This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Hjt And Combofix Log. Please....

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:35:23 PM, on 9/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\windows\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\hkcmd.exe
C:\windows\GWMDMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\windows\system32\wuauclt.exe
C:\windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\Scanner.exe.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: - {31ACD32A-8020-4562-8653-C8547B929802} - C:\windows\lbbho.dll
O2 - BHO: (no name) - {34FC3928-B64B-7EB5-D726-655508F1794F} - C:\windows\system32\mrb.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\windows\GWMDMpi.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PhilipsDM] "C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
O14 - IERESET.INF: MS_START_PAGE_URL=http://www.google.com
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O23 - Service: Aluria Spyware Eliminator Service (ASEService) - Unknown owner - C:\PROGRA~1\ALURIA~1\ASE\ASEserv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 5873 bytes


ComboFix 07-09-17.2 - "MedX" 2007-09-17 18:18:22.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.278 [GMT -6:00]
.

((((((((((((((((((((((((( Files Created from 2007-08-18 to 2007-09-18 )))))))))))))))))))))))))))))))
.

2007-09-17 16:02 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-17 15:45 d——– C:\DOCUME~1\MedX\APPLIC~1\AdobeUM
2007-09-13 16:13 d——– C:\Program Files\Trend Micro
2007-09-13 14:46 d——– C:\DOCUME~1\MedX\APPLIC~1\Symantec
2007-09-13 12:41 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-13 12:40 d——– C:\DOCUME~1\MedX\APPLIC~1\HouseCall 6.6
2007-09-13 12:36 d——– C:\DOCUME~1\MedX\.housecall6.6
2007-09-13 09:35 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-09-13 09:35 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-09-13 09:35 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-17 17:57 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-09-13 09:19 ——— d——– C:\Program Files\Skype
2007-07-30 19:19 92504 –a—— C:\windows\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\windows\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\windows\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\windows\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\windows\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\windows\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\windows\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\windows\system32\wups.dll
2006-06-19 17:24 11817800 –a—— C:\Program Files\GoogleEarth.exe
2005-11-15 09:36 104 –a—— C:\Program Files\Quick Install (2).lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Quick Install.lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Microsoft Outlook.lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Microsoft Outlook (2).lnk
2005-04-06 18:30 1540302 –a—— C:\Program Files\DualSmart.zip
2004-11-28 08:44 6654064 –a—— C:\Program Files\zlsSetup_55_062_000.exe
1998-12-08 20:53 99840 ——— C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 20:53 70144 ——— C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 20:53 48640 ——— C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 20:53 31744 ——— C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 20:53 186368 ——— C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 20:53 17920 ——— C:\Program Files\Common Files\IRASRIAL.DLL
2004-11-07 02:17:36 57,344 –sh–w C:\windows\lbbho.dll
2004-10-05 15:06:30 380,928 –sha-r C:\windows\system32\d?dplay.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31ACD32A-8020-4562-8653-C8547B929802}]
2004-11-06 20:17 57344 —hs—- C:\windows\lbbho.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34FC3928-B64B-7EB5-D726-655508F1794F}]
C:\windows\system32\mrb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-11-18 01:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 01:11]
"GWMDMMSG"="GWMDMMSG.exe" [2004-07-02 18:35 C:\WINDOWS\GWMDMMSG.exe]
"GWMDMpi"="C:\windows\GWMDMpi.exe" [2004-07-02 18:35]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 17:11]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 17:11]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-11-19 13:17]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"PhilipsDM"="C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe" [2005-09-14 23:12]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-04 18:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-16 15:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-08 19:01]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" []

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
Billminder.lnk - C:\Program Files\QUICKENW\BILLMIND.EXE [2004-07-02 20:40:44]
Quicken Startup.lnk - C:\Program Files\QUICKENW\QWDLLS.EXE [2004-07-02 20:40:58]
Symantec Fax Starter Edition Port.lnk - C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 15:51:54]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kkhiuug]
C:\windows\system32\d?dplay.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

R0 iomdisk;Iomega Devices Disk Filter Services;C:\windows\system32\DRIVERS\iomdisk.sys
R1 GhPciScan;GhostPciScanner;\??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
R3 GTWModem;GTW V.92 Voicemodem;C:\windows\system32\DRIVERS\GWMDM.sys
S2 ASEService;Aluria Spyware Eliminator Service;C:\PROGRA~1\ALURIA~1\ASE\ASEserv.exe
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 EPUSBSTOR;EPSON USB Storage Driver;C:\windows\system32\DRIVERS\epusbsto.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-17 18:19:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-17 18:20:06
C:\ComboFix-quarantined-files.txt … 2007-09-17 18:19
.
— E O F —
Howdy Goose_Hunter,


Some infection showing here, so let's take action on that. The log shows you have Aluria Spyware Eliminator installed - as shown here the status of this software as far as being beneficial to have is "Open" to debate. In truth when things are listed this way it means there are some aspects of the software that suggest it is not something to keep, especially with all the other good quality ones available. You should be able to uninstall this through Add/Remove Programs, but if you still opt to keep it be sure to keep it disabled throughout all repair steps here.

——————————————-

Please open Notepad (Start - Run, type notepad and press Enter) and copy/paste in that the contents of the textbox below.

Files::
C:\windows\lbbho.dll
C:\windows\system32\d?dplay.exe
C:\windows\system32\mrb.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{31ACD32A-8020-4562-8653-C8547B929802}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{34FC3928-B64B-7EB5-D726-655508F1794F}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kkhiuug]

Save as "CFScript.txt"
Be sure to include the "quotes" with the name and save this to your desktop.

[external image: Posted Image]


Referring to the picture above, drag CFScript.txt into ComboFix.exe. ComboFix will run as it has before. When the scan completes please post the new C:\ComboFix.txt log back here.

CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

—————————————–

Also Disable your antivirus program (remember to re-enable it once this scan is complete) and go here (be sure to re-enable it after the scan completes) and run an online scan with BitDefender (you will need to use Internet Explorer for this scan). When the ActiveX Control has loaded, click on "Click here to scan" and take a break for a while.

When BitDefender completes the scan, select the "Detected Problems" tab. Click on "Click here to export the scan report". Save the file as an HTML to your Desktop. Then click on the saved file and allow it to open with your browser. Go to Edit - Select All. Then copy/paste that log back here.


Run a new HijackThis scan, and post that back here along with the combofix.txt log and the BitDefender log please.
BitDefender Online Scanner



Scan report generated at: Thu, Sep 20, 2007 - 16:27:47





Scan path: A:\;C:\;D:\;







Statistics

Time
00:32:31

Files
117853

Folders
5839

Boot Sectors
2

Archives
910

Packed Files
5590




Results

Identified Viruses
18

Infected Files
169

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
176




Engines Info

Virus Definitions
822581

Engine build
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

Scan plugins
14

Archive plugins
38

Unpack plugins
7

E-mail plugins
6

System plugins
1




Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions


Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes




Scanned File
Status

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\adjdknaa.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\adjdknaa.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\adjdknaa.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\alrvcfyl.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.FM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\alrvcfyl.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\alrvcfyl.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\audqmnvg.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\audqmnvg.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\audqmnvg.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\catchme2007-09-17_175707.98.zip.bac_a02148=>(Quarantine-4)=>vtstq.dll
Infected with: Generic.Virtumonde.1.7EDD2F21

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\catchme2007-09-17_175707.98.zip.bac_a02148=>(Quarantine-4)=>vtstq.dll
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\catchme2007-09-17_175707.98.zip.bac_a02148=>(Quarantine-4)=>vtstq.dll
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\catchme2007-09-17_175707.98.zip.bac_a02148=>(Quarantine-4)
Updated

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\catchme2007-09-17_175707.98.zip.bac_a02148
Update failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\crtyuhav.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\crtyuhav.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\crtyuhav.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\cyyiucio.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\cyyiucio.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\cyyiucio.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\dmginqnx.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\dmginqnx.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\dmginqnx.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ebwxlgeb.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ebwxlgeb.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ebwxlgeb.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eojvtvha.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Packer.Morphine.B

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eojvtvha.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eojvtvha.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eqrhodme.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.AO

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eqrhodme.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\eqrhodme.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\fbfningl.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\fbfningl.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\fbfningl.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gllvmeft.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Packer.Morphine.B

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gllvmeft.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gllvmeft.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gxqhrbex.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gxqhrbex.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\gxqhrbex.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jbrcehlp.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jbrcehlp.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jbrcehlp.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jddvfone.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jddvfone.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jddvfone.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jliasmbs.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jliasmbs.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\jliasmbs.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kjkyrjqs.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.FM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kjkyrjqs.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kjkyrjqs.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kmvnbyqv.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kmvnbyqv.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kmvnbyqv.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kodbktbb.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kodbktbb.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\kodbktbb.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lfmlajjj.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lfmlajjj.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lfmlajjj.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lhvgmunr.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Virtumod.JQ

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lhvgmunr.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lhvgmunr.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lyasvcim.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Conhook.Y

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lyasvcim.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\lyasvcim.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mexskplf.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mexskplf.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mexskplf.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mljihii.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.Vundo.DLM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mljihii.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mljihii.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mnaugkyf.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mnaugkyf.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\mnaugkyf.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\naegabrt.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.FM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\naegabrt.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\naegabrt.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\oeqtpxey.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\oeqtpxey.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\oeqtpxey.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\omjintsx.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.FM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\omjintsx.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\omjintsx.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\onptejll.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\onptejll.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\onptejll.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\plkyxupx.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\plkyxupx.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\plkyxupx.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pmiihtnf.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Vundo.FM

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pmiihtnf.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pmiihtnf.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pymdyiuh.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pymdyiuh.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pymdyiuh.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pyyvmtvc.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pyyvmtvc.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\pyyvmtvc.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\sggaticr.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Conhook.Y

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\sggaticr.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\sggaticr.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\sllmrvcp.exe.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Fotomoto.A

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\spwokmtj.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Spy.Vbstat.H

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\spwokmtj.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\spwokmtj.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\tlumbygc.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\tlumbygc.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\tlumbygc.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ueerthef.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Conhook.Y

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ueerthef.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\ueerthef.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vlxeqjhd.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vlxeqjhd.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vlxeqjhd.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vungiobj.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vungiobj.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\vungiobj.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjmmoify.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjmmoify.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjmmoify.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjooixfm.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Trojan.Bho.O

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjooixfm.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wjooixfm.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wldcktwu.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: MemScan:Trojan.BHO.BG

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wldcktwu.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wldcktwu.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wmscmajh.dll.vir.bac_a02148=>(Quarantine-4)
Infected with: Packer.Morphine.B

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wmscmajh.dll.vir.bac_a02148=>(Quarantine-4)
Disinfection failed

C:\Documents and Settings\MedX\.housecall6.6\Quarantine\wmscmajh.dll.vir.bac_a02148=>(Quarantine-4)
Deleted

C:\Program Files\Acceleration Software\Anti-Virus\vir_win32_hllm_bagz.cnr
Infected with: Generic.Qhost.7CD20283

C:\Program Files\Acceleration Software\Anti-Virus\vir_win32_hllm_bagz.cnr
Disinfection failed

C:\Program Files\Acceleration Software\Anti-Virus\vir_win32_hllm_bagz.cnr
Deleted

C:\Program Files\Acceleration Software\Anti-Virus\vir_Zotob.cnr
Infected with: Generic.Qhost.0F155C05

C:\Program Files\Acceleration Software\Anti-Virus\vir_Zotob.cnr
Disinfection failed

C:\Program Files\Acceleration Software\Anti-Virus\vir_Zotob.cnr
Deleted

C:\Program Files\Norton AntiVirus\Quarantine8106C98=>(Quarantine-2)
Infected with: Trojan.Vundo.An.DLL

C:\Program Files\Norton AntiVirus\Quarantine8106C98=>(Quarantine-2)
Disinfection failed

C:\Program Files\Norton AntiVirus\Quarantine8106C98=>(Quarantine-2)
Deleted

C:\Program Files\Norton AntiVirus\Quarantine\12086E0A=>(Quarantine-2)
Infected with: Trojan.Downloader.Agent.YF

C:\qoobox\Quarantine\C\WINDOWS\system32\aqyhvtcy.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\blsabfeg.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\blsabfeg.dll.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\cfqvvaha.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\damofoul.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\damofoul.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\damofoul.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\dvjhgjux.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\dvjhgjux.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\dvjhgjux.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\fbrmyfvw.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\fbrmyfvw.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\fbrmyfvw.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\fmobjgit.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\iifgnvwy.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\iletsvcd.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\iletsvcd.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\ipqtqika.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\iuyuoici.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\iuyuoici.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\iydhedjh.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\iydhedjh.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\iydhedjh.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\jsjcmmqn.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\lndsojxs.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\mfkorkqb.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\mfkorkqb.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\mfkorkqb.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\mflphvkl.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\mhbwodwd.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\mhbwodwd.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\mhqryqha.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\nghdoevi.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\nghdoevi.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\njacoopa.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\nqjevihi.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\nqjevihi.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\nqjevihi.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\nxlcyirn.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\nxlcyirn.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\nxlcyirn.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\oqwxdgtc.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\oqwxdgtc.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\oqwxdgtc.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\plslpwjh.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\plslpwjh.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\plslpwjh.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\pxdjxiem.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\qqtrodmo.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\qqvrrwwc.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\qqvrrwwc.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\rgiyexyl.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\riusvvwn.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\svfvnqkj.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\svfvnqkj.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\svfvnqkj.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\tybvspqf.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\tybvspqf.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\tybvspqf.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\vcjdncmp.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\vcjdncmp.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\vcjdncmp.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\vurfckio.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\vurfckio.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\vurfckio.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\xixxypjn.exe.vir
Infected with: Trojan.Fotomoto.E

C:\qoobox\Quarantine\C\WINDOWS\system32\xixxypjn.exe.vir
Disinfection failed

C:\qoobox\Quarantine\C\WINDOWS\system32\xixxypjn.exe.vir
Deleted

C:\qoobox\Quarantine\C\WINDOWS\system32\xroaredy.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\xtfqtvaw.dll.vir
Infected with: Trojan.Vundo.DMP

C:\qoobox\Quarantine\C\WINDOWS\system32\ykyuwlch.dll.vir
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP482\A0020886.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP482\A0020887.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP482\A0020887.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020920.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020920.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020920.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020921.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020921.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020921.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020922.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020922.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020922.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020923.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020923.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020923.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020924.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020924.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020924.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020925.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020925.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020925.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020926.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020926.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020926.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020927.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020927.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020927.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020928.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020928.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020928.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020929.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020929.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020929.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020930.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020930.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020930.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020931.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020931.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020931.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020932.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020932.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020932.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020933.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020933.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020933.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020934.exe
Infected with: Trojan.Fotomoto.A

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020935.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020935.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020936.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020936.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020936.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020937.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020937.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020937.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020938.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020938.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020938.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020939.exe
Infected with: Trojan.Fotomoto.E

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020939.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020939.exe
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020940.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020940.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020940.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020941.dll
Infected with: Trojan.Vundo.FM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020941.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020941.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020943.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020944.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020944.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020945.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020949.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020950.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020950.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020952.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020952.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020952.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020953.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020953.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020953.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020956.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020956.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020956.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020958.dll
Infected with: Packer.Morphine.B

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020958.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020958.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020959.dll
Infected with: Trojan.Vundo.AO

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020959.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020959.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020962.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020962.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020962.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020963.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020965.dll
Infected with: Packer.Morphine.B

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020965.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020965.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020966.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020966.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020966.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020969.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020971.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020972.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020972.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020973.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020973.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020973.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020975.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020975.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020975.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020976.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020978.dll
Infected with: Trojan.Vundo.FM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020978.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020978.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020979.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020979.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020979.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020980.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020980.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020980.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020982.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020982.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020982.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020983.dll
Infected with: Trojan.Virtumod.JQ

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020983.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020983.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020984.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020986.dll
Infected with: Trojan.Conhook.Y

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020986.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020986.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020987.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020987.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020987.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020988.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020989.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020989.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020990.dll
Infected with: MemScan:Trojan.Vundo.DLM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020990.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020990.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020991.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020991.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020991.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020992.dll
Infected with: Trojan.Vundo.FM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020992.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020992.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020993.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020995.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020995.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020995.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020997.dll
Infected with: Trojan.Vundo.FM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020997.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020997.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020998.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020998.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0020998.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021000.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021000.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021000.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021001.dll
Infected with: Trojan.Vundo.FM

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021001.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021001.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021003.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021004.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021004.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021005.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021005.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021005.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021006.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021007.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021007.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021008.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021010.dll
Infected with: Trojan.Conhook.Y

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021010.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021010.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021011.dll
Infected with: Trojan.Spy.Vbstat.H

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021011.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021011.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021015.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021015.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021015.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021019.dll
Infected with: Trojan.Conhook.Y

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021019.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021019.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021021.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021021.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021021.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021022.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021022.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021022.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021023.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021023.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021023.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021024.dll
Infected with: Trojan.Bho.O

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021024.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021024.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021025.dll
Infected with: MemScan:Trojan.BHO.BG

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021025.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021025.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021026.dll
Infected with: Packer.Morphine.B

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021026.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021026.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021027.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021028.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021028.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021029.dll
Infected with: Trojan.Vundo.DMP

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021081.dll
Infected with: Generic.Virtumonde.1.7EDD2F21

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021081.dll
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP483\A0021081.dll
Deleted

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP486\A0021214.exe
Infected with: Trojan.Dropper.PurityScan.I

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP486\A0021214.exe
Disinfection failed

C:\System Volume Information\_restore{203C0DEF-8C81-4D97-B7D5-699C0DC51B02}\RP486\A0021214.exe
Deleted


ComboFix 07-09-17.2 - "MedX" 2007-09-20 13:55:48.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.266 [GMT -6:00]
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-08-20 to 2007-09-20 )))))))))))))))))))))))))))))))
.

2007-09-17 18:47 d——– C:\Program Files\eAcceleration
2007-09-17 18:47 d——– C:\Program Files\Common Files\eAcceleration
2007-09-17 18:47 d——– C:\Program Files\Acceleration Software
2007-09-17 18:47 d——– C:\DOCUME~1\MedX\APPLIC~1\eAcceleration
2007-09-17 18:47 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\eAcceleration
2007-09-17 16:02 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-17 15:45 d——– C:\DOCUME~1\MedX\APPLIC~1\AdobeUM
2007-09-13 16:13 d——– C:\Program Files\Trend Micro
2007-09-13 14:46 d——– C:\DOCUME~1\MedX\APPLIC~1\Symantec
2007-09-13 12:40 d——– C:\DOCUME~1\MedX\APPLIC~1\HouseCall 6.6
2007-09-13 12:36 d——– C:\DOCUME~1\MedX\.housecall6.6
2007-09-13 09:35 23,040 —–c— C:\WINDOWS\system32\dllcache\fltmc.exe
2007-09-13 09:35 16,896 —–c— C:\WINDOWS\system32\dllcache\fltlib.dll
2007-09-13 09:35 128,896 —–c— C:\WINDOWS\system32\dllcache\fltmgr.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-17 18:46 ——— d——– C:\Program Files\Google
2007-09-17 17:57 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-09-13 09:19 ——— d——– C:\Program Files\Skype
2007-07-30 19:19 92504 –a—— C:\windows\system32\cdm.dll
2007-07-30 19:19 549720 –a—— C:\windows\system32\wuapi.dll
2007-07-30 19:19 53080 –a—— C:\windows\system32\wuauclt.exe
2007-07-30 19:19 43352 –a—— C:\windows\system32\wups2.dll
2007-07-30 19:19 325976 –a—— C:\windows\system32\wucltui.dll
2007-07-30 19:19 203096 –a—— C:\windows\system32\wuweb.dll
2007-07-30 19:19 1712984 –a—— C:\windows\system32\wuaueng.dll
2007-07-30 19:18 33624 –a—— C:\windows\system32\wups.dll
2006-06-19 17:24 11817800 –a—— C:\Program Files\GoogleEarth.exe
2005-11-15 09:36 104 –a—— C:\Program Files\Quick Install (2).lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Quick Install.lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Microsoft Outlook.lnk
2005-11-15 09:35 104 –a—— C:\Program Files\Microsoft Outlook (2).lnk
2005-04-06 18:30 1540302 –a—— C:\Program Files\DualSmart.zip
2004-11-28 08:44 6654064 –a—— C:\Program Files\zlsSetup_55_062_000.exe
1998-12-08 20:53 99840 ——— C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 20:53 70144 ——— C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 20:53 48640 ——— C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 20:53 31744 ——— C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 20:53 186368 ——— C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 20:53 17920 ——— C:\Program Files\Common Files\IRASRIAL.DLL
2004-11-07 02:17:36 57,344 –sh–w C:\windows\lbbho.dll
.

((((((((((((((((((((((((((((( snapshot_2007-09-17_175847.96 )))))))))))))))))))))))))))))))))))))))))
.
—-a-w 135,168 2007-07-12 07:22:00 C:\windows\system32\java.exe
—-a-w 135,168 2007-07-12 07:22:04 C:\windows\system32\javaw.exe
—-a-w 139,264 2007-07-12 08:22:38 C:\windows\system32\javaws.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-11-18 01:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-11-18 01:11]
"GWMDMMSG"="GWMDMMSG.exe" [2004-07-02 18:35 C:\WINDOWS\GWMDMMSG.exe]
"GWMDMpi"="C:\windows\GWMDMpi.exe" [2004-07-02 18:35]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-12-02 17:11]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2003-12-02 17:11]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-11-19 13:17]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46]
"PhilipsDM"="C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe" [2005-09-14 23:12]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-04 18:21]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-16 15:44]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-08 19:01]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"SoftwareStation"="C:\Program Files\eAcceleration\Station\station.exe" [2007-05-08 18:12]
"StopSignSsTsMon"="C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll" [2007-07-27 13:53]
"StopSignSsSsMon"="C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll" [2007-07-27 13:53]
"webscan"="C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" [2007-07-27 15:34]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-17 21:00]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"StopSignSsSsMon"=Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll",VerifyStatus /ro

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26]
Billminder.lnk - C:\Program Files\QUICKENW\BILLMIND.EXE [2004-07-02 20:40:44]
Quicken Startup.lnk - C:\Program Files\QUICKENW\QWDLLS.EXE [2004-07-02 20:40:58]
Symantec Fax Starter Edition Port.lnk - C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 15:51:54]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

R0 iomdisk;Iomega Devices Disk Filter Services;C:\windows\system32\DRIVERS\iomdisk.sys
R1 GhPciScan;GhostPciScanner;\??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
R3 GTWModem;GTW V.92 Voicemodem;C:\windows\system32\DRIVERS\GWMDM.sys
S2 ASEService;Aluria Spyware Eliminator Service;C:\PROGRA~1\ALURIA~1\ASE\ASEserv.exe
S3 BCMModem;BCM V.90 56K Modem;C:\windows\system32\DRIVERS\BCMDM.sys
S3 EPUSBSTOR;EPSON USB Storage Driver;C:\windows\system32\DRIVERS\epusbsto.sys

.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-20 13:57:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-09-20 13:58:35
C:\ComboFix-quarantined-files.txt … 2007-09-20 13:58
C:\ComboFix2.txt … 2007-09-17 18:20
.
— E O F —
Looks like time to empty that housecall6.6 Quarantine folder, and we'll need to be sure to delete that C:\qoobox folder once we are finished with the work here. I see you have added eAcceleration's Stop-Sign, though if you have run a scan with it already I notice BitDefender did not pick up anything it assisted with. If you review the info here you might rethink keeping this software, especially with all the other good and free security software options available to you. BitDefender also indicates infection stored in System restore, but that last ComboFix scan reset that and should have removed any others hiding there.


Not seeing any active infection now, but that ComboFix log isn't showing the file removal part I had expected. If you would, locate and post back the following log for now:

C:\ComboFix-quarantined-files.txt
2004-04-02 19:26	  143360	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\wl.exe.vir
2004-10-14 05:10	  2	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\wnstssv.exe.vir
2004-11-06 20:46	  45056	–a——	C:\Qoobox\Quarantine\C\WINDOWS\NDNuninstall4_85-1.exe.vir
2005-10-06 06:04	  182272	–a——	C:\Qoobox\Quarantine\C\WINDOWS\NDNuninstall6_90.exe.vir
2005-10-28 18:35	  182272	–a——	C:\Qoobox\Quarantine\C\WINDOWS\NDNuninstall6_98.exe.vir
2007-04-25 19:41	  281172	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\vtstq.dll.vir
2007-04-27 02:00	  344	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qucicrec.ini.vir
2007-04-28 08:49	  584	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\yraanqwp.ini.vir
2007-04-28 08:49	  644	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\apupnfxk.ini.vir
2007-04-29 19:12	  764	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ajlwknkr.ini.vir
2007-04-30 18:00	  884	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qcquopsh.ini.vir
2007-05-01 17:47	  1063	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\rlqgjate.ini.vir
2007-05-03 18:42	  1184	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\rcdswsqd.ini.vir
2007-05-03 18:43	  1244	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\xmmxxmpy.ini.vir
2007-05-11 15:41	  1487031	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\csvqfmgj.ini.vir
2007-05-11 15:42	  1432439	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\rnumgvhl.ini.vir
2007-05-14 09:28	  1431757	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\risnkwrc.ini.vir
2007-05-16 02:02	  1428578	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ntxjynss.ini.vir
2007-05-16 02:02	  1463178	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\dwsujxji.ini.vir
2007-05-18 02:03	  1461582	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\vbpssrpl.ini.vir
2007-05-18 02:04	  1458605	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\tuxshswt.ini.vir
2007-05-19 02:03	  833161	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\sqjrykjk.ini.vir
2007-05-20 02:04	  833222	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\xstnijmo.ini.vir
2007-05-21 02:04	  833282	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\trbagean.ini.vir
2007-05-22 02:04	  831762	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\lyfcvrla.ini.vir
2007-07-08 21:23	  15399	–a——	C:\Qoobox\Quarantine\C\ComboFix\FProps.vbs.vir
2007-08-14 14:18	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\exqlbnst.dll.vir
2007-08-14 14:19	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\xroaredy.dll.vir
2007-08-14 14:19	  2249639	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\fnthiimp.ini.vir
2007-09-05 11:07	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\mflphvkl.dll.vir
2007-09-05 11:07	  3053393	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\yderaorx.ini.vir
2007-09-05 11:07	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\okksjwqp.dll.vir
2007-09-06 11:04	  3050817	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\lkvhplfm.ini.vir
2007-09-06 11:07	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\xtfqtvaw.dll.vir
2007-09-06 11:07	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\tjkfwhbx.dll.vir
2007-09-06 11:08	  525	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\wavtqftx.ini.vir
2007-09-06 11:31	  1990759	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qtstv.tmp.vir
2007-09-07 11:07	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\njacoopa.dll.vir
2007-09-07 11:07	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ftiwjbbi.dll.vir
2007-09-08 11:08	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\mhqryqha.dll.vir
2007-09-08 11:08	  585	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\apoocajn.ini.vir
2007-09-08 11:08	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\jysygjys.dll.vir
2007-09-09 11:08	  645	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ahqyrqhm.ini.vir
2007-09-09 11:09	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\jsjcmmqn.dll.vir
2007-09-09 11:11	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\eahhoobn.dll.vir
2007-09-10 11:08	  2012657	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qtstv.ini.vir
2007-09-13 08:58	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\syydewrs.dll.vir
2007-09-13 08:58	  824	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\nqmmcjsj.ini.vir
2007-09-13 08:59	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ipqtqika.dll.vir
2007-09-13 08:59	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\pxdjxiem.dll.vir
2007-09-13 08:59	  884	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\akiqtqpi.ini.vir
2007-09-13 09:00	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\amrmnwyx.dll.vir
2007-09-13 12:24	  1004	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\meixjdxp.ini.vir
2007-09-13 12:24	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\hlyhqcud.dll.vir
2007-09-13 12:25	  1065	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\gefbaslb.ini.vir
2007-09-13 12:25	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\iifgnvwy.dll.vir
2007-09-13 12:25	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\edqghjtu.dll.vir
2007-09-13 15:22	  1185	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ywvngfii.ini.vir
2007-09-13 15:22	  1244	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\omdortqq.ini.vir
2007-09-13 15:22	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qqtrodmo.dll.vir
2007-09-13 15:22	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\bmbekmwd.dll.vir
2007-09-13 15:22	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\pbsgnjjq.dll.vir
2007-09-13 15:23	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\cfqvvaha.dll.vir
2007-09-13 15:23	  1304	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ahavvqfc.ini.vir
2007-09-14 15:23	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\lndsojxs.dll.vir
2007-09-14 15:23	  1365	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\sxjosdnl.ini.vir
2007-09-14 15:23	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\nladmvny.dll.vir
2007-09-15 15:23	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\aqyhvtcy.dll.vir
2007-09-15 15:23	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\uhatvpgu.dll.vir
2007-09-16 15:23	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\rgiyexyl.dll.vir
2007-09-16 15:23	  1424	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\yctvhyqa.ini.vir
2007-09-16 15:23	  1484	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\lyxeyigr.ini.vir
2007-09-16 15:23	  2011905	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qtstv.bak1.vir
2007-09-16 15:23	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\yssbmchk.dll.vir
2007-09-16 16:22	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\tpurarvj.dll.vir
2007-09-17 15:34	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\toermrjo.dll.vir
2007-09-17 15:35	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\ykyuwlch.dll.vir
2007-09-17 15:49	  104	–a——	C:\Qoobox\Quarantine\C\DOCUME~1\MedX\Desktop\Internet.lnk.vir
2007-09-17 15:59	  1785	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\hclwuyky.ini.vir
2007-09-17 16:00	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\fmobjgit.dll.vir
2007-09-17 16:00	  125460	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\riusvvwn.dll.vir
2007-09-17 16:00	  1845	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\nwvvsuir.ini.vir
2007-09-17 16:00	  2003733	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qtstv.bak2.vir
2007-09-17 16:02	  1905	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\tigjbomf.ini.vir
2007-09-17 16:02	  69140	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\bsuvgswb.dll.vir
2007-09-17 16:18	  1098	–a——	C:\Qoobox\Quarantine\Registry_backups\LEGACY_DOMAINSERVICE.reg.cf
2007-09-17 16:18	  2956	–a——	C:\Qoobox\Quarantine\Registry_backups\services_DomainService.reg.cf
2007-09-17 16:19	  2005166	–a——	C:\Qoobox\Quarantine\C\WINDOWS\system32\qtstv.ini2.vir
2007-09-17 16:22	  152	–a——	C:\Qoobox\Quarantine\catchme.log
2007-09-19 09:01	  22	–a——	C:\Qoobox\Quarantine\catchme2007-09-17_175707.98.zip


Folder PATH listing
Volume serial number is F824-9412
C:\QOOBOX\QUARANTINE
|   catchme.log
|   catchme2007-09-17_175707.98.zip
|   
+—C
|   +—ComboFix
|   |	   FProps.vbs.vir
|   |	   
|   +—DOCUME~1
|   |   \—MedX
|   |	   \—Desktop
|   |			   Internet.lnk.vir
|   |			   
|   \—WINDOWS
|	   |   NDNuninstall4_85-1.exe.vir
|	   |   NDNuninstall6_90.exe.vir
|	   |   NDNuninstall6_98.exe.vir
|	   |   
|	   \—system32
|			   ahavvqfc.ini.vir
|			   ahqyrqhm.ini.vir
|			   ajlwknkr.ini.vir
|			   akiqtqpi.ini.vir
|			   amrmnwyx.dll.vir
|			   apoocajn.ini.vir
|			   apupnfxk.ini.vir
|			   aqyhvtcy.dll.vir
|			   bmbekmwd.dll.vir
|			   bsuvgswb.dll.vir
|			   cfqvvaha.dll.vir
|			   csvqfmgj.ini.vir
|			   dwsujxji.ini.vir
|			   eahhoobn.dll.vir
|			   edqghjtu.dll.vir
|			   exqlbnst.dll.vir
|			   fmobjgit.dll.vir
|			   fnthiimp.ini.vir
|			   ftiwjbbi.dll.vir
|			   gefbaslb.ini.vir
|			   hclwuyky.ini.vir
|			   hlyhqcud.dll.vir
|			   iifgnvwy.dll.vir
|			   ipqtqika.dll.vir
|			   jsjcmmqn.dll.vir
|			   jysygjys.dll.vir
|			   lkvhplfm.ini.vir
|			   lndsojxs.dll.vir
|			   lyfcvrla.ini.vir
|			   lyxeyigr.ini.vir
|			   meixjdxp.ini.vir
|			   mflphvkl.dll.vir
|			   mhqryqha.dll.vir
|			   njacoopa.dll.vir
|			   nladmvny.dll.vir
|			   nqmmcjsj.ini.vir
|			   ntxjynss.ini.vir
|			   nwvvsuir.ini.vir
|			   okksjwqp.dll.vir
|			   omdortqq.ini.vir
|			   pbsgnjjq.dll.vir
|			   pxdjxiem.dll.vir
|			   qcquopsh.ini.vir
|			   qqtrodmo.dll.vir
|			   qtstv.bak1.vir
|			   qtstv.bak2.vir
|			   qtstv.ini.vir
|			   qtstv.ini2.vir
|			   qtstv.tmp.vir
|			   qucicrec.ini.vir
|			   rcdswsqd.ini.vir
|			   rgiyexyl.dll.vir
|			   risnkwrc.ini.vir
|			   riusvvwn.dll.vir
|			   rlqgjate.ini.vir
|			   rnumgvhl.ini.vir
|			   sqjrykjk.ini.vir
|			   sxjosdnl.ini.vir
|			   syydewrs.dll.vir
|			   tigjbomf.ini.vir
|			   tjkfwhbx.dll.vir
|			   toermrjo.dll.vir
|			   tpurarvj.dll.vir
|			   trbagean.ini.vir
|			   tuxshswt.ini.vir
|			   uhatvpgu.dll.vir
|			   vbpssrpl.ini.vir
|			   vtstq.dll.vir
|			   wavtqftx.ini.vir
|			   wl.exe.vir
|			   wnstssv.exe.vir
|			   xmmxxmpy.ini.vir
|			   xroaredy.dll.vir
|			   xstnijmo.ini.vir
|			   xtfqtvaw.dll.vir
|			   yctvhyqa.ini.vir
|			   yderaorx.ini.vir
|			   ykyuwlch.dll.vir
|			   yraanqwp.ini.vir
|			   yssbmchk.dll.vir
|			   ywvngfii.ini.vir
|			   
\—Registry_backups
		LEGACY_DOMAINSERVICE.reg.cf
		services_DomainService.reg.cf
No indication there either, so going to have to assume other changes were made between steps. Either way the items show as removed, so let's follow with an additional check. Are you having any issues at this time?


Go Here and download ATF cleaner. Click on the downloaded file to run it, and select "Select All", then click Empty Selected (and close ATF).

If you have them, also click on Firefox/Opera at the top and repeat the steps (and close ATF). Firefox/Opera will need to be closed first for the cleaning to be effective.


Then go here for an online AV scan (requires IE to run).

Scan "Local Disks" and when finished save the scan log and then post the log here.
Incident Status Location Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\MedX\Cookies\medx@2o7[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\MedX\Cookies\medx@advertising[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\MedX\Cookies\medx@atdmt[1].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\MedX\Cookies\medx@doubleclick[1].txt Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\MedX\Desktop\ComboFix.exe[nircmd.exe] Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-2fa9da05-19b5c81d.zip[Dummy.class] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Cookies\owner@247realmedia[2].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Owner\Cookies\owner@adrevolver[3].txt Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Owner\Cookies\owner@adtech[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Owner\Cookies\owner@apmebf[1].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Owner\Cookies\owner@atwola[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Owner\Cookies\owner@belnk[1].txt Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Owner\Cookies\owner@bfast[2].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Cookies\[removed]-sys[1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Owner\Cookies\owner@burstnet[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Owner\Cookies\owner@cdfreaks[2].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Owner\Cookies\owner@cgi-bin[1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Owner\Cookies\owner@cgi-bin[3].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Owner\Cookies\owner@cgi-bin[6].txt Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Owner\Cookies\owner@clickbank[1].txt Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Owner\Cookies\owner@com[1].txt Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Owner\Cookies\owner@ct.360i[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Owner\Cookies\owner@findwhat[1].txt Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Owner\Cookies\owner@go[1].txt Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Owner\Cookies\owner@linksynergy[2].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Owner\Cookies\owner@maxserving[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Owner\Cookies\owner@mediaplex[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Owner\Cookies\owner@overture[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Owner\Cookies\owner@realmedia[1].txt Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Owner\Cookies\owner@revenue[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Owner\Cookies\owner@serving-sys[1].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt Spyware:Cookie/Clicktracks Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Owner\Cookies\owner@target[1].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][2].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Owner\Cookies\owner@yadro[2].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Owner\Cookies\[removed][1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt Adware:Adware/WinAD Not disinfected C:\Documents and Settings\Owner\My Documents\Lukes folder\e-mail stuff.exe Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\adm25.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\adm4.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\adm4005.exe Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\admdata.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\admdloader.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\admfdi.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\admprog.dll Potentially unwanted tool:Application/Altnet Not disinfected C:\Program Files\Altnet\Download Manager\altnetuninstall.exe Adware:Adware/RelatedLinks Not disinfected C:\WINDOWS\lbbho.dll Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\NirCmd.exe Potentially unwanted tool:application/altnet Not disinfected C:\WINDOWS\smdat32a.sys Potentially unwanted tool:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys
Looks like protective software you had installed at one of these times blocked ComboFix from removing the files. You have Altnet, which is adware software, so for now go to Add/Remove programs and uninstall Altnet Download Manager.


Also Open HijackThis, and choose None of the above, just start the program. Click Config – Misc Tools - Delete File on Reboot. Navigate to each of the following files, double-click on each, say No to reboot until the last file, say Yes and allow it to reboot.

C:\WINDOWS\lbbho.dll
C:\Documents and Settings\Owner\My Documents\Lukes folder\e-mail stuff.exe

Run ATF Cleaner again after the reboot, and run and post back a new Panda scan log please.
It is always good to try with available uninstall options, but when none are available then we will surely remove that. I have a feeling in looking at the protective software you added/removed in between our steps here one of those was responsible for ComboFix' script not working correctly the last time. Please be sure to disable all protective software when doing this next step, and let's try the use of that again. I'll add those files as well in case you have not removed them.


Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:

File::
C:\WINDOWS\lbbho.dll
C:\WINDOWS\smdat32a.sys
C:\WINDOWS\smdat32m.sys
C:\Documents and Settings\Owner\My Documents\Lukes folder\e-mail stuff.exe
Folder::
C:\Program Files\Altnet\Download Manager

Save this as "CFScript"

(include the "quotation marks" with the name)


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

ComboFix will now run as it did before. When the fix completes it will create a C:\ComboFix.txt log. Please post that log in your next reply please. Also post back how things are running there now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI