This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Attacked again

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a severe crash, reinstalled windows XP, and inadvertently went around my router without any firewall, and I got nailed. I ran the ewido scan in safe mode and hijack this.

here is the Hijack this log


Logfile of HijackThis v1.99.1
Scan saved at 7:22:58 PM, on 9/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\dihd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\xsapt.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,jnhsecc.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Advanced DHTML Enable] C:\dihd.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1157128023796
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IpManager (IPtable) - Unknown owner - C:\WINDOWS\ipconfg32.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)
O23 - Service: Windows Update Manager (UpdateManager) - Unknown owner - C:\WINDOWS\update\updmgr.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

And the ewido log

ewido anti-spyware - Scan Report
———————————————————

+ Created at: 7:20:21 PM 9/1/2006

+ Scan result:



C:\Program Files\Common Files\{142460ED-0726-1033-0327-031104030001}\Update.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0009545.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010314.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011286.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011754.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011854.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012339.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0014824.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016114.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0023005.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025242.EXE -> Adware.Agent : Cleaned with backup (quarantined).
C:\WINDOWS\thiselt.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\Batty2\Batty2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Program Files\Batty2\Batty2.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\Program Files\CMFibula\CMFibula.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012739.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012742.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015203.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015206.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0023790.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0023798.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\WINDOWS\system32\BattyRun2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
C:\WINDOWS\TkI\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\Installer3.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010647.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010648.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011776.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011777.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\warebundlenewer.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010325.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010327.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011297.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011299.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011743.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011756.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011782.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011864.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016120.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025253.EXE -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\em.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010320.EXE -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011292.EXE -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011860.EXE -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014344.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016117.EXE -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025249.EXE -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Program Files\PSLister\PSLister.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012738.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015202.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0023789.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010641.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011722.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012187.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015968.EXE -> Adware.RK : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025022.EXE -> Adware.RK : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rk.exe -> Adware.RK : Cleaned with backup (quarantined).
C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010322.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011294.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011861.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012429.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0014906.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016118.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0023221.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025250.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\MirarSetup_876075.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011774.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011790.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010031.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010650.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011794.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014342.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011798.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011798.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011798.exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011799.dll -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011806.dll -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup (quarantined).
C:\Program Files\whInstall\WhSurvey.exe -> Adware.Webhancer : Cleaned with backup (quarantined).
C:\Program Files\whInstall\whAgent.inf -> Adware.Webhancer : Cleaned with backup (quarantined).
C:\Program Files\whInstall\whInstaller.ini -> Adware.Webhancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010316.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010321.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011288.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011293.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011755.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011809.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011810.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011811.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011812.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011856.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012759.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015221.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016115.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025244.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\WINDOWS\webhdll.dll_tobedeleted -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\WINDOWS\whCC-GIANT.exe/WhAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Adware.WinAD : Cleaned with backup (quarantined).
C:\Program Files\Netscape\Netscape\plugins\npzango.dll -> Adware.WinAD : Cleaned with backup (quarantined).
C:\Program Files\mozilla.org\Mozilla\plugins\npzango.dll -> Adware.WinAD : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010638.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010639.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011719.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011720.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013460.EXE -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016166.EXE -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\TIGEN001.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010636.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011717.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012186.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025021.EXE -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\WINDOWS\system32\winstk32.exe -> Backdoor.Rbot : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010042.exe -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010219.exe -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010244.exe -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011243.exe -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011911.EXE -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014364.exe -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0022642.EXE -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022854.EXE -> Backdoor.Rbot.aem : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0015809.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0024684.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025019.EXE -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\WINDOWS\system32\eraseme_84627.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lsvss.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010088.EXE -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010255.EXE/drxvp.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010285.EXE -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012207.EXE/drxvp.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012225.EXE -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014356.EXE/drxvp.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016129.EXE -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025293.EXE -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\abcd.exe/drxvp.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\winde.exe -> Downloader.Adload.ep : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011814.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013461.EXE -> Downloader.Agent.aqx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016167.EXE -> Downloader.Agent.aqx : Cleaned with backup (quarantined).
C:\topaff.exe -> Downloader.Agent.aqx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011778.dll -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010309.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010326.EXE -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010329.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011281.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011298.EXE -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011302.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011741.EXE -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011753.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011757.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011779.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011849.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011869.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016108.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016123.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025235.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025258.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\WINDOWS\srvaeoqycv.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\WINDOWS\srvwuudivn.exe -> Downloader.Dyfuca.ey : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010029.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022851.DLL -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\xsapt.exe.tmp -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[776] C:\WINDOWS\System32\nqjllfn.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011775.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0008221.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014343.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010087.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010290.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011788.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016136.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025335.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\drsmartload.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011785.exe -> Downloader.VB.alt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011786.exe -> Downloader.VB.alt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011787.exe -> Downloader.VB.alt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010051.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010248.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011247.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011868.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014367.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025257.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\WINDOWS\pxklixyA.exe -> Downloader.VB.alu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010289.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011301.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011742.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011867.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016122.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025256.EXE -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\WINDOWS\offun.exe -> Downloader.VB.nw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0008098.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010041.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010043.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010044.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010243.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010245.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010247.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010263.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011242.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011244.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011246.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011723.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011910.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011912.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011913.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0012188.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014363.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014365.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014366.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0022641.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0022643.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0022644.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022855.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022858.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022859.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025023.EXE -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lqxncr.exe -> Dropper.Paradrop.a : Cleaned with backup (quarantined).
C:\SS1001newer.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010323.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010645.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011295.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011764.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011862.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0014171.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016119.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016843.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025251.EXE -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\WINDOWS\ss1205.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService.NT AUTHORITY.002\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010305.EXE -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011277.EXE -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011845.EXE -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013447.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016105.EXE -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016163.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025231.EXE -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025346.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\WINDOWS\v1201.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Program Files\Uninstall Information\pohyfefe.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\WinZip\rykeho.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011866.EXE -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025255.EXE -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\WINDOWS\pxklixy.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010651.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011784.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
D:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.fix.exe -> Proxy.Delf.aj : Cleaned with backup (quarantined).
D:\downloads\Civilization4.fix.exe -> Proxy.Delf.aj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011780.sys -> Rootkit.Agent.l : Cleaned with backup (quarantined).
:mozilla.102:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:D:\Documents and Settings\Neil\Application Data\Mozilla\Profiles\default\mipamn38.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Neil\Application Data\Phoenix\Profiles\default\nwfmi6j6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:D:\Documents and Settings\Neil\Application Data\Phoenix\Profiles\default\nwfmi6j6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Neil\Application Data\Phoenix\Profiles\default\nwfmi6j6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:D:\Documents and Settings\Neil\Application Data\Phoenix\Profiles\default\nwfmi6j6.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bourque\Cookies\bourque@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00028642.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00028744.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00028745.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00028762.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029245.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029421.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029531.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029532.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029533.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029534.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029536.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029537.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029538.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029539.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029540.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029541.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029542.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029543.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.100:C:\Recycled\NPROTECT\00029544.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028491.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028514.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028744.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028745.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028754.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028756.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028757.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028758.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028759.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00028761.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029231.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029244.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029421.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029422.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029423.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029424.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029450.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029471.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029531.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029532.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029533.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029534.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029536.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029537.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029538.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029539.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029540.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029541.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029542.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029543.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.101:C:\Recycled\NPROTECT\00029544.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00028514.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00028515.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00028743.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029223.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029224.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029225.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029226.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029227.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029228.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029422.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029423.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029424.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029450.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029471.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029531.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029532.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029533.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029534.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029536.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029537.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029538.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029539.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029540.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029541.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029542.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029543.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029544.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.102:C:\Recycled\NPROTECT\00029546.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00028514.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00028515.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029223.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029224.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029225.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029226.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029227.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029228.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029422.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029423.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029424.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029450.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029545.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.103:C:\Recycled\NPROTECT\00029546.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.104:C:\Recycled\NPROTECT\00028343.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.104:C:\Recycled\NPROTECT\00028514.MOZ -> TrackingCookie.Adbrite : Cleaned.
:mozilla.104:C:\Recycled\NPROTECT\00028515.MOZ -> TrackingCookie.Adbrite : Cleaned.


Thanks
1) Create a folder in the root of your C: drive and name it Blacklight.
A brief explanation of how to do this can be found here.

2) Download F-Secure's BlackLight from here and save it into this folder.

3) Log off from the internet and disconnect your modem cable.

4) Go to Start > Run, copy and paste the following into the text box and hit OK:
"C:\Blacklight\blbeta.exe" /expert

The F-Secure Blacklight Beta window should open.
  • Accept the agreement and click OK.
  • Click the Scan button to begin.
  • Leave the PC idle while the scan takes place.
  • When it has completed, click the Close button.
  • A text file, fsbl-date/time, will be saved in the Blacklight folder, copy and paste this into your next post.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

1) Download rootkitrevealer.zip from here and save it to your Desktop.
You will need to extract the file(s) from the zipped folder.

To do this: Right-click on the zipped folder and from the menu that appears, click on Extract All…
In the Extraction Wizard window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see the contents of the rootkitrevealer folder.

2) Log off from the internet and disconnect your modem cable.

3) Exit all applications and keep the system otherwise idle during the RootkitRevealer scanning process.

4) Double click RootkitRevealer.exe and click the Scan button to run it.
When the scan has completed, click on File > Save… and then click on the Save button.
The report will be saved as RootkitReveal.txt in the C:\Windows\System 32 folder - copy and paste it into your next reply.
I had to reinstall Windows XP as things got real bad and an antivirus software got all screwed up and I couldn't do anything on the computer. Everything is good for now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI