This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please tell me where I'm getting this virus from

58 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok I've scanned a dozen times and I've picked up a virus from somewhere that I can't get rid of. Can somebody please review my log and tell me where it is so I can kill it finally?


Logfile of HijackThis v1.99.1
Scan saved at 11:47:29 PM, on 1/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\PopUp Killer\popupkiller.EXE
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Administrator.COM1\My Documents\Highjack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [PopUpKiller] C:\Program Files\PopUp Killer\popupkiller.EXE
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.audatex.us
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169184049226
O17 - HKLM\System\CCS\Services\Tcpip\..\{E50FE16E-A027-484C-B971-865AC2D67486}: NameServer = 85.255.114.42,85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.42 85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.42 85.255.112.20
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe


Thank you for checking this out for me.
Hello Flash Gordon and Welcome to TomCoyote,


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

At the end of the fix, you may need to restart your computer again.


Now lets check some settings on your system.

In the windows control panel. If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections. Then right click on your default connection, usually local area connection for cable and dsl, and left click on properties. Click the Networking tab. Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
Press OK twice to get out of the properties screen and reboot if it asks.
That option might not be avaiable on some systems
Next Go start run type cmd and hit OK
type
ipconfig /flushdns
then hit enter, type exit hit enter
(that space between g and / is needed)


Disable AdWatch:
Please disable AdWatch, as it may hinder the removal of some entries. You can re-enable it after you're clean.To disable AdWatch:
  • Open AdAware SE.
  • Go to AdWatch User Interface .
  • Go to Tools and Preferences.At the bottom of the screen you will see 2 options Active and Automatic.
  • Active : This will turn Ad-Watch On\Off without closing it
  • Automatic : Suspicious activity will be blocked automatically
  • Uncheck both options. You can enable these after resolving your problem.
After all of the fixes are complete it is very important that you enable AdWatch again.

Updating Java
  • Download the latest version of Java Runtime Environment (JRE) 6.0.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

Scan with HijackThis. Place a check against each of the following:
O17 - HKLM\System\CCS\Services\Tcpip\..\{E50FE16E-A027-484C-B971-865AC2D67486}: NameServer = 85.255.114.42,85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.42 85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.42 85.255.112.20

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt
Here's the logs:


Fixwareout
Last edited 1/14/2006
Post this report in the forums please
…
Prerun check
»»»»» HKLM run and Winlogon System values
C:\WINDOWS\system32\csgtn.exe will be moved to C:\WINDOWS\temp\csgtn.ren at reboot.
»»»»» System restarted
…
Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion "pid"
…
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Searching by size/names…

»»»»»
Search five digit cs, dm kd and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\DMGXE.EXE 44,089 2001-08-23

Other suspects.

»»»»» Misc files.

»»»»» Checking for older varients covered by the Rem3 tool.

»»»»» Postrun check
»»»»» HKLM run
»»»»» Winlogon System value
"system"=""
»»»»»


Logfile of HijackThis v1.99.1
Scan saved at 8:44:27 AM, on 1/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Administrator.COM1\My Documents\Highjack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [PopUpKiller] C:\Program Files\PopUp Killer\popupkiller.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.audatex.us
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169184049226
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

I have noticed that it is running faster than before. Thanks again.
Glad your computer is running faster! I do not see an anti-virus application installed. Let's do a scan please.

Please set your system to show all files; please see here if you're unsure how to do this.

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit.
  • Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________
Let's get rid of that bad file first before the scan
Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\SYSTEM32\DMGXE.EXE<=file
Exit Explorer. Empty your recycle bin.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Please post:
  • AVG Anti-spyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Here are the results of the AVG scan. I'm unsure why I needed to quarantine the files rather than delete them. And I've noticed that the system has slowed down considerably again. Unsure as to what is causing it. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 12:46:27 PM 1/21/2007 + Scan result: C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP310\A0016175.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP315\A0017175.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP325\A0017196.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP347\A0018196.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP348\A0019196.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP349\A0020196.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP360\A0021196.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP361\A0021210.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP361\A0021219.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP363\A0021284.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP378\A0021975.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP378\A0022345.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP379\A0022396.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP379\A0022408.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP381\A0025697.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP382\A0025750.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP383\A0026173.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP383\A0026195.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP385\A0026431.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP387\A0026620.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026648.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0027655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0028655.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0029656.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0029680.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\WINDOWS\Temp\csgtn.ren -> Downloader.Agent.uj : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-18\Dc1.IE5\OT2VSP2J\iex[1].exe -> Downloader.VB.vj : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-18\Dc39.tmp -> Downloader.VB.vj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026637.exe -> Hijacker.Small.kg : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator.COMPUTER1\order_smey.exe -> Logger.Small.ex : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\country[1].htm -> Logger.Small.ex : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0029993.exe -> Trojan.DNSChanger.cv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026629.exe -> Trojan.Puper.bx : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\teller2[1].htm -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1010.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1039.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld104D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1078.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld10C4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld114F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld117.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1194.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld11C0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld124B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1272.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1289.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld12C2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld13D8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld13EE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld13FB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld141C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld145C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1465.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld147F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld14CE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1521.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1592.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld15ED.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld15FB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld164C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld16C4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld16F1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1729.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1741.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1760.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1773.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1887.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld188E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1896.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1897.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld189B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld18CE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld18F2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld190E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld193A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1AF7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1B23.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1B3A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1B87.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1B8C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1B8D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1CC9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1CD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1CF6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1D84.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1E2E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1E36.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1E3B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1E63.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1EAC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1EF3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1F1A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1FA8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld1FC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld201.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld203C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2060.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2065.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld20A0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld20F5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld215C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld215F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld21A1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld21E3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld21EE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld21FD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld223B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2261.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld22F6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld22FB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2332.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld237C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld23AD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld23B1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld243E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2496.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld24D2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2526.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2536.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2546.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld256D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2606.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2614.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2628.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld26A7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld27B4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld27C2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld281F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld284A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2869.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld289B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld28B3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld28D6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld29BF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld29FA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A1D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A43.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A44.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A84.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A8A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2A97.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2AA7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2B0A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2BAA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2BE3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2C3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2C99.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2CA4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2CF3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2DD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2E09.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2E0D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2E1C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2E1E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2E96.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2F13.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2F44.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2F9B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2FE4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld2FFC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3002.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3059.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld30A0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld314.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld316A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld31A2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld31FE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld32F2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld32F5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3359.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3373.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld337A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld337B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld349F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld34A8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld34E4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld34E8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3525.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3546.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld357F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld35C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld35C1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld35FA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld363E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld367F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld36A1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld36CC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld371D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3741.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3758.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld380C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3886.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3917.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld391A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld392E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3931.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3957.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld397E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld39C0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3A11.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3A3D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3A56.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3AB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3B54.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3BB2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3BBF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3BCF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3C19.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3C37.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3C41.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3C5E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3C9B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3D3F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3D79.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3E8C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3EA6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3EE6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3EEF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3F12.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3F36.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3FA2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld3FF1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld40A3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld40EC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld413.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4131.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4150.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld41B3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld41B8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld41EF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4256.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld425C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4282.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld42CA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4348.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld437C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld43C5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld440E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4433.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4458.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4468.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld446B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld44B3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld44B6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4579.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld458.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld45C2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld45ED.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld46BB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4770.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4814.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld482B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4832.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld485.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4880.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld48C9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld49AE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld49C6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld49D1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4A1E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4A23.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4A60.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4A86.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4AC7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4AEA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4B8D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4B91.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4CC8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D2E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D45.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D4A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D65.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D85.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D86.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4D8F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4DCC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4DD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4E4E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4E51.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4E7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4EB5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4EEF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4F20.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4FDE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld4FEF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5021.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5084.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld50AB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld50CB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5113.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld515D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld519.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld521A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5268.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld52EB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5365.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld538E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld53F1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5409.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld540F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5430.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5451.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld549A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld54E2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5511.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld554B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld554E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5580.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5590.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5598.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5600.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5681.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5708.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5728.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld577C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld578C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld57FE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld588F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld58B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld58C6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5989.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld598A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld59CA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5A5F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5A94.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5AB7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5AEE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5AF0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5AF9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5B29.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5B67.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5BEC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5C12.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5C3D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5C96.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5CC8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5D4B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5E5E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5EFA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5F42.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5F49.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5FC4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld5FE6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld602E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6057.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6060.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld60E7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld610.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6126.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6146.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6187.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld618D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld61DC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6232.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld624E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld629.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6294.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6299.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld62CC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6313.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6323.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6386.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld63D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld64F4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6540.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld656B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld65A4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld65C2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld65C5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld65D5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6602.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld661A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6662.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6663.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6677.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6689.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld66F6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6786.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld67A8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld67BF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld67E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld689D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld68A4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld68C4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld68E5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6926.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6AD6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6B5E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6B60.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6B83.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6B8B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6BC5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6BD4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6BF7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6C61.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6C76.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6CCD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6D1B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6D4A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6D52.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6D90.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6DC8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6DD1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6DD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6E16.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6E54.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6E7C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6E98.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6EF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld6F67.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld70CE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld70DF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld70F3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld70FE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld713E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7166.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld718.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7197.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld71F0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7266.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld726E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld729E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld72A6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld72C2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld733F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7357.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld738.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld73F4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld741F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld74F8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld751D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld766D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7693.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld76A7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld76AB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld771B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7722.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld776A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld776B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7771.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld779.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7797.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld77A2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7818.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld78AA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld78D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld78FC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld79.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7955.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld79A6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld79AD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld79C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld79CC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7A0D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7A2F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7A31.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7A79.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7C05.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7C6B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7C76.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7CAB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7CC3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7CC6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7D69.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7DA7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7DC8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7DEC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7E51.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7E6B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7E9F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7EA2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7EFA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7F34.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7F4D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7F9B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7FCF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7FE1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld7FF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8011.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld804A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld81D6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8207.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8233.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8266.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld827.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld82A8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld82CC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld82DB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld82E8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld82F9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8330.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld83AF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld83E4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8413.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8433.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8457.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld84E3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld852C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld856A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld860E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld864E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld866E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld870.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld871B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld877D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld879C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld87D3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8899.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld88B1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld88B3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld88D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld892E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8940.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld896B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld89E8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8A26.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8A5E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8A70.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8AAD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8B43.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8B83.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8BC6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8CC2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8D3C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8D54.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8DAD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8DCB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8DD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8E21.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8E54.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8EDF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8EF2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8F2C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8F79.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld8FAA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9003.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9056.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\
C:\WINDOWS\system32\1024\ld905C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld906B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld907C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9092.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9122.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9178.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld91A5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld91B5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld91D6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld91DF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9250.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld92FE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9310.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld93A5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld93DD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9439.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld943D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld947D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld94A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld94FA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld950B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld953B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld959A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld95BE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld960B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9654.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9698.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9746.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld979A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld97BE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld97E3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld97E5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9870.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld98DC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld98E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9926.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld993.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9951.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld99A2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld99E9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A1C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A38.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A4F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A56.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A58.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9A5C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9B7D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9BA7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9BC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9C13.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9C33.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9CAA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9D3C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9D4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9D57.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9D82.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9DB3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9DCB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9DE7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9E77.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9E7C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9EE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9EED.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9F1E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9F46.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9F8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ld9FB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA017.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA035.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA045.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA082.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA0E5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA11.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA1B4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA1D2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA1E4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA24A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA276.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA2CD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA2FE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA355.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA378.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA3FD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA407.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA456.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA4BD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA50C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA525.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA546.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA5F3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA622.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA64.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA653.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA6A1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA714.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA75D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA75E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA82E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA84E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8AC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8B8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8EC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8EE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8F6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA8F9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA90A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA93A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA99.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA99D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldA9A8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAA4E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAAE2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAB19.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAB6E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAB94.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldABA3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldABAF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldABB1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldACB4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldACDD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAD0E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAD6B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAE8E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAEBB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAED8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF18.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF42.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF48.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF62.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF80.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAF85.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldAFB7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB04F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB094.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB108.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB14F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB160.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB1C8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB1CA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB1D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB1EE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB26F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB327.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB353.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB379.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB388.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB3A2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB443.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB474.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB490.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB516.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB525.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB57E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB594.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB596.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB634.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB6BA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB72B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB7E9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB807.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB817.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB828.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB92.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB9A4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB9B6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldB9E4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBA21.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBA5C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBA92.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBAAF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBAB0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBAD0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBB04.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBB19.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBB48.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBB67.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBBCE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBC22.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBC7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBCCB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBCF7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBCFA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBD18.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBD5F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBD9A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBE06.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBE73.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBEF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBF35.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBF97.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBFC2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldBFE3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC000.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC02C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC07E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC0AE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC0BE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC0D7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC0E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC0EB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC12D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC220.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC23D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC27E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC2B5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC2F0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC340.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC366.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC3A6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC3D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC46C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC4AF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC4E0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC564.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC5AD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC64C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC687.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC68C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC69B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC6A6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC6BE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC70E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC71A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC734.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC73D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC821.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC871.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC918.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC931.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC945.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC97F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldC9DE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCACC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCB35.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCB4B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCB5A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCB5C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCBF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC12.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC15.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC2C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC3F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC46.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCC7F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCCC8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCCED.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCCF9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCD27.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCDD4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCE8C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCED1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCF7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCFCB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldCFE9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD05D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD0DD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD0EC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD13.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD140.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD145.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD158.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD184.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD185.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD1D6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD213.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD22E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD23A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD253.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD2E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD338.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD375.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD408.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD443.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD481.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD4AF.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD4CC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD575.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD594.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD5DE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD645.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD68C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD6D5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD794.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7A9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7CE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7D7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7E1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7F2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD7F5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD80E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD832.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD850.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD944.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldD999.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDA4F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDACA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDAF5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDB15.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDBA0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDBAD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDBE9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDC54.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDC65.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDCB0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDCD7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD0A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD1B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD1F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD29.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDD7F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDDD2.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDE0B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDE15.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDE1E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDE8E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDEAD.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDF0A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDF95.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDFC1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldDFDA.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE019.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE117.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE151.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE175.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE205.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE268.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE2AC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE2C9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE2CE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE34D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE389.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE3D0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE42D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE446.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE451.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE47D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE4DB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE4FB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE50D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE5A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE6B3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE706.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE777.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE78D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE795.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE7BB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE7C0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE7DE.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE7E9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE916.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE92A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE935.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE948.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldE98B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEA0C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEA44.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEA7B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEA8E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEB4E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEB58.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEC1A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEC1E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEC41.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEC6A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldECB3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldED.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldED70.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEE12.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEE17.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEE47.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEEA7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEF09.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEF46.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEF6A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEF8B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEF8F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEFC7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldEFE5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF004.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF00E.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF032.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF0F3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF0F9.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF1DC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF225.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF25.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF283.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF2AC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF2C7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF33.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF37B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF380.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF3BB.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF3C4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF3F5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF410.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF507.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF512.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF536.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF556.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF58.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF583.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF5D.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF5E7.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF60.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF616.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF61A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF660.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF665.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF6C8.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF75C.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF7B1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF841.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF87B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF88A.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF88B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF8C5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF911.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldF924.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFA78.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFAA0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFAF1.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFB17.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFB34.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFBB6.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFBC5.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFC3F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFCE3.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFD51.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFD73.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFDBC.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFE0B.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFE20.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFE25.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFE78.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFEA4.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFF1F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFF2F.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\WINDOWS\system32\1024\ldFFB0.tmp -> Trojan.Small : Cleaned with backup (quarantined). C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026638.exe -> Trojan.Small.gq : Cleaned with backup (quarantined). ::Report end
Adding the highjack this log:

Logfile of HijackThis v1.99.1
Scan saved at 1:04:59 PM, on 1/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Administrator.COM1\My Documents\Highjack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.audatex.us
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169184049226
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I'm unsure why I needed to quarantine the files rather than delete them.

I think it is a precaution. In the past there were false positives therefore if file was just quarantined, one could get it back.

Let's run another scan please. Since I did not see anti-virus present, I would like to see Kapersky scan. Sometimes Kapersky will pick something up that AVG did not.

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.

AVG anti-spyware is a complement to an anti-virus application. You need to have an anti-virus application. Please see this link for a listing of some online & their stand-alone antivirus programs:
Virus, Spyware, and Malware Protection and Removal Resources It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Copy and paste that information from Kapersky in your next post.

Please post(reply) with the Kapersky log and the hijackthis log.
Ok I've been scanning for three days straight now. Hopefully this will be the end of it. Here's the Kaspersky scan results: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Sunday, January 21, 2007 7:01:17 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 21/01/2007 Kaspersky Anti-Virus database records: 246045 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ Scan Statistics: Total number of scanned objects: 133535 Number of viruses found: 41 Number of infected objects: 78 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:51:14 Infected Object Name / Virus Name / Last Action C:\777.htm Infected: Trojan.HTML.Starter.a skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\!update-3195[1].0000.bac_a01596 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\!update.exe.bac_a01596 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021327.exe.bac_a01596 Infected: Trojan-Clicker.Win32.VB.kc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021328.exe.bac_a01596 Infected: Trojan.Win32.StartPage.ahg skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021329.exe.bac_a01596 Infected: not-virus:Hoax.Win32.Renos.dv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021338.dll.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jo skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021339.exe.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jl skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021340.dll.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jo skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022364.exe.bac_a03680 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022365.EXE.bac_a03680 Infected: Trojan-Downloader.Win32.Small.caf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022366.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022367.exe.bac_a03680 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022369.exe.bac_a03680 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022370.exe.bac_a03680 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022371.exe.bac_a03680 Infected: Trojan-Dropper.Win32.Agent.agm skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022372.exe.bac_a03680 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022373.exe.bac_a03680 Infected: Trojan-Proxy.Win32.Procin.e skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022374.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Zlob.mv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022375.dll.bac_a03680 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022376.dll.bac_a03680 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022377.exe.bac_a03680 Infected: Backdoor.Win32.VB.apc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022378.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Adload.m skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022379.exe.bac_a03680 Infected: Backdoor.Win32.VB.agz skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ase4[1].exe.bac_a01596 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc38.tmp.bac_a01596 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc40.tmp.bac_a01596 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc41.tmp.bac_a01596 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\drsmartload[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\favset.exe.bac_a03680 Infected: Trojan-Clicker.Win32.Small.kg skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\howiper.exe.bac_a03680 Infected: Trojan.Win32.Small.hl skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ieschedule[1].exe.bac_a01596 Infected: Backdoor.Win32.VB.agz skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ieserver[1].exe.bac_a01596 Infected: Backdoor.Win32.VB.apc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\loaderadv655[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.m skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\paytime[1].txt.bac_a01596 Infected: Trojan.Win32.StartPage.agp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\regperf.exe.bac_a01596 Infected: Trojan-Downloader.Win32.Zlob.mv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\sdb[1].exe.bac_a01596 Infected: Trojan-Dropper.Win32.Agent.agm skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\seven.exe.bac_a03680 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\sploitadv655[1].anr.bac_a01596 Infected: Trojan-Downloader.Win32.Ani.c skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\SVCHST.EXE.bac_a01596 Infected: Trojan-Downloader.Win32.Small.caf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool1[1].txt.bac_a01596 Infected: Trojan.Win32.Pakes skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool3[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool4[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool5[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\toolbar[1].txt.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\uart[1].exe.bac_a01596 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\vbsys2.dll.bac_a01596 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\web[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\winlogon[1].exe.bac_a01596 Infected: Trojan-Proxy.Win32.Procin.e skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xoce[1].ani.bac_a01596 Infected: Trojan-Downloader.Win32.Ani.b skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xpladv655[1].wmf.bac_a01596 Infected: Trojan-Downloader.Win32.Agent.acd skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xpupdate.exe.bac_a01596 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\{19A5172D-E363-491E-A6DA-B0A0ECE316C1}.exe.bac_a03680 Infected: Trojan.Win32.Qhost.hf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\{AB267156-2F92-470E-B476-9EB0B1DAE892}.exe.bac_a03680 Infected: Trojan.Win32.Puper.bx skipped C:\Documents and Settings\Administrator.COM1\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\History\History.IE5\MSHist012007012120070122\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temp\~DF1092.tmp Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temp\~DF10A5.tmp Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Administrator.COM1\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_Compress_20051216_101101_1_1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_PC_CHK.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\Progress_log_Compress.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrDbgOut.INI Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINST.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINSTL.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped C:\Program Files\eori\sura.exe Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\DH9013[1].exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\DH9013[1].exe NSIS: infected - 1 skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\ie0601[1].htm Infected: Trojan-Downloader.HTML.Agent.ao skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\index[6].htm Infected: Exploit.HTML.Agent.c skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\0HEZOTUF\adv655[1].htm Infected: Exploit.HTML.ObjData skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\0HEZOTUF\secure32[1].htm Infected: not-virus:Hoax.Win32.Renos.ax skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\KTUNGHUN\prompt[1].htm Infected: Trojan-Downloader.JS.IstBar.j skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP310\A0016180.exe Infected: Trojan.Win32.DNSChanger.dq skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026630.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0029995.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030074.exe Infected: Trojan.Win32.DNSChanger.dq skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030086.exe Infected: Trojan-Spy.Win32.Small.ex skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030087.exe Infected: Trojan.Win32.VB.agz skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030120.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\ZLT06d7f.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT06d82.TMP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
And the latest highjack this log:

Logfile of HijackThis v1.99.1
Scan saved at 7:07:01 PM, on 1/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator.COM1\My Documents\Highjack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.audatex.us
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169184049226
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111…all/xscan53.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Also I've noticed that it's still running really slow, like something is running in the background hogging up all of the memory. Any ideas?
Hi Flash Gordon,

You had numerous infected files on your system. You need an anti-virus application installed. AVG Anti-spyware is probably slowing your system down some since you did not appear to have any anti-virus application installed. I am glad you have a firewall application! An anti-virus will slow your system down but that is better than the results of not having anti-virus applications installed.

Please delete these files
C:\Program Files\eori\sura.exe<=file
C:\777.htm<=file
Empty your recycle bin!


Free Anti-virus applications for Home Users
http://www.grisoft.com/doc/40/lng/ww
http://www.avast.com/eng/avast_4_home.html

I hope you have patience. You can see other logs and know that some take more time than others to fix. I like to see a clean scan (omitting the _restore files being infected which we fix at the end). Please run Kapersky again.

STEP 1.
======
GMER
Please create a new subfolder in the Program Files folder called GMER. If you have an older version of GMER installed, you must delete it.
  • Download GMER and extract it to the C:\program files\GMER folder.
  • Please rename the GMER file
    Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.
    Run the Gmer.exe renamed program by double-clicking the executable file (gmer.exe) in Windows Explorer.
    You may be prompted to scan immediately if GMER detects rootkit activity.
  • If you are prompted to scan your system click "yes" to begin the scan.
  • If you are not prompted, Click the "Rootkit" tab, then click "Scan".
DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your next reply.

Please post (reply) with the results from Kapersky, the GMER scan, and a fresh hijackthis log.
Here's the new kaspersky scan: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, January 22, 2007 6:55:42 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 22/01/2007 Kaspersky Anti-Virus database records: 246086 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ Scan Statistics: Total number of scanned objects: 132888 Number of viruses found: 38 Number of infected objects: 75 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:54:17 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\!update-3195[1].0000.bac_a01596 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\!update.exe.bac_a01596 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021327.exe.bac_a01596 Infected: Trojan-Clicker.Win32.VB.kc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021328.exe.bac_a01596 Infected: Trojan.Win32.StartPage.ahg skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021329.exe.bac_a01596 Infected: not-virus:Hoax.Win32.Renos.dv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021338.dll.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jo skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021339.exe.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jl skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0021340.dll.bac_a01596 Infected: Trojan-Spy.Win32.Agent.jo skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022364.exe.bac_a03680 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022365.EXE.bac_a03680 Infected: Trojan-Downloader.Win32.Small.caf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022366.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022367.exe.bac_a03680 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022369.exe.bac_a03680 Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022370.exe.bac_a03680 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022371.exe.bac_a03680 Infected: Trojan-Dropper.Win32.Agent.agm skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022372.exe.bac_a03680 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022373.exe.bac_a03680 Infected: Trojan-Proxy.Win32.Procin.e skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022374.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Zlob.mv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022375.dll.bac_a03680 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022376.dll.bac_a03680 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022377.exe.bac_a03680 Infected: Backdoor.Win32.VB.apc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022378.exe.bac_a03680 Infected: Trojan-Downloader.Win32.Adload.m skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\A0022379.exe.bac_a03680 Infected: Backdoor.Win32.VB.agz skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ase4[1].exe.bac_a01596 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc38.tmp.bac_a01596 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc40.tmp.bac_a01596 Infected: Trojan-PSW.Win32.Agent.es skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\Dc41.tmp.bac_a01596 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\drsmartload[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\favset.exe.bac_a03680 Infected: Trojan-Clicker.Win32.Small.kg skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\howiper.exe.bac_a03680 Infected: Trojan.Win32.Small.hl skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ieschedule[1].exe.bac_a01596 Infected: Backdoor.Win32.VB.agz skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\ieserver[1].exe.bac_a01596 Infected: Backdoor.Win32.VB.apc skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\loaderadv655[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.m skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\paytime[1].txt.bac_a01596 Infected: Trojan.Win32.StartPage.agp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\regperf.exe.bac_a01596 Infected: Trojan-Downloader.Win32.Zlob.mv skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\sdb[1].exe.bac_a01596 Infected: Trojan-Dropper.Win32.Agent.agm skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\seven.exe.bac_a03680 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\sploitadv655[1].anr.bac_a01596 Infected: Trojan-Downloader.Win32.Ani.c skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\SVCHST.EXE.bac_a01596 Infected: Trojan-Downloader.Win32.Small.caf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool1[1].txt.bac_a01596 Infected: Trojan.Win32.Pakes skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool3[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool4[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\tool5[1].txt.bac_a01596 Infected: Trojan.Win32.Zapchast.cp skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\toolbar[1].txt.bac_a01596 Infected: Trojan-Downloader.Win32.Adload.j skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\uart[1].exe.bac_a01596 Infected: Trojan-PSW.Win32.Nilage.pa skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\vbsys2.dll.bac_a01596 Infected: Trojan-Clicker.Win32.Agent.ac skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\web[1].exe.bac_a01596 Infected: Trojan-Downloader.Win32.CWS.s skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\winlogon[1].exe.bac_a01596 Infected: Trojan-Proxy.Win32.Procin.e skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xoce[1].ani.bac_a01596 Infected: Trojan-Downloader.Win32.Ani.b skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xpladv655[1].wmf.bac_a01596 Infected: Trojan-Downloader.Win32.Agent.acd skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\xpupdate.exe.bac_a01596 Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\{19A5172D-E363-491E-A6DA-B0A0ECE316C1}.exe.bac_a03680 Infected: Trojan.Win32.Qhost.hf skipped C:\Documents and Settings\Administrator.COM1\.housecall6.6\Quarantine\{AB267156-2F92-470E-B476-9EB0B1DAE892}.exe.bac_a03680 Infected: Trojan.Win32.Puper.bx skipped C:\Documents and Settings\Administrator.COM1\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\History\History.IE5\MSHist012007012120070122\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temp\~DFE38A.tmp Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temp\~DFE39D.tmp Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator.COM1\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Administrator.COM1\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator.COM1\UserData\index.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_Compress_20051216_101101_1_1 Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_PC_CHK.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrCollectDir\Progress_log_Compress.txt Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrDbgOut.INI Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINST.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Brother\BrLog\BrtINSTL.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService.NT AUTHORITY.000\ntuser.dat.LOG Object is locked skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\DH9013[1].exe/data0002 Infected: Trojan-Clicker.Win32.Small.jf skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\DH9013[1].exe NSIS: infected - 1 skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\ie0601[1].htm Infected: Trojan-Downloader.HTML.Agent.ao skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\056Z4PEN\index[6].htm Infected: Exploit.HTML.Agent.c skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\0HEZOTUF\adv655[1].htm Infected: Exploit.HTML.ObjData skipped C:\RECYCLER\S-1-5-18\Dc1.IE5\0HEZOTUF\secure32[1].htm Infected: not-virus:Hoax.Win32.Renos.ax skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[1].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[2].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm/1.htm Infected: Exploit.HTML.CodeBaseExec skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm/frame.exe Infected: Trojan-Downloader.Win32.Agent.ho skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\9S47TLS9\ddfs[3].chm CHM: infected - 2 skipped C:\RECYCLER\S-1-5-18\Dc54.IE5\KTUNGHUN\prompt[1].htm Infected: Trojan-Downloader.JS.IstBar.j skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP310\A0016180.exe Infected: Trojan.Win32.DNSChanger.dq skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP388\A0026630.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0029995.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030074.exe Infected: Trojan.Win32.DNSChanger.dq skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP391\A0030120.exe Infected: not-virus:Hoax.Win32.Renos.gs skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP392\A0030212.exe Infected: Trojan-Downloader.Win32.PurityScan.be skipped C:\System Volume Information\_restore{8C53F380-5487-4AF0-A543-F2D2E581BD21}\RP392\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{046328E0-0083-491A-B9F9-6C4AFCC85E06}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\ZLT02c6c.TMP Object is locked skipped C:\WINDOWS\Temp\ZLT02c6f.TMP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
And the GMER scan results:

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2007-01-21 23:21:45
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ E0, 61, 3F, F0, 70, C4, 3F, … ]
.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ E0, 61, 3F, F0, 70, C4, 3F, … ]

—- User code sections - GMER 1.0.12 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!DialogBoxParamW 77D5662C 5 Bytes JMP 7E1F5415 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!DialogBoxIndirectParamW 77D62043 5 Bytes JMP 7E38C510 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!MessageBoxIndirectA 77D6A05A 5 Bytes JMP 7E38C491 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!DialogBoxParamA 77D6B11C 5 Bytes JMP 7E38C4D5 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!MessageBoxExW 77D80538 5 Bytes JMP 7E38C3D9 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!MessageBoxExA 77D8055C 5 Bytes JMP 7E38C413 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!DialogBoxIndirectParamA 77D86CAD 5 Bytes JMP 7E38C54B C:\WINDOWS\system32\IEFRAME.dll
.text C:\Program Files\Internet Explorer\iexplore.exe[528] USER32.dll!MessageBoxIndirectW 77D96093 5 Bytes JMP 7E38C44D C:\WINDOWS\system32\IEFRAME.dll

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F0407880] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F0407880] vsdatant.sys

—- Files - GMER 1.0.12 —-

ADS C:\Program Files\Yahoo! Games\Mah Jong Medley\MahJong2.exe:{72A87303-9E5B-8FF9-D4EF-73712D06C510}

—- EOF - GMER 1.0.12 —-


And the lastest highjack this log:

Logfile of HijackThis v1.99.1
Scan saved at 7:04:31 AM, on 1/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator.COM1\My Documents\Highjack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: http://*.audatex.us
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169184049226
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111…all/xscan53.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I was looking over my highjack this log and was wondering what these two were: O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) Do I need them or can I dump them? I was wondering since the files were missing.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI