This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank

55 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hi, i'm new here so bear with me. i seem to have a very bad virus on my pc. without making a long speech, it has gone deep into my registry. i keep getting the "about:blank" homepage & it also puts several porn sites in my favorites. i delete them & when i reboot there back again. when i look inside the "msconfig" it changes it's name every time i reboot. nothing i do gets rid of it. i downloaded "firefox" & that's working fine. still when i reboot the new favorites are there. what a mess!!! i won't use internet explorer anymore…i have no problem with that, but the virus is still on the computer. there's got to be something to get of this short of reformatting. help!!!!!!!!!!!!!!!!!!
Logfile of HijackThis v1.99.1
Scan saved at 7:06:10 AM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\winza32.exe
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\qsmol.dll/sp.html#93256
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {0CF480F1-257D-1A25-B315-E66C5C67677C} - C:\WINDOWS\sysxq32.dll
O2 - BHO: Class - {1F565452-33A1-FAF1-92CC-B3819646C738} - C:\WINDOWS\system32\msbs32.dll
O2 - BHO: Class - {260D5212-2854-F711-C5C0-A013C2A4321D} - C:\WINDOWS\atlzi.dll
O2 - BHO: Class - {26240738-07F0-193E-C212-8ECF3EF57114} - C:\WINDOWS\mfcgd32.dll
O2 - BHO: Class - {27627E61-8828-2E5B-F537-73A167A007E5} - C:\WINDOWS\sdkwq32.dll
O2 - BHO: Class - {2B059896-BB0E-9E34-798B-01B795993144} - C:\WINDOWS\system32\appfc32.dll
O2 - BHO: Class - {2E122632-4FED-9881-E123-01F47A935FF6} - C:\WINDOWS\msmf32.dll
O2 - BHO: Class - {30C11652-EA7F-7683-9DA7-4FA50BAD285E} - C:\WINDOWS\system32\iehm.dll
O2 - BHO: Class - {31474984-8326-4EA8-44CF-B3365CB4B194} - C:\WINDOWS\system32\mfceb32.dll
O2 - BHO: Class - {33D1F4D9-B1AE-4491-5DC6-8172846E0C18} - C:\WINDOWS\system32\mfcqm32.dll
O2 - BHO: Class - {3EB79716-BC8C-A65F-5E2B-31BD61248EA1} - C:\WINDOWS\ntid32.dll
O2 - BHO: Class - {47AEB876-B32E-5D5E-B4B0-BAD41300B9F8} - C:\WINDOWS\system32\atlxh.dll
O2 - BHO: Class - {489CB8A5-F200-EAC7-EB4D-CADBFD62480E} - C:\WINDOWS\mfcbs32.dll
O2 - BHO: Class - {50F30C47-91B9-9915-BFCC-9D166CDCA206} - C:\WINDOWS\javack.dll
O2 - BHO: Class - {513E86B0-D516-B255-E656-DEF35121232E} - C:\WINDOWS\system32\winno.dll
O2 - BHO: Class - {5AF6F90A-F3E8-15B3-4B30-88AF19DE461C} - C:\WINDOWS\system32\appjn.dll
O2 - BHO: Class - {5D29CB91-A959-E2C1-4346-FA68E60B26EB} - C:\WINDOWS\ipqq.dll
O2 - BHO: Class - {5EC41BD6-FEA0-30BB-E8A5-7A8C726C5B82} - C:\WINDOWS\system32\netzu32.dll
O2 - BHO: Class - {61BF9567-4606-B8F2-4A15-3227A0E2E184} - C:\WINDOWS\addpy.dll
O2 - BHO: Class - {633C8BFF-B1D2-9627-66F6-74124A682441} - C:\WINDOWS\system32\d3kw.dll
O2 - BHO: Class - {69CD759E-4291-29B5-83E5-2B55FF15D74F} - C:\WINDOWS\d3bi32.dll
O2 - BHO: Class - {6BA66987-2CBD-7E8B-149E-DBD4784AEDA3} - C:\WINDOWS\windn.dll
O2 - BHO: Class - {6E904118-91B8-3F31-2ED7-1F02C7E6CF6E} - C:\WINDOWS\system32\ipoo32.dll
O2 - BHO: Class - {6E9F8B9C-0374-0684-98A2-0FF5E5939B54} - C:\WINDOWS\system32\addtj32.dll
O2 - BHO: Class - {70DE2D85-F521-47F2-FB12-177FEB319E41} - C:\WINDOWS\system32\iedb32.dll
O2 - BHO: Class - {74350DCA-A542-D7B4-3901-455AF6D1F483} - C:\WINDOWS\system32\sysvh.dll
O2 - BHO: Class - {759EE675-E6A9-86F9-750B-6F9D78BD7C3B} - C:\WINDOWS\system32\crwb.dll
O2 - BHO: Class - {7913BA64-727B-66BD-1BFC-D7C367B7E4D4} - C:\WINDOWS\system32\addrh.dll
O2 - BHO: Class - {79EB32ED-B850-EE43-6CC4-AF3F3F4C0FC6} - C:\WINDOWS\system32\msoh32.dll
O2 - BHO: Class - {7AA3263D-C6B3-2D60-F61D-6AA3C98512E0} - C:\WINDOWS\system32\netkd32.dll
O2 - BHO: Class - {7C3F5115-13B8-F3E5-3A5F-4F6BD2411BED} - C:\WINDOWS\apita.dll
O2 - BHO: Class - {85138801-518D-CEC2-27AE-83F4E12401F3} - C:\WINDOWS\system32\winzu32.dll
O2 - BHO: Class - {87BA8C33-B881-C0DA-F0B1-B08EE50CDD55} - C:\WINDOWS\system32\msoi.dll
O2 - BHO: Class - {8853708A-2E5C-80FC-1A5C-B410077C3BE1} - C:\WINDOWS\system32\ipsz.dll
O2 - BHO: Class - {89AD1952-81D3-510D-278A-AD565369AC73} - C:\WINDOWS\ntek.dll
O2 - BHO: Class - {8BD50B82-01E9-872F-41BA-172E15089A98} - C:\WINDOWS\system32\atllo.dll
O2 - BHO: Class - {8D10FF3C-0FBF-83B7-9DE2-4D8513EB92E2} - C:\WINDOWS\crus.dll
O2 - BHO: Class - {8F565E4E-BE67-6D1A-A3F3-3F516A976312} - C:\WINDOWS\atlny.dll
O2 - BHO: Class - {9404FFB4-AA7A-A757-2FB5-29D6F452E365} - C:\WINDOWS\javaod.dll
O2 - BHO: Class - {96D016D9-0CE7-EA14-F994-F6F457061D30} - C:\WINDOWS\system32\crsq32.dll
O2 - BHO: Class - {A3952B4F-6785-CB92-AF25-B6F52EFA13B8} - C:\WINDOWS\system32\crqh32.dll
O2 - BHO: Class - {A7E033B5-C0B6-AAE5-3227-2D8DCA3F2402} - C:\WINDOWS\system32\ipcj.dll
O2 - BHO: Class - {A8995D1C-4882-29FE-B52D-2D99FF80D879} - C:\WINDOWS\winjb32.dll
O2 - BHO: Class - {A9CE5DD2-CF1E-FF19-DF9B-62345AE7CF49} - C:\WINDOWS\javagf32.dll
O2 - BHO: Class - {AC50F23D-F99D-EE5A-71F2-ABCB913DE13A} - C:\WINDOWS\sdkkf32.dll
O2 - BHO: Class - {AD1DBCC5-1F76-3EE9-F75D-5E646CBA5DF8} - C:\WINDOWS\systf.dll
O2 - BHO: Class - {B7B31397-93FC-5ABD-5E72-3C4626580399} - C:\WINDOWS\apiux.dll
O2 - BHO: Class - {C3F84830-18F3-1D3D-C769-86D58A213F17} - C:\WINDOWS\apphd32.dll
O2 - BHO: Class - {C49FBFCC-56B4-3482-9B6D-E95C5AAF1D3D} - C:\WINDOWS\system32\ntgu.dll
O2 - BHO: Class - {CB7CE715-26F7-1C43-E3C5-72E056878705} - C:\WINDOWS\apixk32.dll
O2 - BHO: Class - {CCE4F981-DD69-6A68-6F5D-1A1766D4B271} - C:\WINDOWS\system32\crrf.dll
O2 - BHO: Class - {D02BF681-DD31-FE09-4765-7D08D4817616} - C:\WINDOWS\javaaj.dll
O2 - BHO: Class - {DDAA2D52-24BF-4F9A-DE0A-A77E2CC8EDA1} - C:\WINDOWS\sysjw.dll
O2 - BHO: Class - {E0B2881F-BEE8-B54E-5DFC-37FEF2851A76} - C:\WINDOWS\msrq32.dll
O2 - BHO: Class - {E0FF3D06-7E37-07B2-CEAA-D833E87335B6} - C:\WINDOWS\winll32.dll
O2 - BHO: Class - {E44B2869-3C3C-2E0D-FE6F-F5D9CE7E35FE} - C:\WINDOWS\apirq.dll
O2 - BHO: Class - {EAC75C37-4B26-E9E1-9622-A78D21C5DB24} - C:\WINDOWS\system32\javamu.dll
O2 - BHO: Class - {F22B79FB-1D55-C94F-4938-EAA13A2FB4ED} - C:\WINDOWS\d3yl.dll
O2 - BHO: Class - {F4D7791F-ADA5-B851-33CA-06EB8529CE7E} - C:\WINDOWS\system32\sdkyz32.dll
O2 - BHO: Class - {F510D9F8-BF5E-21C7-6197-342788EE709F} - C:\WINDOWS\winbd.dll
O2 - BHO: Class - {F6BFC595-569B-A80C-DEE4-5AE687AF21D2} - C:\WINDOWS\system32\winza32.dll
O2 - BHO: Class - {F7C45676-146F-4E38-1143-6511A08788D4} - C:\WINDOWS\iefl.dll
O2 - BHO: Class - {F8EA4B26-A394-AA9E-10DB-155FDEB474C6} - C:\WINDOWS\system32\apivj.dll
O2 - BHO: Class - {FB8230DB-512F-D010-9C46-1B908489D798} - C:\WINDOWS\system32\d3im.dll
O2 - BHO: Class - {FC5C235C-B48D-CAF2-1989-24072FA459AD} - C:\WINDOWS\netmf32.dll
O2 - BHO: Class - {FEDEDE09-9933-49F9-EDC7-9EFF9FDECDCB} - C:\WINDOWS\system32\javaew32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [atlxl32.exe] C:\WINDOWS\system32\atlxl32.exe
O4 - HKLM\..\Run: [winza32.exe] C:\WINDOWS\system32\winza32.exe
O4 - HKLM\..\RunOnce: [apifk.exe] C:\WINDOWS\apifk.exe
O4 - HKLM\..\RunOnce: [d3bb32.exe] C:\WINDOWS\system32\d3bb32.exe
O4 - HKLM\..\RunOnce: [ipxh.exe] C:\WINDOWS\system32\ipxh.exe
O4 - HKLM\..\RunOnce: [sdkta.exe] C:\WINDOWS\system32\sdkta.exe
O4 - HKLM\..\RunOnce: [d3if32.exe] C:\WINDOWS\system32\d3if32.exe
O4 - HKLM\..\RunOnce: [crxg.exe] C:\WINDOWS\crxg.exe
O4 - HKLM\..\RunOnce: [addtu.exe] C:\WINDOWS\addtu.exe
O4 - HKLM\..\RunOnce: [appvk32.exe] C:\WINDOWS\system32\appvk32.exe
O4 - HKLM\..\RunOnce: [ipym.exe] C:\WINDOWS\ipym.exe
O4 - HKLM\..\RunOnce: [msda.exe] C:\WINDOWS\msda.exe
O4 - HKLM\..\RunOnce: [appye32.exe] C:\WINDOWS\appye32.exe
O4 - HKLM\..\RunOnce: [crhr32.exe] C:\WINDOWS\system32\crhr32.exe
O4 - HKLM\..\RunOnce: [winps.exe] C:\WINDOWS\system32\winps.exe
O4 - HKLM\..\RunOnce: [addrr.exe] C:\WINDOWS\system32\addrr.exe
O4 - HKLM\..\RunOnce: [javalb32.exe] C:\WINDOWS\javalb32.exe
O4 - HKLM\..\RunOnce: [sdksh.exe] C:\WINDOWS\system32\sdksh.exe
O4 - HKLM\..\RunOnce: [ipcn32.exe] C:\WINDOWS\system32\ipcn32.exe
O4 - HKLM\..\RunOnce: [d3qv32.exe] C:\WINDOWS\system32\d3qv32.exe
O4 - HKLM\..\RunOnce: [atlaf.exe] C:\WINDOWS\system32\atlaf.exe
O4 - HKLM\..\RunOnce: [mfcqo32.exe] C:\WINDOWS\system32\mfcqo32.exe
O4 - HKLM\..\RunOnce: [apiso32.exe] C:\WINDOWS\apiso32.exe
O4 - HKLM\..\RunOnce: [iebh.exe] C:\WINDOWS\iebh.exe
O4 - HKLM\..\RunOnce: [appfj.exe] C:\WINDOWS\system32\appfj.exe
O4 - HKLM\..\RunOnce: [mswk32.exe] C:\WINDOWS\system32\mswk32.exe
O4 - HKLM\..\RunOnce: [mfcfj.exe] C:\WINDOWS\system32\mfcfj.exe
O4 - HKLM\..\RunOnce: [iphw.exe] C:\WINDOWS\system32\iphw.exe
O4 - HKLM\..\RunOnce: [javaji.exe] C:\WINDOWS\javaji.exe
O4 - HKLM\..\RunOnce: [apipd32.exe] C:\WINDOWS\apipd32.exe
O4 - HKLM\..\RunOnce: [mfcpf.exe] C:\WINDOWS\system32\mfcpf.exe
O4 - HKLM\..\RunOnce: [ntth.exe] C:\WINDOWS\system32\ntth.exe
O4 - HKLM\..\RunOnce: [atlhb32.exe] C:\WINDOWS\atlhb32.exe
O4 - HKLM\..\RunOnce: [sdkrn.exe] C:\WINDOWS\sdkrn.exe
O4 - HKLM\..\RunOnce: [apitq.exe] C:\WINDOWS\system32\apitq.exe
O4 - HKLM\..\RunOnce: [ntym32.exe] C:\WINDOWS\ntym32.exe
O4 - HKLM\..\RunOnce: [appdo.exe] C:\WINDOWS\system32\appdo.exe
O4 - HKLM\..\RunOnce: [crqs32.exe] C:\WINDOWS\system32\crqs32.exe
O4 - HKLM\..\RunOnce: [addgf32.exe] C:\WINDOWS\addgf32.exe
O4 - HKLM\..\RunOnce: [javaui32.exe] C:\WINDOWS\system32\javaui32.exe
O4 - HKLM\..\RunOnce: [d3ik.exe] C:\WINDOWS\system32\d3ik.exe
O4 - HKLM\..\RunOnce: [netom32.exe] C:\WINDOWS\system32\netom32.exe
O4 - HKLM\..\RunOnce: [apivz.exe] C:\WINDOWS\apivz.exe
O4 - HKLM\..\RunOnce: [addtj32.exe] C:\WINDOWS\addtj32.exe
O4 - HKLM\..\RunOnce: [ipwu32.exe] C:\WINDOWS\system32\ipwu32.exe
O4 - HKLM\..\RunOnce: [atlhj32.exe] C:\WINDOWS\atlhj32.exe
O4 - HKLM\..\RunOnce: [addrh32.exe] C:\WINDOWS\addrh32.exe
O4 - HKLM\..\RunOnce: [msmc.exe] C:\WINDOWS\msmc.exe
O4 - HKLM\..\RunOnce: [addeb32.exe] C:\WINDOWS\addeb32.exe
O4 - HKLM\..\RunOnce: [criw32.exe] C:\WINDOWS\system32\criw32.exe
O4 - HKLM\..\RunOnce: [mfclr32.exe] C:\WINDOWS\system32\mfclr32.exe
O4 - HKLM\..\RunOnce: [atlam32.exe] C:\WINDOWS\atlam32.exe
O4 - HKLM\..\RunOnce: [msud.exe] C:\WINDOWS\msud.exe
O4 - HKLM\..\RunOnce: [msjy32.exe] C:\WINDOWS\system32\msjy32.exe
O4 - HKLM\..\RunOnce: [winwa32.exe] C:\WINDOWS\winwa32.exe
O4 - HKLM\..\RunOnce: [d3am32.exe] C:\WINDOWS\d3am32.exe
O4 - HKLM\..\RunOnce: [ipyp.exe] C:\WINDOWS\ipyp.exe
O4 - HKLM\..\RunOnce: [ntxa.exe] C:\WINDOWS\system32\ntxa.exe
O4 - HKLM\..\RunOnce: [d3bc.exe] C:\WINDOWS\system32\d3bc.exe
O4 - HKLM\..\RunOnce: [atliz32.exe] C:\WINDOWS\system32\atliz32.exe
O4 - HKLM\..\RunOnce: [mscq.exe] C:\WINDOWS\system32\mscq.exe
O4 - HKLM\..\RunOnce: [ipef.exe] C:\WINDOWS\system32\ipef.exe
O4 - HKLM\..\RunOnce: [mfcdi.exe] C:\WINDOWS\system32\mfcdi.exe
O4 - HKLM\..\RunOnce: [nthk.exe] C:\WINDOWS\nthk.exe
O4 - HKLM\..\RunOnce: [ipqi.exe] C:\WINDOWS\system32\ipqi.exe
O4 - HKLM\..\RunOnce: [d3vs.exe] C:\WINDOWS\system32\d3vs.exe
O4 - HKLM\..\RunOnce: [sdkct.exe] C:\WINDOWS\sdkct.exe
O4 - HKLM\..\RunOnce: [ipnn.exe] C:\WINDOWS\ipnn.exe
O4 - HKLM\..\RunOnce: [winkw.exe] C:\WINDOWS\winkw.exe
O4 - HKLM\..\RunOnce: [netyi.exe] C:\WINDOWS\netyi.exe
O4 - HKLM\..\RunOnce: [mseg.exe] C:\WINDOWS\system32\mseg.exe
O4 - HKLM\..\RunOnce: [craq32.exe] C:\WINDOWS\craq32.exe
O4 - HKLM\..\RunOnce: [d3tb32.exe] C:\WINDOWS\d3tb32.exe
O4 - HKLM\..\RunOnce: [mfcrc32.exe] C:\WINDOWS\mfcrc32.exe
O4 - HKLM\..\RunOnce: [ntog32.exe] C:\WINDOWS\system32\ntog32.exe
O4 - HKLM\..\RunOnce: [ipdb.exe] C:\WINDOWS\ipdb.exe
O4 - HKLM\..\RunOnce: [ieae32.exe] C:\WINDOWS\system32\ieae32.exe
O4 - HKLM\..\RunOnce: [sysuv32.exe] C:\WINDOWS\sysuv32.exe
O4 - HKLM\..\RunOnce: [sdkom.exe] C:\WINDOWS\sdkom.exe
O4 - HKLM\..\RunOnce: [d3os32.exe] C:\WINDOWS\system32\d3os32.exe
O4 - HKLM\..\RunOnce: [mfcqj32.exe] C:\WINDOWS\system32\mfcqj32.exe
O4 - HKLM\..\RunOnce: [javage32.exe] C:\WINDOWS\javage32.exe
O4 - HKLM\..\RunOnce: [d3av32.exe] C:\WINDOWS\system32\d3av32.exe
O4 - HKLM\..\RunOnce: [winqx32.exe] C:\WINDOWS\system32\winqx32.exe
O4 - HKLM\..\RunOnce: [ielg32.exe] C:\WINDOWS\ielg32.exe
O4 - HKLM\..\RunOnce: [netjh32.exe] C:\WINDOWS\netjh32.exe
O4 - HKLM\..\RunOnce: [javafl32.exe] C:\WINDOWS\javafl32.exe
O4 - HKLM\..\RunOnce: [appku.exe] C:\WINDOWS\appku.exe
O4 - HKLM\..\RunOnce: [netjx32.exe] C:\WINDOWS\system32\netjx32.exe
O4 - HKLM\..\RunOnce: [appxf.exe] C:\WINDOWS\appxf.exe
O4 - HKLM\..\RunOnce: [sysnz.exe] C:\WINDOWS\system32\sysnz.exe
O4 - HKLM\..\RunOnce: [atlke.exe] C:\WINDOWS\atlke.exe
O4 - HKLM\..\RunOnce: [addhz.exe] C:\WINDOWS\addhz.exe
O4 - HKLM\..\RunOnce: [ipfc.exe] C:\WINDOWS\system32\ipfc.exe
O4 - HKLM\..\RunOnce: [ntfk32.exe] C:\WINDOWS\system32\ntfk32.exe
O4 - HKLM\..\RunOnce: [apiss32.exe] C:\WINDOWS\apiss32.exe
O4 - HKLM\..\RunOnce: [javaci.exe] C:\WINDOWS\system32\javaci.exe
O4 - HKLM\..\RunOnce: [ntmr32.exe] C:\WINDOWS\system32\ntmr32.exe
O4 - HKLM\..\RunOnce: [appxp32.exe] C:\WINDOWS\appxp32.exe
O4 - HKLM\..\RunOnce: [msnz.exe] C:\WINDOWS\system32\msnz.exe
O4 - HKLM\..\RunOnce: [apigh32.exe] C:\WINDOWS\system32\apigh32.exe
O4 - HKLM\..\RunOnce: [cril32.exe] C:\WINDOWS\cril32.exe
O4 - HKLM\..\RunOnce: [sysyu32.exe] C:\WINDOWS\sysyu32.exe
O4 - HKLM\..\RunOnce: [mfcjy.exe] C:\WINDOWS\system32\mfcjy.exe
O4 - HKLM\..\RunOnce: [d3bi.exe] C:\WINDOWS\system32\d3bi.exe
O4 - HKLM\..\RunOnce: [ntau32.exe] C:\WINDOWS\ntau32.exe
O4 - HKLM\..\RunOnce: [apput.exe] C:\WINDOWS\system32\apput.exe
O4 - HKLM\..\RunOnce: [mfcuy32.exe] C:\WINDOWS\mfcuy32.exe
O4 - HKLM\..\RunOnce: [atlax.exe] C:\WINDOWS\system32\atlax.exe
O4 - HKLM\..\RunOnce: [javakd32.exe] C:\WINDOWS\javakd32.exe
O4 - HKLM\..\RunOnce: [ipuc32.exe] C:\WINDOWS\ipuc32.exe
O4 - HKLM\..\RunOnce: [sysgx.exe] C:\WINDOWS\system32\sysgx.exe
O4 - HKLM\..\RunOnce: [netpd32.exe] C:\WINDOWS\system32\netpd32.exe
O4 - HKLM\..\RunOnce: [mfczc32.exe] C:\WINDOWS\system32\mfczc32.exe
O4 - HKLM\..\RunOnce: [netdk.exe] C:\WINDOWS\netdk.exe
O4 - HKLM\..\RunOnce: [appob.exe] C:\WINDOWS\system32\appob.exe
O4 - HKLM\..\RunOnce: [sdkxh32.exe] C:\WINDOWS\sdkxh32.exe
O4 - HKLM\..\RunOnce: [netpo.exe] C:\WINDOWS\netpo.exe
O4 - HKLM\..\RunOnce: [winym32.exe] C:\WINDOWS\winym32.exe
O4 - HKLM\..\RunOnce: [atldo32.exe] C:\WINDOWS\atldo32.exe
O4 - HKLM\..\RunOnce: [ntpy32.exe] C:\WINDOWS\ntpy32.exe
O4 - HKLM\..\RunOnce: [msot.exe] C:\WINDOWS\msot.exe
O4 - HKLM\..\RunOnce: [creo.exe] C:\WINDOWS\creo.exe
O4 - HKLM\..\RunOnce: [crbj32.exe] C:\WINDOWS\system32\crbj32.exe
O4 - HKLM\..\RunOnce: [mfcjx.exe] C:\WINDOWS\mfcjx.exe
O4 - HKLM\..\RunOnce: [addiy32.exe] C:\WINDOWS\system32\addiy32.exe
O4 - HKLM\..\RunOnce: [ipaf32.exe] C:\WINDOWS\system32\ipaf32.exe
O4 - HKLM\..\RunOnce: [crzs.exe] C:\WINDOWS\system32\crzs.exe
O4 - HKLM\..\RunOnce: [netkj32.exe] C:\WINDOWS\netkj32.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: Network Security Service (NSS) ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apifk.exe" /s (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
hi,
i'm not sure if i'm doing this right but it't been six days since i posted.
this is my original post link……..about:blank
the hijack log is old so i'madding a new one
thanks


Logfile of HijackThis v1.99.1
Scan saved at 5:43:07 AM, on 7/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {054F5E50-28A8-4816-3209-EFF9B61A1BEC} - C:\WINDOWS\system32\javaei32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {10F009D2-02C1-DA9A-40FD-0C116521EA7F} - C:\WINDOWS\system32\ipsm.dll
O2 - BHO: Class - {1C5FE92B-D6A5-2B56-D796-580344D5766A} - C:\WINDOWS\system32\sdksq32.dll
O2 - BHO: Class - {213FF3C4-933A-5728-4344-750F1EBB3DD5} - C:\WINDOWS\sdksx32.dll
O2 - BHO: Class - {26565460-D3FF-D0D6-C07D-1F260FA16CC8} - C:\WINDOWS\ipwx32.dll
O2 - BHO: Class - {32EDCCFD-DAC9-D83E-5DB1-6CB6E0DCD071} - C:\WINDOWS\atlok.dll
O2 - BHO: Class - {407E35F0-F5FF-7693-C8CB-9147DC9626D2} - C:\WINDOWS\system32\atluf32.dll
O2 - BHO: Class - {46E12037-4A39-43D9-3B76-14AD3F253732} - C:\WINDOWS\system32\winfb32.dll
O2 - BHO: Class - {5AC2A38B-A149-E35C-3148-F22B4B257669} - C:\WINDOWS\system32\mspt32.dll
O2 - BHO: Class - {66BC6227-B851-2929-8008-EE055DC63DBF} - C:\WINDOWS\system32\wingz.dll
O2 - BHO: Class - {89E6AA46-56B1-1685-3746-E57CB3CFC36B} - C:\WINDOWS\ntbq32.dll
O2 - BHO: Class - {8EC3A4C0-28A4-8A9B-0541-C660D3D07E09} - C:\WINDOWS\system32\appcz.dll
O2 - BHO: Class - {967871F3-038A-F72E-C5FF-CE710FAFDEA8} - C:\WINDOWS\crtb32.dll
O2 - BHO: Class - {9DCAC14C-5AED-ADB0-13C7-BC0FD19AC9B5} - C:\WINDOWS\system32\iezb32.dll
O2 - BHO: Class - {AA3DBC87-F177-8D58-138B-069152EFDEAC} - C:\WINDOWS\system32\sysot32.dll
O2 - BHO: Class - {B30A7120-DF83-F544-F99D-F86F68F50C2F} - C:\WINDOWS\system32\javafg32.dll
O2 - BHO: Class - {BE2B01AC-C74F-FE86-69B1-C961A25C369C} - C:\WINDOWS\crld.dll
O2 - BHO: Class - {D006F3DF-6883-5152-C428-17EFD3009EF0} - C:\WINDOWS\system32\apimm32.dll
O2 - BHO: Class - {D7C2CB9D-F607-600B-91D0-599679F9A88F} - C:\WINDOWS\system32\apimk.dll
O2 - BHO: Class - {DF704C87-46E7-AE73-9934-657FBE2E1426} - C:\WINDOWS\system32\ntyg32.dll
O2 - BHO: Class - {FA1487A3-BE0B-8C8F-EE8B-A7306DC4EB4E} - C:\WINDOWS\msvo.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [apiso32.exe] C:\WINDOWS\apiso32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apiso32.exe" /s (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Hello mat2056 and welcome to TomCoyote :wavey: You have the newest version of About:Blank so I'll need another fresh HijackThis log from you. After posting the new log, do not reboot the computer nor use Internet Explorer if possible. Doing so may cause the file names to change. I will receive an email notification of your reply and will respond as soon as possible.
hi alsocom,
thanks for replying to me…i was getting a little worried.

anyway, since my first post i've installed firefox & am not using ie anymore.

i've also downloaded a few spyware programs & it seems to be helping a lot.

i think i got rid of coolwwwsearch & klez.

i think i still have 2 problems….about:blank & home search assistant

the hsremove changed the start page from about:blank to hsremove's home page but about blank is still with me.

this is one tough cookie!!!!! :rofl:

here's my latest hijack this log

i won't reboot or use ie

thanks again

Logfile of HijackThis v1.99.1
Scan saved at 4:51:12 AM, on 7/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {054F5E50-28A8-4816-3209-EFF9B61A1BEC} - C:\WINDOWS\system32\javaei32.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {10F009D2-02C1-DA9A-40FD-0C116521EA7F} - C:\WINDOWS\system32\ipsm.dll
O2 - BHO: Class - {1C5FE92B-D6A5-2B56-D796-580344D5766A} - C:\WINDOWS\system32\sdksq32.dll
O2 - BHO: Class - {213FF3C4-933A-5728-4344-750F1EBB3DD5} - C:\WINDOWS\sdksx32.dll
O2 - BHO: Class - {26565460-D3FF-D0D6-C07D-1F260FA16CC8} - C:\WINDOWS\ipwx32.dll
O2 - BHO: Class - {32EDCCFD-DAC9-D83E-5DB1-6CB6E0DCD071} - C:\WINDOWS\atlok.dll
O2 - BHO: Class - {407E35F0-F5FF-7693-C8CB-9147DC9626D2} - C:\WINDOWS\system32\atluf32.dll
O2 - BHO: Class - {46E12037-4A39-43D9-3B76-14AD3F253732} - C:\WINDOWS\system32\winfb32.dll
O2 - BHO: Class - {5AC2A38B-A149-E35C-3148-F22B4B257669} - C:\WINDOWS\system32\mspt32.dll
O2 - BHO: Class - {66BC6227-B851-2929-8008-EE055DC63DBF} - C:\WINDOWS\system32\wingz.dll
O2 - BHO: Class - {89E6AA46-56B1-1685-3746-E57CB3CFC36B} - C:\WINDOWS\ntbq32.dll
O2 - BHO: Class - {8EC3A4C0-28A4-8A9B-0541-C660D3D07E09} - C:\WINDOWS\system32\appcz.dll
O2 - BHO: Class - {967871F3-038A-F72E-C5FF-CE710FAFDEA8} - C:\WINDOWS\crtb32.dll
O2 - BHO: Class - {9DCAC14C-5AED-ADB0-13C7-BC0FD19AC9B5} - C:\WINDOWS\system32\iezb32.dll
O2 - BHO: Class - {AA3DBC87-F177-8D58-138B-069152EFDEAC} - C:\WINDOWS\system32\sysot32.dll
O2 - BHO: Class - {B30A7120-DF83-F544-F99D-F86F68F50C2F} - C:\WINDOWS\system32\javafg32.dll
O2 - BHO: Class - {BE2B01AC-C74F-FE86-69B1-C961A25C369C} - C:\WINDOWS\crld.dll
O2 - BHO: Class - {D006F3DF-6883-5152-C428-17EFD3009EF0} - C:\WINDOWS\system32\apimm32.dll
O2 - BHO: Class - {D7C2CB9D-F607-600B-91D0-599679F9A88F} - C:\WINDOWS\system32\apimk.dll
O2 - BHO: Class - {DF704C87-46E7-AE73-9934-657FBE2E1426} - C:\WINDOWS\system32\ntyg32.dll
O2 - BHO: Class - {FA1487A3-BE0B-8C8F-EE8B-A7306DC4EB4E} - C:\WINDOWS\msvo.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\RunOnce: [apiso32.exe] C:\WINDOWS\apiso32.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -

http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apiso32.exe" /s (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Hello mat2056 and welcome to TomCoyote. :wavey:

This fix may take a few runs to completely remove the infection. Be sure not to stray from the instructions and try anything on your own as it will make the fix much more difficult.


You have Spybot S&D's Teatimer running which is good, but we need you to disable it for the remainder of the fix as it will interfere with the registry changes being made.
Open Spybot S&D in advanced mode, click Tools > Resident, and remove the check from "Resident Tea-Timer".

Leave this disabled until the computer is completely clean as it will block the fixes we are about to do.


Step#1:Getting Ready


Please save these instructions to WordPad so that you have them accessible while following the steps. You also may want to print out these directions as the Internet will not be available.

After downloading the tools, you must disconnect from the internet totally, because staying connected while fixing will prevent the fix from working. Also please keep Internet Explorer and Outlook Express closed throughout as opening either will reinstall the infection.

To replace Internet Explorer to use during this fix, please use Internet Explorer once to download and install FireFox, to be used as your alternate browser throughout this fix.

Close Outlook Express and Internet Explorer for the duration of this fix

Please start by downloading the tools you will need to clean this infection with FireFox. If you have a problem or question with any please continue to follow the list step by step to the end and ask the questions when you are asked to reply. Just be sure to let us know what the problem was when you finally reply.


Step#2:Show All Hidden Files Very Important
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.

Step#3:Download CWShredder

1. Please Download the most recent version of CWShredder, from CWSInstall.exe

2. Check for Updates but please Do NOT use it yet


Step#4:Download About Buster

1. Please download About:Buster from here: http://www.malwarebytes.biz/AboutBuster5.zip.

2. Once it is downloaded extract it to c:\aboutbuster.

3. Check to make sure it is up-to-date. Please Do NOT use it yet


Step#5:Download Registrar Lite

Another program to download is Registrar Lite for use later: Please download Registrar Lite and install it to C:\Program Files\RegLite\ . This is a registry editor that is very easy to use. Caution should be exercised when editing the registry as it is very easy to render a Computer unbootable by deleting the wrong key


Step#6:Download Ewido Security Suite
  • Download and install Ewido security suite
  • Right Click on the “E” icon in your taskbar and open Ewido Security Suite then click “update” to get the most recent definitions for it to use.
  • When it prompts you to update, click the OK button.
  • download the updates and when they are finished installing, close the window
  • Please Do Not Use It Yet

Step#7:Download A Registry File to Remove Registry Entries
  • Please download the following zip file to your desktop:
    HSfix
  • Double Click on HSfix.zip and it will unzip to a new folder it makes on your desktop, called HSfix
  • Do Not Use It Yet

Please disconnect from the Internet

Reboot your computer into Safe Mode by tapping F8 while booting up and continue for the rest of the fix in SAFE MODE




Step#8:Disable The Bad Service ** Very Important!!**
  • Click on start > control panel > administrative programs > services. Look for a service called Network Security Service. Double click on that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.

Step#9:Stop The Running Processes

Press control-alt-delete to get into the task manager and end the following processes if they exist:

Skip this step



Step#10:Delete the Offending Files

I now need you to delete the following files:

C:\WINDOWS\system32\javaei32.dll
C:\WINDOWS\system32\ipsm.dll
C:\WINDOWS\system32\sdksq32.dll
C:\WINDOWS\system32\atluf32.dll
C:\WINDOWS\system32\winfb32.dll
C:\WINDOWS\system32\mspt32.dll
C:\WINDOWS\system32\wingz.dll
C:\WINDOWS\system32\appcz.dll
C:\WINDOWS\system32\iezb32.dll
C:\WINDOWS\system32\sysot32.dll
C:\WINDOWS\system32\javafg32.dll
C:\WINDOWS\system32\apimm32.dll
C:\WINDOWS\system32\apimk.dll
C:\WINDOWS\system32\ntyg32.dll

C:\WINDOWS\ntbq32.dll
C:\WINDOWS\sdksx32.dll
C:\WINDOWS\ipwx32.dll
C:\WINDOWS\atlok.dll
C:\WINDOWS\crtb32.dll
C:\WINDOWS\crld.dll
C:\WINDOWS\msvo.dll
C:\WINDOWS\apiso32.exe



If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Step#11:Cleaning With HijackThis

Open HijackThis, run a scan and put a checkmark next to each of these entries (some may be gone after uninstalling some programs):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {054F5E50-28A8-4816-3209-EFF9B61A1BEC} - C:\WINDOWS\system32\javaei32.dll
O2 - BHO: Class - {10F009D2-02C1-DA9A-40FD-0C116521EA7F} - C:\WINDOWS\system32\ipsm.dll
O2 - BHO: Class - {1C5FE92B-D6A5-2B56-D796-580344D5766A} - C:\WINDOWS\system32\sdksq32.dll
O2 - BHO: Class - {213FF3C4-933A-5728-4344-750F1EBB3DD5} - C:\WINDOWS\sdksx32.dll
O2 - BHO: Class - {26565460-D3FF-D0D6-C07D-1F260FA16CC8} - C:\WINDOWS\ipwx32.dll
O2 - BHO: Class - {32EDCCFD-DAC9-D83E-5DB1-6CB6E0DCD071} - C:\WINDOWS\atlok.dll
O2 - BHO: Class - {407E35F0-F5FF-7693-C8CB-9147DC9626D2} - C:\WINDOWS\system32\atluf32.dll
O2 - BHO: Class - {46E12037-4A39-43D9-3B76-14AD3F253732} - C:\WINDOWS\system32\winfb32.dll
O2 - BHO: Class - {5AC2A38B-A149-E35C-3148-F22B4B257669} - C:\WINDOWS\system32\mspt32.dll
O2 - BHO: Class - {66BC6227-B851-2929-8008-EE055DC63DBF} - C:\WINDOWS\system32\wingz.dll
O2 - BHO: Class - {89E6AA46-56B1-1685-3746-E57CB3CFC36B} - C:\WINDOWS\ntbq32.dll
O2 - BHO: Class - {8EC3A4C0-28A4-8A9B-0541-C660D3D07E09} - C:\WINDOWS\system32\appcz.dll
O2 - BHO: Class - {967871F3-038A-F72E-C5FF-CE710FAFDEA8} - C:\WINDOWS\crtb32.dll
O2 - BHO: Class - {9DCAC14C-5AED-ADB0-13C7-BC0FD19AC9B5} - C:\WINDOWS\system32\iezb32.dll
O2 - BHO: Class - {AA3DBC87-F177-8D58-138B-069152EFDEAC} - C:\WINDOWS\system32\sysot32.dll
O2 - BHO: Class - {B30A7120-DF83-F544-F99D-F86F68F50C2F} - C:\WINDOWS\system32\javafg32.dll
O2 - BHO: Class - {BE2B01AC-C74F-FE86-69B1-C961A25C369C} - C:\WINDOWS\crld.dll
O2 - BHO: Class - {D006F3DF-6883-5152-C428-17EFD3009EF0} - C:\WINDOWS\system32\apimm32.dll
O2 - BHO: Class - {D7C2CB9D-F607-600B-91D0-599679F9A88F} - C:\WINDOWS\system32\apimk.dll
O2 - BHO: Class - {DF704C87-46E7-AE73-9934-657FBE2E1426} - C:\WINDOWS\system32\ntyg32.dll
O2 - BHO: Class - {FA1487A3-BE0B-8C8F-EE8B-A7306DC4EB4E} - C:\WINDOWS\msvo.dll

O4 - HKLM\..\RunOnce: [apiso32.exe] C:\WINDOWS\apiso32.exe

O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\apiso32.exe" /s (file missing)


With all other programs and browsers closed, click Fix Checked.



Step#12: Backup The Registry

In the next step we are going to remove a service that gets installed by this malware.

1. Open Registrar Lite and run it.

2. Copy and paste the bold text below into the address bar of Registrar Lite:(this is making a Registry backup for safety in case of error)

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\

Go to File> Export and and save as (in the C:\Program Files\Registrar Lite (Reglite) folder):

1.) Winkey.reg (Save as type: regedit4 .reg type)
2.) Winkey.hiv (Save as type: Scroll to select-regetd32/WinAPI *hiv *dat files)






Step#13: Use the HSfix.reg file
  • Navigate to the HSfix folder on your Desktop
  • Then double-click on the HSfix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.
  • if you have a popup from any of your protection programs asking if you want to make a change to the registry, say Yes or Accept it

Step#14:Fixing With CWShredder
  • CLOSE ALL WINDOWS except CWShredder
  • Run the program by clicking 'fix' and letting it fix all CWS remnants.


Step#15:Fixing With About Buster

This is the step where we will use About:Buster that you had downloaded previously.
  • Navigate to the c:\aboutbuster directory
  • double-click on aboutbuster.exe
  • When the tool opens press the OK button, then Start button, then the OK button
  • then finally the Yes button. It will start scanning your computer for files.
  • If it asks if you would like to do a second pass, allow it to do so.
  • Post the log file in your next reply


Step#16:Scan With Ewido Security Suite
  • Launch Ewido again
  • Click on Scanner>Complete System Scan.
  • Let the program scan your PC.
  • When the scan asks to clean files click OK.
  • When scan is completed, click Save report. to your desktop.
  • Post the report in your next reply.

Reboot your computer back to normal mode


Step#17:Scan and Post a New HJT log with other logs
  • Scan again with HijackThis and save log.

    Reconnect To The Internet
  • Post your logs from HijackThis, About Buster, and Ewido Security Suite here in this thread with any questions or problems that you have run into.
  • There are still some steps that are necessary to clear out all of the malware. There will be necessary files that it has deleted that will need to be replaced.
hi,
wow what a difference!!!

the only problem was that when i ran hijack this the O23-service key was not there,
otherwise all went smooth.

here are all my logs:

Logfile of HijackThis v1.99.1
Scan saved at 8:47:08 AM, on 7/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [7:13:06 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was ABORTED at 7:13:12 AM


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [7:37:34 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\axgvpn.dat
Removed File! : C:\Windows\uoegh.dat
Removed File! : C:\Windows\netkf.exe
Removed File! : C:\Windows\aujqji.dat
Removed File! : C:\Windows\winip32.exe
Removed File! : C:\Windows\vhgdf.dat
Removed File! : C:\Windows\jarrl.dat
Removed File! : C:\Windows\jxfdf.dat
Removed File! : C:\Windows\tphgu.dat
Removed File! : C:\Windows\emrel.dat
————————————————
Scan was ABORTED at 7:39:20 AM


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [7:41:32 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\System32\mfhij.dat
Removed File! : C:\Windows\System32\atliq.exe
Removed File! : C:\Windows\System32\atlum.exe
Removed File! : C:\Windows\System32\zvcjb.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 7:44:30 AM


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [7:48:00 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 7:53:02 AM


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [7:54:02 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was ABORTED at 7:54:10 AM


AboutBuster 5.0 reference file 30
Scan started on [7/18/2005] at [8:17:16 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 8:21:26 AM


AboutBuster 5.0 reference file 31
Scan started on [7/20/2005] at [8:11:27 AM]
————————————————
Streams(ADS) not scanned: System not NTFS
————————————————
Removed File! : C:\Windows\nxitb.dat
Removed File! : C:\Windows\pwvdbb.dat
Removed File! : C:\Windows\rodup.dat
Removed File! : C:\Windows\zmrwk.dat
Removed File! : C:\Windows\tzdscf.dat
Removed File! : C:\Windows\wjxvyx.dat
Removed File! : C:\Windows\llczi.dat
Removed File! : C:\Windows\urnrwr.dat
Removed File! : C:\Windows\hezsm.dat
Removed File! : C:\Windows\reorf.dat
Removed File! : C:\Windows\rwsjnt.dat
Removed File! : C:\Windows\uqmbu.dat
Removed File! : C:\Windows\System32\mpolb.dat
Removed File! : C:\Windows\System32\bdbdl.dat
Removed File! : C:\Windows\System32\nuwlo.dat
Removed File! : C:\Windows\System32\bpaso.dat
Removed File! : C:\Windows\System32\zygcn.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 8:14:22 AM


i have to post ewido seperately i think…too long


::Report End
ewido in 2 parts…i hope ewido security suite - Scan report ——————————————————— + Created on: 8:43:10 AM, 7/20/2005 + Report-Checksum: DF388C7E + Scan result: HKLM\SOFTWARE\Classes\CLSID\{00AF6BF7-1C8A-2F68-11A6-3DD4FD5A3DED} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{031788DE-6282-F9CD-262A-AA22CDA2B068} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{065FC1F3-9ED6-83E8-0595-519D9C0E43FF} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{08BFBA35-C44B-38A4-2263-278430DC9376} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{097FBE5D-0CB9-381B-B07B-EDBEFEEADD4B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0ADD4D53-B7DD-20F8-2AC9-AB9CB538A46F} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0ADEF183-C204-6BFB-2DA8-5C12061DE911} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B4F9B2C-F81D-7C42-AE33-07F0FCB846EC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B6BE68E-B55A-5883-3DBC-30D73208D3E7} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0ECEBD98-802F-9B4D-7308-C983A18EDBEC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0FBFA147-FFB4-19A8-49F8-D1A17B80E32D} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0FEF3DCB-727B-207F-1E58-40117737169C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{12130DCB-3DF4-96EC-27B9-61E0D766F680} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{15E6172A-5F7D-3085-1E94-14DA8D1A4479} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1A5161CF-197C-FCC5-52C8-1AE7E0BB4A51} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{24E10FF7-10AA-6198-95AE-258D49D9ABCA} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{25742C0F-DC0D-F5DC-55DE-C66285AA22AB} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2A9B7B46-3BB6-BB3C-9E0A-6C988B9DE22E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2C21BAA6-325A-A257-9DFA-7425A21F1A16} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2FB10B1F-E342-08A1-CBAA-D4A2CD2ABAC6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3592B2D9-6ECF-2944-7066-4AD1D7DD85E6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{37E5E66E-C168-B55B-BE2E-8478ED77CD96} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{38A09FC8-FCAF-3D1E-A6D6-FB0A0E2E2D98} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{518D1E4B-6041-652D-733B-A730792CAADD} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{52CA0FCE-F9E0-2125-6CA6-2627141A47E9} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5FA3F496-5B56-4EC5-3AF9-C3365181BC99} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{62AAF848-9010-0094-6A6B-611B828A74F6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6F8FA771-74ED-EABB-5DE2-9E2B3143177C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{765369C1-D4E0-D6A4-69B4-6261D4E1319A} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{794DE92B-5B3E-DFB3-BD79-2505954D24D5} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7C36455F-C2B4-5BC0-575A-253825413F0C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{877DBFE0-6233-B1C4-8252-A4475BCF6DD2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8BBD3FEB-8F56-FA45-F83E-0589E7E09434} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8BF830DB-C16D-72B1-3E41-BAC8D1F199E1} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8E22B410-9A68-7588-EDE1-05BA98980E7E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8E883EC3-ABB5-0CD9-EC0A-78CB81A818D1} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{966FA744-197F-E95E-EB31-73BE39619DE2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{96EEA21B-4AA3-4627-EA0A-176241DBD1A4} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9EDC0D8F-954E-A638-C240-D52042910A62} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A6A537E1-A69B-6C58-00AC-B6C4E8539037} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B279D474-B064-DCC7-5638-6B0E0A96537C} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B6233EB3-872F-7898-F4A8-3F6A3BAA6D57} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BD757058-7180-2CE5-E5B6-8C70AEF236CC} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BD9A8BB0-8BF8-EC2E-5A23-8010E127E35B} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C0C3B877-2F73-D5F0-470E-5687890C47C6} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C75B8795-6012-883F-06EE-5F1501763CFE} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CC6B2B65-2D60-CC2D-B4A6-7C0945964771} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D75897AF-4779-FE93-0121-038FA5AA18C4} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DBC8BCC3-8C2E-707C-3D8D-72B88F17460E} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DF7066E9-8EE8-8682-F43E-2BF8E7E7D760} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E897B7A0-EBE4-3A18-7DD3-77E65116B006} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EB3166D5-6855-FBE1-8A6F-C933AE42DD82} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EE7430B5-880B-955D-AF46-8C653AEAD8F8} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F032F043-EDA1-57B1-CD1D-20AEBAA824CB} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F22B79FB-1D55-C94F-4938-EAA13A2FB4ED} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F6BFC595-569B-A80C-DEE4-5AE687AF21D2} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FF1518B7-D821-1BF0-0368-AD32CBCF17E0} -> Spyware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\TypeLib\{F5EE52D3-2ECC-409E-A92F-A73F2B8DD407} -> Spyware.HiWire : Cleaned with backup HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchAssistantUtility -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1A5161CF-197C-FCC5-52C8-1AE7E0BB4A51} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4C1B116F-2860-46DB-8E6C-B4BFC4DFD683} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B279D474-B064-DCC7-5638-6B0E0A96537C} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EB3166D5-6855-FBE1-8A6F-C933AE42DD82} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE7430B5-880B-955D-AF46-8C653AEAD8F8} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A5161CF-197C-FCC5-52C8-1AE7E0BB4A51} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C1B116F-2860-46DB-8E6C-B4BFC4DFD683} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B279D474-B064-DCC7-5638-6B0E0A96537C} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF704C87-46E7-AE73-9934-657FBE2E1426} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EB3166D5-6855-FBE1-8A6F-C933AE42DD82} -> Spyware.CoolWebSearch : Cleaned with backup HKU\S-1-5-21-1960408961-746137067-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE7430B5-880B-955D-AF46-8C653AEAD8F8} -> Spyware.CoolWebSearch : Cleaned with backup C:\WINDOWS\system32\apprh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcna32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3eb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipht.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addvz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlnk32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netuk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crpq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlsj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javarg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apifi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysia32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdknv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcqn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iewi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkza32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlmc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msfl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntjv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appoy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msrq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipwl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipuj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addad.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javakl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlnk32.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msse.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apihh.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netky32.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winou32.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ieep.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntbo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3ab.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apiny.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apiny.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winsa32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winsa32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winqq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winqq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javavl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javavl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfchd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfchd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysmf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysmf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkpq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkpq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfcvs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfcvs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkdf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atloy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieus.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ieus.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntxl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlcn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javaup.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apiar32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkgu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\adddx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntnz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iegv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ierg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntla.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crka32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crsx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\wintv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\wintv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apiji32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apiji32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winpc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winpc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javasv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javasv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apixx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apixx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysbi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysbi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcrc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfcrc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iewx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iewx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkap32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlfj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atldi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msic32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntwe.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntmv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appzx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mser.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apiaj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netxs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netxs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winbk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javaom32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysxz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcfm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieif32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlzs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieeu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieck.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\nthf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\applx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msqz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipts32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apphm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msmg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msmg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netlo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipgs.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdkpk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdkpk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appgp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appef32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appef32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3ja.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipxc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ipxc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipns32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipns32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addau.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addau.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3fp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3fp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3df32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netjh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netjh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addob.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addob.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winma32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crru32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crru32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netew.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netew.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winih32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winih32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javala.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javala.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apiqc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apiqc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\systu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\systu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javazp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javazp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcch32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3fr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crvh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netij32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javaml32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winzj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addno32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3qg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netvj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winzt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winui.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winsh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javayb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apidv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apibu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msio.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlks.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntrd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msjz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipns.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crgn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netmh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apitm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysee32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcsv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfcsv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieyx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntbp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntbp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlgk32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlgk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlei.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlei.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msrc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msrc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntxw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntxw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntvv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntvv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msdi32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msdi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipjk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ipjk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appoe.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appoe.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addmv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addmv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3zx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3zx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iper.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iper.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netcq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netcq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addik32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addik32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crnm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3wq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addel.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysaj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkui.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcfj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iphw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iexr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iepa32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ipcx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipcx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addhr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3kj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3kj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netym32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addbw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addbw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crgy32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crgy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netkr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netkr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winpl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winpl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javase.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apify.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysjr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysjr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javaot.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javaot.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcre32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcre32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysxg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysxg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ieuw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdkaz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfcnt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atllr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ieql.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntwg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntue32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlzy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msea32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mscr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntht.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appvn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ippi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appvk32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3ae.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3ae.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3yd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3yd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netdx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netdx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addgq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addgq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\cruk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\cruk32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netxd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netxd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\wincf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apils.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apils.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sysok32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysok32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javate.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javate.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcfx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdknk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlqd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iewf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdkbz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlms.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ntkx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlqr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msvt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mstk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipye.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appbx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3pz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipsk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\addxm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3xa32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crtp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crrf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crfu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winzs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\syspa32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javavv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sdkgp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfclr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appig32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msoi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iprb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appwv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appwv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3ao32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipfi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\crvd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crtt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netzn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\wincg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crhi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apinc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\apikt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\javadp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appzm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipmp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3vk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\netae.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\atlxi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iecc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mspv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msnm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msnm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appyi32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\appyi32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netet32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winfc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\criv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apiop.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\apimg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\winri32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\javacb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfciv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\syslo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\sdkqi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcta32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\iezd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntkv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntkv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlpp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\msti.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntyc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntgy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\syslb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3bi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apput.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlax.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sysgx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netpd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfczc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appob.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfcnv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlrl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ieas.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlxl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ntdl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mstf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appeu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\ipgc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appoq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netml.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\windl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipka.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addyc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winon.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\d3eu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crdn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crpr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iexj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javaib32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntld.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winza32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\mfcqm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysvh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mfceb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iehm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\atlxh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\iedb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\msbs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appjn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\appfc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\d3kw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\ipoo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addtj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crwb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\netzu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\winno.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\crqh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\addjr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipwh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crbj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntuw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addiy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipaf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crzs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atldn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winsc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\msup32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlgn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winwu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appzk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\system32\d3mn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\nettv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mscb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ielh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netoe.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appbm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addhm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netrl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ieof32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netdi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlnh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sysvk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apinn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winvg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlmn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlox.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdktp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfcgx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appfq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winpo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netbm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\croc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipfm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apipk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\msml.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\craz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addmh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntnp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apppm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfckj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atlkt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\nttt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iewx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdkbh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdkeq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\wintf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netso.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addof.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javach32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netvg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\msem32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iema32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\d3mk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\d3pc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javall.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipmy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addas.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mswm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfcdb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iexs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javaka32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\cret32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winpi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdkdk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfcmv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\d3jw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfcbg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javaus32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appjt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\cryl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\sysws32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iplt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\atltv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ipnn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdkbp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\sdklb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addfk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\mfctm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntri.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\nted.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javapw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appmp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ielc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\winlq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javaeh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addju32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crwo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\system32\mskr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\appsy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntwi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addzn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ntkw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\apiog32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\msdb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\ieah32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\javafr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addwy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\iemf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\addrp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netnl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\crgs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\system32\netta32.exe -> Trojan.Agent.bi : Cleaned with backup
part 2 C:\WINDOWS\sdkro.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addqk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netxu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\syshz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iegs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipnn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\xjirol.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crep32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appzd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msny.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\znzvsa.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addpn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\n_dkrjta.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atltj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkuu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apihj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysml32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\syskc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javape.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcvy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcsx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysyr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkll.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkjk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atloe32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieug.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addeb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msgm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winyh.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlcs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crxg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieah.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcnb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msmc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iequ.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iebi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addav32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iehm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addlu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntno.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntlf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlqh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msdb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msts.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipgu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appmo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appkn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3ph.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\zhhkbq.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winkq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\applx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apibh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ldtuht.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieyb32.exe -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\vgnwkj.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\tcbofr.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netiz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlcc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appxb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfczg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ippm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javafu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javafu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apilo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apilo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apijn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apijn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysoh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysoh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javatj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javatj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javara.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javara.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcxc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcxc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\syskw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\syskw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\iean.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iean.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdknp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdknp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcsj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcsj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlqh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iewc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\iewc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkbe32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkbe32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntzu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ntzu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apptt.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atleo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atleo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mssr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mssr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysfl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javasf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\xrcdcl.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcwy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\bfqwzn.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javanx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3lb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mssr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlrs.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netqv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ilnwyy.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ienx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ddehce.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javalb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlcc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkue.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mswu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkrs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3bj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crux.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlmw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javakb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msgk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipjd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winuj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3cr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntxg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addoa.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\windw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\criz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netot.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netot.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apimr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apimr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\winrl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crwg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crwg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javaue.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javaue.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apizy32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apizy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysna.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysna.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mgvdiv.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addul.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysdr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javaqt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javaqt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcvn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkea32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkcz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkcz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlht.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlht.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieuv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\iekm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlby32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msgb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javavi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msnd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cryd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\htulga.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3sq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netbp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieud.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crwz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntay.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iprn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atltz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winlu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crqo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apivq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apith.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winzb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javaed32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addlm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\nttg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntln32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addjd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crof.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\nettz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netrq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javact32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winlz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msda.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcpw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javaak.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apinf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3dm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysuq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysqx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javawr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieyo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iplh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysso32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addtu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appim.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkyj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appuw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addar.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkmy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netmj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ds32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaas.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkdq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcaq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cryn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javali.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntko.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msye32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlxq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkad.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crcs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcwo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcwo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieag32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ieag32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkna.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msab.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkna.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkdr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkdr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlqt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlqt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntfd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iewn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ietm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ietm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntzg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntzg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlcz.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlcz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msht.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msht.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appyo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appyo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3by32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3by32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipgb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipgb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appjw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addkt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3pn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netsg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crav32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msoq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iplt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\xqnwqt.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipbs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkke32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msrc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addas32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iprj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msud.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\neteo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iprj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appfd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netme.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkcg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiij.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javavb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipcg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apitj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ttqkoe.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfczs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apifk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\pmjyfw.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javacl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlam32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlwf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iebh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntag32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieaj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addph.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syszv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlun32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipbf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iekl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apimm.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\xkjato.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iltfny.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winyp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crdk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winwa32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mklpuz.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysfw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlac32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iefw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysyf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javaji.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apipd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3am32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlhb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipyp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipgu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\vfsiyy.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\nfdnab.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netyi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javawe.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkrn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iebm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkud.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\neteu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apimo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkux32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netmb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntym32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlom.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\nthk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysfk32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieox.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlns32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msav.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iegj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntzi32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlfc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysjm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysjm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javawg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javawg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mshh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntmc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mstj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mstj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlup.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipnm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipzd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipzd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appra.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3wu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3wu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3ut32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3ut32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipan32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipan32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addgf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appcw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addfp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addfp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3hy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\adddg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\adddg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3hy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3ia32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3ia32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netwc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netwc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netmt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netmt.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winzv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\winzv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crep32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crcn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apihi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apihi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winnc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\winnc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winla32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javaqu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javaqu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netlr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netlr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apidx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apidx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addyl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfctn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfctn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addyl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\syshp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\syshp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javamj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javamj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkka32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkka32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcpc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\iesv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkyp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlbi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ieoc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ntsv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appxx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msap32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crbe32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crbe32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netdf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netgy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msnj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netgy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addgf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cruh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javanj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javanj.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkct.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkjf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcoz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apisd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ntvm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\wingf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\wingf32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apivz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaov32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addtj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iptc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysww32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysww32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appye32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apixl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appbp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netbo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javajy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appxm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3co.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javajy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3co.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcos32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipfh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipfh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcos32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addsb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msmz.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addiz.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addiz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3wt32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3wt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcmj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcmj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netbo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netzm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysrl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysrl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netzm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\wineg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\wineg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crki32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkxf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkxf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crki32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\criz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\criz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apinb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apinb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winqm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javado.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javado.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiji.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiji.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apihh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apihh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysmb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javard.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkpt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcvo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysiq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ieyg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdklj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkve32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlot.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\appye32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3cp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ippr32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlhj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3xe32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ippr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addsk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addsk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3bi32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netdg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netdg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netbx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addrh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysom.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\craq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3tb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcrc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3zv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netcn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addpi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\addny.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\crsa32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netyu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\wingy.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mevins.txt -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appeg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\msrb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipwd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ipdb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysuv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkom.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iput32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3qj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javage32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addzv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iezd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkmn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3fq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ielg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netjh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javafl32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipup.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieel.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3dg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\wkulxt.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\netii32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\d3dc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winbs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javagm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javagm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\javaec.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\apike.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\syspz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysnx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javasr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcgt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcwk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ieje.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkog.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkmx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlrz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\iext.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ievk.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntam32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlng.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlde.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysrc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appxf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlke.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addhz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netfw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiss32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntih32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\atlla32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\appxp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cril32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winqa.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysyu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntau32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcuy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javakd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipuc32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netsv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntfp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netdk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javafd32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkxh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netpo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieng32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netch32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiai.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netjm32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkci.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdktp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atluy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysnr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfczb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntha32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apizh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netit.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaya.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipmd.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sdkcp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winmw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieeu32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlob32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addgh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipbr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apifs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcjq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iech32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\adddr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crvu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\netix.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysxq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sysxq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\javack.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcgd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkwq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\mfcbs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\atlzi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\iefl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ntid32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\syscd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apphd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\msmf32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\ipqq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\d3yl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\addpy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apixk32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\windn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\apiuy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winbd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\sdkiy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\winym32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atldo32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiko32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\ntpy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appjp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msot.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\creo.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iecw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysxn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcjx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iesx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\cfrcuf.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\mfcsj.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINDOWS\sysdu.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netkj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\windi.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlgf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addab32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3fs.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addkv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appsq.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apijg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netdz32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netxq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addcd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiwd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcil.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\systk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdknb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.2.0.007\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.2.0.007\npwthost.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.1.0.037\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.1.0.037\npwthost.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.0.0.173\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\3.0.0.173\npwthost.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtupdates\wtwebdriver\files\2.2.0.100\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup C:\WINDOWS\sysuc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appwp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkfv32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3hs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysyz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syskb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcyj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appwc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysmj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3qt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3af.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msoh32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netxg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlep32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysrk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkqf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addox32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipjp.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apihk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appap.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\d3ic32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntqw32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appkv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfchb32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntrc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\nettx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\iptf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\apiao.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javame.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntrw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msvg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipmg.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atltb.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipsx32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysph.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfctz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winop.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfctr.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appag.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ieni32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\wineg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\mfcvn.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipch32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crwd.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appfj32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netho32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipkt32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appsc.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winki32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netok32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syspw.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaxx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ievf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\netkf32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addsr32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crvg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\atlkg32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipok32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appjx.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crjv.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sysot.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crqp32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkrq32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaac.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msax.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\msax.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\WINDOWS\crdl.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\appup32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javajs32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\addcf.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javaqh.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\javasy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winei32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\syspk.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\sdkav32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\crfz.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ipth32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\ntbn32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\craj.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\winjy32.exe -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\uqmbun.txt -> TrojanDownloader.Agent.bq : Cleaned with backup C:\Program Files\HijackThis\backups\backup-20050720-080102-672.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\Program Files\WildTangent\Components\SystemConfig0100.dll -> Spyware.WinAD : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000016.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000017.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000018.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000019.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000020.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000021.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000022.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000023.exe -> Trojan.Agent.bi : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000036.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000037.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000038.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000039.DLL -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000040.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000041.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000042.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000043.DLL -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000044.dll -> TrojanDownloader.Agent.bc : Cleaned with backup C:\System Volume Information\_restore{FF319846-426A-4559-9D40-F514DD992BF5}\RP2\A0000045.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
That is definitely the longest Ewido log I have ever seen. :rofl:

Step#1:Restore Deleted System Files

Now we need to see if we need to restore some deleted files:Please check for the following files using the Windows Search Engine:
  • control.exe
  • rundll32.exe
  • wmplayer.exe
  • msconfig.exe
  • notepad.exe
  • shell.dll
  • SDHelper.dll
If any are missing or not working properly then you can download new copies from
Merijn's Files and following the instructions at that site to have them where they belong for your OS.
  • If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in Win2K or XP. In XP there are two copies of this file, one in Windows (WINNT) and one in Windows\System32. It does not delete the one in Windows\System so it does not affect Win9x/ME. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows (WINNT) and Windows\System32 .
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
Step#2:Download CCleaner
Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Options < Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Click Run Cleaner to run the program.
  • After it has completed it's process, click Exit.
Caution : It is not recommended to use the 'Issues' tab as it is known to find legitimate items.



Step#3:Complete An Online AntiVirus Scan

Run an online antivirus scan at:

Trend Micro-Housecall Online AV

Reboot



Step#4:Find the Infected Files On Your Hard Drive
  • Navigate to C:\Windows
  • look for files that were created at the approximate time and date as the infection occurred.
  • look for those that end in exe, DAT and DLL and if found, right click on the file and check properties. Legitimate files should be copyrighted by Microsoft
  • if you determine they are bad files, right click on them and choose delete
  • Navigate to C:\Windows\System or C:\Windows\System32 (depending on the OS) and repeat each of the above steps to check for those ending in exe, DAT and/or DLL
  • if the above files will not delete, then make a new folder on your desktop by right clicking on the desktop and choosing New > Folder. Name the folder CWS Files.
  • Move the files from C:\Windows or C:\Windows\System or C:\Windows\system32
    to the new folder CWS Files.
Step#5:Scan And Post a New HijackThis Log

1. Scan again with HijackThis

2. POST your log file using Add Reply to see what is left to fix.
hi,
i did everything you said except when i ran the trend housecall (step 3) it found 166 infected files…. 95% were in my system restore & were troj_agent_gah.
it also had me install some java software.
(step 4) i have so many dat files in my windows directory it would take a long time to check the properties on them, well i wanted to show you my hijack this log first.

i also have some bogus & unchecked ???32 files (some without the 32, but i know they're bad) in my startup config utility (msconfig)

maybe i can't get rid of everything :(

Logfile of HijackThis v1.99.1
Scan saved at 4:22:49 PM, on 7/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Re-enable everything on the Startup tab in Msconfig and click apply. If it asks to reboot the computer, do not reboot the computer.
Scan with HijackThis and post another log as a reply to this thread. Those entries should now show in the new log. Same as before, do not reboot the computer until you here from me again.

I'll then give instructions on removing them.

Don't worry about the items in System Restore as we'll clean those out later.
hi alan,
you're the best.

Logfile of HijackThis v1.99.1
Scan saved at 5:07:00 PM, on 7/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button

Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button

Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program

Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [winza32.exe] C:\WINDOWS\system32\winza32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program

Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - HKLM\..\Run: [ShowBehind] C:\WINDOWS\sbnet\ShowBehind.exe
O4 - HKLM\..\Run: [ntkx.exe] C:\WINDOWS\system32\ntkx.exe
O4 - HKLM\..\Run: [mspv.exe] C:\WINDOWS\system32\mspv.exe
O4 - HKLM\..\Run: [msoi.exe] C:\WINDOWS\system32\msoi.exe
O4 - HKLM\..\Run: [mfcwo32.exe] C:\WINDOWS\mfcwo32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [d3zv32.exe] C:\WINDOWS\d3zv32.exe
O4 - HKLM\..\Run: [d3wu.exe] C:\WINDOWS\d3wu.exe
O4 - HKLM\..\Run: [d3co.exe] C:\WINDOWS\d3co.exe
O4 - HKLM\..\Run: [atlxl32.exe] C:\WINDOWS\system32\atlxl32.exe
O4 - HKLM\..\Run: [appzk.exe] C:\WINDOWS\system32\appzk.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator

5\DirectCD\DirectCD.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]

"C:\PROGRA~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Global Startup: SDDServerService.lnk = C:\Program

Files\Amada\SDDServerService\SddServerService.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office\OSA9.EXE
O4 - Global Startup: Compaq Wireless Configuration.lnk = C:\Program

Files\Compaq\Compaq 11 Mbps Wireless USB Adapter\configA.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP -

C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -

{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -

http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) -

http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program

Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. -

C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program

Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program

Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
Step 1
Open HijackThis, run a scan, then check the following:

O4 - HKLM\..\Run: [winza32.exe] C:\WINDOWS\system32\winza32.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TimeSink Ad Client] "C:\Program Files\TimeSink\AdGateway\TsAdBot.exe"
O4 - HKLM\..\Run: [ShowBehind] C:\WINDOWS\sbnet\ShowBehind.exe
O4 - HKLM\..\Run: [ntkx.exe] C:\WINDOWS\system32\ntkx.exe
O4 - HKLM\..\Run: [mspv.exe] C:\WINDOWS\system32\mspv.exe
O4 - HKLM\..\Run: [msoi.exe] C:\WINDOWS\system32\msoi.exe
O4 - HKLM\..\Run: [mfcwo32.exe] C:\WINDOWS\mfcwo32.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iexplore.exe] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKLM\..\Run: [d3zv32.exe] C:\WINDOWS\d3zv32.exe
O4 - HKLM\..\Run: [d3wu.exe] C:\WINDOWS\d3wu.exe
O4 - HKLM\..\Run: [d3co.exe] C:\WINDOWS\d3co.exe
O4 - HKLM\..\Run: [atlxl32.exe] C:\WINDOWS\system32\atlxl32.exe
O4 - HKLM\..\Run: [appzk.exe] C:\WINDOWS\system32\appzk.exe


Optional items to check with HijackThis for improved performance.
Resource hog that launches common MS Office components to help speed up the launch of Office programs. Some users claim there's no difference with or without it but it isn't required either way.
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


With all other programs and browsers closed, click fix checked.


Step 2
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 3
Please delete the following files/folders:

C:\Program Files\TimeSink << Whole Folder
C:\WINDOWS\sbnet << Whole Folder

These files may have already been removed earlier in the fix but double check to make sure.
C:\WINDOWS\system32\winza32.exe << File Only
C:\WINDOWS\system32\ntkx.exe << File Only
C:\WINDOWS\system32\mspv.exe << File Only
C:\WINDOWS\system32\msoi.exe << File Only
C:\WINDOWS\system32\atlxl32.exe << File Only
C:\WINDOWS\system32\appzk.exe << File Only
C:\WINDOWS\mfcwo32.exe << File Only
C:\WINDOWS\d3zv32.exe << File Only
C:\WINDOWS\d3wu.exe << File Only
C:\WINDOWS\d3co.exe << File Only

If you have any problem deleting these items, reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter') and try again.


Step 4
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread. Before replying, Open Notepad < Click Format and uncheck Word Wrap.
Please let us know of any complications you had and how the computer is behaving.
hi alan,
all the files you wanted me to delete were already gone….i did notice several 4 or 5 letter .exe files with 0 kb in the folder???

anyway, computer is a lot faster & i guess we have to uncheck a few things in the startup utility(msconfig)??? & hopefully we can get rid of some of the software we downloaded…unless you think i need all of them???

when all is done should i just stick with firefox???

here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 6:08:16 PM, on 7/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\POP-UP~1\PSFREE.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Compaq\EASYAC~1\EAUSBKBD.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Eraser\eraser.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Chameleon\app\cmonitor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Program Files\Compaq\Easy Access Button Support\eaclean.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\POP-UP~1\PSFREE.EXE"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - Startup: Chameleon Monitor.lnk = C:\Chameleon\app\cmonitor.exe
O4 - Global Startup: SDDServerService.lnk = C:\Program Files\Amada\SDDServerService\SddServerService.exe
O4 - Global Startup: Compaq Wireless Configuration.lnk = C:\Program Files\Compaq\Compaq 11 Mbps Wireless USB Adapter\configA.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.140/code/PWActiveXImgCtl.CAB
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI