Folders in Windows 7
  • To show hidden files, just click on the Organize button in any folder, and then select “Folder and Search Options” from the menu.
  • Click the View tab, and then you should select “Show hidden files and folders” in the list.
  • Then click OK.
=========================

[external image: Posted Image] Delete a File/Folder

Using Windows Explorer (Windows Key + E), locate the following folder, and DELETE the entire contents of the temp folder (if still present):
  • c:\Users\Paul.Paul-PC\AppData\Local\temp\delete all the files in the temp folder, NOT the temp folder itself
Exit Explorer

=========================

[external image: Posted Image] Reboot

=========================

[external image: Posted Image] RogueKiller

Download to your desktop RogueKiller (by tigzy)
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Quit all programs
  • Wait until Prescan has finished …
  • Click on Scan, Do Not Fix Anything at this point.
  • Click the Report button, save the report to your desktop
=========================

[external image: Posted Image] Re-run Malwarebytes Anti-Rootkit

In your next post please provide the following:
  • RogueKiller log
  • mbar-log-(date & time)
  • system-log
  • How is the computer running at the moment?
My programs and processes seem to be running at a good pace. I have attached the system-log file because the post was too large with it included.

RogueKiller V8.7.0 [Sep 30 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Paul [Admin rights]
Mode : Scan – Date : 10/02/2013 22:57:19
| ARK || FAK || MBR |

¤¤¤ Bad processes : 1 ¤¤¤
[SUSP PATH] SearchProtection.exe – C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.exe [7] -> KILLED [TermProc]

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKCU\[…]\Run : SearchProtection ("C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart [7]) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-2674026609-1698660912-1609442580-1003\[…]\Run : SearchProtection ("C:\Users\Paul.Paul-PC\AppData\Roaming\Search Protection\SearchProtection.EXE" /autostart [7]) -> FOUND
[HJ POL][PUM] HKLM\[…]\System : DisableRegistryTools (0) -> FOUND
[HJ SMENU][PUM] HKCU\[…]\Advanced : Start_ShowMyGames (0) -> FOUND
[HJ DESK][PUM] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
[Address] SSDT[13] : NtAlertResumeThread @ 0x82CFDC99 -> HOOKED (Unknown @ 0x86C771C0)
[Address] SSDT[14] : NtAlertThread @ 0x82C50BE0 -> HOOKED (Unknown @ 0x86C772A0)
[Address] SSDT[19] : NtAllocateVirtualMemory @ 0x82C49BEC -> HOOKED (Unknown @ 0x86C77C78)
[Address] SSDT[59] : ExpInterlockedPopEntrySListResume @ 0x82C97F59 -> HOOKED (Unknown @ 0x86C28AE8)
[Address] SSDT[74] : NtCreateMutant @ 0x82C302B2 -> HOOKED (Unknown @ 0x86C7DF00)
[Address] SSDT[87] : NtCreateThread @ 0x82CFBECA -> HOOKED (Unknown @ 0x86C77F28)
[Address] SSDT[131] : NtFreeVirtualMemory @ 0x82AD7AEC -> HOOKED (Unknown @ 0x86C77AD8)
[Address] SSDT[145] : NtImpersonateAnonymousToken @ 0x82C158E0 -> HOOKED (Unknown @ 0x86C7DFD0)
[Address] SSDT[147] : NtImpersonateThread @ 0x82C9984C -> HOOKED (Unknown @ 0x86C770E0)
[Address] SSDT[168] : NtMapViewOfSection @ 0x82C66532 -> HOOKED (Unknown @ 0x86C779F8)
[Address] SSDT[177] : NtOpenEvent @ 0x82C2FCAE -> HOOKED (Unknown @ 0x86C7DE20)
[Address] SSDT[191] : NtOpenProcessToken @ 0x82C8423F -> HOOKED (Unknown @ 0x86C77EF0)
[Address] SSDT[199] : NtOpenThreadToken @ 0x82C98534 -> HOOKED (Unknown @ 0x86C77778)
[Address] SSDT[304] : NtResumeThread @ 0x82C90592 -> HOOKED (Unknown @ 0x86C61160)
[Address] SSDT[316] : NtSetContextThread @ 0x82CFD745 -> HOOKED (Unknown @ 0x86C77698)
[Address] SSDT[333] : NtSetInformationProcess @ 0x82C5878D -> HOOKED (Unknown @ 0x86C77868)
[Address] SSDT[335] : NtSetInformationThread @ 0x82C89CF6 -> HOOKED (Unknown @ 0x86C775A8)
[Address] SSDT[366] : NtSuspendProcess @ 0x82CFDBD3 -> HOOKED (Unknown @ 0x86C7DD40)
[Address] SSDT[367] : NtSuspendThread @ 0x82CB5085 -> HOOKED (Unknown @ 0x86C773E8)
[Address] SSDT[370] : NtTerminateProcess @ 0x82C7ABFB -> HOOKED (Unknown @ 0x86C74110)
[Address] SSDT[371] : NtTerminateThread @ 0x82C98584 -> HOOKED (Unknown @ 0x86C774C8)
[Address] SSDT[385] : NtUnmapViewOfSection @ 0x82C8487A -> HOOKED (Unknown @ 0x86C77938)
[Address] SSDT[399] : NtWriteVirtualMemory @ 0x82C7F958 -> HOOKED (Unknown @ 0x86C77BA8)
[Address] IAT @explorer.exe (GetUserNameExW) : Secur32.dll -> HOOKED (C:\Windows\system32\SSPICLI.DLL @ 0x74E22AAF)
[Inline] EAT @explorer.exe (?s_pClassInfo@CCSysLink@DirectUI@@0PAUIClassInfo@2@A) : DUI70.dll -> HOOKED (Unknown @ 0x6BC4C2F1)
[Inline] EAT @explorer.exe (?s_pClassInfo@Element@DirectUI@@0PAUIClassInfo@2@A) : DUI70.dll -> HOOKED (Unknown @ 0xA1C4C069)
[Inline] EAT @explorer.exe (?s_pClassInfo@RadioButtonGlyph@DirectUI@@0PAUIClassInfo@2@A) : DUI70.dll -> HOOKED (Unknown @ 0x6BC4C21F)
[Inline] EAT @explorer.exe (?s_pClassInfo@TextGraphic@DirectUI@@0PAUIClassInfo@2@A) : DUI70.dll -> HOOKED (Unknown @ 0x6BC4C310)
[Inline] EAT @explorer.exe (??_7?$basic_streambuf@GU?$char_traits@G@std@@@std@@6B@) : MSVCP100.dll -> HOOKED (Unknown @ 0x3E742483)
[Inline] EAT @explorer.exe (?MILLIS_PER_SECOND@GCDate@@2JB) : GrooveUtil.DLL -> HOOKED (Unknown @ 0xCAFB333C)
[Inline] EAT @explorer.exe (?ms_Semaphore@GCUtilDLL@@2VGCSemaphore@@A) : GrooveUtil.DLL -> HOOKED (Unknown @ 0x69FEBAE4)
[Inline] EAT @explorer.exe (_pctype) : MSVCR80.dll -> HOOKED (Unknown @ 0x5BDC8335)
[Inline] EAT @explorer.exe (?m_csFlushPtrs@CWbemProviderGlue@@0VCCritSec@@A) : framedynos.dll -> HOOKED (Unknown @ 0x5B5B9768)
[Inline] EAT @explorer.exe (?_Ptr_wcout@std@@3PAV?$basic_ostream@GU?$char_traits@G@std@@@1@A) : MSVCP80.dll -> HOOKED (Unknown @ 0x21E572A5)

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
–> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ( @ ) - +++++
— User —
[MBR] fe4679dab526afc4da4e5822248afccb
[BSP] ddc7f77e7ac2068aa0890f7e3ec8163c : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 81920 | Size: 15000 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 30801920 | Size: 223434 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[0]_S_10022013_225719.txt >>



Malwarebytes Anti-Rootkit BETA 1.07.0.1005
www.malwarebytes.org

Database version: v2013.10.03.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Paul :: PAUL-PC [administrator]

10/2/2013 11:16:58 PM
mbar-log-2013-10-02 (23-16-58).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 341281
Time elapsed: 2 hour(s), 12 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1828
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0masaq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ovm8l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0p8zik.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0pcs8a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0qdin5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0qw525.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0r51ax.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0rkf8z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ssmvy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0tgkcl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0tn1vk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0vzgis.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0w8vh5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0wnhq3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0x2lvf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0zhjj2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0zt90a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0zx3sc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r10p3yb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj5l3mz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj6gzrr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj6wh0o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj7wvts.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj8cjbc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj8kev2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rja7os4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjan8vx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjauwkv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjb14am.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjc0rhf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjcqy3s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjcs8qo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjctsb6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjdbil0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjdotkp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjeyz0z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjf1n36.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjf5e3w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjfisib.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjg3iid.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjgqbnm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjigul4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjj2777.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjjbfcm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjjgia0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjjjc9g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjl3yho.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjlsdzt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjmatxt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjme9q2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjn9rp6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjnk0vk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9buguf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9db0cp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9eo01g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9gxw4p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9htu1y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9hv3jy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9jc53j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9ktziv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9kzyc7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9lf463.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9lqp23.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9lzrlt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9ma0p4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9mc04w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9ns9ow.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9nth0r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9ocay8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsazmnf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsb7yw2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsbpfwe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rscwhk5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsd6cah.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsfclim.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsi1183.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsi3e3j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsio93q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsj3y29.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsj56v8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsk2h9t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rskpoa1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsky01q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rslfh6b.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsmwanc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsn9egh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsnod2o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rso7p4r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsoksvl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsoya25.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsp9j32.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rspg3lf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re1xv1v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re2hcso.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re3dpi4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re3oc8e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re4704u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re7lzci.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re7ojm9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re894o6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re8d51y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re97oyj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re9owzn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rea3jgt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rebfd8o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$recox7t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$recyho5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$redif1g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$redwuy6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$reeohsm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ref8r1r.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4m5i3y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4mv3qq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4n7vzn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4op8fr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4p3zpl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4pe5m0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4pf5kr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4pn6qx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4q25uk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4rigcj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4rnhun.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4svbq5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4talgd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4ttklc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4w41z4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4wump6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4wze05.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4xamez.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4xm5m8.tmp (Rootkit.0Access) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4yh2c6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4ymwoz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4zx1tl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r50zp5h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r52n31m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r53rpny.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r53zoz9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r54tnst.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r551t00.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r567dbm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r56kd31.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r576mv0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r57fz2m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r57hdfv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r57ilx9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rod6pat.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rodf5xy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roe00jt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roen92t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roflgny.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rogcp7i.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roggwxf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rogxglg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rogxkcs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roi3p74.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roil65n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rokabrh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roklpj3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rol5vv0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$romzv40.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ronggwh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roo6ugb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ropsjla.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roqg6gt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvkd43s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvmdk35.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvn9tvs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvnjz6l.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvo99om.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvojfn8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvp59r2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvplicg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvqpnzu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvrtlqh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvs9u9c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvswzfk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvt9brp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvtfki1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvu3dzp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvudryu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvuk3a4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvvelot.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvvh0ny.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvvqxmh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvw7uz2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvwcso6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvwhq3z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvwt0d4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvxazug.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvxizqr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvxpoi9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvxy9ji.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm9ppn7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rma29cu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmabdh7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmadeyq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmc2tar.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmd4yie.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmdwlhc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmev6ma.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmf563f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmg052f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmg624q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmgflpk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmj7b9h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmk8t3j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmlbxky.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmlfnuh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmllp5t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmlww0a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmn0qlf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmngi56.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmnjqci.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rga008i.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgb5zxb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgbtwrk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgdmqbn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgduzrk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rge5yp4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgebhl8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgf8b16.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgfblha.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rggb5ez.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rggjm9s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rggmjjb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rggq2oi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rggrplx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgh4jg2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgjblte.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgmsfx6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgn863p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgosmkv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgp5gxt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgqnwgz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgre9nr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgrlqdd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgrw10h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgs7fks.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgs9c1a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgt34rt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgtny6s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgtq7p4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgucmef.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgujmmo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgwkp67.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcg4oig.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcgmr1o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rchrit2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rchw14y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rci8nzk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcieeow.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcivh2z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcjo1yk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcjppe1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcln3md.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcmwyl1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcnq28k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcnuw20.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcob3xj.tmp (Rootkit.Zaccess) -> Delete on reboot.
C:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$RCOMKHR.tmp (Trojan.Small) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcovj8d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcpkzgn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcrbege.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rct0cg8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rct3fse.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rct65uc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcu706o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcuyu18.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcv8wdp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxytc6x.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxyv8f7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxzsc9u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry0exx8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry0jcox.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry1e53a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry1wv7p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry2la00.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry3i333.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry3sroh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry4nzky.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry4u5ep.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry52mzz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry58502.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry5dfdi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry5w4f3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry7gc0f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry8ebe1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry8vfgn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry8x15p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ry9flw0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryad4nq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryadg0w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryax3vn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rybpgjf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryc4o5h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryd2veq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rydb1ds.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rye2f3s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryg4wmj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryhdmeg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryhe79n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryhyun2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7h1t9m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7hcfb5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7i1fvz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ia5b4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7iq6bw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7k2dr2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7kub8f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7l0lpi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7l7bwu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ljtms.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ls2na.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ly0eq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7m99v7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7oan3t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7pc0ym.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7pw8mf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7qjp6w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7qnlt2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7r03dl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7r2n6l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7rqsdx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7txn7q.tmp (Rootkit.0Access) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7tzoyk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7v155f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7vklj9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7xaoje.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7y83e5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ycfcj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r22lzxm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2466n0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r251o6n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2532pm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r25hn9r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r26aquj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r26eoet.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r26hh56.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r26nz7a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r27bf8u.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r27e9y1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r27uv2v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r28nzw5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2avp5u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2b00ix.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2bbamw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2bzbzz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2dihdk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2e9pnv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2f668q.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2g3az4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2g9i44.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2gbd75.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2gi9bs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2hlczq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru34y6t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru3a2y8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru3e15c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru3yslq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru474l5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru606f3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru76t8s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rua1l61.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rua3aye.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rua3ckl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruarhhx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruatuaq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rubdd12.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rubk592.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rubleex.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rucxsnw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rudbz1x.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruep63i.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rufcrrh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq38hx6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq4f31r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq4rfqy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq5a3t7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq5p2xt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq5zeju.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq6zqdj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq776o3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq7y19z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq7yep8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq8ocs8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq9fzuv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq9levl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqaa0ku.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqcosh2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqdap9i.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqdjq0j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqe07ks.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqekvob.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqfbue6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqfvbbv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkfrxju.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkfu4ul.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkfzbq9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkghb79.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkjd43e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkjubuz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkkw6qk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkm99du.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkmcvwe.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkmzb22.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rknfn2q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rknna8l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rko7hlb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkoglju.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkpu8mh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkq2trr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkqp6sd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rks3y4z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rks59aj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rks5pqz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rktrglu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkuvjvi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkv1gsg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkv4t3j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkvf15m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkw2yfj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkwudot.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkwv8k6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkyfdru.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkzfi5r.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rna8kdj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rna8p1t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnaje04.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnczx18.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rndbgok.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnejfp8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rneypbb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnh6uc0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnikwkp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rniw142.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnk2wtk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnle0jt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnlq9vz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnm4tlr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnn3996.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnnoxmk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnopngl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnqvmwr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnrbuuz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnrpofk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnrva4v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnrvw9j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rntgr58.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rntrv6c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rntuij0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1188sn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1f3rwz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1ozabi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2hs223.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2wncba.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3bfc8n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3yvbpk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4lcnnk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5a17z7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5q1wb3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r652w6j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6erybr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6w23hy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7fsiv8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ysjm0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8krdk4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r90qgwg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhqob2r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhrkzgi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhtlk2b.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhv2w0p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhvcc4t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhvcor7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhwj8pt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhwumql.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhzgvmp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhzqhhu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri0p39h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri1ilmk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri2qx1b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri3991e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri3letp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri3src4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri3umc6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri3zf9j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri5jnaf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri79iw0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri7p7xr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rar8ryi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raswc3p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rau5fua.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rau9rzh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raus8ak.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ravg8no.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ravqjne.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raw4ld4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rawt53z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raxdhbp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raxgp3o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raxk77a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rayrvxg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raz9o16.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$razvhik.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb3padu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb3qyxq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb5yuqp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb7txjp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r65u8kj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r65xsix.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r66v7l3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r66xplx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r67he6r.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r67qlyo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r67xxht.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r68vd7c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r69b789.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r69z57k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6b185g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6bdkg7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6bqf0a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6csxaq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6dba97.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6dw17e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6e8c36.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwoozay.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwqkh7w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwtfbcx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwu8tga.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwvpu3t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwwfn8w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwy210s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwy5ml1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwzjbaq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx15p8s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx2dvdu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx2fyqn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx2tgej.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx3jenn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx43t5q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx4al9o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx7abj4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx7ud66.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx8hr43.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx963ku.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt4oe4v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt55fw3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt6s2og.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt7uhn8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt7zc9c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt8gxoz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt91hgp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt9771y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt9p2cg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt9v7wg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rta41va.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rta4e84.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtalld2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtax3nq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtbz5lm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtddw14.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtdg6vf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtdzzs8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtecq4f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtee3h3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtehudx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtev38o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtf44yz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtf4sn5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtfqsqx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtfzel3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtgruaq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rthcgzq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rthxosg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1fms6m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1g4tz6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1gju4m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1gk2fp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1h4gta.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1h7goh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1h96fp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1hso4m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1imbzk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1inngk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1j2952.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1jsd8c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1kixyd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1kt2d2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1kvdo7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1kzuj6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1lmw27.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1mpti0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1n66sr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1o313o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1o3ujz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz1xeck.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz26bsl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz2rfwb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz3m1o0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz3qvfw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz40y7z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz4rnaz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz5p3nx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz64aw0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz6pi37.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz6ps0e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz71plw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz7ejsh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz8hsxo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz8l4cy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz9pkw1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfnmee2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfp9gfj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfrbnrm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfseylh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfthtya.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rftsg7h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rftvtjb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rftz0lu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfubarh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfuw2co.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfv2fnr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfv7eqw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfwyzfb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfxe092.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfxl1es.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfyfemh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfymxv1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfyw52c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3cpi6a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3d6p5x.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3ez0oa.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3f32sh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3f7hrx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3fj89n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3fok6w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3fon9y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3hwxi6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3i76xu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3ij6zd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3iqk9v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3isz15.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3jy1zk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3kbqjf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3majjl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3n3e95.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3nnpp1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3nsvzx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3ohv6f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3phk0b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3pwggo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3qgexj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3rneo6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3skt47.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3slg89.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3slvgd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3ttrjw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3wz7p3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3x9f3c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3xqqqi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8kyqyx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8lu76e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8oisos.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8p30lc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8pilna.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8q1wdy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8qi9im.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8rgb0t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8ro38l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8s3ic8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8sbno7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8soh5v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8t3uth.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8t58tl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8tf8li.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8tob9h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8x84oj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8xu6nf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8yyxbo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8zhg8g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8zolr4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8zu95g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd8z5kq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd94rp1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdba8m9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdbcwg3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdd0irp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rddh3t2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdf4tzv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdfggka.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdfxl4y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdfykiq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdg2bzo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdghgzm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdglmnh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdhazr2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdhb7t2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdhnvnk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdjd7n3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdm1y3h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdmdu34.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdmfhxe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdn7u09.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdn8mqm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqzcw0i.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqzwqz5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr027tt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr10ium.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr166uh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr1v5gp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr4vo7e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr4wcj5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr6aq81.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr99dg9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rr9cxz6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rra0nyw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rra16rw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rra5ddm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rra5may.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rraha2a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrb6tre.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrbjpyi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrbx1vm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrcwtvd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrdif0w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrdtd90.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rre09yr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrgp01x.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrhk46f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rri164t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrjux98.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrl1n2o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp85uu6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp8gf6z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp8u58g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp9da47.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpa50cp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpar1kd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpb0oqj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpdc7a9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpdd0zi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpdlfaa.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpdm5b7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpdry3k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpe2r7m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpf2sb9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpgy68k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpi4g1z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpjg7fj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rple7b7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpls83y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpoaqkv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlkvi3n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlm3sja.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlm9xwf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlmk264.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlnrxfv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rloe42j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlooh5k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlpnexx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlptmvb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlqyql8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlqyyd0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlrl2aq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlrlw4y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlrx6ae.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlt1m4i.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlux8sq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlv3a6e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlws8ly.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rly7m06.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm0ywdj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm1tjvj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm3dk20.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm3rrgo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm4kz0y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm4pmqg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm4ygxx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm5437f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm5h9cg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm71m0d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm7dtaf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm7zlbj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruyyhav.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruzfiv9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruzpmey.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv0co2k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv0cyrr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv0kqrz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv0yk7h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv1poco.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv29a1g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv2o13d.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv2o1de.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv3jdzt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv3sb3m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv3sbl2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv5yidu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv63kms.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv6wjif.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rv73ctc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvbje51.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvbjh05.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvcrftu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvcv1p7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvdp2j9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvg7htc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvgr0fq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvhantx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rviij32.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvj1629.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rikfgxq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rikfmt2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rim7bz3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rio7wle.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riosue5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rip6ymj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ripb4xs.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ripkgdz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riqsjz0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rirmhqh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ris401c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riss1xp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rit1nrq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ritp942.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rive0rq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riwz59p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rixds2h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rixkvfd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riyhrgy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj0168h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj08s7c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj1x7lh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj2x106.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj2zh2a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj4oi78.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj4rg5m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rj56sc3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjoow1l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjoxdzz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjp7ptj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjpliy3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjs35az.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjslagn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjuogca.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjv9c9u.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjvm3i0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjxf95m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjxlr4k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk0nvhd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk0wnyr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk1su0v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk32tyl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk3comd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk3g8v9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk3mvly.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk4dzdp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk4s9da.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk59iyq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk5rdhi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk6io7t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk6kvs8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk77v5y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk83nqc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk8tpjq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk8xpws.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rk9u5b7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkcjigz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkesoe4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rjnpi6k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rkf14wi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl01vxt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlk3att.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rm998c5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmnl9qu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn98ddt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnu7d98.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rorso1y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp85hgg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rposg4i.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq1otl2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqg3pgi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrle8ps.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbtasm7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbtjoa5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbtlnkx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbtltoz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbvww86.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbx00lr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbxz7q7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rby2mk8.tmp (Rootkit.0Access) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rby3hwn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbyk5q0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbzdamk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbzedk1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbztoaw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc1f3au.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc2n0x0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc2t7k9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc2vir0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc3nw2f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc3w0ry.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc4gd7p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc4hvr6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc5ays8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc5lxls.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc60yq6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc6iwhy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc8j65v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc92gqs.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rc9ck39.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rca2jaq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcbdj67.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcc6o2q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rccz4z3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rce1a8q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5b5ezm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5bds07.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5bt2qm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5cbd04.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5diq2f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5em853.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5enbtw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5f43un.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5h0h8c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5ii5sw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5janc8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5kh8gq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5knhjn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5lmmwn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5o4msh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5o8mfx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5oa0ag.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5pzgkn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6x4n99.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6xnhhk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6yl0f1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6ysm44.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6zlv63.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7003ex.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r70giva.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r72e58y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r72m6j1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r73c0j6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r75i0cf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r75lxko.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r75y9i9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r75y9pc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r77bh2d.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r77zi12.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r78i63w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r79b41z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r79c583.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r79u96v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7aesv9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7aewbg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7bgjuu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7cpnlk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7cvr0p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ds16l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7eb0it.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7ecxl3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra4mkk8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra4y7db.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra6llht.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra87arq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra8mjfg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra8rgal.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra9d2z3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra9okoy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra9rdym.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra9yqa0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra9ywps.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raa4znf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raa90b0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raaabew.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rabm9p7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$radai29.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$radoya7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$radq3gc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$radsan6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgxaqui.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgxufb6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgy7x8z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgyu802.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgzryzt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh0ilbf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh16t3t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh4khne.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh61wc1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh6o1km.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh6vc28.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rh9tp6b.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhab6d6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhagt2a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhajvq2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhc3d36.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhd561y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhe54vr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhf2dwd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhfraem.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhg5icj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhiseu3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhixcfu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhj8fa2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhjv0do.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhkeeo5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhknuls.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhmgcy6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhn7kyp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhoko98.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvz8qmz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvzfqps.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw0m24t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw26ja8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw2dlgf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw3jpub.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw3lamq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw53ibx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw5aghj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw715ji.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw7e85d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw7tpt7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw8ul10.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rw99e54.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwa4du2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwac0zy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwag0ig.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmnobm5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmnync1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmpu7k6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmpvm8l.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rms8u1l.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmt16yx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmtbtoo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmu2nfq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmvhrlw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmvyxjd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmwm9u6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmx40l7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmxa2ck.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmxm3td.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmy2hka.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rmygfhl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn29lo5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn438ws.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn45hl5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn49e1s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn4juxr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn5cfyp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn5tokl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn702ug.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn7bq1x.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn7lp52.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn7yyvf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn8hw0l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rn8scur.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxhmk7w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxi168p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxj3e05.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxjrnoh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxjv1rq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxk8y82.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxlif05.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxllci5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxm215m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxmnht4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxn4yzj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxoxvvs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxpltek.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxqnk8c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxrce9p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxrdour.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxrizd1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxskh51.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxst8z8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxuk9oh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxuzlrk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxvt7pd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxxgkm8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxxs0ji.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxybv0u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxyopol.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2iopzn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2k03av.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2kkxjw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2kzgho.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2m9g5m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2nc84c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2okluc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2oko0w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2q2nqp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2rc0ts.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2s219u.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2scwnh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2u7e2t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2ua975.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2uiz2a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2uyohg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2v9jva.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2vyeko.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2wcqfk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rewk7y2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rexdw10.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rexfcrd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rexriou.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf06qo4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf0vyu9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf2fd43.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf35zr1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf3rco3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf6znxy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf6zrct.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf7ad7w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf7mtic.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf7rmqp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf8evgn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rf9ct83.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfag3qy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfbpnt2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfbu6ok.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfcywzj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfd9kzl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rffdvkm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfgi9v0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfgk0rt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfgplok.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfh9zss.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfhxvlu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfi27kq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfjfjrq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfkkcm7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfkty3j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3zse40.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r40jive.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r41o389.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r41q20k.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r42p00f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r434v3l.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r43p7gd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r443xmf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r444hst.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r44iqz9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r44na0o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r44upyr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r45xk0e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r464csz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r469epm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r485v6f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r48ywf9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r49d2hn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4cvgs4.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4d3qm7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4dbyma.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4djb03.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4erb93.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4erfn1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4h2k4d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4h5c9a.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4hfbii.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4hxti5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r4i64xf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnuoi3n.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnx0ti5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rny13xx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rny1tbe.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnyjkal.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnzu2vm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnzw5ri.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rnzwfr1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro0kx1w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro1dizs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro1hsmb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro1ntg3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro1w3og.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro2co4n.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro48s6n.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro5fadm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro5llaw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro5znz6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro6a9ib.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro6f2l4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro7jp8m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro82ex3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro9g0gl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ro9vk7g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roasvll.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcvgsti.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcvtb9s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcw7ikw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcwhjds.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcx0oeb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcxspee.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcy1rh6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcybjuj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcysgam.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcyx1oi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rczce49.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rczgbog.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd0dupk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd0zj4m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd125im.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd28sli.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd2lb96.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd33pnv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd3o7gp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd4qoud.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd598rv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd5b5rf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd5p0pt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd6louo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd791xf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd7ctf0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd7gikc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd7hiw0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd8472k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd8azo9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtj6fna.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtjogqt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtkqd5s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtl30oh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtlhxn8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtlsz3e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtm13bu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtm4mj9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtnji5y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rto1wew.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtoazsy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtog1vi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtpxwad.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtqccyj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtqi2rl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtqpwkq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtscg5h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rttfwut.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rttqn75.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtua7qm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtuqtmu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtvhjdp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtx3yv6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtxal3w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtyruuf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ru20m69.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r00434e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r00lqab.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r014aly.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r01etil.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r02d92s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r02ezrr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r04dkoo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r05yg8x.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r08i8p2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r08wiv0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r09bsni.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0axvip.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ayd80.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0c6ti7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ch59h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0cr6au.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0d89gi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ea6q7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ew510.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0ey7i7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0f3x02.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0fk83b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0fqyj6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0gk2nw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0hgkva.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0hhhbz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0j0b30.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r0j29i5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rznoboc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzokfrv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzokg19.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzpfuu7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzq8kjo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzqn1i8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzrjcjv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzrovq6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rztarx0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rztgh81.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rztpuz7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzty3p6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzu32sx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzugbng.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzvc7vg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzvp5r6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzvq9tb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzvy4gh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzw64a0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzwd28u.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzwvrj0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzwx1i0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzx414y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzxj15a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzyv3i7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzzavyn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzzbjl0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7yv9ug.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r7zasnh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r802sqh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r80kh99.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r81seeu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r82atug.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r83khhy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8464c5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r85fk6w.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r86qsk2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r86rc4b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r877q63.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r89huk0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8bbivg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8bh8ca.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8cerho.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8cohmb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8d8utc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8dfwon.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8dsf1e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8ec7s1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8ekf0h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8esuoz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8fpkap.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8fr1pj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8g6cro.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8gjahe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8gpo69.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r8jy3kh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rymb2xi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryn1kxx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rynjqkw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rynv3ev.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryo44ee.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryoe8ma.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryog4ak.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rypdihg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rypzsfb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryrk8ab.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rysjk4b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryt4r6t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryta3v2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rytnokt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryufi9h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryuy93g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryw9bf2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rywgbkf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryxohkp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryybk7a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ryztbth.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz0v1lx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz0xatr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz1b2jz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrmxkbl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrn9znd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrnasck.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrnq0o6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrnrm3c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rro7ymv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrpcioq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrpq1sd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrpqlii.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrr31vr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrrc3zw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrt8gyz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrthzr9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrv884y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrw1lin.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rryk2ju.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rryolqe.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrzk67z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rrztvow.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs169am.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs1zv3j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs49myz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs53hdo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs6rs57.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs715j2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs9d42d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs9jei6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rs9mq9z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqg8xra.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqgmopo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqh1a6e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqh6gp0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqh6pwp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqhweum.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqj4z39.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqjma5u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqlajk7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqmftuo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqmqm6h.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqmsh37.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqnd0tk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqnjopo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqnkfd3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqov6ag.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqpyc0z.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqr47ap.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqt4pry.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqt61gp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqt7trw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rquneq3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqv3t4b.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqvhlkd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqvxboy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqx04iy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rqyf38h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl0mmz7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl1p13e.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl2lwch.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl3ga5v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl4z9xp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl5kie7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl7mrqn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl80suk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl99u32.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rl9upj5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlaezn9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlan4vo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlbj4hi.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlc0pz2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlcgb64.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlechs3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlfa3z2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlfinwg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlfnski.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlgdmm5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rlh36h2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rljqw2g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r11imua.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r11zfqx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r12rnd5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r12xv3o.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1384yo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r142mmf.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r142qbw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r161gh5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r16adv8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r16b2i6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r178oma.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r18oado.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r19czqp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r19i338.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r19wqkh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r19y3fq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1a3zpc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1bnu69.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1caftc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1d3yoe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1disah.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1dqxw0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1e4oi5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rss3ke6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rssdshe.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rssui8l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rssv52v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rst37w2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rstd3yk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rstmmlk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rstn80y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rstonfp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsvdjo7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rswvcs6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rswzcoj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsy1uop.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsydh9g.tmp (Rootkit.0Access) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsyrlbc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt0mh5m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt0qe8f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt1s9zk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt1tupj.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt2zlj3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt3mxx0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpqeu7q.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpqfxxr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpr4duo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rprv9rt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpth3g3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rptpk01.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpui4jb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpvk3e6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpw5lyx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpwd4ry.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpwto8x.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpx3rwz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpx97ov.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpy5o9o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rpz9iy7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq0xzc7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rq1nz7m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r916jqm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r91fhsd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r91jqv1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r91omnx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r91vpcx.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r92gbca.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r92itwh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r93fpyr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r953s28.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9563lj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r95vku6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r96svc0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r978vvy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r97qqsq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9a0j7g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9b95di.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9bq9hw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raf1ray.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rafdyik.tmp (Rootkit.0Access) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rafem1o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rafmwwb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ragfraj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raixuop.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raj6cw9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rajj3ct.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rak21sy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ralw9zd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ralyb2n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ramzmte.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ranlanp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rao47cp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rao7a9j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raoly4s.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raowg96.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rapo542.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rapoprs.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raptbfh.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1p4e6g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1pgitg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1qey8l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1qnzvo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1qov7d.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1r6520.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1st6hb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1t4dcj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1t9av9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1uarti.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1uzran.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1v5ldz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1x81qv.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1xhai0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1zm2ck.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r1zykom.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r20rxz4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r22h1xw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2x1ar7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2x8r4l.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2xm362.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r2zpoyy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30ecnw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30fd5e.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30gmal.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30i3eh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30i3vn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r30luyi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r311qee.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3272zm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3345a8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r34cnzd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r35qts1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r371o5q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r38in08.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r38t40j.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3917wr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r393ka0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r39j1pa.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r3ab07j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdp7k9r.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdpvwxx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rds8axh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdskkac.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdtphx6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdu0pth.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdu5bgb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rduldx7.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rduwrro.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdwvysp.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdwyg65.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdxnenb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdzbbkw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdzg5w6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re0aeyr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$roshpt2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rotkqqh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rou6low.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rouav7a.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rovsz0j.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rowiiqn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rowip6w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rozsrfx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp09jyx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp0r6jz.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp0ycmn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp1qibq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp1rir7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp2xcaa.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp46zlk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp4cjnq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp4yssf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp5f7zg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp5x3rb.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp733ja.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rp77wij.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri832ej.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri8h1cd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ria261g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ribckrr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ribco5g.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ribda5t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ric4jgj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rid1h5f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ridg5ah.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ridk4oq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rieoqio.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rif73ft.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rifhhe6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rig7z65.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rigiw6m.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riglgbt.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riglqj2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rigu2q0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riihy7t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$riisocl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb8lgc6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb9tqzf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbbtyo7.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbchb5n.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbe29qe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbe4qd4.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbg3fja.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbgs9f9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbh1g4t.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbinv46.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbjrsz3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbl1hgg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbnbu9k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbnqwmr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbnv9z0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbojanr.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbp7u2i.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9opihj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra3cprp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raeo9vy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$raqep8z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rb8f27m.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rbqc8mu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rce2o65.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rcvg8eg.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rd8uk4b.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rdnferk.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$re0vy3w.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$refjaep.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$revp63y.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfl0lvo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfz93we.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg82hbn.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rgx48g1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rhplcb6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ri7regr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rijanpl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx9dvgg.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx9jmz0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx9stcu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxa2lof.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxa51ly.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxa9k9q.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxactom.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxb0qdf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxbqce3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxdmmry.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxe199v.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxekx57.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxfpvgm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxfx1uf.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxgyskt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxh3ag2.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxhj0em.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6eu6c8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6f9zy0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6fcne0.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6fkwwo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6gbmv3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6gfw2c.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6i3v1d.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6kc5e9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6om3g8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6onn1i.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6p2e90.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6t2aqb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6udvbz.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6vdd9k.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6w1wv1.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwbsozw.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwbu6sc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwdq0ni.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwegm1g.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwfhnwa.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwfse8y.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwfyh6v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwfypdw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwg6uuo.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwg72yc.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwglpzb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwji4iq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwjq96d.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwk0fz6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwlusqe.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwlx0o9.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwmnuhx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwmpo1z.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwodlb8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$reh3b4o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rehdgp6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rej2bbr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rejcip0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rejf1hc.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rejf8un.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$relb4yx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$reluoa2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rena75u.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$renlsul.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rep1j2s.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$reptxjm.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$req8gi3.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$reqqawp.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rer58t0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rerv5e1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$retq651.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$revo6ff.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rugk7pj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruhvxx1.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruiqd38.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rujdhle.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rujshzd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rukyced.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$run1fi6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$run20pd.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruo2xt8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruozt5c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rupco36.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rupeq7v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruurtio.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruvqfnu.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruwjpj0.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruxokia.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruxudrq.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfzd8z6.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rfzhg71.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg01iw5.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg0h5fe.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg0nxpy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg0uywt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg394th.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg48pg5.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg4g6nr.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg4q95f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg4se87.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg53qbl.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg622fx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg6bwy2.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg6j32c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rg7suyt.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5r7gph.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5sekr8.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5tdu90.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5tm6ho.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5tzi8c.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5ubz6r.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5v2fzo.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5w7gx9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r5ynxxx.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r60orot.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r615n7h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6161l9.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r61pt8f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r627qqh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r63u757.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r640yyl.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r641bep.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r64vt7q.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r6528cy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9q7p9t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9qa3bw.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9qb4tq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9r1axq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9uio4q.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9ul08f.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9uyxfj.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9v9ywm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9vd2um.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9xgw1p.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9xpc8f.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9yop70.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9yw0sy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$r9z57uk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra08ypd.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra1no84.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ra2iu9h.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzcdm2x.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzcsvxy.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzcxomk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzdl0cq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzdq79o.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rze1u7v.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rze2cwy.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzfbo76.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzfthbi.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzh0e53.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzjhf7t.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzl3jbm.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzllzzu.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzlxwds.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzm7w9x.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rzmzt9p.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rsqxkta.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rt4lcpb.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rtj3dgq.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rufeh50.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$ruyqkob.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvjgrl3.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rvyijtv.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwb8xvk.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rwomst8.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rx9arbh.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxhjkjn.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rxyoton.tmp (Rootkit.Zaccess) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rylbl63.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rz1gx25.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rza8lo6.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.
c:\$RECYCLE.BIN\S-1-5-21-2674026609-1698660912-1609442580-1003\$rznie02.tmp (Trojan.Dropper.BCMiner) -> Delete on reboot.

Physical Sectors Detected: 0
(No malicious items detected)

(end)

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI