This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] spyware won't go away

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I'm getting lots and lots of redirects.

After running spybot and rebooting - my network connectivity gets hosed up.

I have not been able to restore the network configuration without doing a system restore - which restores the spyware as well (at least that is what seems to be happening).

Here's the hijack this logfile… thanks in advance.



Logfile of HijackThis v1.99.1
Scan saved at 8:30:11 AM, on 12/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [48169de1] rundll32.exe "C:\WINDOWS\system32\pinsyoye.dll",b
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.


Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Using Windows Explore by right-clicking the Start button and left clicking Explore navigate to: C:\Program Files\HijackThis\HijackThis.exe

Right-click on HijackThis.exe & select Rename to iseeu.exe and post back a new Hijackthis log.


Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Thanks for the quick reply!

Here's the new log file:

Logfile of HijackThis v1.99.1
Scan saved at 10:30:49 AM, on 12/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Hijackthis\iseeu.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A0D962A2-D59C-4878-8996-C357A3928CAF} - C:\WINDOWS\system32\pmkhh.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: {1dad39e4-415b-577a-8564-14ccd5664b8b} - {b8b4665d-cc41-4658-a775-b5144e93dad1} - C:\WINDOWS\system32\gjagsudt.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [48169de1] rundll32.exe "C:\WINDOWS\system32\pinsyoye.dll",b
O4 - HKLM\..\RunOnce: [SpybotDeletingA7393] command /c del "C:\WINDOWS\system32\rlls.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3625] cmd /c del "C:\WINDOWS\system32\rlls.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1272] command /c del "C:\WINDOWS\system32\pmkhh.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4459] cmd /c del "C:\WINDOWS\system32\pmkhh.dll_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8700] command /c del "C:\WINDOWS\system32\rlls.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7457] cmd /c del "C:\WINDOWS\system32\rlls.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5266] command /c del "C:\WINDOWS\system32\pmkhh.dll_tobedeleted"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7317] cmd /c del "C:\WINDOWS\system32\pmkhh.dll_tobedeleted"
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\rlls.dll' missing
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



>>>>> And the uninstall list:

|ìTorrent
ACETON
Actiontec Gateway
Ad-aware 6 Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
Adobe Photoshop Album Starter Edition
Adobe Premiere Pro
Adobe Reader 7.0.8
Adobe Reader Japanese Fonts
Adobe? Photoshop? Album Starter Edition 3.0
Adobe?Photoshop?Album Starter Edition 3.0.1
Apple Mobile Device Support
Apple Software Update
ArcSoft Multimedia Email
ArcSoft PhotoImpression 5
ArcSoft PhotoImpression 5
ArcSoft ShowBiz 2
Ashampoo Burning Studio 6
ATI Control Panel
ATI Display Driver
ATI DVD Decoder 2.2.0.0
ATI HYDRAVISION
ATI Multimedia Center [removed]
Atomic Clock Sync
AVS Disc Creator version 2.1
Battlecraft Vietnam
Battlefield 1942
Battlefield 1942: Secret Weapons of WWII
Battlefield 1942: The Road To Rome
Battlefield Vietnam™
Blackhawk Striker from ATI (remove only)
Blackhawk Striker from Compaq (remove only)
Blasterball 2 from ATI (remove only)
Blasterball 2 from Compaq (remove only)
Bounce from ATI (remove only)
Bounce from Compaq (remove only)
BRATZ - Rock Angelz
Cannonballs from ATI (remove only)
Cannonballs from Compaq (remove only)
Cartoon Cove
Cinderella's Dollhouse
Cisco Systems VPN Client 4.7.00.0533
Command & Conquer Generals
Command & Conquer The First Decade
Command & Conquer Windows 95
Command and ConquerTM Generals Zero Hour
Compaq Connections
Compaq Organize
Creative WebCam Center
Creative WebCam Instant Driver (1.01.02.0729)
Creative WebCam Instant User's Guide (English)
DAO
dBpowerAMP Music Converter
Desktop Weather by The Weather Channel
Dexter's Labyrinth
Disney's Arcade Frenzy
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DominateGame 20040310 (dominate)
DVD to DivX
Easy Internet Sign-up
eMule
EPSON CX 3800 Guide
EPSON Printer Software
EPSON Scan
Escape From Horrorland
Excavation from ATI (remove only)
Excavation from Compaq (remove only)
FamilyFeudOnlineParty (remove only)
Fast And Flurrious
FIFA 07
File Scavenger 2.1v
Filzip 3.03
Five Card Frenzy from ATI (remove only)
Five Card Frenzy from Compaq (remove only)
Form Fill (Windows Live Toolbar)
FPE 2001
Gaim (remove only)
GameSpy Arcade
GemMaster 3 from ATI (remove only)
GemMaster 3 from Compaq (remove only)
Get Yahoo! Messenger
Google Earth
Google Toolbar for Internet Explorer
GTK+ Runtime 2.4.3 rev a (remove only)
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
Hijackthis 1.99.1
HijackThis 1.99.1
Honeycombs from ATI (remove only)
Honeycombs from Compaq (remove only)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
HP Deskjet Preloaded Printer Drivers
Instant Support
Intel® Extreme Graphics Driver
IntelliMover Data Transfer Demo
InterVideo WinDVD Player
ItsDeductible Express
iTunes
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.1_02
Java Web Start
KBD
LimeWire 4.13.0
LiveUpdate 1.90 (Symantec Corporation)
Logitech Desktop Messenger
Logitech Gaming Software
Logitech Print Service
Logitech QuickCam Software
Logitech? Camera Driver
Macromedia Shockwave Player
Map Button (Windows Live Toolbar)
Mars Rover from Compaq (remove only)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Learning and Research Plus Support Files
Microsoft Money 2003
Microsoft Money 2003 System Pack
Microsoft Office 2000 SR-1 Professional
Microsoft Picture It! Express 7.0
Microsoft Plus! Digital Media Edition
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# .NET Redistributable Package 1.1
Microsoft Windows Journal Viewer
Microsoft Works 7.0
mIRC
MostFun Game Player
Mozilla Firefox (2.0.0.11)
MSN
MSN Internet Software
MSN Music Assistant
Musicmatch? Jukebox
Natural Color
Nicktoons Basketball
NVIDIA Gart Driver
NVIDIA Windows 2000/XP Display Drivers
OmniPass
OneCare Advisor (Windows Live Toolbar)
Orbital from ATI (remove only)
Orbital from Compaq (remove only)
Otto from ATI (remove only)
Otto from Compaq (remove only)
PC Powerwash
PC-Doctor for Windows
PirateFish5
Polar Bowler from Compaq (remove only)
Popup Blocker (Windows Live Toolbar)
PS2
PunkBuster for Battlefield Vietnam
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2003 New User Edition
QuickTime
RealPlayer
RecordNow!
RelevantKnowledge
Rhapsody Player Engine
RitzPix E-Z Print & Share
Roll
RollerCoaster Tycoon 2
RollerCoaster Tycoon? 3
S3Display
S3Gamma2
S3Info2
S3Overlay
Screensavers Installer
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
Shockwave
SimCity 4
SiS 900 PCI Fast Ethernet Adapter Driver
Slyder from ATI (remove only)
Slyder from Compaq (remove only)
Smart Menus (Windows Live Toolbar)
Sonic Update Manager
SpamSubtract
Spy Kids 3D
Spybot - Search & Destroy 1.4
Star Wars Empire at War
Star Wars Empire at War Forces of Corruption
STX from ATI (remove only)
STX from Compaq (remove only)
StyleXP (remove only)
Tabbed Browsing (Windows Live Toolbar)
The History Channel: Civil War
The Sims 2
The Sims 2 University
The Sims Deluxe Edition
The Sims House Party
To The Eds-treme
Trend Micro OfficeScan WinNT
TurboTax 2005
TurboTax Basic 2003
TurboTax Deluxe 2004
TurboTax Deluxe Deduction Maximizer 2006
TurboTax ItsDeductible 2005
TurboTax ItsDeductible 2006
Uniblue SpeedUpMyPC 3
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
VideoLAN VLC media player 0.8.6a
Viewpoint Manager (Remove Only)
Virtual Warfare from Compaq (remove only)
Weather Services
Weblink
WexTech AnswerWorks
WildTangent GameChannel (remove only)
Windows Driver Package - Realtek Semiconductor Corp. MEDIA 12/12/2003 5.10.00.5410
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Live Favorites for Windows Live Toolbar
Windows Live Messenger
Windows Live Outlook Toolbar (Windows Live Toolbar)
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Toolbar Feed Detector (Windows Live Toolbar)
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
World of Warcraft
Yahoo! Anti-Spy
Yahoo! Install Manager
Yahoo! Messenger
Yahoo! Music Jukebox
Yahoo! Toolbar for Internet Explorer
HI

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.


If you already have Combofix, please delete that copy and download it again as it's being updated regularly.

Please download Combofix from Bleeping Computer.

If you can't download it from there, please try these 2 alternative sites:

Forospyware
Geeks to Go

  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Click Start>Run copy/paste or type "%userprofile%\desktop\combofix.exe" /killall into the Run box and click OK.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
Vundofix.txt
ComboFix.txt
New HijackThis log taken after the above scan has run
Hi Scotty,

I've run Vundofix, ComboFix and HijackThis. The log files follow in order.

I've also had to run system restores after ComboFix to get my network connectivity to function. The HijackThis logs at the end are before a system restore and after a system restore.

The system event log errors when the network isn't working are:

Service Control Manager errors:

ID 7023
The Application Management service terminated with the following error:
The specified module could not be found.

ID 7023
The ASP.NET State Service service terminated with the following error:
The requested service provider could not be loaded or initialized

ID 7000
The mrtRate service failed to start due to the following error:
The system cannot find the file specified.

ID 7023
The IPSEC Services service terminated with the following error:
The requested service provider could not be loaded or initialized.

Thanks again…..



VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 11:26:05 AM 12/24/2007

Listing files found while scanning….

C:\WINDOWS\system32\abpjuqwy.dll
C:\windows\system32\agsqdpdf.dll
C:\WINDOWS\system32\akejuixi.dll
C:\WINDOWS\system32\amvxtree.dll
C:\WINDOWS\system32\aolbnqsm.dll
C:\WINDOWS\system32\assxcxkp.dll
C:\WINDOWS\system32\aubrjekg.dll
C:\WINDOWS\system32\avkpitwa.dll
C:\WINDOWS\system32\avoccjqd.dll
C:\WINDOWS\system32\axekxeag.dll
C:\WINDOWS\system32\bhibdfum.dll
C:\WINDOWS\system32\bibjntjn.dll
C:\WINDOWS\system32\bjeyyfea.dll
C:\WINDOWS\system32\blvtlmry.dll
C:\WINDOWS\system32\btwxkvya.dll
C:\WINDOWS\system32\bvpvsmqj.dll
C:\WINDOWS\system32\bvufhsra.dll
C:\WINDOWS\system32\bvysdbam.dll
C:\WINDOWS\system32\bxcfnlnw.dll
C:\WINDOWS\system32\bydlxnnc.dll
C:\WINDOWS\system32\byyqwpjg.dll
C:\WINDOWS\system32\ccavuebg.dll
C:\WINDOWS\system32\cejxjkmm.dll
C:\WINDOWS\system32\cfntahck.dll
C:\WINDOWS\system32\cgqehgdg.dll
C:\WINDOWS\system32\clcuqdkv.dll
C:\WINDOWS\system32\cnujmjsq.dll
C:\WINDOWS\system32\crfrdueq.dll
C:\WINDOWS\system32\crvjmxkg.dll
C:\WINDOWS\system32\cstvrxbr.dll
C:\WINDOWS\system32\cyoqpyco.dll
C:\WINDOWS\system32\dakkwghb.dll
C:\WINDOWS\system32\deavehfq.dll
C:\WINDOWS\system32\dffekvhm.dll
C:\WINDOWS\system32\dififgib.dll
C:\WINDOWS\system32\dlocxckr.dll
C:\WINDOWS\system32\dmulefhp.dll
C:\WINDOWS\system32\dolmbmrc.dll
C:\WINDOWS\system32\douhroue.ini
C:\WINDOWS\system32\dqyejkbs.dll
C:\WINDOWS\system32\drlwpdbh.dll
C:\WINDOWS\system32\dtaowlwk.dll
C:\WINDOWS\system32\dtdmdnxa.dll
C:\WINDOWS\system32\dtogriby.dll
C:\WINDOWS\system32\dvvnvbqe.dll
C:\WINDOWS\system32\dwlxsjqt.dll
C:\WINDOWS\system32\dxiybtfb.dll
C:\WINDOWS\system32\ebuuhopn.dll
C:\WINDOWS\system32\eccolsbr.dll
C:\WINDOWS\system32\ehewrrxx.dll
C:\WINDOWS\system32\emnsopyr.dll
C:\WINDOWS\system32\eoovrnit.dll
C:\WINDOWS\system32\epdpmthg.dll
C:\WINDOWS\system32\eqwnqypa.dll
C:\WINDOWS\system32\ermimpcw.dll
C:\WINDOWS\system32\euorhuod.dll
C:\WINDOWS\system32\fjjefpix.dll
C:\WINDOWS\system32\fmiggojd.dll
C:\WINDOWS\system32\frashidj.dll
C:\WINDOWS\system32\fvoashnf.dll
C:\WINDOWS\system32\fyyaucps.dll
C:\WINDOWS\system32\gbqcrlpj.dll
C:\WINDOWS\system32\gclucwop.dll
C:\WINDOWS\system32\gdggjhge.dll
C:\WINDOWS\system32\gdhemxch.dll
C:\WINDOWS\system32\gfkdjeyx.dll
C:\WINDOWS\system32\ghisfvjj.dll
C:\WINDOWS\system32\ghjrdynb.dll
C:\WINDOWS\system32\gjagsudt.dll
C:\WINDOWS\system32\gjpwqyyb.ini
C:\WINDOWS\system32\gjyqywjb.dll
C:\WINDOWS\system32\gkxmjvrc.ini
C:\WINDOWS\system32\goakwwek.dll
C:\WINDOWS\system32\gtcxixho.dll
C:\WINDOWS\system32\guknumpo.dll
C:\WINDOWS\system32\gxbsmpcc.dll
C:\WINDOWS\system32\hbyejemg.dll
C:\WINDOWS\system32\hdqicfen.dll
C:\WINDOWS\system32\hkygbkag.dll
C:\WINDOWS\system32\hpybvxyd.dll
C:\WINDOWS\system32\hsqxbogj.dll
C:\WINDOWS\system32\hvuaenoj.dll
C:\WINDOWS\system32\hxlqaalo.dll
C:\WINDOWS\system32\hyipoveq.dll
C:\WINDOWS\system32\icbpjpgi.dll
C:\WINDOWS\system32\ielxawgl.dll
C:\WINDOWS\system32\ijjscrty.dll
C:\WINDOWS\system32\inbjpfjm.dll
C:\WINDOWS\system32\iocysrus.dll
C:\WINDOWS\system32\ithridxr.dll
C:\WINDOWS\system32\itkrpmhu.dll
C:\WINDOWS\system32\iuwkvvyk.dll
C:\WINDOWS\system32\ivxbvnmm.dll
C:\WINDOWS\system32\iydcithw.dll
C:\WINDOWS\system32\iyyywtgf.dll
C:\WINDOWS\system32\jbdbasst.dll
C:\WINDOWS\system32\jdtxsptk.dll
C:\WINDOWS\system32\jimuluya.dll
C:\WINDOWS\system32\jirukuxi.dll
C:\WINDOWS\system32\jnomampe.dll
C:\WINDOWS\system32\joepfivk.dll
C:\WINDOWS\system32\jqsrywvv.dll
C:\WINDOWS\system32\jriyukse.dll
C:\WINDOWS\system32\jsipjfqo.dll
C:\WINDOWS\system32\jsrhxjnl.dll
C:\WINDOWS\system32\jvduouag.dll
C:\WINDOWS\system32\jvxehlxm.dll
C:\WINDOWS\system32\jwqbtmyl.dll
C:\WINDOWS\system32\kawfihja.dll
C:\WINDOWS\system32\kddcsotj.dll
C:\WINDOWS\system32\keuspuhf.dll
C:\WINDOWS\system32\klojpnch.dll
C:\WINDOWS\system32\kmggsexv.dll
C:\WINDOWS\system32\koimffgb.dll
C:\WINDOWS\system32\kokavygf.dll
C:\WINDOWS\system32\kqoymksq.dll
C:\WINDOWS\system32\krcidbnf.dll
C:\WINDOWS\system32\kswxwtxk.dll
C:\WINDOWS\system32\ktelrgqw.dll
C:\WINDOWS\system32\kunkqcpm.dll
C:\WINDOWS\system32\kwyniyao.dll
C:\WINDOWS\system32\lakgahvi.dll
C:\WINDOWS\system32\llaocuih.dll
C:\WINDOWS\system32\llkcyatg.dll
C:\WINDOWS\system32\llqcyhtd.dll
C:\WINDOWS\system32\lnfiwpbi.dll
C:\WINDOWS\system32\lnhqtcek.dll
C:\WINDOWS\system32\lqhxdjev.dll
C:\WINDOWS\system32\lsbcxcte.dll
C:\WINDOWS\system32\lsltdsbu.dll
C:\WINDOWS\system32\lwxdulsr.dll
C:\WINDOWS\system32\lxrwsptw.dll
C:\WINDOWS\system32\lypwlvew.dll
C:\WINDOWS\system32\mchdxtkc.dll
C:\WINDOWS\system32\mhpcthsj.dll
C:\WINDOWS\system32\mkugckev.dll
C:\WINDOWS\system32\msqnbloa.ini
C:\WINDOWS\system32\mumuogoc.dll
C:\WINDOWS\system32\muurjqej.dll
C:\WINDOWS\system32\nhytjdrf.dll
C:\WINDOWS\system32\nixidkvv.dll
C:\WINDOWS\system32\njrgkalu.dll
C:\WINDOWS\system32\njsrytfc.dll
C:\WINDOWS\system32\nrwqsejx.dll
C:\WINDOWS\system32\ntleqalc.dll
C:\WINDOWS\system32\nxhlvpnx.dll
C:\WINDOWS\system32\oboaiusp.dll
C:\WINDOWS\system32\obxlhxcd.dll
C:\WINDOWS\system32\ofxslooc.dll
C:\WINDOWS\system32\ohrpbxnt.dll
C:\WINDOWS\system32\oiyftbeo.dll
C:\WINDOWS\system32\okmbhwxw.dll
C:\WINDOWS\system32\okwkupbq.dll
C:\WINDOWS\system32\omwlnmni.dll
C:\WINDOWS\system32\oofttdcn.dll
C:\WINDOWS\system32\opluigkc.dll
C:\WINDOWS\system32\opsbplfe.dll
C:\WINDOWS\system32\oqepvkbg.dll
C:\WINDOWS\system32\oqkvcvru.dll
C:\WINDOWS\system32\orqoqgye.dll
C:\WINDOWS\system32\osmjabir.dll
C:\WINDOWS\system32\pbwaikrk.dll
C:\WINDOWS\system32\pcxtrxyd.dll
C:\WINDOWS\system32\pdcvaxjr.dll
C:\WINDOWS\system32\phkblrnd.dll
C:\WINDOWS\system32\pinsyoye.dll
C:\WINDOWS\system32\pjjkfbgu.dll
C:\WINDOWS\system32\pkdbjbem.dll
C:\WINDOWS\system32\pkqvefcd.dll
C:\WINDOWS\system32\plxyilft.dll
C:\WINDOWS\system32\pmfcxchv.dll
C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\poxmdmxq.dll
C:\WINDOWS\system32\psjtjemk.dll
C:\WINDOWS\system32\pvpvmjrg.dll
C:\WINDOWS\system32\pyhgrqty.dll
C:\WINDOWS\system32\qdfdaboi.dll
C:\WINDOWS\system32\qfiyphvh.dll
C:\WINDOWS\system32\qhbyxxnc.dll
C:\WINDOWS\system32\qkcwebxa.dll
C:\WINDOWS\system32\qojtipxi.dll
C:\WINDOWS\system32\qomlsuiw.dll
C:\WINDOWS\system32\qoxudpqu.dll
C:\WINDOWS\system32\qqxdrepy.dll
C:\WINDOWS\system32\queygmmy.dll
C:\WINDOWS\system32\raktioyu.dll
C:\WINDOWS\system32\raqdgcec.dll
C:\WINDOWS\system32\rbnecpcn.dll
C:\WINDOWS\system32\rcqsocfy.dll
C:\WINDOWS\system32\rdfeolpd.dll
C:\WINDOWS\system32\rehhinbq.dll
C:\WINDOWS\system32\rfxutiin.dll
C:\WINDOWS\system32\rknqocve.dll
C:\WINDOWS\system32\rmktgpma.dll
C:\WINDOWS\system32\rultphei.dll
C:\WINDOWS\system32\rvcmhjye.dll
C:\WINDOWS\system32\rwxfvrhy.dll
C:\WINDOWS\system32\ryqewmyp.dll
C:\WINDOWS\system32\sdltwqcl.dll
C:\WINDOWS\system32\seacfsdf.dll
C:\WINDOWS\system32\sjajlfcm.dll
C:\WINDOWS\system32\slmxkgwr.dll
C:\WINDOWS\system32\solenyec.dll
C:\WINDOWS\system32\sopoajfq.dll
C:\WINDOWS\system32\sqxxifhj.dll
C:\WINDOWS\system32\srekyjnp.dll
C:\WINDOWS\system32\suxjemtp.dll
C:\WINDOWS\system32\swxjmoud.dll
C:\WINDOWS\system32\taqfjjjb.dll
C:\WINDOWS\system32\tbfbjpcv.dll
C:\WINDOWS\system32\tdvhnotp.dll
C:\WINDOWS\system32\tikeplxe.dll
C:\WINDOWS\system32\tjgvkbvo.dll
C:\WINDOWS\system32\tlupuule.dll
C:\WINDOWS\system32\tmatduff.dll
C:\WINDOWS\system32\todgyohw.dll
C:\WINDOWS\system32\tuuqjyek.dll
C:\WINDOWS\system32\twsbgmhw.dll
C:\WINDOWS\system32\txeujawj.dll
C:\WINDOWS\system32\tydfqaui.dll
C:\WINDOWS\system32\ucoabfmo.dll
C:\WINDOWS\system32\ucxwuhjg.dll
C:\WINDOWS\system32\ufjjejri.dll
C:\WINDOWS\system32\uhadvepg.dll
C:\WINDOWS\system32\uhasmsxv.dll
C:\WINDOWS\system32\uhcokfmx.dll
C:\WINDOWS\system32\uheupxnx.dll
C:\WINDOWS\system32\uhweoisi.dll
C:\WINDOWS\system32\uhxjijiw.dll
C:\WINDOWS\system32\uiagfdow.dll
C:\WINDOWS\system32\ujdjyepi.dll
C:\WINDOWS\system32\ujgovkkn.dll
C:\WINDOWS\system32\utijrhmh.dll
C:\WINDOWS\system32\vbgmxxgt.dll
C:\WINDOWS\system32\vkipblot.dll
C:\WINDOWS\system32\vlwkmusq.dll
C:\WINDOWS\system32\vmhyigge.dll
C:\WINDOWS\system32\vnglixoh.dll
C:\WINDOWS\system32\vouwacxj.dll
C:\WINDOWS\system32\vptrxgum.dll
C:\WINDOWS\system32\vqbnrtxy.dll
C:\WINDOWS\system32\vrxfgtvo.dll
C:\WINDOWS\system32\vuqwqaad.dll
C:\WINDOWS\system32\vvrjlqyh.dll
C:\windows\system32\vwbluknx.dll
C:\WINDOWS\system32\vwsgpmkb.dll
C:\WINDOWS\system32\vxthpbrf.dll
C:\WINDOWS\system32\wadvoken.dll
C:\WINDOWS\system32\waojyofo.dll
C:\WINDOWS\system32\wiccnujs.dll
C:\WINDOWS\system32\wiymahlb.dll
C:\WINDOWS\system32\wkorbgem.dll
C:\WINDOWS\system32\wljwsvdp.dll
C:\WINDOWS\system32\womridbk.dll
C:\WINDOWS\system32\wrxqbinr.dll
C:\WINDOWS\system32\wtgksfah.dll
C:\WINDOWS\system32\wtlonxif.dll
C:\WINDOWS\system32\wvyglppc.dll
C:\WINDOWS\system32\wybmpogt.dll
C:\WINDOWS\system32\wytssvbo.dll
C:\WINDOWS\system32\xamsuqhh.dll
C:\WINDOWS\system32\xbnqocjo.dll
C:\WINDOWS\system32\xbshvbex.dll
C:\WINDOWS\system32\xedwwaod.dll
C:\WINDOWS\system32\xeljocyh.dll
C:\WINDOWS\system32\xiefuihy.dll
C:\WINDOWS\system32\xktqmicq.dll
C:\WINDOWS\system32\xnwwxpfv.dll
C:\WINDOWS\system32\xoeanguk.dll
C:\WINDOWS\system32\xrulqnox.dll
C:\WINDOWS\system32\xvmwrohp.dll
C:\WINDOWS\system32\xyiscdom.dll
C:\WINDOWS\system32\yaqjlpvj.dll
C:\WINDOWS\system32\yearfsjh.dll
C:\WINDOWS\system32\yemgsvoy.dll
C:\WINDOWS\system32\yffnmgii.dll
C:\WINDOWS\system32\yfrmojba.dll
C:\WINDOWS\system32\yisdjthv.dll
C:\WINDOWS\system32\yjcescmp.dll
C:\WINDOWS\system32\yjmwteic.dll
C:\WINDOWS\system32\ykirhuvc.dll
C:\WINDOWS\system32\yoooxcuc.dll
C:\WINDOWS\system32\yovovkbw.dll
C:\WINDOWS\system32\ytalepdb.dll
C:\WINDOWS\system32\yxhhdamp.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\abpjuqwy.dll
C:\WINDOWS\system32\abpjuqwy.dll Has been deleted!

Attempting to delete C:\windows\system32\agsqdpdf.dll
C:\windows\system32\agsqdpdf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\akejuixi.dll
C:\WINDOWS\system32\akejuixi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\amvxtree.dll
C:\WINDOWS\system32\amvxtree.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aolbnqsm.dll
C:\WINDOWS\system32\aolbnqsm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\assxcxkp.dll
C:\WINDOWS\system32\assxcxkp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aubrjekg.dll
C:\WINDOWS\system32\aubrjekg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\avkpitwa.dll
C:\WINDOWS\system32\avkpitwa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\avoccjqd.dll
C:\WINDOWS\system32\avoccjqd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\axekxeag.dll
C:\WINDOWS\system32\axekxeag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bhibdfum.dll
C:\WINDOWS\system32\bhibdfum.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bibjntjn.dll
C:\WINDOWS\system32\bibjntjn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bjeyyfea.dll
C:\WINDOWS\system32\bjeyyfea.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\blvtlmry.dll
C:\WINDOWS\system32\blvtlmry.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\btwxkvya.dll
C:\WINDOWS\system32\btwxkvya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvpvsmqj.dll
C:\WINDOWS\system32\bvpvsmqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvufhsra.dll
C:\WINDOWS\system32\bvufhsra.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvysdbam.dll
C:\WINDOWS\system32\bvysdbam.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bxcfnlnw.dll
C:\WINDOWS\system32\bxcfnlnw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bydlxnnc.dll
C:\WINDOWS\system32\bydlxnnc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byyqwpjg.dll
C:\WINDOWS\system32\byyqwpjg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ccavuebg.dll
C:\WINDOWS\system32\ccavuebg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cejxjkmm.dll
C:\WINDOWS\system32\cejxjkmm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfntahck.dll
C:\WINDOWS\system32\cfntahck.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cgqehgdg.dll
C:\WINDOWS\system32\cgqehgdg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\clcuqdkv.dll
C:\WINDOWS\system32\clcuqdkv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cnujmjsq.dll
C:\WINDOWS\system32\cnujmjsq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\crfrdueq.dll
C:\WINDOWS\system32\crfrdueq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\crvjmxkg.dll
C:\WINDOWS\system32\crvjmxkg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cstvrxbr.dll
C:\WINDOWS\system32\cstvrxbr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cyoqpyco.dll
C:\WINDOWS\system32\cyoqpyco.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dakkwghb.dll
C:\WINDOWS\system32\dakkwghb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\deavehfq.dll
C:\WINDOWS\system32\deavehfq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dffekvhm.dll
C:\WINDOWS\system32\dffekvhm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dififgib.dll
C:\WINDOWS\system32\dififgib.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dlocxckr.dll
C:\WINDOWS\system32\dlocxckr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dmulefhp.dll
C:\WINDOWS\system32\dmulefhp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dolmbmrc.dll
C:\WINDOWS\system32\dolmbmrc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\douhroue.ini
C:\WINDOWS\system32\douhroue.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dqyejkbs.dll
C:\WINDOWS\system32\dqyejkbs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\drlwpdbh.dll
C:\WINDOWS\system32\drlwpdbh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtaowlwk.dll
C:\WINDOWS\system32\dtaowlwk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtdmdnxa.dll
C:\WINDOWS\system32\dtdmdnxa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtogriby.dll
C:\WINDOWS\system32\dtogriby.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dvvnvbqe.dll
C:\WINDOWS\system32\dvvnvbqe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dwlxsjqt.dll
C:\WINDOWS\system32\dwlxsjqt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dxiybtfb.dll
C:\WINDOWS\system32\dxiybtfb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ebuuhopn.dll
C:\WINDOWS\system32\ebuuhopn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eccolsbr.dll
C:\WINDOWS\system32\eccolsbr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ehewrrxx.dll
C:\WINDOWS\system32\ehewrrxx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\emnsopyr.dll
C:\WINDOWS\system32\emnsopyr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eoovrnit.dll
C:\WINDOWS\system32\eoovrnit.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\epdpmthg.dll
C:\WINDOWS\system32\epdpmthg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eqwnqypa.dll
C:\WINDOWS\system32\eqwnqypa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ermimpcw.dll
C:\WINDOWS\system32\ermimpcw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\euorhuod.dll
C:\WINDOWS\system32\euorhuod.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fjjefpix.dll
C:\WINDOWS\system32\fjjefpix.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fmiggojd.dll
C:\WINDOWS\system32\fmiggojd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\frashidj.dll
C:\WINDOWS\system32\frashidj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fvoashnf.dll
C:\WINDOWS\system32\fvoashnf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fyyaucps.dll
C:\WINDOWS\system32\fyyaucps.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gbqcrlpj.dll
C:\WINDOWS\system32\gbqcrlpj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gclucwop.dll
C:\WINDOWS\system32\gclucwop.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gdggjhge.dll
C:\WINDOWS\system32\gdggjhge.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gdhemxch.dll
C:\WINDOWS\system32\gdhemxch.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gfkdjeyx.dll
C:\WINDOWS\system32\gfkdjeyx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ghisfvjj.dll
C:\WINDOWS\system32\ghisfvjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ghjrdynb.dll
C:\WINDOWS\system32\ghjrdynb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjagsudt.dll
C:\WINDOWS\system32\gjagsudt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjpwqyyb.ini
C:\WINDOWS\system32\gjpwqyyb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjyqywjb.dll
C:\WINDOWS\system32\gjyqywjb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gkxmjvrc.ini
C:\WINDOWS\system32\gkxmjvrc.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\goakwwek.dll
C:\WINDOWS\system32\goakwwek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gtcxixho.dll
C:\WINDOWS\system32\gtcxixho.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\guknumpo.dll
C:\WINDOWS\system32\guknumpo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gxbsmpcc.dll
C:\WINDOWS\system32\gxbsmpcc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hbyejemg.dll
C:\WINDOWS\system32\hbyejemg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hdqicfen.dll
C:\WINDOWS\system32\hdqicfen.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hkygbkag.dll
C:\WINDOWS\system32\hkygbkag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hpybvxyd.dll
C:\WINDOWS\system32\hpybvxyd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hsqxbogj.dll
C:\WINDOWS\system32\hsqxbogj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hvuaenoj.dll
C:\WINDOWS\system32\hvuaenoj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hxlqaalo.dll
C:\WINDOWS\system32\hxlqaalo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hyipoveq.dll
C:\WINDOWS\system32\hyipoveq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\icbpjpgi.dll
C:\WINDOWS\system32\icbpjpgi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ielxawgl.dll
C:\WINDOWS\system32\ielxawgl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ijjscrty.dll
C:\WINDOWS\system32\ijjscrty.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\inbjpfjm.dll
C:\WINDOWS\system32\inbjpfjm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iocysrus.dll
C:\WINDOWS\system32\iocysrus.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ithridxr.dll
C:\WINDOWS\system32\ithridxr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\itkrpmhu.dll
C:\WINDOWS\system32\itkrpmhu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iuwkvvyk.dll
C:\WINDOWS\system32\iuwkvvyk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ivxbvnmm.dll
C:\WINDOWS\system32\ivxbvnmm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iydcithw.dll
C:\WINDOWS\system32\iydcithw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iyyywtgf.dll
C:\WINDOWS\system32\iyyywtgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jbdbasst.dll
C:\WINDOWS\system32\jbdbasst.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jdtxsptk.dll
C:\WINDOWS\system32\jdtxsptk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jimuluya.dll
C:\WINDOWS\system32\jimuluya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jirukuxi.dll
C:\WINDOWS\system32\jirukuxi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jnomampe.dll
C:\WINDOWS\system32\jnomampe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\joepfivk.dll
C:\WINDOWS\system32\joepfivk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jqsrywvv.dll
C:\WINDOWS\system32\jqsrywvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jriyukse.dll
C:\WINDOWS\system32\jriyukse.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jsipjfqo.dll
C:\WINDOWS\system32\jsipjfqo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jsrhxjnl.dll
C:\WINDOWS\system32\jsrhxjnl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jvduouag.dll
C:\WINDOWS\system32\jvduouag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jvxehlxm.dll
C:\WINDOWS\system32\jvxehlxm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jwqbtmyl.dll
C:\WINDOWS\system32\jwqbtmyl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kawfihja.dll
C:\WINDOWS\system32\kawfihja.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kddcsotj.dll
C:\WINDOWS\system32\kddcsotj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\keuspuhf.dll
C:\WINDOWS\system32\keuspuhf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\klojpnch.dll
C:\WINDOWS\system32\klojpnch.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kmggsexv.dll
C:\WINDOWS\system32\kmggsexv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\koimffgb.dll
C:\WINDOWS\system32\koimffgb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kokavygf.dll
C:\WINDOWS\system32\kokavygf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kqoymksq.dll
C:\WINDOWS\system32\kqoymksq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\krcidbnf.dll
C:\WINDOWS\system32\krcidbnf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kswxwtxk.dll
C:\WINDOWS\system32\kswxwtxk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ktelrgqw.dll
C:\WINDOWS\system32\ktelrgqw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kunkqcpm.dll
C:\WINDOWS\system32\kunkqcpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kwyniyao.dll
C:\WINDOWS\system32\kwyniyao.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lakgahvi.dll
C:\WINDOWS\system32\lakgahvi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llaocuih.dll
C:\WINDOWS\system32\llaocuih.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llkcyatg.dll
C:\WINDOWS\system32\llkcyatg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llqcyhtd.dll
C:\WINDOWS\system32\llqcyhtd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lnfiwpbi.dll
C:\WINDOWS\system32\lnfiwpbi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lnhqtcek.dll
C:\WINDOWS\system32\lnhqtcek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lqhxdjev.dll
C:\WINDOWS\system32\lqhxdjev.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lsbcxcte.dll
C:\WINDOWS\system32\lsbcxcte.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lsltdsbu.dll
C:\WINDOWS\system32\lsltdsbu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lwxdulsr.dll
C:\WINDOWS\system32\lwxdulsr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lxrwsptw.dll
C:\WINDOWS\system32\lxrwsptw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lypwlvew.dll
C:\WINDOWS\system32\lypwlvew.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mchdxtkc.dll
C:\WINDOWS\system32\mchdxtkc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mhpcthsj.dll
C:\WINDOWS\system32\mhpcthsj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mkugckev.dll
C:\WINDOWS\system32\mkugckev.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\msqnbloa.ini
C:\WINDOWS\system32\msqnbloa.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mumuogoc.dll
C:\WINDOWS\system32\mumuogoc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\muurjqej.dll
C:\WINDOWS\system32\muurjqej.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nhytjdrf.dll
C:\WINDOWS\system32\nhytjdrf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nixidkvv.dll
C:\WINDOWS\system32\nixidkvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\njrgkalu.dll
C:\WINDOWS\system32\njrgkalu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\njsrytfc.dll
C:\WINDOWS\system32\njsrytfc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nrwqsejx.dll
C:\WINDOWS\system32\nrwqsejx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ntleqalc.dll
C:\WINDOWS\system32\ntleqalc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nxhlvpnx.dll
C:\WINDOWS\system32\nxhlvpnx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oboaiusp.dll
C:\WINDOWS\system32\oboaiusp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\obxlhxcd.dll
C:\WINDOWS\system32\obxlhxcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ofxslooc.dll
C:\WINDOWS\system32\ofxslooc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ohrpbxnt.dll
C:\WINDOWS\system32\ohrpbxnt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oiyftbeo.dll
C:\WINDOWS\system32\oiyftbeo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\okmbhwxw.dll
C:\WINDOWS\system32\okmbhwxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\okwkupbq.dll
C:\WINDOWS\system32\okwkupbq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\omwlnmni.dll
C:\WINDOWS\system32\omwlnmni.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oofttdcn.dll
C:\WINDOWS\system32\oofttdcn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opluigkc.dll
C:\WINDOWS\system32\opluigkc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opsbplfe.dll
C:\WINDOWS\system32\opsbplfe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oqepvkbg.dll
C:\WINDOWS\system32\oqepvkbg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oqkvcvru.dll
C:\WINDOWS\system32\oqkvcvru.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\orqoqgye.dll
C:\WINDOWS\system32\orqoqgye.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\osmjabir.dll
C:\WINDOWS\system32\osmjabir.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pbwaikrk.dll
C:\WINDOWS\system32\pbwaikrk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pcxtrxyd.dll
C:\WINDOWS\system32\pcxtrxyd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pdcvaxjr.dll
C:\WINDOWS\system32\pdcvaxjr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\phkblrnd.dll
C:\WINDOWS\system32\phkblrnd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pinsyoye.dll
C:\WINDOWS\system32\pinsyoye.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\pjjkfbgu.dll
C:\WINDOWS\system32\pjjkfbgu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pkdbjbem.dll
C:\WINDOWS\system32\pkdbjbem.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pkqvefcd.dll
C:\WINDOWS\system32\pkqvefcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\plxyilft.dll
C:\WINDOWS\system32\plxyilft.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmfcxchv.dll
C:\WINDOWS\system32\pmfcxchv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\pmkhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\poxmdmxq.dll
C:\WINDOWS\system32\poxmdmxq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\psjtjemk.dll
C:\WINDOWS\system32\psjtjemk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pvpvmjrg.dll
C:\WINDOWS\system32\pvpvmjrg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pyhgrqty.dll
C:\WINDOWS\system32\pyhgrqty.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qdfdaboi.dll
C:\WINDOWS\system32\qdfdaboi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qfiyphvh.dll
C:\WINDOWS\system32\qfiyphvh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qhbyxxnc.dll
C:\WINDOWS\system32\qhbyxxnc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qkcwebxa.dll
C:\WINDOWS\system32\qkcwebxa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qojtipxi.dll
C:\WINDOWS\system32\qojtipxi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomlsuiw.dll
C:\WINDOWS\system32\qomlsuiw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qoxudpqu.dll
C:\WINDOWS\system32\qoxudpqu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qqxdrepy.dll
C:\WINDOWS\system32\qqxdrepy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\queygmmy.dll
C:\WINDOWS\system32\queygmmy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\raktioyu.dll
C:\WINDOWS\system32\raktioyu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\raqdgcec.dll
C:\WINDOWS\system32\raqdgcec.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rbnecpcn.dll
C:\WINDOWS\system32\rbnecpcn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rcqsocfy.dll
C:\WINDOWS\system32\rcqsocfy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rdfeolpd.dll
C:\WINDOWS\system32\rdfeolpd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rehhinbq.dll
C:\WINDOWS\system32\rehhinbq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rfxutiin.dll
C:\WINDOWS\system32\rfxutiin.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rknqocve.dll
C:\WINDOWS\system32\rknqocve.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rmktgpma.dll
C:\WINDOWS\system32\rmktgpma.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rultphei.dll
C:\WINDOWS\system32\rultphei.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rvcmhjye.dll
C:\WINDOWS\system32\rvcmhjye.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rwxfvrhy.dll
C:\WINDOWS\system32\rwxfvrhy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ryqewmyp.dll
C:\WINDOWS\system32\ryqewmyp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sdltwqcl.dll
C:\WINDOWS\system32\sdltwqcl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\seacfsdf.dll
C:\WINDOWS\system32\seacfsdf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sjajlfcm.dll
C:\WINDOWS\system32\sjajlfcm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\slmxkgwr.dll
C:\WINDOWS\system32\slmxkgwr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\solenyec.dll
C:\WINDOWS\system32\solenyec.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sopoajfq.dll
C:\WINDOWS\system32\sopoajfq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sqxxifhj.dll
C:\WINDOWS\system32\sqxxifhj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\srekyjnp.dll
C:\WINDOWS\system32\srekyjnp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\suxjemtp.dll
C:\WINDOWS\system32\suxjemtp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\swxjmoud.dll
C:\WINDOWS\system32\swxjmoud.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\taqfjjjb.dll
C:\WINDOWS\system32\taqfjjjb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tbfbjpcv.dll
C:\WINDOWS\system32\tbfbjpcv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tdvhnotp.dll
C:\WINDOWS\system32\tdvhnotp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tikeplxe.dll
C:\WINDOWS\system32\tikeplxe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tjgvkbvo.dll
C:\WINDOWS\system32\tjgvkbvo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tlupuule.dll
C:\WINDOWS\system32\tlupuule.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmatduff.dll
C:\WINDOWS\system32\tmatduff.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\todgyohw.dll
C:\WINDOWS\system32\todgyohw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuuqjyek.dll
C:\WINDOWS\system32\tuuqjyek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\twsbgmhw.dll
C:\WINDOWS\system32\twsbgmhw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\txeujawj.dll
C:\WINDOWS\system32\txeujawj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tydfqaui.dll
C:\WINDOWS\system32\tydfqaui.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ucoabfmo.dll
C:\WINDOWS\system32\ucoabfmo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ucxwuhjg.dll
C:\WINDOWS\system32\ucxwuhjg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ufjjejri.dll
C:\WINDOWS\system32\ufjjejri.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhadvepg.dll
C:\WINDOWS\system32\uhadvepg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhasmsxv.dll
C:\WINDOWS\system32\uhasmsxv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhcokfmx.dll
C:\WINDOWS\system32\uhcokfmx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uheupxnx.dll
C:\WINDOWS\system32\uheupxnx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhweoisi.dll
C:\WINDOWS\system32\uhweoisi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhxjijiw.dll
C:\WINDOWS\system32\uhxjijiw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uiagfdow.dll
C:\WINDOWS\system32\uiagfdow.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ujdjyepi.dll
C:\WINDOWS\system32\ujdjyepi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ujgovkkn.dll
C:\WINDOWS\system32\ujgovkkn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\utijrhmh.dll
C:\WINDOWS\system32\utijrhmh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vbgmxxgt.dll
C:\WINDOWS\system32\vbgmxxgt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vkipblot.dll
C:\WINDOWS\system32\vkipblot.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vlwkmusq.dll
C:\WINDOWS\system32\vlwkmusq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vmhyigge.dll
C:\WINDOWS\system32\vmhyigge.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vnglixoh.dll
C:\WINDOWS\system32\vnglixoh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vouwacxj.dll
C:\WINDOWS\system32\vouwacxj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vptrxgum.dll
C:\WINDOWS\system32\vptrxgum.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vqbnrtxy.dll
C:\WINDOWS\system32\vqbnrtxy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vrxfgtvo.dll
C:\WINDOWS\system32\vrxfgtvo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vuqwqaad.dll
C:\WINDOWS\system32\vuqwqaad.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vvrjlqyh.dll
C:\WINDOWS\system32\vvrjlqyh.dll Has been deleted!

Attempting to delete C:\windows\system32\vwbluknx.dll
C:\windows\system32\vwbluknx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vwsgpmkb.dll
C:\WINDOWS\system32\vwsgpmkb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vxthpbrf.dll
C:\WINDOWS\system32\vxthpbrf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wadvoken.dll
C:\WINDOWS\system32\wadvoken.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\waojyofo.dll
C:\WINDOWS\system32\waojyofo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wiccnujs.dll
C:\WINDOWS\system32\wiccnujs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wiymahlb.dll
C:\WINDOWS\system32\wiymahlb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wkorbgem.dll
C:\WINDOWS\system32\wkorbgem.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wljwsvdp.dll
C:\WINDOWS\system32\wljwsvdp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\womridbk.dll
C:\WINDOWS\system32\womridbk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wrxqbinr.dll
C:\WINDOWS\system32\wrxqbinr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wtgksfah.dll
C:\WINDOWS\system32\wtgksfah.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wtlonxif.dll
C:\WINDOWS\system32\wtlonxif.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvyglppc.dll
C:\WINDOWS\system32\wvyglppc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wybmpogt.dll
C:\WINDOWS\system32\wybmpogt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wytssvbo.dll
C:\WINDOWS\system32\wytssvbo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xamsuqhh.dll
C:\WINDOWS\system32\xamsuqhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbnqocjo.dll
C:\WINDOWS\system32\xbnqocjo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbshvbex.dll
C:\WINDOWS\system32\xbshvbex.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xedwwaod.dll
C:\WINDOWS\system32\xedwwaod.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xeljocyh.dll
C:\WINDOWS\system32\xeljocyh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xiefuihy.dll
C:\WINDOWS\system32\xiefuihy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xktqmicq.dll
C:\WINDOWS\system32\xktqmicq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xnwwxpfv.dll
C:\WINDOWS\system32\xnwwxpfv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xoeanguk.dll
C:\WINDOWS\system32\xoeanguk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xrulqnox.dll
C:\WINDOWS\system32\xrulqnox.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xvmwrohp.dll
C:\WINDOWS\system32\xvmwrohp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xyiscdom.dll
C:\WINDOWS\system32\xyiscdom.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yaqjlpvj.dll
C:\WINDOWS\system32\yaqjlpvj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yearfsjh.dll
C:\WINDOWS\system32\yearfsjh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yemgsvoy.dll
C:\WINDOWS\system32\yemgsvoy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yffnmgii.dll
C:\WINDOWS\system32\yffnmgii.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yfrmojba.dll
C:\WINDOWS\system32\yfrmojba.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yisdjthv.dll
C:\WINDOWS\system32\yisdjthv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yjcescmp.dll
C:\WINDOWS\system32\yjcescmp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yjmwteic.dll
C:\WINDOWS\system32\yjmwteic.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ykirhuvc.dll
C:\WINDOWS\system32\ykirhuvc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yoooxcuc.dll
C:\WINDOWS\system32\yoooxcuc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yovovkbw.dll
C:\WINDOWS\system32\yovovkbw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ytalepdb.dll
C:\WINDOWS\system32\ytalepdb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yxhhdamp.dll
C:\WINDOWS\system32\yxhhdamp.dll Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\WINDOWS\system32\pinsyoye.dll
C:\WINDOWS\system32\pinsyoye.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 12:28:27 PM 12/24/2007

Listing files found while scanning….

No infected files were found.


VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 7:41:55 PM 12/24/2007

Listing files found while scanning….

C:\WINDOWS\system32\abpjuqwy.dll
C:\WINDOWS\system32\agntwrxl.dll
C:\windows\system32\agsqdpdf.dll
C:\WINDOWS\system32\akejuixi.dll
C:\WINDOWS\system32\amvxtree.dll
C:\WINDOWS\system32\aolbnqsm.dll
C:\WINDOWS\system32\assxcxkp.dll
C:\WINDOWS\system32\aubrjekg.dll
C:\WINDOWS\system32\avkpitwa.dll
C:\WINDOWS\system32\avoccjqd.dll
C:\WINDOWS\system32\axekxeag.dll
C:\WINDOWS\system32\bhibdfum.dll
C:\WINDOWS\system32\bibjntjn.dll
C:\WINDOWS\system32\bjeyyfea.dll
C:\WINDOWS\system32\blvtlmry.dll
C:\WINDOWS\system32\btwxkvya.dll
C:\WINDOWS\system32\bvpvsmqj.dll
C:\WINDOWS\system32\bvufhsra.dll
C:\WINDOWS\system32\bvysdbam.dll
C:\WINDOWS\system32\bxcfnlnw.dll
C:\WINDOWS\system32\bydlxnnc.dll
C:\WINDOWS\system32\byyqwpjg.dll
C:\WINDOWS\system32\ccavuebg.dll
C:\WINDOWS\system32\cejxjkmm.dll
C:\WINDOWS\system32\cfntahck.dll
C:\WINDOWS\system32\cgqehgdg.dll
C:\WINDOWS\system32\clcuqdkv.dll
C:\WINDOWS\system32\cnujmjsq.dll
C:\WINDOWS\system32\crfrdueq.dll
C:\WINDOWS\system32\crvjmxkg.dll
C:\WINDOWS\system32\cstvrxbr.dll
C:\WINDOWS\system32\cyoqpyco.dll
C:\WINDOWS\system32\dakkwghb.dll
C:\WINDOWS\system32\deavehfq.dll
C:\WINDOWS\system32\dffekvhm.dll
C:\WINDOWS\system32\dififgib.dll
C:\WINDOWS\system32\dlocxckr.dll
C:\WINDOWS\system32\dmulefhp.dll
C:\WINDOWS\system32\dolmbmrc.dll
C:\WINDOWS\system32\douhroue.ini
C:\WINDOWS\system32\dqyejkbs.dll
C:\WINDOWS\system32\drlwpdbh.dll
C:\WINDOWS\system32\dtaowlwk.dll
C:\WINDOWS\system32\dtdmdnxa.dll
C:\WINDOWS\system32\dtogriby.dll
C:\WINDOWS\system32\dvvnvbqe.dll
C:\WINDOWS\system32\dwlxsjqt.dll
C:\WINDOWS\system32\dxiybtfb.dll
C:\WINDOWS\system32\ebuuhopn.dll
C:\WINDOWS\system32\eccolsbr.dll
C:\WINDOWS\system32\ehewrrxx.dll
C:\WINDOWS\system32\emnsopyr.dll
C:\WINDOWS\system32\eoovrnit.dll
C:\WINDOWS\system32\epdpmthg.dll
C:\WINDOWS\system32\eqwnqypa.dll
C:\WINDOWS\system32\ermimpcw.dll
C:\WINDOWS\system32\euorhuod.dll
C:\WINDOWS\system32\fjjefpix.dll
C:\WINDOWS\system32\fmiggojd.dll
C:\WINDOWS\system32\frashidj.dll
C:\WINDOWS\system32\fvoashnf.dll
C:\WINDOWS\system32\fyyaucps.dll
C:\WINDOWS\system32\gbqcrlpj.dll
C:\WINDOWS\system32\gclucwop.dll
C:\WINDOWS\system32\gdggjhge.dll
C:\WINDOWS\system32\gdhemxch.dll
C:\WINDOWS\system32\gfkdjeyx.dll
C:\WINDOWS\system32\ghisfvjj.dll
C:\WINDOWS\system32\ghjrdynb.dll
C:\WINDOWS\system32\gjagsudt.dll
C:\WINDOWS\system32\gjpwqyyb.ini
C:\WINDOWS\system32\gjyqywjb.dll
C:\WINDOWS\system32\gkxmjvrc.ini
C:\WINDOWS\system32\goakwwek.dll
C:\WINDOWS\system32\gtcxixho.dll
C:\WINDOWS\system32\guknumpo.dll
C:\WINDOWS\system32\gxbsmpcc.dll
C:\WINDOWS\system32\hbyejemg.dll
C:\WINDOWS\system32\hdqicfen.dll
C:\WINDOWS\system32\hkygbkag.dll
C:\WINDOWS\system32\hpybvxyd.dll
C:\WINDOWS\system32\hsqxbogj.dll
C:\WINDOWS\system32\hvuaenoj.dll
C:\WINDOWS\system32\hxlqaalo.dll
C:\WINDOWS\system32\hyipoveq.dll
C:\WINDOWS\system32\icbpjpgi.dll
C:\WINDOWS\system32\ielxawgl.dll
C:\WINDOWS\system32\ijjscrty.dll
C:\WINDOWS\system32\inbjpfjm.dll
C:\WINDOWS\system32\iocysrus.dll
C:\WINDOWS\system32\ithridxr.dll
C:\WINDOWS\system32\itkrpmhu.dll
C:\WINDOWS\system32\iuwkvvyk.dll
C:\WINDOWS\system32\ivxbvnmm.dll
C:\WINDOWS\system32\iydcithw.dll
C:\WINDOWS\system32\iyyywtgf.dll
C:\WINDOWS\system32\jbdbasst.dll
C:\WINDOWS\system32\jdtxsptk.dll
C:\WINDOWS\system32\jimuluya.dll
C:\WINDOWS\system32\jirukuxi.dll
C:\WINDOWS\system32\jnomampe.dll
C:\WINDOWS\system32\joepfivk.dll
C:\WINDOWS\system32\jqsrywvv.dll
C:\WINDOWS\system32\jriyukse.dll
C:\WINDOWS\system32\jsipjfqo.dll
C:\WINDOWS\system32\jsrhxjnl.dll
C:\WINDOWS\system32\jvduouag.dll
C:\WINDOWS\system32\jvxehlxm.dll
C:\WINDOWS\system32\jwqbtmyl.dll
C:\WINDOWS\system32\kawfihja.dll
C:\WINDOWS\system32\kddcsotj.dll
C:\WINDOWS\system32\keuspuhf.dll
C:\WINDOWS\system32\klojpnch.dll
C:\WINDOWS\system32\kmggsexv.dll
C:\WINDOWS\system32\koimffgb.dll
C:\WINDOWS\system32\kokavygf.dll
C:\WINDOWS\system32\kqoymksq.dll
C:\WINDOWS\system32\krcidbnf.dll
C:\WINDOWS\system32\kriokrjy.dll
C:\WINDOWS\system32\kswxwtxk.dll
C:\WINDOWS\system32\ktelrgqw.dll
C:\WINDOWS\system32\kunkqcpm.dll
C:\WINDOWS\system32\kwyniyao.dll
C:\WINDOWS\system32\lakgahvi.dll
C:\WINDOWS\system32\llaocuih.dll
C:\WINDOWS\system32\llkcyatg.dll
C:\WINDOWS\system32\llqcyhtd.dll
C:\WINDOWS\system32\lnfiwpbi.dll
C:\WINDOWS\system32\lnhqtcek.dll
C:\WINDOWS\system32\lqhxdjev.dll
C:\WINDOWS\system32\lsbcxcte.dll
C:\WINDOWS\system32\lsltdsbu.dll
C:\WINDOWS\system32\lwxdulsr.dll
C:\WINDOWS\system32\lxrwsptw.dll
C:\WINDOWS\system32\lxrwtnga.ini
C:\WINDOWS\system32\lypwlvew.dll
C:\WINDOWS\system32\mchdxtkc.dll
C:\WINDOWS\system32\mhpcthsj.dll
C:\WINDOWS\system32\mkugckev.dll
C:\WINDOWS\system32\msqnbloa.ini
C:\WINDOWS\system32\mumuogoc.dll
C:\WINDOWS\system32\muurjqej.dll
C:\WINDOWS\system32\nhytjdrf.dll
C:\WINDOWS\system32\nixidkvv.dll
C:\WINDOWS\system32\njrgkalu.dll
C:\WINDOWS\system32\njsrytfc.dll
C:\WINDOWS\system32\nrwqsejx.dll
C:\WINDOWS\system32\ntleqalc.dll
C:\WINDOWS\system32\nxhlvpnx.dll
C:\WINDOWS\system32\oboaiusp.dll
C:\WINDOWS\system32\obxlhxcd.dll
C:\WINDOWS\system32\ofxslooc.dll
C:\WINDOWS\system32\ohrpbxnt.dll
C:\WINDOWS\system32\oiyftbeo.dll
C:\WINDOWS\system32\okmbhwxw.dll
C:\WINDOWS\system32\okwkupbq.dll
C:\WINDOWS\system32\omwlnmni.dll
C:\WINDOWS\system32\oofttdcn.dll
C:\WINDOWS\system32\opluigkc.dll
C:\WINDOWS\system32\opsbplfe.dll
C:\WINDOWS\system32\oqepvkbg.dll
C:\WINDOWS\system32\oqkvcvru.dll
C:\WINDOWS\system32\orqoqgye.dll
C:\WINDOWS\system32\osmjabir.dll
C:\WINDOWS\system32\pbwaikrk.dll
C:\WINDOWS\system32\pcxtrxyd.dll
C:\WINDOWS\system32\pdcvaxjr.dll
C:\WINDOWS\system32\phkblrnd.dll
C:\WINDOWS\system32\pjjkfbgu.dll
C:\WINDOWS\system32\pkdbjbem.dll
C:\WINDOWS\system32\pkqvefcd.dll
C:\WINDOWS\system32\plxyilft.dll
C:\WINDOWS\system32\pmfcxchv.dll
C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\poxmdmxq.dll
C:\WINDOWS\system32\psjtjemk.dll
C:\WINDOWS\system32\pvpvmjrg.dll
C:\WINDOWS\system32\pyhgrqty.dll
C:\WINDOWS\system32\qdfdaboi.dll
C:\WINDOWS\system32\qfiyphvh.dll
C:\WINDOWS\system32\qhbyxxnc.dll
C:\WINDOWS\system32\qkcwebxa.dll
C:\WINDOWS\system32\qojtipxi.dll
C:\WINDOWS\system32\qomlsuiw.dll
C:\WINDOWS\system32\qoxudpqu.dll
C:\WINDOWS\system32\qqxdrepy.dll
C:\WINDOWS\system32\queygmmy.dll
C:\WINDOWS\system32\raktioyu.dll
C:\WINDOWS\system32\raqdgcec.dll
C:\WINDOWS\system32\rbnecpcn.dll
C:\WINDOWS\system32\rcqsocfy.dll
C:\WINDOWS\system32\rdfeolpd.dll
C:\WINDOWS\system32\rehhinbq.dll
C:\WINDOWS\system32\rfxutiin.dll
C:\WINDOWS\system32\rknqocve.dll
C:\WINDOWS\system32\rmktgpma.dll
C:\WINDOWS\system32\rultphei.dll
C:\WINDOWS\system32\rvcmhjye.dll
C:\WINDOWS\system32\rwxfvrhy.dll
C:\WINDOWS\system32\ryqewmyp.dll
C:\WINDOWS\system32\sdltwqcl.dll
C:\WINDOWS\system32\seacfsdf.dll
C:\WINDOWS\system32\sjajlfcm.dll
C:\WINDOWS\system32\slmxkgwr.dll
C:\WINDOWS\system32\solenyec.dll
C:\WINDOWS\system32\sopoajfq.dll
C:\WINDOWS\system32\sqxxifhj.dll
C:\WINDOWS\system32\srekyjnp.dll
C:\WINDOWS\system32\suxjemtp.dll
C:\WINDOWS\system32\swxjmoud.dll
C:\WINDOWS\system32\taqfjjjb.dll
C:\WINDOWS\system32\tbfbjpcv.dll
C:\WINDOWS\system32\tdvhnotp.dll
C:\WINDOWS\system32\tikeplxe.dll
C:\WINDOWS\system32\tlupuule.dll
C:\WINDOWS\system32\tmatduff.dll
C:\WINDOWS\system32\todgyohw.dll
C:\WINDOWS\system32\tuuqjyek.dll
C:\WINDOWS\system32\twsbgmhw.dll
C:\WINDOWS\system32\txeujawj.dll
C:\WINDOWS\system32\tydfqaui.dll
C:\WINDOWS\system32\ucoabfmo.dll
C:\WINDOWS\system32\ucxwuhjg.dll
C:\WINDOWS\system32\ufjjejri.dll
C:\WINDOWS\system32\uhadvepg.dll
C:\WINDOWS\system32\uhasmsxv.dll
C:\WINDOWS\system32\uhcokfmx.dll
C:\WINDOWS\system32\uheupxnx.dll
C:\WINDOWS\system32\uhweoisi.dll
C:\WINDOWS\system32\uhxjijiw.dll
C:\WINDOWS\system32\uiagfdow.dll
C:\WINDOWS\system32\ujdjyepi.dll
C:\WINDOWS\system32\ujgovkkn.dll
C:\WINDOWS\system32\utijrhmh.dll
C:\WINDOWS\system32\vbgmxxgt.dll
C:\WINDOWS\system32\vkipblot.dll
C:\WINDOWS\system32\vlwkmusq.dll
C:\WINDOWS\system32\vmhyigge.dll
C:\WINDOWS\system32\vnglixoh.dll
C:\WINDOWS\system32\vouwacxj.dll
C:\WINDOWS\system32\vptrxgum.dll
C:\WINDOWS\system32\vqbnrtxy.dll
C:\WINDOWS\system32\vrxfgtvo.dll
C:\WINDOWS\system32\vuqwqaad.dll
C:\WINDOWS\system32\vvrjlqyh.dll
C:\windows\system32\vwbluknx.dll
C:\WINDOWS\system32\vwsgpmkb.dll
C:\WINDOWS\system32\vxthpbrf.dll
C:\WINDOWS\system32\wadvoken.dll
C:\WINDOWS\system32\waojyofo.dll
C:\WINDOWS\system32\wiccnujs.dll
C:\WINDOWS\system32\wiymahlb.dll
C:\WINDOWS\system32\wkorbgem.dll
C:\WINDOWS\system32\wljwsvdp.dll
C:\WINDOWS\system32\womridbk.dll
C:\WINDOWS\system32\wqohveqp.dll
C:\WINDOWS\system32\wrxqbinr.dll
C:\WINDOWS\system32\wtgksfah.dll
C:\WINDOWS\system32\wtlonxif.dll
C:\WINDOWS\system32\wvyglppc.dll
C:\WINDOWS\system32\wybmpogt.dll
C:\WINDOWS\system32\wytssvbo.dll
C:\WINDOWS\system32\xamsuqhh.dll
C:\WINDOWS\system32\xbnqocjo.dll
C:\WINDOWS\system32\xbshvbex.dll
C:\WINDOWS\system32\xedwwaod.dll
C:\WINDOWS\system32\xeljocyh.dll
C:\WINDOWS\system32\xiefuihy.dll
C:\WINDOWS\system32\xktqmicq.dll
C:\WINDOWS\system32\xnwwxpfv.dll
C:\WINDOWS\system32\xoeanguk.dll
C:\WINDOWS\system32\xrulqnox.dll
C:\WINDOWS\system32\xvmwrohp.dll
C:\WINDOWS\system32\xyiscdom.dll
C:\WINDOWS\system32\yaqjlpvj.dll
C:\WINDOWS\system32\yearfsjh.dll
C:\WINDOWS\system32\yemgsvoy.dll
C:\WINDOWS\system32\yffnmgii.dll
C:\WINDOWS\system32\yfrmojba.dll
C:\WINDOWS\system32\yisdjthv.dll
C:\WINDOWS\system32\yjcescmp.dll
C:\WINDOWS\system32\yjmwteic.dll
C:\WINDOWS\system32\ykirhuvc.dll
C:\WINDOWS\system32\yoooxcuc.dll
C:\WINDOWS\system32\yovovkbw.dll
C:\WINDOWS\system32\ytalepdb.dll
C:\WINDOWS\system32\yxhhdamp.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\abpjuqwy.dll
C:\WINDOWS\system32\abpjuqwy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\agntwrxl.dll
C:\WINDOWS\system32\agntwrxl.dll Has been deleted!

Attempting to delete C:\windows\system32\agsqdpdf.dll
C:\windows\system32\agsqdpdf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\akejuixi.dll
C:\WINDOWS\system32\akejuixi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\amvxtree.dll
C:\WINDOWS\system32\amvxtree.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aolbnqsm.dll
C:\WINDOWS\system32\aolbnqsm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\assxcxkp.dll
C:\WINDOWS\system32\assxcxkp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aubrjekg.dll
C:\WINDOWS\system32\aubrjekg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\avkpitwa.dll
C:\WINDOWS\system32\avkpitwa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\avoccjqd.dll
C:\WINDOWS\system32\avoccjqd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\axekxeag.dll
C:\WINDOWS\system32\axekxeag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bhibdfum.dll
C:\WINDOWS\system32\bhibdfum.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bibjntjn.dll
C:\WINDOWS\system32\bibjntjn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bjeyyfea.dll
C:\WINDOWS\system32\bjeyyfea.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\blvtlmry.dll
C:\WINDOWS\system32\blvtlmry.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\btwxkvya.dll
C:\WINDOWS\system32\btwxkvya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvpvsmqj.dll
C:\WINDOWS\system32\bvpvsmqj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvufhsra.dll
C:\WINDOWS\system32\bvufhsra.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bvysdbam.dll
C:\WINDOWS\system32\bvysdbam.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bxcfnlnw.dll
C:\WINDOWS\system32\bxcfnlnw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bydlxnnc.dll
C:\WINDOWS\system32\bydlxnnc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byyqwpjg.dll
C:\WINDOWS\system32\byyqwpjg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ccavuebg.dll
C:\WINDOWS\system32\ccavuebg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cejxjkmm.dll
C:\WINDOWS\system32\cejxjkmm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cfntahck.dll
C:\WINDOWS\system32\cfntahck.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cgqehgdg.dll
C:\WINDOWS\system32\cgqehgdg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\clcuqdkv.dll
C:\WINDOWS\system32\clcuqdkv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cnujmjsq.dll
C:\WINDOWS\system32\cnujmjsq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\crfrdueq.dll
C:\WINDOWS\system32\crfrdueq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\crvjmxkg.dll
C:\WINDOWS\system32\crvjmxkg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cstvrxbr.dll
C:\WINDOWS\system32\cstvrxbr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cyoqpyco.dll
C:\WINDOWS\system32\cyoqpyco.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dakkwghb.dll
C:\WINDOWS\system32\dakkwghb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\deavehfq.dll
C:\WINDOWS\system32\deavehfq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dffekvhm.dll
C:\WINDOWS\system32\dffekvhm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dififgib.dll
C:\WINDOWS\system32\dififgib.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dlocxckr.dll
C:\WINDOWS\system32\dlocxckr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dmulefhp.dll
C:\WINDOWS\system32\dmulefhp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dolmbmrc.dll
C:\WINDOWS\system32\dolmbmrc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\douhroue.ini
C:\WINDOWS\system32\douhroue.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dqyejkbs.dll
C:\WINDOWS\system32\dqyejkbs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\drlwpdbh.dll
C:\WINDOWS\system32\drlwpdbh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtaowlwk.dll
C:\WINDOWS\system32\dtaowlwk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtdmdnxa.dll
C:\WINDOWS\system32\dtdmdnxa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dtogriby.dll
C:\WINDOWS\system32\dtogriby.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dvvnvbqe.dll
C:\WINDOWS\system32\dvvnvbqe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dwlxsjqt.dll
C:\WINDOWS\system32\dwlxsjqt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\dxiybtfb.dll
C:\WINDOWS\system32\dxiybtfb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ebuuhopn.dll
C:\WINDOWS\system32\ebuuhopn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eccolsbr.dll
C:\WINDOWS\system32\eccolsbr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ehewrrxx.dll
C:\WINDOWS\system32\ehewrrxx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\emnsopyr.dll
C:\WINDOWS\system32\emnsopyr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eoovrnit.dll
C:\WINDOWS\system32\eoovrnit.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\epdpmthg.dll
C:\WINDOWS\system32\epdpmthg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eqwnqypa.dll
C:\WINDOWS\system32\eqwnqypa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ermimpcw.dll
C:\WINDOWS\system32\ermimpcw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\euorhuod.dll
C:\WINDOWS\system32\euorhuod.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fjjefpix.dll
C:\WINDOWS\system32\fjjefpix.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fmiggojd.dll
C:\WINDOWS\system32\fmiggojd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\frashidj.dll
C:\WINDOWS\system32\frashidj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fvoashnf.dll
C:\WINDOWS\system32\fvoashnf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fyyaucps.dll
C:\WINDOWS\system32\fyyaucps.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gbqcrlpj.dll
C:\WINDOWS\system32\gbqcrlpj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gclucwop.dll
C:\WINDOWS\system32\gclucwop.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gdggjhge.dll
C:\WINDOWS\system32\gdggjhge.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gdhemxch.dll
C:\WINDOWS\system32\gdhemxch.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gfkdjeyx.dll
C:\WINDOWS\system32\gfkdjeyx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ghisfvjj.dll
C:\WINDOWS\system32\ghisfvjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ghjrdynb.dll
C:\WINDOWS\system32\ghjrdynb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjagsudt.dll
C:\WINDOWS\system32\gjagsudt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjpwqyyb.ini
C:\WINDOWS\system32\gjpwqyyb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\gjyqywjb.dll
C:\WINDOWS\system32\gjyqywjb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gkxmjvrc.ini
C:\WINDOWS\system32\gkxmjvrc.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\goakwwek.dll
C:\WINDOWS\system32\goakwwek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gtcxixho.dll
C:\WINDOWS\system32\gtcxixho.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\guknumpo.dll
C:\WINDOWS\system32\guknumpo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gxbsmpcc.dll
C:\WINDOWS\system32\gxbsmpcc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hbyejemg.dll
C:\WINDOWS\system32\hbyejemg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hdqicfen.dll
C:\WINDOWS\system32\hdqicfen.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hkygbkag.dll
C:\WINDOWS\system32\hkygbkag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hpybvxyd.dll
C:\WINDOWS\system32\hpybvxyd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hsqxbogj.dll
C:\WINDOWS\system32\hsqxbogj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hvuaenoj.dll
C:\WINDOWS\system32\hvuaenoj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hxlqaalo.dll
C:\WINDOWS\system32\hxlqaalo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hyipoveq.dll
C:\WINDOWS\system32\hyipoveq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\icbpjpgi.dll
C:\WINDOWS\system32\icbpjpgi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ielxawgl.dll
C:\WINDOWS\system32\ielxawgl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ijjscrty.dll
C:\WINDOWS\system32\ijjscrty.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\inbjpfjm.dll
C:\WINDOWS\system32\inbjpfjm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iocysrus.dll
C:\WINDOWS\system32\iocysrus.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ithridxr.dll
C:\WINDOWS\system32\ithridxr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\itkrpmhu.dll
C:\WINDOWS\system32\itkrpmhu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iuwkvvyk.dll
C:\WINDOWS\system32\iuwkvvyk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ivxbvnmm.dll
C:\WINDOWS\system32\ivxbvnmm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iydcithw.dll
C:\WINDOWS\system32\iydcithw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\iyyywtgf.dll
C:\WINDOWS\system32\iyyywtgf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jbdbasst.dll
C:\WINDOWS\system32\jbdbasst.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jdtxsptk.dll
C:\WINDOWS\system32\jdtxsptk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jimuluya.dll
C:\WINDOWS\system32\jimuluya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jirukuxi.dll
C:\WINDOWS\system32\jirukuxi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jnomampe.dll
C:\WINDOWS\system32\jnomampe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\joepfivk.dll
C:\WINDOWS\system32\joepfivk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jqsrywvv.dll
C:\WINDOWS\system32\jqsrywvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jriyukse.dll
C:\WINDOWS\system32\jriyukse.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jsipjfqo.dll
C:\WINDOWS\system32\jsipjfqo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jsrhxjnl.dll
C:\WINDOWS\system32\jsrhxjnl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jvduouag.dll
C:\WINDOWS\system32\jvduouag.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jvxehlxm.dll
C:\WINDOWS\system32\jvxehlxm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jwqbtmyl.dll
C:\WINDOWS\system32\jwqbtmyl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kawfihja.dll
C:\WINDOWS\system32\kawfihja.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kddcsotj.dll
C:\WINDOWS\system32\kddcsotj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\keuspuhf.dll
C:\WINDOWS\system32\keuspuhf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\klojpnch.dll
C:\WINDOWS\system32\klojpnch.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kmggsexv.dll
C:\WINDOWS\system32\kmggsexv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\koimffgb.dll
C:\WINDOWS\system32\koimffgb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kokavygf.dll
C:\WINDOWS\system32\kokavygf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kqoymksq.dll
C:\WINDOWS\system32\kqoymksq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\krcidbnf.dll
C:\WINDOWS\system32\krcidbnf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kriokrjy.dll
C:\WINDOWS\system32\kriokrjy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kswxwtxk.dll
C:\WINDOWS\system32\kswxwtxk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ktelrgqw.dll
C:\WINDOWS\system32\ktelrgqw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kunkqcpm.dll
C:\WINDOWS\system32\kunkqcpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kwyniyao.dll
C:\WINDOWS\system32\kwyniyao.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lakgahvi.dll
C:\WINDOWS\system32\lakgahvi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llaocuih.dll
C:\WINDOWS\system32\llaocuih.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llkcyatg.dll
C:\WINDOWS\system32\llkcyatg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llqcyhtd.dll
C:\WINDOWS\system32\llqcyhtd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lnfiwpbi.dll
C:\WINDOWS\system32\lnfiwpbi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lnhqtcek.dll
C:\WINDOWS\system32\lnhqtcek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lqhxdjev.dll
C:\WINDOWS\system32\lqhxdjev.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lsbcxcte.dll
C:\WINDOWS\system32\lsbcxcte.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lsltdsbu.dll
C:\WINDOWS\system32\lsltdsbu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lwxdulsr.dll
C:\WINDOWS\system32\lwxdulsr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lxrwsptw.dll
C:\WINDOWS\system32\lxrwsptw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lxrwtnga.ini
C:\WINDOWS\system32\lxrwtnga.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\lypwlvew.dll
C:\WINDOWS\system32\lypwlvew.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mchdxtkc.dll
C:\WINDOWS\system32\mchdxtkc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mhpcthsj.dll
C:\WINDOWS\system32\mhpcthsj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mkugckev.dll
C:\WINDOWS\system32\mkugckev.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\msqnbloa.ini
C:\WINDOWS\system32\msqnbloa.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\mumuogoc.dll
C:\WINDOWS\system32\mumuogoc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\muurjqej.dll
C:\WINDOWS\system32\muurjqej.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nhytjdrf.dll
C:\WINDOWS\system32\nhytjdrf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nixidkvv.dll
C:\WINDOWS\system32\nixidkvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\njrgkalu.dll
C:\WINDOWS\system32\njrgkalu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\njsrytfc.dll
C:\WINDOWS\system32\njsrytfc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nrwqsejx.dll
C:\WINDOWS\system32\nrwqsejx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ntleqalc.dll
C:\WINDOWS\system32\ntleqalc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nxhlvpnx.dll
C:\WINDOWS\system32\nxhlvpnx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oboaiusp.dll
C:\WINDOWS\system32\oboaiusp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\obxlhxcd.dll
C:\WINDOWS\system32\obxlhxcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ofxslooc.dll
C:\WINDOWS\system32\ofxslooc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ohrpbxnt.dll
C:\WINDOWS\system32\ohrpbxnt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oiyftbeo.dll
C:\WINDOWS\system32\oiyftbeo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\okmbhwxw.dll
C:\WINDOWS\system32\okmbhwxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\okwkupbq.dll
C:\WINDOWS\system32\okwkupbq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\omwlnmni.dll
C:\WINDOWS\system32\omwlnmni.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oofttdcn.dll
C:\WINDOWS\system32\oofttdcn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opluigkc.dll
C:\WINDOWS\system32\opluigkc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\opsbplfe.dll
C:\WINDOWS\system32\opsbplfe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oqepvkbg.dll
C:\WINDOWS\system32\oqepvkbg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oqkvcvru.dll
C:\WINDOWS\system32\oqkvcvru.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\orqoqgye.dll
C:\WINDOWS\system32\orqoqgye.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\osmjabir.dll
C:\WINDOWS\system32\osmjabir.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pbwaikrk.dll
C:\WINDOWS\system32\pbwaikrk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pcxtrxyd.dll
C:\WINDOWS\system32\pcxtrxyd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pdcvaxjr.dll
C:\WINDOWS\system32\pdcvaxjr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\phkblrnd.dll
C:\WINDOWS\system32\phkblrnd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pjjkfbgu.dll
C:\WINDOWS\system32\pjjkfbgu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pkdbjbem.dll
C:\WINDOWS\system32\pkdbjbem.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pkqvefcd.dll
C:\WINDOWS\system32\pkqvefcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\plxyilft.dll
C:\WINDOWS\system32\plxyilft.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmfcxchv.dll
C:\WINDOWS\system32\pmfcxchv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmkhh.dll
C:\WINDOWS\system32\pmkhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\poxmdmxq.dll
C:\WINDOWS\system32\poxmdmxq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\psjtjemk.dll
C:\WINDOWS\system32\psjtjemk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pvpvmjrg.dll
C:\WINDOWS\system32\pvpvmjrg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pyhgrqty.dll
C:\WINDOWS\system32\pyhgrqty.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qdfdaboi.dll
C:\WINDOWS\system32\qdfdaboi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qfiyphvh.dll
C:\WINDOWS\system32\qfiyphvh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qhbyxxnc.dll
C:\WINDOWS\system32\qhbyxxnc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qkcwebxa.dll
C:\WINDOWS\system32\qkcwebxa.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qojtipxi.dll
C:\WINDOWS\system32\qojtipxi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomlsuiw.dll
C:\WINDOWS\system32\qomlsuiw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qoxudpqu.dll
C:\WINDOWS\system32\qoxudpqu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qqxdrepy.dll
C:\WINDOWS\system32\qqxdrepy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\queygmmy.dll
C:\WINDOWS\system32\queygmmy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\raktioyu.dll
C:\WINDOWS\system32\raktioyu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\raqdgcec.dll
C:\WINDOWS\system32\raqdgcec.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rbnecpcn.dll
C:\WINDOWS\system32\rbnecpcn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rcqsocfy.dll
C:\WINDOWS\system32\rcqsocfy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rdfeolpd.dll
C:\WINDOWS\system32\rdfeolpd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rehhinbq.dll
C:\WINDOWS\system32\rehhinbq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rfxutiin.dll
C:\WINDOWS\system32\rfxutiin.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rknqocve.dll
C:\WINDOWS\system32\rknqocve.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rmktgpma.dll
C:\WINDOWS\system32\rmktgpma.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rultphei.dll
C:\WINDOWS\system32\rultphei.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rvcmhjye.dll
C:\WINDOWS\system32\rvcmhjye.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rwxfvrhy.dll
C:\WINDOWS\system32\rwxfvrhy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ryqewmyp.dll
C:\WINDOWS\system32\ryqewmyp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sdltwqcl.dll
C:\WINDOWS\system32\sdltwqcl.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\seacfsdf.dll
C:\WINDOWS\system32\seacfsdf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sjajlfcm.dll
C:\WINDOWS\system32\sjajlfcm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\slmxkgwr.dll
C:\WINDOWS\system32\slmxkgwr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\solenyec.dll
C:\WINDOWS\system32\solenyec.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sopoajfq.dll
C:\WINDOWS\system32\sopoajfq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\sqxxifhj.dll
C:\WINDOWS\system32\sqxxifhj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\srekyjnp.dll
C:\WINDOWS\system32\srekyjnp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\suxjemtp.dll
C:\WINDOWS\system32\suxjemtp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\swxjmoud.dll
C:\WINDOWS\system32\swxjmoud.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\taqfjjjb.dll
C:\WINDOWS\system32\taqfjjjb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tbfbjpcv.dll
C:\WINDOWS\system32\tbfbjpcv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tdvhnotp.dll
C:\WINDOWS\system32\tdvhnotp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tikeplxe.dll
C:\WINDOWS\system32\tikeplxe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tlupuule.dll
C:\WINDOWS\system32\tlupuule.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tmatduff.dll
C:\WINDOWS\system32\tmatduff.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\todgyohw.dll
C:\WINDOWS\system32\todgyohw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuuqjyek.dll
C:\WINDOWS\system32\tuuqjyek.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\twsbgmhw.dll
C:\WINDOWS\system32\twsbgmhw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\txeujawj.dll
C:\WINDOWS\system32\txeujawj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tydfqaui.dll
C:\WINDOWS\system32\tydfqaui.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ucoabfmo.dll
C:\WINDOWS\system32\ucoabfmo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ucxwuhjg.dll
C:\WINDOWS\system32\ucxwuhjg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ufjjejri.dll
C:\WINDOWS\system32\ufjjejri.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhadvepg.dll
C:\WINDOWS\system32\uhadvepg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhasmsxv.dll
C:\WINDOWS\system32\uhasmsxv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhcokfmx.dll
C:\WINDOWS\system32\uhcokfmx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uheupxnx.dll
C:\WINDOWS\system32\uheupxnx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhweoisi.dll
C:\WINDOWS\system32\uhweoisi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uhxjijiw.dll
C:\WINDOWS\system32\uhxjijiw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\uiagfdow.dll
C:\WINDOWS\system32\uiagfdow.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ujdjyepi.dll
C:\WINDOWS\system32\ujdjyepi.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ujgovkkn.dll
C:\WINDOWS\system32\ujgovkkn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\utijrhmh.dll
C:\WINDOWS\system32\utijrhmh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vbgmxxgt.dll
C:\WINDOWS\system32\vbgmxxgt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vkipblot.dll
C:\WINDOWS\system32\vkipblot.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vlwkmusq.dll
C:\WINDOWS\system32\vlwkmusq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vmhyigge.dll
C:\WINDOWS\system32\vmhyigge.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vnglixoh.dll
C:\WINDOWS\system32\vnglixoh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vouwacxj.dll
C:\WINDOWS\system32\vouwacxj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vptrxgum.dll
C:\WINDOWS\system32\vptrxgum.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vqbnrtxy.dll
C:\WINDOWS\system32\vqbnrtxy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vrxfgtvo.dll
C:\WINDOWS\system32\vrxfgtvo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vuqwqaad.dll
C:\WINDOWS\system32\vuqwqaad.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vvrjlqyh.dll
C:\WINDOWS\system32\vvrjlqyh.dll Has been deleted!

Attempting to delete C:\windows\system32\vwbluknx.dll
C:\windows\system32\vwbluknx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vwsgpmkb.dll
C:\WINDOWS\system32\vwsgpmkb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vxthpbrf.dll
C:\WINDOWS\system32\vxthpbrf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wadvoken.dll
C:\WINDOWS\system32\wadvoken.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\waojyofo.dll
C:\WINDOWS\system32\waojyofo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wiccnujs.dll
C:\WINDOWS\system32\wiccnujs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wiymahlb.dll
C:\WINDOWS\system32\wiymahlb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wkorbgem.dll
C:\WINDOWS\system32\wkorbgem.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wljwsvdp.dll
C:\WINDOWS\system32\wljwsvdp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\womridbk.dll
C:\WINDOWS\system32\womridbk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wqohveqp.dll
C:\WINDOWS\system32\wqohveqp.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\wrxqbinr.dll
C:\WINDOWS\system32\wrxqbinr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wtgksfah.dll
C:\WINDOWS\system32\wtgksfah.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wtlonxif.dll
C:\WINDOWS\system32\wtlonxif.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wvyglppc.dll
C:\WINDOWS\system32\wvyglppc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wybmpogt.dll
C:\WINDOWS\system32\wybmpogt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\wytssvbo.dll
C:\WINDOWS\system32\wytssvbo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xamsuqhh.dll
C:\WINDOWS\system32\xamsuqhh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbnqocjo.dll
C:\WINDOWS\system32\xbnqocjo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xbshvbex.dll
C:\WINDOWS\system32\xbshvbex.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xedwwaod.dll
C:\WINDOWS\system32\xedwwaod.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xeljocyh.dll
C:\WINDOWS\system32\xeljocyh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xiefuihy.dll
C:\WINDOWS\system32\xiefuihy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xktqmicq.dll
C:\WINDOWS\system32\xktqmicq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xnwwxpfv.dll
C:\WINDOWS\system32\xnwwxpfv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xoeanguk.dll
C:\WINDOWS\system32\xoeanguk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xrulqnox.dll
C:\WINDOWS\system32\xrulqnox.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xvmwrohp.dll
C:\WINDOWS\system32\xvmwrohp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xyiscdom.dll
C:\WINDOWS\system32\xyiscdom.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yaqjlpvj.dll
C:\WINDOWS\system32\yaqjlpvj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yearfsjh.dll
C:\WINDOWS\system32\yearfsjh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yemgsvoy.dll
C:\WINDOWS\system32\yemgsvoy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yffnmgii.dll
C:\WINDOWS\system32\yffnmgii.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yfrmojba.dll
C:\WINDOWS\system32\yfrmojba.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yisdjthv.dll
C:\WINDOWS\system32\yisdjthv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yjcescmp.dll
C:\WINDOWS\system32\yjcescmp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yjmwteic.dll
C:\WINDOWS\system32\yjmwteic.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ykirhuvc.dll
C:\WINDOWS\system32\ykirhuvc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yoooxcuc.dll
C:\WINDOWS\system32\yoooxcuc.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yovovkbw.dll
C:\WINDOWS\system32\yovovkbw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ytalepdb.dll
C:\WINDOWS\system32\ytalepdb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yxhhdamp.dll
C:\WINDOWS\system32\yxhhdamp.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.7.7

Checking Java version…

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 9:05:24 PM 12/24/2007

Listing files found while scanning….

C:\WINDOWS\system32\pqevhoqw.ini
C:\WINDOWS\system32\wqohveqp.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\pqevhoqw.ini
C:\WINDOWS\system32\pqevhoqw.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\wqohveqp.dll
C:\WINDOWS\system32\wqohveqp.dll Has been deleted!

Performing Repairs to the registry.
Done!


ComboFix Log:

ComboFix 07-12-21.4 - Greg 2007-12-25 6:52:18.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.86.1033.18.1134 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: /killall
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\NetworkService\Application Data\Starware
C:\Documents and Settings\Paul\Application Data\Starware
C:\Documents and Settings\Paul\Application Data\Starware\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Paul\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Configurator\ConfiguratorOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Configurator\ConfiguratorOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Games\GamesOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Games\GamesOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Layouts\PreferencesLayout.xml
C:\Documents and Settings\Paul\Application Data\Starware\Layouts\PreferencesLayout.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Paul\Application Data\Starware\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Manager\ManagerOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Movies\MoviesOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Movies\MoviesOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Reference\ReferenceOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Reference\ReferenceOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Screensavers\ScreensaversOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\SearchMatch\SearchMatchOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup
C:\Documents and Settings\Paul\Application Data\Starware\Weather\WeatherOptions.xml
C:\Documents and Settings\Paul\Application Data\Starware\Weather\WeatherOptions.xml.backup
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml
C:\Program Files\screensavers.com\Installer\bin\iebyterange.xml.backup
C:\Program Files\screensavers.com\Installer\bin\ScreensaversInst.dll
C:\Program Files\screensavers.com\Installer\bin\siuninst.exe
C:\Program Files\screensavers.com\Installer\temp\blank.gif
C:\Program Files\screensavers.com\Installer\temp\dm2B.tmp
C:\Program Files\screensavers.com\Installer\temp\dm89.tmp
C:\Program Files\screensavers.com\Installer\temp\stubinstaller.ini
C:\Program Files\screensavers.com\Installer\temp\The_Weather_Channel_Application.exe
C:\Program Files\screensavers.com\Wallpaper\Combat Flight Simulator 3.jpg
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\Program Files\screensavers.com\Wallpaper\Wintery Woods.jpg
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\bakhctox.dll
C:\WINDOWS\system32\catmflju.dll
C:\WINDOWS\system32\fgmfmket.dll
C:\WINDOWS\system32\ftoxoita.dll
C:\WINDOWS\system32\hhkmp.bak1
C:\WINDOWS\system32\hhkmp.bak2
C:\WINDOWS\system32\hhkmp.ini
C:\WINDOWS\system32\hhkmp.ini2
C:\WINDOWS\system32\hhkmp.tmp
C:\WINDOWS\system32\hkscshjm.dll
C:\WINDOWS\system32\jmtenkfo.dll
C:\WINDOWS\system32\ldpackage.dll
C:\WINDOWS\system32\model.dat
C:\WINDOWS\system32\ohtkmplr.dll
C:\WINDOWS\system32\ptpcripk.dll
C:\WINDOWS\system32\rlls.dll
C:\WINDOWS\system32\rlxf.dll
C:\WINDOWS\system32\rmsxhacq.dll
C:\WINDOWS\system32\silc_dll.dll
C:\WINDOWS\system32\tdpyrngr.dll
C:\WINDOWS\system32\vovepyvu.dll
C:\WINDOWS\system32\vudbieqg.dll
C:\WINDOWS\system32\wfrnbuqy.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\nm


((((((((((((((((((((((((( Files Created from 2007-11-25 to 2007-12-25 )))))))))))))))))))))))))))))))
.

2007-12-24 13:32 . 2007-12-24 13:32 d——– C:\Documents and Settings\Greg\Application Data\Zango
2007-12-24 13:32 . 2007-12-24 13:32 d——– C:\Documents and Settings\All Users\Application Data\ZangoSA
2007-12-24 13:32 . 2007-12-24 13:32 d——– C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2007-12-24 11:26 . 2007-12-24 22:20 d——– C:\VundoFix Backups
2007-12-24 07:55 . 2007-12-24 13:38 992,956 —hs—- C:\WINDOWS\system32\eyoysnip.ini
2007-12-23 23:30 . 2007-12-24 07:55 987,272 —hs—- C:\WINDOWS\system32\ovbkvgjt.ini
2007-12-23 22:08 . 2007-12-23 23:28 354 —hs—- C:\WINDOWS\system32\ybisjfyp.ini
2007-12-23 21:58 . 2007-12-23 21:58 d——– C:\Program Files\Dynamic Toolbar
2007-12-23 14:24 . 2007-12-23 21:21 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-23 14:24 . 2007-12-23 14:24 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-22 20:37 . 2007-12-22 20:37 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-12-21 19:45 . 2007-12-23 22:08 792,682 —hs—- C:\WINDOWS\system32\eggiyhmv.ini
2007-12-21 15:20 . 2007-12-21 19:42 774,631 —hs—- C:\WINDOWS\system32\mewhftnw.ini
2007-12-21 15:00 . 2007-12-21 15:17 774,511 —hs—- C:\WINDOWS\system32\rufuehui.ini
2007-12-21 08:07 . 2007-12-21 15:00 870,382 —hs—- C:\WINDOWS\system32\wiirppak.ini
2007-12-20 08:01 . 2007-12-21 08:05 774,271 —hs—- C:\WINDOWS\system32\gjqwhvad.ini
2007-12-18 08:03 . 2007-12-20 07:58 777,924 —hs—- C:\WINDOWS\system32\sdlxdoye.ini
2007-12-17 15:17 . 2007-12-18 08:01 781,854 —hs—- C:\WINDOWS\system32\pqvgcyan.ini
2007-12-17 08:15 . 2007-12-17 15:15 782,560 —hs—- C:\WINDOWS\system32\wmwxvitb.ini
2007-12-16 14:03 . 2007-12-17 08:15 781,627 —hs—- C:\WINDOWS\system32\ywwhqtni.ini
2007-12-16 12:24 . 2007-12-16 14:01 781,447 —hs—- C:\WINDOWS\system32\jhfuerbg.ini
2007-12-15 00:16 . 2007-12-16 12:23 761,597 —hs—- C:\WINDOWS\system32\dpmjgfbw.ini
2007-12-13 10:53 . 2007-12-15 00:16 762,452 —hs—- C:\WINDOWS\system32\bxlhxioi.ini
2007-12-13 10:51 . 2007-12-13 10:51 d——– C:\Documents and Settings\Pam\Application Data\Yahoo!
2007-12-13 08:53 . 2007-12-13 10:50 890,418 —hs—- C:\WINDOWS\system32\qpgfemwv.ini
2007-12-13 03:11 . 2007-12-13 03:11 118 –a—— C:\WINDOWS\system32\MRT.INI
2007-12-12 09:01 . 2007-12-13 08:51 790,778 —hs—- C:\WINDOWS\system32\atpsnesi.ini
2007-12-11 20:11 . 2007-12-12 08:58 816,241 —hs—- C:\WINDOWS\system32\kueqrfgp.ini
2007-12-11 19:36 . 2007-12-11 20:08 805,536 —hs—- C:\WINDOWS\system32\bijcmdvu.ini
2007-12-11 18:41 . 2007-12-11 19:34 805,356 —hs—- C:\WINDOWS\system32\msrvohfo.ini
2007-12-11 15:11 . 2007-12-11 18:39 989,940 —hs—- C:\WINDOWS\system32\nwwfdahc.ini
2007-12-11 08:09 . 2007-12-11 15:11 1,008,720 —hs—- C:\WINDOWS\system32\ydajrmkb.ini
2007-12-10 09:44 . 2007-12-11 08:08 891,256 —hs—- C:\WINDOWS\system32\tnrwyhce.ini
2007-12-10 08:08 . 2007-12-10 09:41 851,964 —hs—- C:\WINDOWS\system32\hdeskfuo.ini
2007-12-09 20:39 . 2007-12-10 08:06 834,760 —hs—- C:\WINDOWS\system32\tpaxcfhp.ini
2007-12-09 20:30 . 2007-12-09 20:39 834,640 —hs—- C:\WINDOWS\system32\qerwvljh.ini
2007-12-09 19:29 . 2007-12-09 20:28 834,520 —hs—- C:\WINDOWS\system32\khxfyvea.ini
2007-12-09 13:10 . 2007-12-09 19:29 834,280 —hs—- C:\WINDOWS\system32\qicrfoxm.ini
2007-12-09 13:02 . 2007-12-09 13:07 834,160 —hs—- C:\WINDOWS\system32\ycpuqgye.ini
2007-12-09 12:49 . 2007-12-09 12:49 834,220 —hs—- C:\WINDOWS\system32\lgwaxlei.ini
2007-12-09 09:44 . 2007-12-09 12:47 834,160 —hs—- C:\WINDOWS\system32\ssumafud.ini
2007-12-09 08:26 . 2007-12-09 08:26 834,400 —hs—- C:\WINDOWS\system32\xnpvlhxn.ini
2007-12-08 15:49 . 2007-12-09 08:26 834,340 —hs—- C:\WINDOWS\system32\odyafqev.ini
2007-12-08 13:39 . 2007-12-08 15:47 834,220 —hs—- C:\WINDOWS\system32\vvssfdtw.ini
2007-12-08 09:20 . 2007-12-08 09:20 835,060 —hs—- C:\WINDOWS\system32\wijijxhu.ini
2007-12-08 00:39 . 2007-12-08 09:20 835,000 —hs—- C:\WINDOWS\system32\dbehrxpn.ini
2007-12-07 21:20 . 2007-12-08 00:37 834,880 —hs—- C:\WINDOWS\system32\hcvvlglb.ini
2007-12-07 18:47 . 2007-12-07 21:19 834,760 —hs—- C:\WINDOWS\system32\fgqrkpvb.ini
2007-12-07 18:40 . 2007-12-07 18:45 834,640 —hs—- C:\WINDOWS\system32\cqprstyl.ini
2007-12-07 18:31 . 2007-12-07 18:38 834,520 —hs—- C:\WINDOWS\system32\xabgsbco.ini
2007-12-07 17:33 . 2007-12-07 18:28 834,400 —hs—- C:\WINDOWS\system32\jjwaxvix.ini
2007-12-07 17:23 . 2007-12-07 17:32 834,280 —hs—- C:\WINDOWS\system32\kgfsmmee.ini
2007-12-07 15:54 . 2007-12-07 17:23 834,160 —hs—- C:\WINDOWS\system32\mxsqhixi.ini
2007-12-07 15:12 . 2007-12-07 15:13 834,340 —hs—- C:\WINDOWS\system32\eskuyirj.ini
2007-12-07 15:04 . 2007-12-07 15:10 834,280 —hs—- C:\WINDOWS\system32\vknhvqiv.ini
2007-12-07 14:56 . 2007-12-07 15:04 834,160 —hs—- C:\WINDOWS\system32\hxgqftui.ini
2007-12-07 08:17 . 2007-12-07 08:17 832,935 —hs—- C:\WINDOWS\system32\vcpjbfbt.ini
2007-12-06 22:38 . 2007-12-07 08:17 834,160 —hs—- C:\WINDOWS\system32\hqbwsuup.ini
2007-12-06 08:27 . 2007-12-06 16:55 740,672 —hs—- C:\WINDOWS\system32\pwwdutvq.ini
2007-12-05 22:22 . 2007-12-06 08:25 740,492 —hs—- C:\WINDOWS\system32\bomlteup.ini
2007-12-05 21:27 . 2007-12-05 22:22 740,372 —hs—- C:\WINDOWS\system32\xtsskhbn.ini
2007-12-05 21:19 . 2007-12-05 21:27 740,192 —hs—- C:\WINDOWS\system32\rmnckows.ini
2007-12-05 18:29 . 2007-12-05 21:19 740,072 —hs—- C:\WINDOWS\system32\lmvbkbrb.ini
2007-12-05 16:56 . 2007-12-05 18:29 752,139 —hs—- C:\WINDOWS\system32\scubnijm.ini
2007-12-05 08:33 . 2007-12-05 16:53 832,762 —hs—- C:\WINDOWS\system32\llhwuhof.ini
2007-12-04 20:30 . 2007-12-05 08:31 756,916 —hs—- C:\WINDOWS\system32\emcwpeua.ini
2007-12-04 19:43 . 2007-12-04 20:30 756,796 —hs—- C:\WINDOWS\system32\vsbhuvrr.ini
2007-12-04 17:16 . 2007-12-04 19:42 756,676 —hs—- C:\WINDOWS\system32\uurtplfu.ini
2007-12-04 16:31 . 2007-12-04 17:16 756,556 —hs—- C:\WINDOWS\system32\hqposypg.ini
2007-12-04 16:16 . 2007-12-04 16:30 756,436 —hs—- C:\WINDOWS\system32\xgugkctx.ini
2007-12-04 16:08 . 2007-12-04 16:16 756,256 —hs—- C:\WINDOWS\system32\ghxsifkw.ini
2007-12-04 15:16 . 2007-12-04 16:06 756,136 —hs—- C:\WINDOWS\system32\wdaecoco.ini
2007-12-04 15:02 . 2007-12-04 15:14 760,630 —hs—- C:\WINDOWS\system32\efxtkkmp.ini
2007-12-04 08:12 . 2007-12-04 15:00 821,466 —hs—- C:\WINDOWS\system32\chaaxlrv.ini
2007-12-03 23:49 . 2007-12-04 08:10 788,531 —hs—- C:\WINDOWS\system32\bwupaxre.ini
2007-12-03 21:16 . 2007-12-03 23:49 793,887 —hs—- C:\WINDOWS\system32\ciahkvps.ini
2007-12-03 19:13 . 2007-12-03 21:14 794,580 —hs—- C:\WINDOWS\system32\kkvfnubk.ini
2007-12-03 16:31 . 2007-12-03 19:11 794,460 —hs—- C:\WINDOWS\system32\cqcsjxai.ini
2007-12-03 16:20 . 2007-12-03 16:31 794,340 —hs—- C:\WINDOWS\system32\dqakebud.ini
2007-12-03 08:08 . 2007-12-03 16:20 792,516 —hs—- C:\WINDOWS\system32\obkwmtur.ini
2007-12-03 00:01 . 2007-12-03 08:07 354 —hs—- C:\WINDOWS\system32\bntxchoc.ini
2007-12-02 22:24 . 2007-12-03 00:01 793,544 —hs—- C:\WINDOWS\system32\qcimqtkx.ini
2007-12-02 19:30 . 2007-12-02 22:24 794,324 —hs—- C:\WINDOWS\system32\wkumqtec.ini
2007-12-02 19:23 . 2007-12-02 19:30 794,204 —hs—- C:\WINDOWS\system32\axdtptxn.ini
2007-12-02 19:11 . 2007-12-02 19:21 794,084 —hs—- C:\WINDOWS\system32\jqdadafe.ini
2007-12-02 18:58 . 2007-12-02 19:09 793,964 —hs—- C:\WINDOWS\system32\scmbbnmk.ini
2007-12-02 18:51 . 2007-12-02 18:57 793,844 —hs—- C:\WINDOWS\system32\ryyoeanx.ini
2007-12-02 18:11 . 2007-12-02 18:50 354 —hs—- C:\WINDOWS\system32\wqwrsbsg.ini
2007-12-02 16:04 . 2007-12-02 18:11 722,732 —hs—- C:\WINDOWS\system32\iehptlur.ini
2007-12-02 15:51 . 2007-12-02 16:02 722,612 —hs—- C:\WINDOWS\system32\xjoagqiu.ini
2007-12-02 15:36 . 2007-12-02 15:49 722,492 —hs—- C:\WINDOWS\system32\sbcfutsw.ini
2007-12-02 15:02 . 2007-12-02 15:36 722,372 —hs—- C:\WINDOWS\system32\fbvdtufj.ini
2007-12-02 14:47 . 2007-12-02 15:02 722,072 —hs—- C:\WINDOWS\system32\owblmfeh.ini
2007-12-02 13:18 . 2007-12-02 14:45 721,892 —hs—- C:\WINDOWS\system32\widtvepb.ini
2007-12-02 00:55 . 2007-12-02 13:18 721,772 —hs—- C:\WINDOWS\system32\auvqyqnm.ini
2007-12-02 00:48 . 2007-12-02 00:55 721,652 —hs—- C:\WINDOWS\system32\cchtvemr.ini
2007-12-02 00:42 . 2007-12-02 00:48 721,532 —hs—- C:\WINDOWS\system32\bhpfvemi.ini
2007-12-02 00:37 . 2007-12-02 00:42 721,412 —hs—- C:\WINDOWS\system32\tgefhcpu.ini
2007-12-02 00:26 . 2007-12-02 00:34 721,292 —hs—- C:\WINDOWS\system32\vxdjvuxe.ini
2007-12-01 22:38 . 2007-12-02 00:26 721,172 —hs—- C:\WINDOWS\system32\ygoqjanr.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 12:42 ——— d—–w C:\Program Files\OfficeScan NT
2007-12-24 02:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-17 20:54 ——— d—–w C:\Program Files\World of Warcraft
2007-11-30 14:47 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-18 00:30 ——— d—–w C:\Documents and Settings\Greg\Application Data\Apple Computer
2007-11-15 05:12 ——— d—–w C:\Documents and Settings\Pam\Application Data\Apple Computer
2007-11-15 05:11 ——— d—–w C:\Program Files\iTunes
2007-11-15 05:10 ——— d—–w C:\Program Files\iPod
2007-11-15 05:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-15 05:09 ——— d—–w C:\Program Files\QuickTime
2007-11-15 05:07 ——— d—–w C:\Program Files\Apple Software Update
2007-11-15 05:06 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-15 05:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-14 14:47 ——— d—–w C:\Documents and Settings\Pam\Application Data\dvdcss
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2007-11-07 01:17 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trymedia
2007-11-05 16:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-05 16:31 ——— d—–w C:\Program Files\epson
2007-11-04 21:10 ——— d—–w C:\Documents and Settings\Greg\Application Data\.gaim
2007-10-15 13:26 110 —-a-w C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
2004-08-04 17:13 26,953,157 —-a-w C:\Documents and Settings\Pam\NAV10ESD.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487581C2-0F36-4549-9BB3-5E4946E2F31D}]
C:\WINDOWS\system32\pmkhh.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d3d403aa-82b0-460d-a478-14d3121e12f3}]
C:\WINDOWS\system32\kriokrjy.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-26 21:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"48169de1"="C:\WINDOWS\system32\wqohveqp.dll" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 17:38]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 08:11:14]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-07-26 02:57:44]

C:\Documents and Settings\Pam\Start Menu\Programs\Startup\
MostFun.lnk - C:\Program Files\MostFun\Bin\MostFun.exe [2007-08-28 16:47:20]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=C:\WINDOWS\pss\NaturalColorLoad.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\48169de1]
rundll32.exe C:\WINDOWS\system32\ielxawgl.dll,b

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 –a—— C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ashampoo PopUpBlocker]
2004-02-03 12:13 1216000 –a—— C:\PROGRA~1\PCPOWE~1\PopUpKiller.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-09-12 21:10 335872 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
2004-07-30 11:04 245760 –a—— C:\Program Files\Creative\Shared Files\CAMTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 01:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
2005-11-07 15:49 601200 –a—— C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 EPSON Stylus CX3800 Series /O6 USB001 /M Stylus CX3800

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 08:07 114688 –a—— C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 17:04 52736 –a—— c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 08:19 155648 –a—— C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IO-Monitor]
2002-05-02 08:11 446464 –a—— C:\Program Files\OfficeScan NT\pccntmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 21:02 61440 –a—— C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-02-19 22:30 67128 –a—— C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-01-18 16:47 458752 –a—— C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 16:37 217088 –a—— C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-10-08 10:52 221184 –a—— C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-24 22:20 28672 –a—— C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-11-07 15:41 8192 –a—— C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
rundll32.exe nview.dll,nViewLoadHook

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OurPictures]
C:\Program Files\RitzPix E-Z Print & Share\OurPictures.exe /AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-07-31 21:28 81920 –a—— C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealOne Player\realplay.exe /RunUPGToolCommandReBoot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-13 22:42 212992 –a—— C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2006-10-12 03:10 49263 –a—— C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-03 23:10 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch]
C:\Program Files\WhenUSearch\Search.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZangoOE]
C:\Program Files\Zango\bin\10.0.370.0\OEAddOn.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZangoSA]
C:\Program Files\Zango\bin\10.0.370.0\ZangoSA.exe

R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 11:12]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2003-03-25 03:37]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2003-03-25 03:37]
S3 pnicml;pnicml;C:\DOCUME~1\Pam\LOCALS~1\Temp\pnicml.sys [2003-10-26 20:58]
S3 portenum;Intek21 PCI IO Driver;C:\WINDOWS\system32\DRIVERS\portenum.sys [2001-07-22 15:36]
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2003-03-25 03:37]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2003-03-25 03:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\SETUP.EXE -autorun

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39b152b3-11b7-11d9-b967-00095be00dfd}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 14:47:50 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2003-12-26 22:30:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2007-11-15 05:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-04 00:23:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 07:05:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-25 7:08:23 - machine was rebooted
.
2007-12-24 04:12:59 — E O F —



HijackThis log:


Logfile of HijackThis v1.99.1
Scan saved at 7:11:24 AM, on 12/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\conime.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {487581C2-0F36-4549-9BB3-5E4946E2F31D} - C:\WINDOWS\system32\pmkhh.dll (file missing)
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {3f21e121-3d41-874a-d064-0b28aa304d3d} - {d3d403aa-82b0-460d-a478-14d3121e12f3} - C:\WINDOWS\system32\kriokrjy.dll (file missing)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [48169de1] rundll32.exe "C:\WINDOWS\system32\wqohveqp.dll",b
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\rlls.dll' missing
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



Last HijackThis log after system restore:

Logfile of HijackThis v1.99.1
Scan saved at 09:52, on 2007-12-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {487581C2-0F36-4549-9BB3-5E4946E2F31D} - C:\WINDOWS\system32\pmkhh.dll (file missing)
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: {3f21e121-3d41-874a-d064-0b28aa304d3d} - {d3d403aa-82b0-460d-a478-14d3121e12f3} - C:\WINDOWS\system32\kriokrjy.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [48169de1] rundll32.exe "C:\WINDOWS\system32\wqohveqp.dll",b
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi

Hope you had a good Xmas. :)

First off, dont do a System Restore. The Restore points will be infected, and you will be re-infected. We will clean these at the end.

Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java Runtime Environment (JRE) (4th one down the list), which is JRE6u3, and click Yes at the page warning, then accept the Licence Agreement before downloading the Offline file.


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\rlls.dll
C:\WINDOWS\system32\eyoysnip.ini
C:\WINDOWS\system32\ovbkvgjt.ini
C:\WINDOWS\system32\ybisjfyp.ini
C:\WINDOWS\system32\eggiyhmv.ini
C:\WINDOWS\system32\mewhftnw.ini
C:\WINDOWS\system32\rufuehui.ini
C:\WINDOWS\system32\wiirppak.ini
C:\WINDOWS\system32\gjqwhvad.ini
C:\WINDOWS\system32\sdlxdoye.ini
C:\WINDOWS\system32\pqvgcyan.ini
C:\WINDOWS\system32\wmwxvitb.ini
C:\WINDOWS\system32\ywwhqtni.ini
C:\WINDOWS\system32\jhfuerbg.ini
C:\WINDOWS\system32\dpmjgfbw.ini
C:\WINDOWS\system32\bxlhxioi.ini
C:\WINDOWS\system32\qpgfemwv.ini
C:\WINDOWS\system32\atpsnesi.ini
C:\WINDOWS\system32\kueqrfgp.ini
C:\WINDOWS\system32\bijcmdvu.ini
C:\WINDOWS\system32\msrvohfo.ini
C:\WINDOWS\system32\nwwfdahc.ini
C:\WINDOWS\system32\ydajrmkb.ini
C:\WINDOWS\system32\tnrwyhce.ini
C:\WINDOWS\system32\hdeskfuo.ini
C:\WINDOWS\system32\tpaxcfhp.ini
C:\WINDOWS\system32\qerwvljh.ini
C:\WINDOWS\system32\khxfyvea.ini
C:\WINDOWS\system32\qicrfoxm.ini
C:\WINDOWS\system32\ycpuqgye.ini
C:\WINDOWS\system32\lgwaxlei.ini
C:\WINDOWS\system32\ssumafud.ini
C:\WINDOWS\system32\xnpvlhxn.ini
C:\WINDOWS\system32\odyafqev.ini
C:\WINDOWS\system32\vvssfdtw.ini
C:\WINDOWS\system32\wijijxhu.ini
C:\WINDOWS\system32\dbehrxpn.ini
C:\WINDOWS\system32\hcvvlglb.ini
C:\WINDOWS\system32\fgqrkpvb.ini
C:\WINDOWS\system32\cqprstyl.ini
C:\WINDOWS\system32\xabgsbco.ini
C:\WINDOWS\system32\jjwaxvix.ini
C:\WINDOWS\system32\kgfsmmee.ini
C:\WINDOWS\system32\mxsqhixi.ini
C:\WINDOWS\system32\eskuyirj.ini
C:\WINDOWS\system32\vknhvqiv.ini
C:\WINDOWS\system32\hxgqftui.ini
C:\WINDOWS\system32\vcpjbfbt.ini
C:\WINDOWS\system32\hqbwsuup.ini
C:\WINDOWS\system32\pwwdutvq.ini
C:\WINDOWS\system32\bomlteup.ini
C:\WINDOWS\system32\xtsskhbn.ini
C:\WINDOWS\system32\rmnckows.ini
C:\WINDOWS\system32\lmvbkbrb.ini
C:\WINDOWS\system32\scubnijm.ini
C:\WINDOWS\system32\llhwuhof.ini
C:\WINDOWS\system32\emcwpeua.ini
C:\WINDOWS\system32\vsbhuvrr.ini
C:\WINDOWS\system32\uurtplfu.ini
C:\WINDOWS\system32\hqposypg.ini
C:\WINDOWS\system32\xgugkctx.ini
C:\WINDOWS\system32\ghxsifkw.ini
C:\WINDOWS\system32\wdaecoco.ini
C:\WINDOWS\system32\efxtkkmp.ini
C:\WINDOWS\system32\chaaxlrv.ini
C:\WINDOWS\system32\bwupaxre.ini
C:\WINDOWS\system32\ciahkvps.ini
C:\WINDOWS\system32\kkvfnubk.ini
C:\WINDOWS\system32\cqcsjxai.ini
C:\WINDOWS\system32\dqakebud.ini
C:\WINDOWS\system32\obkwmtur.ini
C:\WINDOWS\system32\bntxchoc.ini
C:\WINDOWS\system32\qcimqtkx.ini
C:\WINDOWS\system32\wkumqtec.ini
C:\WINDOWS\system32\axdtptxn.ini
C:\WINDOWS\system32\jqdadafe.ini
C:\WINDOWS\system32\scmbbnmk.ini
C:\WINDOWS\system32\ryyoeanx.ini
C:\WINDOWS\system32\wqwrsbsg.ini
C:\WINDOWS\system32\iehptlur.ini
C:\WINDOWS\system32\xjoagqiu.ini
C:\WINDOWS\system32\sbcfutsw.ini
C:\WINDOWS\system32\fbvdtufj.ini
C:\WINDOWS\system32\owblmfeh.ini
C:\WINDOWS\system32\widtvepb.ini
C:\WINDOWS\system32\auvqyqnm.ini
C:\WINDOWS\system32\cchtvemr.ini
C:\WINDOWS\system32\bhpfvemi.ini
C:\WINDOWS\system32\tgefhcpu.ini
C:\WINDOWS\system32\vxdjvuxe.ini
C:\WINDOWS\system32\ygoqjanr.ini
C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
C:\DOCUME~1\Pam\LOCALS~1\Temp\pnicml.sys
C:\Documents and Settings\Pam\Start Menu\Programs\Startup\MostFun.lnk

Folder::
C:\Documents and Settings\Greg\Application Data\Zango
C:\Documents and Settings\All Users\Application Data\ZangoSA
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\VundoFix Backups
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Program Files\WhenUSearch
C:\Program Files\Zango
C:\Program Files\MostFun

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{487581C2-0F36-4549-9BB3-5E4946E2F31D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d3d403aa-82b0-460d-a478-14d3121e12f3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"48169de1"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\48169de1]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearch]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZangoOE]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZangoSA]

Driver::
pnicml

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download Lspfix. Extract(unzip) it to its own folder.
DO NOT RUN THIS YET!

If you can't connect to the internet after rebooting please do the following things:
First disconnect the cable from the internet, and close all browser windows.
Double-click LSPFix.
Click Finish. Don't use the "X" in the upper right hand corner to close the window, or the program won't execute.
Reboot Windows normally.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
Thanks again Scotty :thumbup:

Things are looking much better - LSPFix restored the network connection after ComboFix.

A very Merry Christmas to you too! - and here are the log files:



ComboFix 07-12-21.4 - Greg 2007-12-25 19:37:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.86.1033.18.1143 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Greg\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\DOCUME~1\Pam\LOCALS~1\Temp\pnicml.sys
C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
C:\Documents and Settings\Pam\Start Menu\Programs\Startup\MostFun.lnk
C:\WINDOWS\system32\atpsnesi.ini
C:\WINDOWS\system32\auvqyqnm.ini
C:\WINDOWS\system32\axdtptxn.ini
C:\WINDOWS\system32\bhpfvemi.ini
C:\WINDOWS\system32\bijcmdvu.ini
C:\WINDOWS\system32\bntxchoc.ini
C:\WINDOWS\system32\bomlteup.ini
C:\WINDOWS\system32\bwupaxre.ini
C:\WINDOWS\system32\bxlhxioi.ini
C:\WINDOWS\system32\cchtvemr.ini
C:\WINDOWS\system32\chaaxlrv.ini
C:\WINDOWS\system32\ciahkvps.ini
C:\WINDOWS\system32\cqcsjxai.ini
C:\WINDOWS\system32\cqprstyl.ini
C:\WINDOWS\system32\dbehrxpn.ini
C:\WINDOWS\system32\dpmjgfbw.ini
C:\WINDOWS\system32\dqakebud.ini
C:\WINDOWS\system32\efxtkkmp.ini
C:\WINDOWS\system32\eggiyhmv.ini
C:\WINDOWS\system32\emcwpeua.ini
C:\WINDOWS\system32\eskuyirj.ini
C:\WINDOWS\system32\eyoysnip.ini
C:\WINDOWS\system32\fbvdtufj.ini
C:\WINDOWS\system32\fgqrkpvb.ini
C:\WINDOWS\system32\ghxsifkw.ini
C:\WINDOWS\system32\gjqwhvad.ini
C:\WINDOWS\system32\hcvvlglb.ini
C:\WINDOWS\system32\hdeskfuo.ini
C:\WINDOWS\system32\hqbwsuup.ini
C:\WINDOWS\system32\hqposypg.ini
C:\WINDOWS\system32\hxgqftui.ini
C:\WINDOWS\system32\iehptlur.ini
C:\WINDOWS\system32\jhfuerbg.ini
C:\WINDOWS\system32\jjwaxvix.ini
C:\WINDOWS\system32\jqdadafe.ini
C:\WINDOWS\system32\kgfsmmee.ini
C:\WINDOWS\system32\khxfyvea.ini
C:\WINDOWS\system32\kkvfnubk.ini
C:\WINDOWS\system32\kueqrfgp.ini
C:\WINDOWS\system32\lgwaxlei.ini
C:\WINDOWS\system32\llhwuhof.ini
C:\WINDOWS\system32\lmvbkbrb.ini
C:\WINDOWS\system32\mewhftnw.ini
C:\WINDOWS\system32\msrvohfo.ini
C:\WINDOWS\system32\mxsqhixi.ini
C:\WINDOWS\system32\nwwfdahc.ini
C:\WINDOWS\system32\obkwmtur.ini
C:\WINDOWS\system32\odyafqev.ini
C:\WINDOWS\system32\ovbkvgjt.ini
C:\WINDOWS\system32\owblmfeh.ini
C:\WINDOWS\system32\pqvgcyan.ini
C:\WINDOWS\system32\pwwdutvq.ini
C:\WINDOWS\system32\qcimqtkx.ini
C:\WINDOWS\system32\qerwvljh.ini
C:\WINDOWS\system32\qicrfoxm.ini
C:\WINDOWS\system32\qpgfemwv.ini
C:\WINDOWS\system32\rlls.dll
C:\WINDOWS\system32\rmnckows.ini
C:\WINDOWS\system32\rufuehui.ini
C:\WINDOWS\system32\ryyoeanx.ini
C:\WINDOWS\system32\sbcfutsw.ini
C:\WINDOWS\system32\scmbbnmk.ini
C:\WINDOWS\system32\scubnijm.ini
C:\WINDOWS\system32\sdlxdoye.ini
C:\WINDOWS\system32\ssumafud.ini
C:\WINDOWS\system32\tgefhcpu.ini
C:\WINDOWS\system32\tnrwyhce.ini
C:\WINDOWS\system32\tpaxcfhp.ini
C:\WINDOWS\system32\uurtplfu.ini
C:\WINDOWS\system32\vcpjbfbt.ini
C:\WINDOWS\system32\vknhvqiv.ini
C:\WINDOWS\system32\vsbhuvrr.ini
C:\WINDOWS\system32\vvssfdtw.ini
C:\WINDOWS\system32\vxdjvuxe.ini
C:\WINDOWS\system32\wdaecoco.ini
C:\WINDOWS\system32\widtvepb.ini
C:\WINDOWS\system32\wiirppak.ini
C:\WINDOWS\system32\wijijxhu.ini
C:\WINDOWS\system32\wkumqtec.ini
C:\WINDOWS\system32\wmwxvitb.ini
C:\WINDOWS\system32\wqwrsbsg.ini
C:\WINDOWS\system32\xabgsbco.ini
C:\WINDOWS\system32\xgugkctx.ini
C:\WINDOWS\system32\xjoagqiu.ini
C:\WINDOWS\system32\xnpvlhxn.ini
C:\WINDOWS\system32\xtsskhbn.ini
C:\WINDOWS\system32\ybisjfyp.ini
C:\WINDOWS\system32\ycpuqgye.ini
C:\WINDOWS\system32\ydajrmkb.ini
C:\WINDOWS\system32\ygoqjanr.ini
C:\WINDOWS\system32\ywwhqtni.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
C:\Documents and Settings\All Users\Application Data\Trymedia
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{1BB236DD-DFEA-6966-C1CA-CE4D234EF7EB}
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{6A5CB438-5B3A-7072-6D0A-909D3DB78336}
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{6C87C783-B381-4FB9-F3C3-B8EA63AC83AD}
C:\Documents and Settings\All Users\Application Data\Trymedia\data\{97A478D0-A5C0-EC71-BAB0-ED032BAAC763}
C:\Documents and Settings\All Users\Application Data\ZangoSA
C:\Documents and Settings\Greg\Application Data\Zango
C:\Documents and Settings\NetworkService\Application Data\Starware
C:\Documents and Settings\Pam\Start Menu\Programs\Startup\MostFun.lnk
C:\Documents and Settings\Paul\Application Data\Starware
C:\Program Files\MostFun
C:\Program Files\MostFun\Bin\InitialCluster.xml
C:\Program Files\MostFun\Bin\InstallConfig.xml
C:\Program Files\MostFun\Bin\Kinitos.ContentDistribution2.dll
C:\Program Files\MostFun\Bin\Kinitos.CoreCapability.Logging.dll
C:\Program Files\MostFun\Bin\Kinitos.CoreCapability.Network.dll
C:\Program Files\MostFun\Bin\Kinitos.CoreCapability.Orchestration.dll
C:\Program Files\MostFun\Bin\Kinitos.CustInstAction.Runner.exe
C:\Program Files\MostFun\Bin\Kinitos.CustInstAction.Runner.exe.config
C:\Program Files\MostFun\Bin\Kinitos.CustomInstall.Platform.dll
C:\Program Files\MostFun\Bin\Kinitos.InternetPeering.dll
C:\Program Files\MostFun\Bin\Kinitos.Network.HttpTransport.dll
C:\Program Files\MostFun\Bin\Kinitos.SmartClientMgmt.Integration.DesktopRuntimeHost.dll
C:\Program Files\MostFun\Bin\Kinitos.SmartClientMgmt.Services.Client.dll
C:\Program Files\MostFun\Bin\Kinitos.SmartClientMgmt.Services.dll
C:\Program Files\MostFun\Bin\Kinitos.Transport.BDTcp.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.ASPHost.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Construct.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.DesktopRuntimeHost.Integration.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.EventHandling.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Framework.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.InternetPeeringFramework.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.RuntimeHosting.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.SmartClientMgmt.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.SmartClientMgmt.SmartForm.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Uninstall.exe
C:\Program Files\MostFun\Bin\Lib\Kinitos.Uninstall.exe.config
C:\Program Files\MostFun\Bin\Lib\Kinitos.Util.AppDomainBootstrapper.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Util.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Util.Remoting.dll
C:\Program Files\MostFun\Bin\Lib\Kinitos.Util.Windows.Forms.dll
C:\Program Files\MostFun\Bin\Lib\NeoEdge.AgentLauncher.Framework.dll
C:\Program Files\MostFun\Bin\Lib\NeoEdge.AgentLauncher.Gui.dll
C:\Program Files\MostFun\Bin\Lib\NeoEdge.AgentLauncher.Scripting.dll
C:\Program Files\MostFun\Bin\Lib\NeoEdge.AgentLauncher.Util.dll
C:\Program Files\MostFun\Bin\Lib\NeoEdge.CustomInstallActions.Agent.exe
C:\Program Files\MostFun\Bin\Lib\NeoEdge.CustomInstallActions.Agent.exe.config
C:\Program Files\MostFun\Bin\Lib\neoedge.custominstallactions.agent.InstallState
C:\Program Files\MostFun\Bin\Lib\SmartClientMgmt.CustomInstallActions.Client.exe
C:\Program Files\MostFun\Bin\Lib\SmartClientMgmt.CustomInstallActions.Client.exe.config
C:\Program Files\MostFun\Bin\Lib\smartclientmgmt.custominstallactions.client.InstallState
C:\Program Files\MostFun\Bin\MostFun.AgentLauncher.exe
C:\Program Files\MostFun\Bin\MostFun.AgentLauncher.exe.config
C:\Program Files\MostFun\Bin\MostFun.exe
C:\Program Files\MostFun\Bin\MostFun.exe.config
C:\Program Files\MostFun\Bin\NeoEdge.Integration.DesktopRuntimeHost.dll
C:\Program Files\MostFun\Bin\scl.exe
C:\Program Files\MostFun\Bin\scl.exe.config
C:\Program Files\screensavers.com
C:\Program Files\screensavers.com\Installer\bin\ScreensaversInst.dll
C:\Program Files\screensavers.com\Installer\bin\siuninst.exe
C:\Program Files\screensavers.com\Installer\temp\stubinstaller.ini
C:\Program Files\screensavers.com\Installer\temp\The_Weather_Channel_Application.exe
C:\Program Files\screensavers.com\Wallpaper\swpstart.exe
C:\VundoFix Backups
C:\VundoFix Backups\abpjuqwy.dll.bad
C:\VundoFix Backups\agntwrxl.dll.bad
C:\VundoFix Backups\agsqdpdf.dll.bad
C:\VundoFix Backups\akejuixi.dll.bad
C:\VundoFix Backups\amvxtree.dll.bad
C:\VundoFix Backups\aolbnqsm.dll.bad
C:\VundoFix Backups\assxcxkp.dll.bad
C:\VundoFix Backups\aubrjekg.dll.bad
C:\VundoFix Backups\avkpitwa.dll.bad
C:\VundoFix Backups\avoccjqd.dll.bad
C:\VundoFix Backups\axekxeag.dll.bad
C:\VundoFix Backups\bhibdfum.dll.bad
C:\VundoFix Backups\bibjntjn.dll.bad
C:\VundoFix Backups\bjeyyfea.dll.bad
C:\VundoFix Backups\blvtlmry.dll.bad
C:\VundoFix Backups\btwxkvya.dll.bad
C:\VundoFix Backups\bvpvsmqj.dll.bad
C:\VundoFix Backups\bvufhsra.dll.bad
C:\VundoFix Backups\bvysdbam.dll.bad
C:\VundoFix Backups\bxcfnlnw.dll.bad
C:\VundoFix Backups\bydlxnnc.dll.bad
C:\VundoFix Backups\byyqwpjg.dll.bad
C:\VundoFix Backups\ccavuebg.dll.bad
C:\VundoFix Backups\cejxjkmm.dll.bad
C:\VundoFix Backups\cfntahck.dll.bad
C:\VundoFix Backups\cgqehgdg.dll.bad
C:\VundoFix Backups\clcuqdkv.dll.bad
C:\VundoFix Backups\cnujmjsq.dll.bad
C:\VundoFix Backups\crfrdueq.dll.bad
C:\VundoFix Backups\crvjmxkg.dll.bad
C:\VundoFix Backups\cstvrxbr.dll.bad
C:\VundoFix Backups\cyoqpyco.dll.bad
C:\VundoFix Backups\dakkwghb.dll.bad
C:\VundoFix Backups\deavehfq.dll.bad
C:\VundoFix Backups\dffekvhm.dll.bad
C:\VundoFix Backups\dififgib.dll.bad
C:\VundoFix Backups\dlocxckr.dll.bad
C:\VundoFix Backups\dmulefhp.dll.bad
C:\VundoFix Backups\dolmbmrc.dll.bad
C:\VundoFix Backups\douhroue.ini.bad
C:\VundoFix Backups\dqyejkbs.dll.bad
C:\VundoFix Backups\drlwpdbh.dll.bad
C:\VundoFix Backups\dtaowlwk.dll.bad
C:\VundoFix Backups\dtdmdnxa.dll.bad
C:\VundoFix Backups\dtogriby.dll.bad
C:\VundoFix Backups\dvvnvbqe.dll.bad
C:\VundoFix Backups\dwlxsjqt.dll.bad
C:\VundoFix Backups\dxiybtfb.dll.bad
C:\VundoFix Backups\ebuuhopn.dll.bad
C:\VundoFix Backups\eccolsbr.dll.bad
C:\VundoFix Backups\ehewrrxx.dll.bad
C:\VundoFix Backups\emnsopyr.dll.bad
C:\VundoFix Backups\eoovrnit.dll.bad
C:\VundoFix Backups\epdpmthg.dll.bad
C:\VundoFix Backups\eqwnqypa.dll.bad
C:\VundoFix Backups\ermimpcw.dll.bad
C:\VundoFix Backups\euorhuod.dll.bad
C:\VundoFix Backups\fjjefpix.dll.bad
C:\VundoFix Backups\fmiggojd.dll.bad
C:\VundoFix Backups\frashidj.dll.bad
C:\VundoFix Backups\fvoashnf.dll.bad
C:\VundoFix Backups\fyyaucps.dll.bad
C:\VundoFix Backups\gbqcrlpj.dll.bad
C:\VundoFix Backups\gclucwop.dll.bad
C:\VundoFix Backups\gdggjhge.dll.bad
C:\VundoFix Backups\gdhemxch.dll.bad
C:\VundoFix Backups\gfkdjeyx.dll.bad
C:\VundoFix Backups\ghisfvjj.dll.bad
C:\VundoFix Backups\ghjrdynb.dll.bad
C:\VundoFix Backups\gjagsudt.dll.bad
C:\VundoFix Backups\gjpwqyyb.ini.bad
C:\VundoFix Backups\gjyqywjb.dll.bad
C:\VundoFix Backups\gkxmjvrc.ini.bad
C:\VundoFix Backups\goakwwek.dll.bad
C:\VundoFix Backups\gtcxixho.dll.bad
C:\VundoFix Backups\guknumpo.dll.bad
C:\VundoFix Backups\gxbsmpcc.dll.bad
C:\VundoFix Backups\hbyejemg.dll.bad
C:\VundoFix Backups\hdqicfen.dll.bad
C:\VundoFix Backups\hkygbkag.dll.bad
C:\VundoFix Backups\hpybvxyd.dll.bad
C:\VundoFix Backups\hsqxbogj.dll.bad
C:\VundoFix Backups\hvuaenoj.dll.bad
C:\VundoFix Backups\hxlqaalo.dll.bad
C:\VundoFix Backups\hyipoveq.dll.bad
C:\VundoFix Backups\icbpjpgi.dll.bad
C:\VundoFix Backups\ielxawgl.dll.bad
C:\VundoFix Backups\ijjscrty.dll.bad
C:\VundoFix Backups\inbjpfjm.dll.bad
C:\VundoFix Backups\iocysrus.dll.bad
C:\VundoFix Backups\ithridxr.dll.bad
C:\VundoFix Backups\itkrpmhu.dll.bad
C:\VundoFix Backups\iuwkvvyk.dll.bad
C:\VundoFix Backups\ivxbvnmm.dll.bad
C:\VundoFix Backups\iydcithw.dll.bad
C:\VundoFix Backups\iyyywtgf.dll.bad
C:\VundoFix Backups\jbdbasst.dll.bad
C:\VundoFix Backups\jdtxsptk.dll.bad
C:\VundoFix Backups\jimuluya.dll.bad
C:\VundoFix Backups\jirukuxi.dll.bad
C:\VundoFix Backups\jnomampe.dll.bad
C:\VundoFix Backups\joepfivk.dll.bad
C:\VundoFix Backups\jqsrywvv.dll.bad
C:\VundoFix Backups\jriyukse.dll.bad
C:\VundoFix Backups\jsipjfqo.dll.bad
C:\VundoFix Backups\jsrhxjnl.dll.bad
C:\VundoFix Backups\jvduouag.dll.bad
C:\VundoFix Backups\jvxehlxm.dll.bad
C:\VundoFix Backups\jwqbtmyl.dll.bad
C:\VundoFix Backups\kawfihja.dll.bad
C:\VundoFix Backups\kddcsotj.dll.bad
C:\VundoFix Backups\keuspuhf.dll.bad
C:\VundoFix Backups\klojpnch.dll.bad
C:\VundoFix Backups\kmggsexv.dll.bad
C:\VundoFix Backups\koimffgb.dll.bad
C:\VundoFix Backups\kokavygf.dll.bad
C:\VundoFix Backups\kqoymksq.dll.bad
C:\VundoFix Backups\krcidbnf.dll.bad
C:\VundoFix Backups\kriokrjy.dll.bad
C:\VundoFix Backups\kswxwtxk.dll.bad
C:\VundoFix Backups\ktelrgqw.dll.bad
C:\VundoFix Backups\kunkqcpm.dll.bad
C:\VundoFix Backups\kwyniyao.dll.bad
C:\VundoFix Backups\lakgahvi.dll.bad
C:\VundoFix Backups\llaocuih.dll.bad
C:\VundoFix Backups\llkcyatg.dll.bad
C:\VundoFix Backups\llqcyhtd.dll.bad
C:\VundoFix Backups\lnfiwpbi.dll.bad
C:\VundoFix Backups\lnhqtcek.dll.bad
C:\VundoFix Backups\lqhxdjev.dll.bad
C:\VundoFix Backups\lsbcxcte.dll.bad
C:\VundoFix Backups\lsltdsbu.dll.bad
C:\VundoFix Backups\lwxdulsr.dll.bad
C:\VundoFix Backups\lxrwsptw.dll.bad
C:\VundoFix Backups\lxrwtnga.ini.bad
C:\VundoFix Backups\lypwlvew.dll.bad
C:\VundoFix Backups\mchdxtkc.dll.bad
C:\VundoFix Backups\mhpcthsj.dll.bad
C:\VundoFix Backups\mkugckev.dll.bad
C:\VundoFix Backups\msqnbloa.ini.bad
C:\VundoFix Backups\mumuogoc.dll.bad
C:\VundoFix Backups\muurjqej.dll.bad
C:\VundoFix Backups\nhytjdrf.dll.bad
C:\VundoFix Backups\nixidkvv.dll.bad
C:\VundoFix Backups\njrgkalu.dll.bad
C:\VundoFix Backups\njsrytfc.dll.bad
C:\VundoFix Backups\nrwqsejx.dll.bad
C:\VundoFix Backups\ntleqalc.dll.bad
C:\VundoFix Backups\nxhlvpnx.dll.bad
C:\VundoFix Backups\oboaiusp.dll.bad
C:\VundoFix Backups\obxlhxcd.dll.bad
C:\VundoFix Backups\ofxslooc.dll.bad
C:\VundoFix Backups\ohrpbxnt.dll.bad
C:\VundoFix Backups\oiyftbeo.dll.bad
C:\VundoFix Backups\okmbhwxw.dll.bad
C:\VundoFix Backups\okwkupbq.dll.bad
C:\VundoFix Backups\omwlnmni.dll.bad
C:\VundoFix Backups\oofttdcn.dll.bad
C:\VundoFix Backups\opluigkc.dll.bad
C:\VundoFix Backups\opsbplfe.dll.bad
C:\VundoFix Backups\oqepvkbg.dll.bad
C:\VundoFix Backups\oqkvcvru.dll.bad
C:\VundoFix Backups\orqoqgye.dll.bad
C:\VundoFix Backups\osmjabir.dll.bad
C:\VundoFix Backups\pbwaikrk.dll.bad
C:\VundoFix Backups\pcxtrxyd.dll.bad
C:\VundoFix Backups\pdcvaxjr.dll.bad
C:\VundoFix Backups\phkblrnd.dll.bad
C:\VundoFix Backups\pinsyoye.dll.bad
C:\VundoFix Backups\pjjkfbgu.dll.bad
C:\VundoFix Backups\pkdbjbem.dll.bad
C:\VundoFix Backups\pkqvefcd.dll.bad
C:\VundoFix Backups\plxyilft.dll.bad
C:\VundoFix Backups\pmfcxchv.dll.bad
C:\VundoFix Backups\pmkhh.dll.bad
C:\VundoFix Backups\poxmdmxq.dll.bad
C:\VundoFix Backups\pqevhoqw.ini.bad
C:\VundoFix Backups\psjtjemk.dll.bad
C:\VundoFix Backups\pvpvmjrg.dll.bad
C:\VundoFix Backups\pyhgrqty.dll.bad
C:\VundoFix Backups\qdfdaboi.dll.bad
C:\VundoFix Backups\qfiyphvh.dll.bad
C:\VundoFix Backups\qhbyxxnc.dll.bad
C:\VundoFix Backups\qkcwebxa.dll.bad
C:\VundoFix Backups\qojtipxi.dll.bad
C:\VundoFix Backups\qomlsuiw.dll.bad
C:\VundoFix Backups\qoxudpqu.dll.bad
C:\VundoFix Backups\qqxdrepy.dll.bad
C:\VundoFix Backups\queygmmy.dll.bad
C:\VundoFix Backups\raktioyu.dll.bad
C:\VundoFix Backups\raqdgcec.dll.bad
C:\VundoFix Backups\rbnecpcn.dll.bad
C:\VundoFix Backups\rcqsocfy.dll.bad
C:\VundoFix Backups\rdfeolpd.dll.bad
C:\VundoFix Backups\rehhinbq.dll.bad
C:\VundoFix Backups\rfxutiin.dll.bad
C:\VundoFix Backups\rknqocve.dll.bad
C:\VundoFix Backups\rmktgpma.dll.bad
C:\VundoFix Backups\rultphei.dll.bad
C:\VundoFix Backups\rvcmhjye.dll.bad
C:\VundoFix Backups\rwxfvrhy.dll.bad
C:\VundoFix Backups\ryqewmyp.dll.bad
C:\VundoFix Backups\sdltwqcl.dll.bad
C:\VundoFix Backups\seacfsdf.dll.bad
C:\VundoFix Backups\sjajlfcm.dll.bad
C:\VundoFix Backups\slmxkgwr.dll.bad
C:\VundoFix Backups\solenyec.dll.bad
C:\VundoFix Backups\sopoajfq.dll.bad
C:\VundoFix Backups\sqxxifhj.dll.bad
C:\VundoFix Backups\srekyjnp.dll.bad
C:\VundoFix Backups\suxjemtp.dll.bad
C:\VundoFix Backups\swxjmoud.dll.bad
C:\VundoFix Backups\taqfjjjb.dll.bad
C:\VundoFix Backups\tbfbjpcv.dll.bad
C:\VundoFix Backups\tdvhnotp.dll.bad
C:\VundoFix Backups\tikeplxe.dll.bad
C:\VundoFix Backups\tjgvkbvo.dll.bad
C:\VundoFix Backups\tlupuule.dll.bad
C:\VundoFix Backups\tmatduff.dll.bad
C:\VundoFix Backups\todgyohw.dll.bad
C:\VundoFix Backups\tuuqjyek.dll.bad
C:\VundoFix Backups\twsbgmhw.dll.bad
C:\VundoFix Backups\txeujawj.dll.bad
C:\VundoFix Backups\tydfqaui.dll.bad
C:\VundoFix Backups\ucoabfmo.dll.bad
C:\VundoFix Backups\ucxwuhjg.dll.bad
C:\VundoFix Backups\ufjjejri.dll.bad
C:\VundoFix Backups\uhadvepg.dll.bad
C:\VundoFix Backups\uhasmsxv.dll.bad
C:\VundoFix Backups\uhcokfmx.dll.bad
C:\VundoFix Backups\uheupxnx.dll.bad
C:\VundoFix Backups\uhweoisi.dll.bad
C:\VundoFix Backups\uhxjijiw.dll.bad
C:\VundoFix Backups\uiagfdow.dll.bad
C:\VundoFix Backups\ujdjyepi.dll.bad
C:\VundoFix Backups\ujgovkkn.dll.bad
C:\VundoFix Backups\utijrhmh.dll.bad
C:\VundoFix Backups\vbgmxxgt.dll.bad
C:\VundoFix Backups\vkipblot.dll.bad
C:\VundoFix Backups\vlwkmusq.dll.bad
C:\VundoFix Backups\vmhyigge.dll.bad
C:\VundoFix Backups\vnglixoh.dll.bad
C:\VundoFix Backups\vouwacxj.dll.bad
C:\VundoFix Backups\vptrxgum.dll.bad
C:\VundoFix Backups\vqbnrtxy.dll.bad
C:\VundoFix Backups\vrxfgtvo.dll.bad
C:\VundoFix Backups\vuqwqaad.dll.bad
C:\VundoFix Backups\vvrjlqyh.dll.bad
C:\VundoFix Backups\vwbluknx.dll.bad
C:\VundoFix Backups\vwsgpmkb.dll.bad
C:\VundoFix Backups\vxthpbrf.dll.bad
C:\VundoFix Backups\wadvoken.dll.bad
C:\VundoFix Backups\waojyofo.dll.bad
C:\VundoFix Backups\wiccnujs.dll.bad
C:\VundoFix Backups\wiymahlb.dll.bad
C:\VundoFix Backups\wkorbgem.dll.bad
C:\VundoFix Backups\wljwsvdp.dll.bad
C:\VundoFix Backups\womridbk.dll.bad
C:\VundoFix Backups\wqohveqp.dll.bad
C:\VundoFix Backups\wrxqbinr.dll.bad
C:\VundoFix Backups\wtgksfah.dll.bad
C:\VundoFix Backups\wtlonxif.dll.bad
C:\VundoFix Backups\wvyglppc.dll.bad
C:\VundoFix Backups\wybmpogt.dll.bad
C:\VundoFix Backups\wytssvbo.dll.bad
C:\VundoFix Backups\xamsuqhh.dll.bad
C:\VundoFix Backups\xbnqocjo.dll.bad
C:\VundoFix Backups\xbshvbex.dll.bad
C:\VundoFix Backups\xedwwaod.dll.bad
C:\VundoFix Backups\xeljocyh.dll.bad
C:\VundoFix Backups\xiefuihy.dll.bad
C:\VundoFix Backups\xktqmicq.dll.bad
C:\VundoFix Backups\xnwwxpfv.dll.bad
C:\VundoFix Backups\xoeanguk.dll.bad
C:\VundoFix Backups\xrulqnox.dll.bad
C:\VundoFix Backups\xvmwrohp.dll.bad
C:\VundoFix Backups\xyiscdom.dll.bad
C:\VundoFix Backups\yaqjlpvj.dll.bad
C:\VundoFix Backups\yearfsjh.dll.bad
C:\VundoFix Backups\yemgsvoy.dll.bad
C:\VundoFix Backups\yffnmgii.dll.bad
C:\VundoFix Backups\yfrmojba.dll.bad
C:\VundoFix Backups\yisdjthv.dll.bad
C:\VundoFix Backups\yjcescmp.dll.bad
C:\VundoFix Backups\yjmwteic.dll.bad
C:\VundoFix Backups\ykirhuvc.dll.bad
C:\VundoFix Backups\yoooxcuc.dll.bad
C:\VundoFix Backups\yovovkbw.dll.bad
C:\VundoFix Backups\ytalepdb.dll.bad
C:\VundoFix Backups\yxhhdamp.dll.bad
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\atpsnesi.ini
C:\WINDOWS\system32\auvqyqnm.ini
C:\WINDOWS\system32\axdtptxn.ini
C:\WINDOWS\system32\bakhctox.dll
C:\WINDOWS\system32\bhpfvemi.ini
C:\WINDOWS\system32\bijcmdvu.ini
C:\WINDOWS\system32\bntxchoc.ini
C:\WINDOWS\system32\bomlteup.ini
C:\WINDOWS\system32\bwupaxre.ini
C:\WINDOWS\system32\bxlhxioi.ini
C:\WINDOWS\system32\catmflju.dll
C:\WINDOWS\system32\cchtvemr.ini
C:\WINDOWS\system32\chaaxlrv.ini
C:\WINDOWS\system32\ciahkvps.ini
C:\WINDOWS\system32\cqcsjxai.ini
C:\WINDOWS\system32\cqprstyl.ini
C:\WINDOWS\system32\dbehrxpn.ini
C:\WINDOWS\system32\dpmjgfbw.ini
C:\WINDOWS\system32\dqakebud.ini
C:\WINDOWS\system32\efxtkkmp.ini
C:\WINDOWS\system32\eggiyhmv.ini
C:\WINDOWS\system32\emcwpeua.ini
C:\WINDOWS\system32\eskuyirj.ini
C:\WINDOWS\system32\eyoysnip.ini
C:\WINDOWS\system32\fbvdtufj.ini
C:\WINDOWS\system32\fgmfmket.dll
C:\WINDOWS\system32\fgqrkpvb.ini
C:\WINDOWS\system32\ftoxoita.dll
C:\WINDOWS\system32\ghxsifkw.ini
C:\WINDOWS\system32\gjqwhvad.ini
C:\WINDOWS\system32\hcvvlglb.ini
C:\WINDOWS\system32\hdeskfuo.ini
C:\WINDOWS\system32\hkscshjm.dll
C:\WINDOWS\system32\hqbwsuup.ini
C:\WINDOWS\system32\hqposypg.ini
C:\WINDOWS\system32\hxgqftui.ini
C:\WINDOWS\system32\iehptlur.ini
C:\WINDOWS\system32\jhfuerbg.ini
C:\WINDOWS\system32\jjwaxvix.ini
C:\WINDOWS\system32\jmtenkfo.dll
C:\WINDOWS\system32\jqdadafe.ini
C:\WINDOWS\system32\kgfsmmee.ini
C:\WINDOWS\system32\khxfyvea.ini
C:\WINDOWS\system32\kkvfnubk.ini
C:\WINDOWS\system32\kueqrfgp.ini
C:\WINDOWS\system32\ldpackage.dll
C:\WINDOWS\system32\lgwaxlei.ini
C:\WINDOWS\system32\llhwuhof.ini
C:\WINDOWS\system32\lmvbkbrb.ini
C:\WINDOWS\system32\mewhftnw.ini
C:\WINDOWS\system32\msrvohfo.ini
C:\WINDOWS\system32\mxsqhixi.ini
C:\WINDOWS\system32\nwwfdahc.ini
C:\WINDOWS\system32\obkwmtur.ini
C:\WINDOWS\system32\odyafqev.ini
C:\WINDOWS\system32\ohtkmplr.dll
C:\WINDOWS\system32\ovbkvgjt.ini
C:\WINDOWS\system32\owblmfeh.ini
C:\WINDOWS\system32\pqvgcyan.ini
C:\WINDOWS\system32\ptpcripk.dll
C:\WINDOWS\system32\pwwdutvq.ini
C:\WINDOWS\system32\qcimqtkx.ini
C:\WINDOWS\system32\qerwvljh.ini
C:\WINDOWS\system32\qicrfoxm.ini
C:\WINDOWS\system32\qpgfemwv.ini
C:\WINDOWS\system32\rlls.dll
C:\WINDOWS\system32\rlxf.dll
C:\WINDOWS\system32\rmnckows.ini
C:\WINDOWS\system32\rmsxhacq.dll
C:\WINDOWS\system32\rufuehui.ini
C:\WINDOWS\system32\ryyoeanx.ini
C:\WINDOWS\system32\sbcfutsw.ini
C:\WINDOWS\system32\scmbbnmk.ini
C:\WINDOWS\system32\scubnijm.ini
C:\WINDOWS\system32\sdlxdoye.ini
C:\WINDOWS\system32\silc_dll.dll
C:\WINDOWS\system32\ssumafud.ini
C:\WINDOWS\system32\tdpyrngr.dll
C:\WINDOWS\system32\tgefhcpu.ini
C:\WINDOWS\system32\tnrwyhce.ini
C:\WINDOWS\system32\tpaxcfhp.ini
C:\WINDOWS\system32\uurtplfu.ini
C:\WINDOWS\system32\vcpjbfbt.ini
C:\WINDOWS\system32\vknhvqiv.ini
C:\WINDOWS\system32\vovepyvu.dll
C:\WINDOWS\system32\vsbhuvrr.ini
C:\WINDOWS\system32\vudbieqg.dll
C:\WINDOWS\system32\vvssfdtw.ini
C:\WINDOWS\system32\vxdjvuxe.ini
C:\WINDOWS\system32\wdaecoco.ini
C:\WINDOWS\system32\wfrnbuqy.dll
C:\WINDOWS\system32\widtvepb.ini
C:\WINDOWS\system32\wiirppak.ini
C:\WINDOWS\system32\wijijxhu.ini
C:\WINDOWS\system32\wkumqtec.ini
C:\WINDOWS\system32\wmwxvitb.ini
C:\WINDOWS\system32\wqwrsbsg.ini
C:\WINDOWS\system32\xabgsbco.ini
C:\WINDOWS\system32\xgugkctx.ini
C:\WINDOWS\system32\xjoagqiu.ini
C:\WINDOWS\system32\xnpvlhxn.ini
C:\WINDOWS\system32\xtsskhbn.ini
C:\WINDOWS\system32\ybisjfyp.ini
C:\WINDOWS\system32\ycpuqgye.ini
C:\WINDOWS\system32\ydajrmkb.ini
C:\WINDOWS\system32\ygoqjanr.ini
C:\WINDOWS\system32\ywwhqtni.ini
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_PNICML
——-\nm
——-\pnicml


((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 )))))))))))))))))))))))))))))))
.

2007-12-23 21:58 . 2007-12-23 21:58 d——– C:\Program Files\Dynamic Toolbar
2007-12-23 14:24 . 2007-12-23 21:21 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-23 14:24 . 2007-12-23 14:24 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-22 20:37 . 2007-12-22 20:37 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-12-13 10:51 . 2007-12-13 10:51 d——– C:\Documents and Settings\Pam\Application Data\Yahoo!
2007-12-13 03:11 . 2007-12-13 03:11 118 –a—— C:\WINDOWS\system32\MRT.INI
2007-12-01 22:23 . 2007-12-01 22:35 721,052 —hs—- C:\WINDOWS\system32\yauuxwiq.ini
2007-12-01 21:52 . 2007-12-01 22:23 720,932 —hs—- C:\WINDOWS\system32\mkprsirb.ini
2007-12-01 21:30 . 2007-12-01 21:49 720,812 —hs—- C:\WINDOWS\system32\xotsaqga.ini
2007-12-01 21:25 . 2007-12-01 21:30 720,691 —hs—- C:\WINDOWS\system32\qpkclfng.ini
2007-12-01 21:17 . 2007-12-01 21:23 794,084 —hs—- C:\WINDOWS\system32\qwqpexvd.ini
2007-12-01 20:57 . 2007-12-01 21:15 793,964 —hs—- C:\WINDOWS\system32\pcomgrue.ini
2007-12-01 18:23 . 2007-12-01 20:55 793,844 —hs—- C:\WINDOWS\system32\mpwldrsp.ini
2007-12-01 17:58 . 2007-12-01 18:23 793,724 —hs—- C:\WINDOWS\system32\xypqxait.ini
2007-12-01 17:27 . 2007-12-01 17:28 656,153 —hs—- C:\WINDOWS\system32\ptonhvdt.ini
2007-12-01 16:41 . 2007-12-01 17:27 656,093 —hs—- C:\WINDOWS\system32\nxkkyfdq.ini
2007-12-01 15:17 . 2007-12-01 16:38 655,973 —hs—- C:\WINDOWS\system32\wkyimhal.ini
2007-12-01 15:08 . 2007-12-01 15:17 655,853 —hs—- C:\WINDOWS\system32\hqerjdoc.ini
2007-12-01 14:59 . 2007-12-01 15:06 655,733 —hs—- C:\WINDOWS\system32\vtfgrdru.ini
2007-12-01 14:51 . 2007-12-01 14:57 655,613 —hs—- C:\WINDOWS\system32\cwnolafj.ini
2007-12-01 13:53 . 2007-12-01 14:49 655,493 —hs—- C:\WINDOWS\system32\hmehrsnn.ini
2007-12-01 13:46 . 2007-12-01 13:53 655,373 —hs—- C:\WINDOWS\system32\mqxfflyk.ini
2007-12-01 13:42 . 2007-12-01 13:46 655,251 —hs—- C:\WINDOWS\system32\jicqebhj.ini
2007-12-01 13:03 . 2007-12-01 13:39 794,924 —hs—- C:\WINDOWS\system32\puxvcggx.ini
2007-12-01 12:54 . 2007-12-01 13:02 794,804 —hs—- C:\WINDOWS\system32\igbxnady.ini
2007-12-01 12:46 . 2007-12-01 12:54 794,684 —hs—- C:\WINDOWS\system32\uolaxqsc.ini
2007-12-01 09:33 . 2007-12-01 12:46 794,564 —hs—- C:\WINDOWS\system32\aemkhait.ini
2007-12-01 06:58 . 2007-12-01 09:33 794,444 —hs—- C:\WINDOWS\system32\xaprewdq.ini
2007-11-30 15:21 . 2007-12-01 06:56 794,324 —hs—- C:\WINDOWS\system32\tmoekdgt.ini
2007-11-30 14:08 . 2007-11-30 15:13 701,756 —hs—- C:\WINDOWS\system32\aaxyxifo.ini
2007-11-30 08:46 . 2007-11-30 08:46 d——– C:\Program Files\Windows Live Favorites
2007-11-30 06:41 . 2007-11-30 14:07 700,458 —hs—- C:\WINDOWS\system32\rqbdcwku.ini
2007-11-29 17:47 . 2007-11-30 06:41 700,338 —hs—- C:\WINDOWS\system32\eqlclspc.ini
2007-11-29 17:40 . 2007-11-29 17:45 700,447 —hs—- C:\WINDOWS\system32\yfcvrysn.ini
2007-11-29 06:23 . 2007-11-29 17:38 701,946 —hs—- C:\WINDOWS\system32\nwktbiqd.ini
2007-11-28 19:57 . 2007-11-29 06:21 710,868 —hs—- C:\WINDOWS\system32\aqkqlftf.ini
2007-11-28 10:17 . 2007-11-28 19:57 793,003 —hs—- C:\WINDOWS\system32\iqyqxwvl.ini
2007-11-28 07:03 . 2007-11-28 10:17 792,823 —hs—- C:\WINDOWS\system32\gpvuxvej.ini
2007-11-27 19:56 . 2007-11-28 07:01 786,105 —hs—- C:\WINDOWS\system32\seailfhu.ini
2007-11-27 19:23 . 2007-11-27 19:23 d——– C:\Ver 1.80
2007-11-27 18:33 . 2007-11-27 19:50 785,925 —hs—- C:\WINDOWS\system32\ewdqjrwk.ini
2007-11-27 18:12 . 2007-11-27 18:31 785,805 —hs—- C:\WINDOWS\system32\tudeceal.ini
2007-11-27 18:07 . 2007-11-27 18:12 785,685 —hs—- C:\WINDOWS\system32\cshdiwhh.ini
2007-11-27 17:49 . 2007-11-27 18:04 785,565 —hs—- C:\WINDOWS\system32\meyqbkmg.ini
2007-11-27 17:41 . 2007-11-27 17:47 785,445 —hs—- C:\WINDOWS\system32\mqdsndbw.ini
2007-11-27 16:32 . 2007-11-27 17:39 785,325 —hs—- C:\WINDOWS\system32\glvbqirn.ini
2007-11-27 15:14 . 2007-11-27 16:30 785,205 —hs—- C:\WINDOWS\system32\quweyhwp.ini
2007-11-27 07:08 . 2007-11-27 15:14 785,086 —hs—- C:\WINDOWS\system32\qktoptgw.ini
2007-11-26 22:54 . 2007-11-27 07:06 781,405 —hs—- C:\WINDOWS\system32\jqwjcxus.ini
2007-11-26 19:45 . 2007-11-26 22:52 781,044 —hs—- C:\WINDOWS\system32\hldgmbpb.ini
2007-11-26 18:40 . 2007-11-26 19:45 780,924 —hs—- C:\WINDOWS\system32\easosdrx.ini
2007-11-26 09:02 . 2007-11-26 18:40 780,804 —hs—- C:\WINDOWS\system32\dfnxwcgq.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 12:42 ——— d—–w C:\Program Files\OfficeScan NT
2007-12-24 02:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-17 20:54 ——— d—–w C:\Program Files\World of Warcraft
2007-11-30 14:47 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-18 00:30 ——— d—–w C:\Documents and Settings\Greg\Application Data\Apple Computer
2007-11-15 05:12 ——— d—–w C:\Documents and Settings\Pam\Application Data\Apple Computer
2007-11-15 05:11 ——— d—–w C:\Program Files\iTunes
2007-11-15 05:10 ——— d—–w C:\Program Files\iPod
2007-11-15 05:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-15 05:09 ——— d—–w C:\Program Files\QuickTime
2007-11-15 05:07 ——— d—–w C:\Program Files\Apple Software Update
2007-11-15 05:06 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-15 05:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-14 14:47 ——— d—–w C:\Documents and Settings\Pam\Application Data\dvdcss
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2007-11-05 16:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-05 16:31 ——— d—–w C:\Program Files\epson
2007-11-04 21:10 ——— d—–w C:\Documents and Settings\Greg\Application Data\.gaim
2004-08-04 17:13 26,953,157 —-a-w C:\Documents and Settings\Pam\NAV10ESD.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-26 21:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 17:38]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 08:11:14]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-07-26 02:57:44]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=C:\WINDOWS\pss\NaturalColorLoad.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 –a—— C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ashampoo PopUpBlocker]
2004-02-03 12:13 1216000 –a—— C:\PROGRA~1\PCPOWE~1\PopUpKiller.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-09-12 21:10 335872 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
2004-07-30 11:04 245760 –a—— C:\Program Files\Creative\Shared Files\CAMTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 01:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
2005-11-07 15:49 601200 –a—— C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 EPSON Stylus CX3800 Series /O6 USB001 /M Stylus CX3800

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 08:07 114688 –a—— C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 17:04 52736 –a—— c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 08:19 155648 –a—— C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IO-Monitor]
2002-05-02 08:11 446464 –a—— C:\Program Files\OfficeScan NT\pccntmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 21:02 61440 –a—— C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-02-19 22:30 67128 –a—— C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-01-18 16:47 458752 –a—— C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 16:37 217088 –a—— C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-10-08 10:52 221184 –a—— C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-24 22:20 28672 –a—— C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-11-07 15:41 8192 –a—— C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
rundll32.exe nview.dll,nViewLoadHook

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OurPictures]
C:\Program Files\RitzPix E-Z Print & Share\OurPictures.exe /AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-07-31 21:28 81920 –a—— C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealOne Player\realplay.exe /RunUPGToolCommandReBoot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-13 22:42 212992 –a—— C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-03 23:10 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 11:12]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2003-03-25 03:37]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2003-03-25 03:37]
S3 portenum;Intek21 PCI IO Driver;C:\WINDOWS\system32\DRIVERS\portenum.sys [2001-07-22 15:36]
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2003-03-25 03:37]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2003-03-25 03:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\SETUP.EXE -autorun

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39b152b3-11b7-11d9-b967-00095be00dfd}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 14:47:50 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2003-12-26 22:30:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2007-11-15 05:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-04 00:23:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 19:49:23
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-25 19:52:38 - machine was rebooted [Greg]
C:\ComboFix … 2007-12-25 19:52
C:\ComboFix2.txt … 2007-12-25 09:22
C:\ComboFix3.txt … 2007-12-25 07:08
.
2007-12-24 04:12:59 — E O F —

Logfile of HijackThis v1.99.1
Scan saved at 8:06:54 PM, on 12/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\rsvp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi

Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\MRT.INI
Click Send.
Please post the results of this scan to this thread.


Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\yauuxwiq.ini
C:\WINDOWS\system32\mkprsirb.ini
C:\WINDOWS\system32\xotsaqga.ini
C:\WINDOWS\system32\qpkclfng.ini
C:\WINDOWS\system32\qwqpexvd.ini
C:\WINDOWS\system32\pcomgrue.ini
C:\WINDOWS\system32\mpwldrsp.ini
C:\WINDOWS\system32\xypqxait.ini
C:\WINDOWS\system32\ptonhvdt.ini
C:\WINDOWS\system32\nxkkyfdq.ini
C:\WINDOWS\system32\wkyimhal.ini
C:\WINDOWS\system32\hqerjdoc.ini
C:\WINDOWS\system32\vtfgrdru.ini
C:\WINDOWS\system32\cwnolafj.ini
C:\WINDOWS\system32\hmehrsnn.ini
C:\WINDOWS\system32\mqxfflyk.ini
C:\WINDOWS\system32\jicqebhj.ini
C:\WINDOWS\system32\puxvcggx.ini
C:\WINDOWS\system32\igbxnady.ini
C:\WINDOWS\system32\uolaxqsc.ini
C:\WINDOWS\system32\aemkhait.ini
C:\WINDOWS\system32\xaprewdq.ini
C:\WINDOWS\system32\tmoekdgt.ini
C:\WINDOWS\system32\aaxyxifo.ini
C:\WINDOWS\system32\rqbdcwku.ini
C:\WINDOWS\system32\eqlclspc.ini
C:\WINDOWS\system32\yfcvrysn.ini
C:\WINDOWS\system32\nwktbiqd.ini
C:\WINDOWS\system32\aqkqlftf.ini
C:\WINDOWS\system32\iqyqxwvl.ini
C:\WINDOWS\system32\gpvuxvej.ini
C:\WINDOWS\system32\seailfhu.ini
C:\WINDOWS\system32\ewdqjrwk.ini
C:\WINDOWS\system32\tudeceal.ini
C:\WINDOWS\system32\cshdiwhh.ini
C:\WINDOWS\system32\meyqbkmg.ini
C:\WINDOWS\system32\mqdsndbw.ini
C:\WINDOWS\system32\glvbqirn.ini
C:\WINDOWS\system32\quweyhwp.ini
C:\WINDOWS\system32\qktoptgw.ini
C:\WINDOWS\system32\jqwjcxus.ini
C:\WINDOWS\system32\hldgmbpb.ini
C:\WINDOWS\system32\easosdrx.ini
C:\WINDOWS\system32\dfnxwcgq.ini

DirLook::
C:\Ver 1.80

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
HI Scotty,

New logs - thanks again…

Antivirus Version Last Update Result
AhnLab-V3 2007.12.26.10 2007.12.26 -
AntiVir 7.6.0.46 2007.12.26 -
Authentium 4.93.8 2007.12.26 -
Avast 4.7.1098.0 2007.12.26 -
AVG 7.5.0.516 2007.12.25 -
BitDefender 7.2 2007.12.26 -
CAT-QuickHeal 9.00 2007.12.25 -
ClamAV 0.91.2 2007.12.26 -
DrWeb 4.44.0.09170 2007.12.26 -
eSafe 7.0.15.0 2007.12.25 -
eTrust-Vet 31.3.5400 2007.12.24 -
Ewido 4.0 2007.12.26 -
FileAdvisor 1 2007.12.26 -
Fortinet 3.14.0.0 2007.12.26 -
F-Prot 4.4.2.54 2007.12.25 -
F-Secure 6.70.13030.0 2007.12.26 -
Ikarus T3.1.1.15 2007.12.26 -
Kaspersky 7.0.0.125 2007.12.26 -
McAfee 5192 2007.12.24 -
Microsoft 1.3109 2007.12.26 -
NOD32v2 2747 2007.12.25 -
Norman 5.80.02 2007.12.26 -
Panda 9.0.0.4 2007.12.25 -
Prevx1 V2 2007.12.26 -
Rising 20.24.21.00 2007.12.26 -
Sophos 4.24.0 2007.12.26 -
Sunbelt 2.2.907.0 2007.12.21 -
Symantec 10 2007.12.26 -
TheHacker 6.2.9.168 2007.12.22 -
VBA32 3.12.2.5 2007.12.26 -
VirusBuster 4.3.26:9 2007.12.26 -
Webwasher-Gateway 6.6.2 2007.12.26 BlockReason.0
Additional information
File size: 118 bytes
MD5: 24a6b3b272937d2e683a50bc4f885ac8
SHA1: 157970b7151f48e29e39c0c17516f59c0922006e
PEiD: -


ComboFix 07-12-21.4 - Greg 2007-12-26 7:59:29.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.86.1033.18.1094 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Greg\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\aaxyxifo.ini
C:\WINDOWS\system32\aemkhait.ini
C:\WINDOWS\system32\aqkqlftf.ini
C:\WINDOWS\system32\cshdiwhh.ini
C:\WINDOWS\system32\cwnolafj.ini
C:\WINDOWS\system32\dfnxwcgq.ini
C:\WINDOWS\system32\easosdrx.ini
C:\WINDOWS\system32\eqlclspc.ini
C:\WINDOWS\system32\ewdqjrwk.ini
C:\WINDOWS\system32\glvbqirn.ini
C:\WINDOWS\system32\gpvuxvej.ini
C:\WINDOWS\system32\hldgmbpb.ini
C:\WINDOWS\system32\hmehrsnn.ini
C:\WINDOWS\system32\hqerjdoc.ini
C:\WINDOWS\system32\igbxnady.ini
C:\WINDOWS\system32\iqyqxwvl.ini
C:\WINDOWS\system32\jicqebhj.ini
C:\WINDOWS\system32\jqwjcxus.ini
C:\WINDOWS\system32\meyqbkmg.ini
C:\WINDOWS\system32\mkprsirb.ini
C:\WINDOWS\system32\mpwldrsp.ini
C:\WINDOWS\system32\mqdsndbw.ini
C:\WINDOWS\system32\mqxfflyk.ini
C:\WINDOWS\system32\nwktbiqd.ini
C:\WINDOWS\system32\nxkkyfdq.ini
C:\WINDOWS\system32\pcomgrue.ini
C:\WINDOWS\system32\ptonhvdt.ini
C:\WINDOWS\system32\puxvcggx.ini
C:\WINDOWS\system32\qktoptgw.ini
C:\WINDOWS\system32\qpkclfng.ini
C:\WINDOWS\system32\quweyhwp.ini
C:\WINDOWS\system32\qwqpexvd.ini
C:\WINDOWS\system32\rqbdcwku.ini
C:\WINDOWS\system32\seailfhu.ini
C:\WINDOWS\system32\tmoekdgt.ini
C:\WINDOWS\system32\tudeceal.ini
C:\WINDOWS\system32\uolaxqsc.ini
C:\WINDOWS\system32\vtfgrdru.ini
C:\WINDOWS\system32\wkyimhal.ini
C:\WINDOWS\system32\xaprewdq.ini
C:\WINDOWS\system32\xotsaqga.ini
C:\WINDOWS\system32\xypqxait.ini
C:\WINDOWS\system32\yauuxwiq.ini
C:\WINDOWS\system32\yfcvrysn.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\aaxyxifo.ini
C:\WINDOWS\system32\aemkhait.ini
C:\WINDOWS\system32\aqkqlftf.ini
C:\WINDOWS\system32\cshdiwhh.ini
C:\WINDOWS\system32\cwnolafj.ini
C:\WINDOWS\system32\dfnxwcgq.ini
C:\WINDOWS\system32\easosdrx.ini
C:\WINDOWS\system32\eqlclspc.ini
C:\WINDOWS\system32\ewdqjrwk.ini
C:\WINDOWS\system32\glvbqirn.ini
C:\WINDOWS\system32\gpvuxvej.ini
C:\WINDOWS\system32\hldgmbpb.ini
C:\WINDOWS\system32\hmehrsnn.ini
C:\WINDOWS\system32\hqerjdoc.ini
C:\WINDOWS\system32\igbxnady.ini
C:\WINDOWS\system32\iqyqxwvl.ini
C:\WINDOWS\system32\jicqebhj.ini
C:\WINDOWS\system32\jqwjcxus.ini
C:\WINDOWS\system32\meyqbkmg.ini
C:\WINDOWS\system32\mkprsirb.ini
C:\WINDOWS\system32\mpwldrsp.ini
C:\WINDOWS\system32\mqdsndbw.ini
C:\WINDOWS\system32\mqxfflyk.ini
C:\WINDOWS\system32\nwktbiqd.ini
C:\WINDOWS\system32\nxkkyfdq.ini
C:\WINDOWS\system32\pcomgrue.ini
C:\WINDOWS\system32\ptonhvdt.ini
C:\WINDOWS\system32\puxvcggx.ini
C:\WINDOWS\system32\qktoptgw.ini
C:\WINDOWS\system32\qpkclfng.ini
C:\WINDOWS\system32\quweyhwp.ini
C:\WINDOWS\system32\qwqpexvd.ini
C:\WINDOWS\system32\rqbdcwku.ini
C:\WINDOWS\system32\seailfhu.ini
C:\WINDOWS\system32\tmoekdgt.ini
C:\WINDOWS\system32\tudeceal.ini
C:\WINDOWS\system32\uolaxqsc.ini
C:\WINDOWS\system32\vtfgrdru.ini
C:\WINDOWS\system32\wkyimhal.ini
C:\WINDOWS\system32\xaprewdq.ini
C:\WINDOWS\system32\xotsaqga.ini
C:\WINDOWS\system32\xypqxait.ini
C:\WINDOWS\system32\yauuxwiq.ini
C:\WINDOWS\system32\yfcvrysn.ini

.
((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 )))))))))))))))))))))))))))))))
.

2007-12-23 21:58 . 2007-12-23 21:58 d——– C:\Program Files\Dynamic Toolbar
2007-12-23 14:24 . 2007-12-23 21:21 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-23 14:24 . 2007-12-23 14:24 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-22 20:37 . 2007-12-22 20:37 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-12-13 10:51 . 2007-12-13 10:51 d——– C:\Documents and Settings\Pam\Application Data\Yahoo!
2007-12-13 03:11 . 2007-12-13 03:11 118 –a—— C:\WINDOWS\system32\MRT.INI
2007-11-30 08:46 . 2007-11-30 08:46 d——– C:\Program Files\Windows Live Favorites
2007-11-27 19:23 . 2007-11-27 19:23 d——– C:\Ver 1.80

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 12:42 ——— d—–w C:\Program Files\OfficeScan NT
2007-12-24 02:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-17 20:54 ——— d—–w C:\Program Files\World of Warcraft
2007-11-30 14:47 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-18 00:30 ——— d—–w C:\Documents and Settings\Greg\Application Data\Apple Computer
2007-11-15 05:12 ——— d—–w C:\Documents and Settings\Pam\Application Data\Apple Computer
2007-11-15 05:11 ——— d—–w C:\Program Files\iTunes
2007-11-15 05:10 ——— d—–w C:\Program Files\iPod
2007-11-15 05:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-15 05:09 ——— d—–w C:\Program Files\QuickTime
2007-11-15 05:07 ——— d—–w C:\Program Files\Apple Software Update
2007-11-15 05:06 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-15 05:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-14 14:47 ——— d—–w C:\Documents and Settings\Pam\Application Data\dvdcss
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2007-11-06 21:20 67,648 —-a-w C:\WINDOWS\system32\vfctlqni.dll
2007-11-06 12:20 67,648 —-a-w C:\WINDOWS\system32\owvwyusa.dll
2007-11-05 16:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-05 16:31 ——— d—–w C:\Program Files\epson
2007-11-05 06:40 67,648 —-a-w C:\WINDOWS\system32\xnewcdqa.dll
2007-11-04 21:10 ——— d—–w C:\Documents and Settings\Greg\Application Data\.gaim
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 13:14 67,648 —-a-w C:\WINDOWS\system32\qtdysiti.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-23 00:06 67,136 —-a-w C:\WINDOWS\system32\kkwjsink.dll
2007-10-22 08:39 267,272 —-a-w C:\WINDOWS\system32\xactengine2_10.dll
2007-10-22 08:37 17,928 —-a-w C:\WINDOWS\system32\X3DAudio1_2.dll
2007-10-20 05:06 67,136 —-a-w C:\WINDOWS\system32\pfcmoqbv.dll
2007-10-12 20:14 3,734,536 —-a-w C:\WINDOWS\system32\d3dx9_36.dll
2007-10-12 20:14 1,374,232 —-a-w C:\WINDOWS\system32\D3DCompiler_36.dll
2007-10-02 14:56 444,776 —-a-w C:\WINDOWS\system32\d3dx10_36.dll
2004-08-04 17:13 26,953,157 —-a-w C:\Documents and Settings\Pam\NAV10ESD.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\Ver 1.80 —-

2001-07-18 01:41 9308 –a—— C:\Ver 1.80\LINUX\redhat6.0\FA31X.O
2001-07-18 01:41 42821 –a—— C:\Ver 1.80\LINUX\redhat6.0\FA31X.C
2001-07-18 01:41 32962 –a—— C:\Ver 1.80\LINUX\redhat6.0\FA31X.H
2001-07-18 01:41 148 –a—— C:\Ver 1.80\LINUX\redhat6.0\MAKEFILE
2001-07-17 12:26 3205 –a—— C:\Ver 1.80\HELP\LINUX\LINUX.TXT
2001-07-17 11:57 1223 –a—— C:\Ver 1.80\LINUX\redhat7.1\readme.txt
2001-07-17 11:56 1840 –a—— C:\Ver 1.80\LINUX\redhat7.0\readme.txt
2001-07-17 11:56 1840 –a—— C:\Ver 1.80\LINUX\redhat6.2\readme.txt
2001-07-17 11:56 1840 –a—— C:\Ver 1.80\LINUX\redhat6.1\readme.txt
2001-07-17 11:56 1840 –a—— C:\Ver 1.80\LINUX\redhat6.0\readme.txt
2001-07-16 18:32 9308 –a—— C:\Ver 1.80\LINUX\redhat6.1\FA31X.O
2001-07-16 18:32 42821 –a—— C:\Ver 1.80\LINUX\redhat6.1\FA31X.C
2001-07-16 18:32 32962 –a—— C:\Ver 1.80\LINUX\redhat6.1\FA31X.H
2001-07-16 18:32 148 –a—— C:\Ver 1.80\LINUX\redhat6.1\MAKEFILE
2001-07-16 18:16 9384 –a—— C:\Ver 1.80\LINUX\redhat6.2\FA31X.O
2001-07-16 18:16 42821 –a—— C:\Ver 1.80\LINUX\redhat6.2\FA31X.C
2001-07-16 18:16 32962 –a—— C:\Ver 1.80\LINUX\redhat6.2\FA31X.H
2001-07-16 18:16 148 –a—— C:\Ver 1.80\LINUX\redhat6.2\MAKEFILE
2001-07-16 14:54 9316 –a—— C:\Ver 1.80\LINUX\redhat7.0\FA31X.O
2001-07-16 14:45 32962 –a—— C:\Ver 1.80\LINUX\redhat7.0\FA31X.H
2001-07-16 14:42 42821 –a—— C:\Ver 1.80\LINUX\redhat7.0\FA31X.C
2001-07-16 14:22 174 –a—— C:\Ver 1.80\LINUX\redhat7.0\MAKEFILE
2001-06-29 13:40 39193 –a—— C:\Ver 1.80\LINUX\redhat7.1\natsemi.c
2001-06-29 13:40 17408 –a—— C:\Ver 1.80\LINUX\redhat7.1\natsemi.o
2001-06-29 13:33 237 –a—— C:\Ver 1.80\LINUX\redhat7.1\makefile
2001-05-10 16:48 6656 –a—— C:\Ver 1.80\HELP\NETWARE\NW50.TXT
2001-05-10 16:46 8734 –a—— C:\Ver 1.80\HELP\NETWARE\NW41X.TXT
2001-05-10 16:44 4378 –a—— C:\Ver 1.80\HELP\NDIS2DOS\LANTASTI.TXT
2001-05-08 09:25 15915 –a—— C:\Ver 1.80\HELP\SCO\SCOOPEN.TXT
2001-05-04 09:08 2634 –a—— C:\Ver 1.80\HELP\README.TXT
2001-05-04 09:00 9202 –a—— C:\Ver 1.80\HELP\FAQ.TXT
2001-05-04 08:56 3272 –a—— C:\Ver 1.80\HELP\DIAG.TXT
2001-05-04 08:55 43924 –a—— C:\Ver 1.80\HELP.EXE
2001-05-04 08:48 4830 –a—— C:\Ver 1.80\HELP\NETWARE\CLIENT32.TXT
2001-05-04 08:47 7496 –a—— C:\Ver 1.80\HELP\WIN95_98\WIN98.TXT
2001-05-04 08:47 5448 –a—— C:\Ver 1.80\HELP\WINNT\NT40.TXT
2001-05-04 08:46 7027 –a—— C:\Ver 1.80\HELP\WIN95_98\WIN95.TXT
2001-05-04 08:46 2627 –a—— C:\Ver 1.80\HELP\Win2k_me\Win2k_me.txt
2001-05-04 08:45 1810 –a—— C:\Ver 1.80\HELP\WFW311\WFW311.TXT
2001-05-04 08:44 958 –a—— C:\Ver 1.80\HELP\NDIS2DOS\NDIS2DOS.TXT
2001-05-04 08:42 3446 –a—— C:\Ver 1.80\NETWARE\SERVER\NW50\fa31x.ldi
2001-05-04 08:41 3446 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\fa31x.ldi
2001-05-04 08:41 3446 –a—— C:\Ver 1.80\NETWARE\CLIENT32\fa31x.ldi
2001-05-03 17:22 120158 –a—— C:\Ver 1.80\DIAG.EXE
2001-04-19 09:47 18944 –a—— C:\Ver 1.80\SCO\FA31XMDI
2001-04-18 10:35 23849 –a—— C:\Ver 1.80\NETWARE\SERVER\NW50\FA31X.LAN
2001-04-18 10:35 23849 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\FA31X.LAN
2001-04-18 10:35 23849 –a—— C:\Ver 1.80\NETWARE\CLIENT32\FA31X.LAN
2001-04-17 18:55 437 –a—— C:\Ver 1.80\WFW311\OEMSETUP.INF
2001-04-17 18:27 6340 –a—— C:\Ver 1.80\Netfa31x.inf
2001-04-17 18:25 24919 –a—— C:\Ver 1.80\OEMSETUP.INF
2001-04-17 18:25 17868 –a—— C:\Ver 1.80\FA31xNd3.sys
2001-04-17 18:23 390 –a—— C:\Ver 1.80\MAINMENU.DAT
2001-04-17 18:23 371 –a—— C:\Ver 1.80\FILEPATH.DAT
2001-04-17 18:13 19700 –a—— C:\Ver 1.80\FA31xND4.sys
2001-04-17 17:41 16025 –a—— C:\Ver 1.80\FA31xND5.sys
2001-04-17 15:35 35326 –a—— C:\Ver 1.80\WFW311\Fa31x.dos
2001-04-17 15:35 35326 –a—— C:\Ver 1.80\NDIS2DOS\Fa31x.dos
2001-04-17 14:42 1722 –a—— C:\Ver 1.80\NDIS2DOS\PROTOCOL.INI
1999-05-12 10:13 94723 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\MSM.NLM
1998-09-22 14:05 12073 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\ETHERTSM.NLM
1998-09-17 10:25 31531 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\NBI.NLM
1995-07-19 09:30 40888 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\LSWAP.EXE
1995-07-19 09:03 123459 –a—— C:\Ver 1.80\NETWARE\SERVER\NW41X\LOADER.EXE
1994-06-09 22:00 17976 –a—— C:\Ver 1.80\LINUX\redhat7.1\COPYING
1994-06-09 22:00 17976 –a—— C:\Ver 1.80\LINUX\redhat7.0\COPYING
1994-06-09 22:00 17976 –a—— C:\Ver 1.80\LINUX\redhat6.2\COPYING
1994-06-09 22:00 17976 –a—— C:\Ver 1.80\LINUX\redhat6.1\COPYING
1994-06-09 22:00 17976 –a—— C:\Ver 1.80\LINUX\redhat6.0\COPYING


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-26 21:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 17:38]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 08:11:14]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-07-26 02:57:44]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=C:\WINDOWS\pss\NaturalColorLoad.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 –a—— C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ashampoo PopUpBlocker]
2004-02-03 12:13 1216000 –a—— C:\PROGRA~1\PCPOWE~1\PopUpKiller.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-09-12 21:10 335872 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
2004-07-30 11:04 245760 –a—— C:\Program Files\Creative\Shared Files\CAMTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 01:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
2005-11-07 15:49 601200 –a—— C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 EPSON Stylus CX3800 Series /O6 USB001 /M Stylus CX3800

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 08:07 114688 –a—— C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 17:04 52736 –a—— c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 08:19 155648 –a—— C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IO-Monitor]
2002-05-02 08:11 446464 –a—— C:\Program Files\OfficeScan NT\pccntmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 21:02 61440 –a—— C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-02-19 22:30 67128 –a—— C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-01-18 16:47 458752 –a—— C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 16:37 217088 –a—— C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-10-08 10:52 221184 –a—— C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-24 22:20 28672 –a—— C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-11-07 15:41 8192 –a—— C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
rundll32.exe nview.dll,nViewLoadHook

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OurPictures]
C:\Program Files\RitzPix E-Z Print & Share\OurPictures.exe /AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-07-31 21:28 81920 –a—— C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealOne Player\realplay.exe /RunUPGToolCommandReBoot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-13 22:42 212992 –a—— C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-03 23:10 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 11:12]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2003-03-25 03:37]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2003-03-25 03:37]
S3 portenum;Intek21 PCI IO Driver;C:\WINDOWS\system32\DRIVERS\portenum.sys [2001-07-22 15:36]
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2003-03-25 03:37]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2003-03-25 03:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\SETUP.EXE -autorun

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39b152b3-11b7-11d9-b967-00095be00dfd}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 14:47:50 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2003-12-26 22:30:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2007-11-15 05:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-04 00:23:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-26 08:05:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
Completion time: 2007-12-26 8:06:43
C:\ComboFix … 2007-12-26 08:06
C:\ComboFix2.txt … 2007-12-25 19:52
C:\ComboFix3.txt … 2007-12-25 09:22
.
2007-12-24 04:12:59 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 8:11:41 AM, on 12/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi

I take it you know what this folder is? C:\Ver 1.80. You are a Linux user too?

Remember to disconnect from the Internet and disable your anti-virus before carrying out the next instruction, and to reenable the anti-virus before reconnecting to the Internet


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\vfctlqni.dll
C:\WINDOWS\system32\owvwyusa.dll
C:\WINDOWS\system32\xnewcdqa.dll
C:\WINDOWS\system32\qtdysiti.dll
C:\WINDOWS\system32\kkwjsink.dll
C:\WINDOWS\system32\pfcmoqbv.dll

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task-Manager use the Processes tab (press ctrl alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
Hi Scotty,

I do not use Linux on my home PCs - must have been one of the kids. I'll have to find out why this was done. It seems that I'm always finding strange software on this machine. :wacko:

I do use AIX at work - so I am familiar with unix.

Thanks again for all of your great help!

Here are the latest log files:

ComboFix 07-12-21.4 - Greg 2007-12-27 8:38:16.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.936.86.1033.18.1129 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Greg\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\kkwjsink.dll
C:\WINDOWS\system32\owvwyusa.dll
C:\WINDOWS\system32\pfcmoqbv.dll
C:\WINDOWS\system32\qtdysiti.dll
C:\WINDOWS\system32\vfctlqni.dll
C:\WINDOWS\system32\xnewcdqa.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\kkwjsink.dll
C:\WINDOWS\system32\owvwyusa.dll
C:\WINDOWS\system32\pfcmoqbv.dll
C:\WINDOWS\system32\qtdysiti.dll
C:\WINDOWS\system32\vfctlqni.dll
C:\WINDOWS\system32\xnewcdqa.dll

.
((((((((((((((((((((((((( Files Created from 2007-11-27 to 2007-12-27 )))))))))))))))))))))))))))))))
.

2007-12-23 21:58 . 2007-12-23 21:58 d——– C:\Program Files\Dynamic Toolbar
2007-12-23 14:24 . 2007-12-23 21:21 54,156 –ah—– C:\WINDOWS\QTFont.qfn
2007-12-23 14:24 . 2007-12-23 14:24 1,409 –a—— C:\WINDOWS\QTFont.for
2007-12-22 20:37 . 2007-12-22 20:37 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-12-13 10:51 . 2007-12-13 10:51 d——– C:\Documents and Settings\Pam\Application Data\Yahoo!
2007-12-13 03:11 . 2007-12-13 03:11 118 –a—— C:\WINDOWS\system32\MRT.INI
2007-11-30 08:46 . 2007-11-30 08:46 d——– C:\Program Files\Windows Live Favorites
2007-11-27 19:23 . 2007-11-27 19:23 d——– C:\Ver 1.80

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 12:42 ——— d—–w C:\Program Files\OfficeScan NT
2007-12-24 02:54 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-17 20:54 ——— d—–w C:\Program Files\World of Warcraft
2007-11-30 14:47 ——— d—–w C:\Program Files\Windows Live Toolbar
2007-11-18 00:30 ——— d—–w C:\Documents and Settings\Greg\Application Data\Apple Computer
2007-11-15 05:12 ——— d—–w C:\Documents and Settings\Pam\Application Data\Apple Computer
2007-11-15 05:11 ——— d—–w C:\Program Files\iTunes
2007-11-15 05:10 ——— d—–w C:\Program Files\iPod
2007-11-15 05:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-15 05:09 ——— d—–w C:\Program Files\QuickTime
2007-11-15 05:07 ——— d—–w C:\Program Files\Apple Software Update
2007-11-15 05:06 ——— d—–w C:\Program Files\Common Files\Apple
2007-11-15 05:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-14 14:47 ——— d—–w C:\Documents and Settings\Pam\Application Data\dvdcss
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 18:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\ATI MMC
2007-11-05 16:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-05 16:31 ——— d—–w C:\Program Files\epson
2007-11-04 21:10 ——— d—–w C:\Documents and Settings\Greg\Application Data\.gaim
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-22 08:39 267,272 —-a-w C:\WINDOWS\system32\xactengine2_10.dll
2007-10-22 08:37 17,928 —-a-w C:\WINDOWS\system32\X3DAudio1_2.dll
2007-10-12 20:14 3,734,536 —-a-w C:\WINDOWS\system32\d3dx9_36.dll
2007-10-12 20:14 1,374,232 —-a-w C:\WINDOWS\system32\D3DCompiler_36.dll
2007-10-02 14:56 444,776 —-a-w C:\WINDOWS\system32\d3dx10_36.dll
2004-08-04 17:13 26,953,157 —-a-w C:\Documents and Settings\Pam\NAV10ESD.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-03 23:10]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-26 21:31]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-13 17:38]

C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
mod_sm.lnk - C:\hp\bin\cloaker.exe [1999-11-07 08:11:14]

C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
spamsubtract.lnk - C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe [2003-07-26 02:57:44]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2003-02-21 04:50 40960 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NaturalColorLoad.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NaturalColorLoad.lnk
backup=C:\WINDOWS\pss\NaturalColorLoad.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quicken Scheduled Updates.lnk
backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=C:\WINDOWS\pss\VPN Client.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
backup=C:\WINDOWS\pss\ymetray.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Greg^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
path=C:\Documents and Settings\Greg\Start Menu\Programs\Startup\PowerReg Scheduler.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler.exeStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 22:46 57344 –a—— C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ashampoo PopUpBlocker]
2004-02-03 12:13 1216000 –a—— C:\PROGRA~1\PCPOWE~1\PopUpKiller.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATI Launchpad]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2003-09-12 21:10 335872 –a—— C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe –force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
2004-07-30 11:04 245760 –a—— C:\Program Files\Creative\Shared Files\CAMTRAY.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 01:56 15360 –a—— C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
2005-11-07 15:49 601200 –a—— C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX3800 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE /P26 EPSON Stylus CX3800 Series /O6 USB001 /M Stylus CX3800

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2003-04-07 08:07 114688 –a—— C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 17:04 52736 –a—— c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2003-04-07 08:19 155648 –a—— C:\WINDOWS\System32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IO-Monitor]
2002-05-02 08:11 446464 –a—— C:\Program Files\OfficeScan NT\pccntmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 –a—— C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 21:02 61440 –a—— C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-02-19 22:30 67128 –a—— C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
C:\Program Files\Logitech\Video\ManifestEngine.exe boot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-01-18 16:47 458752 –a—— C:\Program Files\Logitech\Video\ISStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 16:37 217088 –a—— C:\Program Files\Logitech\Video\LogiTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2004-10-08 10:52 221184 –a—— C:\WINDOWS\system32\LVCOMSX.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2002-07-24 22:20 28672 –a—— C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2006-11-07 15:41 8192 –a—— C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIEW]
rundll32.exe nview.dll,nViewLoadHook

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OurPictures]
C:\Program Files\RitzPix E-Z Print & Share\OurPictures.exe /AutoStart

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2002-07-31 21:28 81920 –a—— C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealPlayer]
C:\Program Files\Real\RealOne Player\realplay.exe /RunUPGToolCommandReBoot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-13 22:42 212992 –a—— C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-03 23:10 68856 –a—— C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe /r

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE -quiet

R3 FA312;NETGEAR FA330/FA312/FA311 Fast Ethernet Adapter Driver;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 11:12]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2003-03-25 03:37]
R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2003-03-25 03:37]
S3 portenum;Intek21 PCI IO Driver;C:\WINDOWS\system32\DRIVERS\portenum.sys [2001-07-22 15:36]
S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2003-03-25 03:37]
S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2003-03-25 03:37]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\SETUP.EXE -autorun

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39b152b3-11b7-11d9-b967-00095be00dfd}]
\Shell\AutoRun\command - JDSecure\Windows\JDSecure20.exe

.
Contents of the 'Scheduled Tasks' folder
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 14:47:50 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2003-12-26 22:30:07 C:\WINDOWS\Tasks\Easy Internet Sign-up.job"
- C:\Program Files\Easy Internet signup\HPSdpApp.exe
"2007-11-15 05:08:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-11-15 05:07:36 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-08-04 00:23:02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-27 08:43:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll
.
Completion time: 2007-12-27 8:44:36
C:\ComboFix … 2007-12-27 08:44
C:\ComboFix2.txt … 2007-12-26 08:06
C:\ComboFix3.txt … 2007-12-25 19:52
.
2007-12-24 04:12:59 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 8:57:33 AM, on 12/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\OfficeScan NT\ntrtscan.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OfficeScan NT\tmlisten.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\dmadmin.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: &Windows; Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

R3 - URLSearchHook: {1A03F196-9617-4CA0-842B-A83CEECB022B} - - (no file)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked exit HijackThis and reboot the computer.

Delete the older versions of Java and download the newest.
Please follow these steps to remove older version Java components.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Then download the latest version of Java Runtime Environment (JRE) (4th one down the list), which is JRE6u3, and click Yes at the page warning, then accept the Licence Agreement before downloading the Offline file.


I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight Viewpoint Manager Service, click Remove.
  • Do the same for each Viewpoint component.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log..

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.
Hi Scotty,

Here are the new logs…

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, December 27, 2007 1:34:09 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 27/12/2007
Kaspersky Anti-Virus database records: 497856
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 204300
Number of viruses found: 48
Number of infected objects: 694
Number of suspicious objects: 0
Duration of the scan process: 02:46:09

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Documents\bitstorm.exe/data0009 Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k skipped
C:\Documents and Settings\All Users\Documents\bitstorm.exe Inno: infected - 1 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-2104ec88.VIR CryptFF.b: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-4337cc2d.VIR CryptFF.b: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-11faa9ed-49d39bfe.VIR CryptFF.b: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR/GetAccess.class Infected: Trojan.Java.ClassLoader.c skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR/InsecureClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\classload.jar-53d6da01-61d38b5b.VIR CryptFF.b: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\count.jar-394a7981-69c3d1d8.VIR/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\count.jar-394a7981-69c3d1d8.VIR/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\count.jar-394a7981-69c3d1d8.VIR/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\count.jar-394a7981-69c3d1d8.VIR ZIP: infected - 3 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\count.jar-394a7981-69c3d1d8.VIR CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR/NewSecurityClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR/NewURLClassLoader.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\java.jar-8fba448-312f2413.VIR CryptFF.b: infected - 4 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\loaderadv702.jar-309c8f5f-11665014.VIR/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\loaderadv702.jar-309c8f5f-11665014.VIR/Counter.class Infected: Trojan.Java.ClassLoader.h skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\loaderadv702.jar-309c8f5f-11665014.VIR/Parser.class Infected: Trojan.Java.ClassLoader.d skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\loaderadv702.jar-309c8f5f-11665014.VIR ZIP: infected - 3 skipped
C:\Documents and Settings\Greg\.jpi_cache\jar\1.0\loaderadv702.jar-309c8f5f-11665014.VIR CryptFF.b: infected - 3 skipped
C:\Documents and Settings\Greg\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Greg\Desktop\Applications\kf141.zip/keyfinder.exe/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Greg\Desktop\Applications\kf141.zip/keyfinder.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Greg\Desktop\Applications\kf141.zip/keyfinder.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Greg\Desktop\Applications\kf141.zip/keyfinder.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
C:\Documents and Settings\Greg\Desktop\Applications\kf141.zip ZIP: infected - 4 skipped
C:\Documents and Settings\Greg\Desktop\New Folder\AntiVirusInstallFreeNM_en.exe Infected: not-a-virus:Downloader.Win32.WinFixer.an skipped
C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Greg\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Greg\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Greg\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Greg\ntuser.dat Object is locked skipped
C:\Documents and Settings\Greg\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Pam\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-681c693e.zip/vmain.class Infected: Exploit.Java.Gimsh.b skipped
C:\Documents and Settings\Pam\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-681c693e.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Pam\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Pam\Desktop\artisanburner.exe/data0008 Infected: not-a-virus:Server-Proxy.Win32.MarketScore.k skipped
C:\Documents and Settings\Pam\Desktop\artisanburner.exe Inno: infected - 1 skipped
C:\Documents and Settings\Pam\Desktop\Setup(2).exe Infected: not-a-virus:AdTool.Win32.Zango.b skipped
C:\Documents and Settings\Pam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Pam\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Pam\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pam\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Pam\ntuser.dat Object is locked skipped
C:\Documents and Settings\Pam\ntuser.dat.LOG Object is locked skipped
C:\e1dea0646305774fbf38\sp2\update\update.exe Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\billing_Pam.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\client_Pam.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\network_Pam.log Object is locked skipped
C:\Program Files\Yahoo!\Messenger\logs\voice.log Object is locked skipped
C:\qoobox\Quarantine\C\Program Files\Screensavers.com\Installer\bin\ScreensaversInst.dll.vir Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\kkwjsink.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\owvwyusa.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\pfcmoqbv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\qtdysiti.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\vfctlqni.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\xnewcdqa.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP11\A0080191.exe Infected: not-a-virus:AdWare.Win32.RK.k skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP11\A0081175.dll Infected: not-a-virus:AdWare.Win32.RK.m skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP16\A0144087.dll Infected: not-a-virus:AdWare.Win32.180Solutions.bl skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP16\A0144092.dll Infected: not-a-virus:AdWare.Win32.HotBar.ch skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP16\A0144103.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.180Solutions.bj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP16\A0144103.exe/stream Infected: not-a-virus:AdWare.Win32.180Solutions.bj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP16\A0144103.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP17\A0153333.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP17\A0160422.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165453.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165478.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165506.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165533.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165553.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165573.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165610.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165638.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165697.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165725.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165744.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165772.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165773.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165782.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165805.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165824.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0165876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0166876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0166877.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0166914.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP18\A0166933.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0167313.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0167314.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0167343.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0167375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0167408.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0172483.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0172507.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0172516.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0173516.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP21\A0174536.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP22\A0174552.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP23\A0174589.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP23\A0174619.exe Infected: not-a-virus:AdWare.Win32.RK.n skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP23\A0174625.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP23\A0174626.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP23\A0174627.dll Infected: not-a-virus:AdWare.Win32.RK.o skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174744.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174776.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174786.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174817.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174838.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174861.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174922.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174979.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0174987.exe Infected: not-a-virus:AdWare.Win32.RK.q skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0175038.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0175061.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176061.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176106.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176133.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176155.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176181.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0176189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0177189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0178189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0180189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0181189.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0181197.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0182205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0183205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0184205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0185205.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0185229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0186229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0187229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0188229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0189229.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0189271.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0189272.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0190271.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0190280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0191280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0192280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0194280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0195280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0196280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP25\A0198280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0199280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0202280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0203280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0204280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0205280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0207280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0208280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0209280.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0209300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0210300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0211300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0212300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0214300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0215300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0217300.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0217309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0218309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0219309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0222309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0223309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0225309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0226309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0227309.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0227328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0228328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0229328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0230328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0231328.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0231353.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0232353.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0234353.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0235353.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0236353.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0236375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0237375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0239375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0240375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0241375.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0241422.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0241455.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0241463.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0241485.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0242485.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0242497.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0243497.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0243519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0244519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0245519.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP26\A0245535.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0246668.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0246690.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0247690.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0257698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0258698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0258699.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0259698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0260698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0261698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0262698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0263698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0265698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0266698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0267698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0268698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0269698.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0269708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0271708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0272708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0273708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0274708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0275708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0276708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0277708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0278708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0279708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0280708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0281708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0282708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0283708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0284708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0285708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0287708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0291708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0292708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0293708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0295708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0296708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0297708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0298708.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0298720.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0298746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0299746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0300746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0301746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0302746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0303746.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0303771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0304771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0304772.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0305771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0306771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0307771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0309771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0310771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0311771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0311772.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0312771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0313771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0315771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0316771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0317771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0318796.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0319796.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0320796.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0320843.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0322843.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0322852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0323852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0324852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0325852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0326852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0327852.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0327878.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP27\A0327879.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0327893.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0328906.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0329549.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0330549.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0331549.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0331550.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0332557.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0332566.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0332592.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0332617.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0333617.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0333626.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0333635.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0334635.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP28\A0334655.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP29\A0334847.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aex skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP29\A0335655.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP29\A0335695.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP29\A0335721.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP30\A0336809.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0336875.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0336876.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0337881.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0338902.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0338933.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0338995.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0340995.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0341995.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP31\A0342995.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343006.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343049.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343060.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343085.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP32\A0343145.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP33\A0343163.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP33\A0343185.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP34\A0343197.ini Infected: Backdoor.IRC.Zapchast skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP34\A0343207.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP35\A0343240.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP35\A0343325.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP35\A0343329.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP35\A0343336.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP35\A0343356.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP37\A0343709.ini Infected: Backdoor.IRC.Zapchast skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP38\A0343753.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343770.ini Infected: Backdoor.IRC.Zapchast skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343783.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343785.dll Infected: Trojan.Win32.BHO.rg skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343786.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343787.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343788.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343789.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343791.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343792.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343793.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343794.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343799.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343803.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343804.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343805.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343806.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343807.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343809.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343810.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343811.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343813.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343814.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343818.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343822.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343823.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343824.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343825.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.al skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343827.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343830.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343831.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343832.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343835.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343836.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343837.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343838.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343840.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343841.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343844.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343847.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343848.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343849.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343850.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343856.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343859.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343860.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343863.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343868.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343870.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343871.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343872.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343874.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343876.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343877.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343878.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343880.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343881.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343882.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343883.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343885.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343890.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343891.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343893.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343895.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343899.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343900.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343901.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343902.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343906.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.al skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343907.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343908.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343910.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343912.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343914.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343917.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343918.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343921.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343922.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343923.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343925.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343926.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343927.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343928.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343929.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343930.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343931.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343933.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343934.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343936.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343938.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343940.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343941.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343944.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343945.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343946.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ag skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343948.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343950.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ag skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343951.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343954.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343955.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343956.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343957.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343958.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343960.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343963.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343964.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343965.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343967.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343970.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343971.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343972.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343973.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343974.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343976.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343977.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343984.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343985.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343986.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343987.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343988.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343989.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343991.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343992.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343994.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343996.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.agh skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343997.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343998.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0343999.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344003.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344004.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344006.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344009.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344010.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344011.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344012.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344013.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344015.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344018.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344019.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344021.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344023.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344024.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344025.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344030.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344032.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344033.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344034.dll Infected: Trojan.Win32.BHO.rg skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344035.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344036.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344037.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344038.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344042.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344044.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344045.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344046.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344047.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344048.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344050.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344051.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344053.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344054.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344056.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344057.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344059.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344061.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344063.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP39\A0344072.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP40\A0344103.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP40\A0344112.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344120.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344121.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344123.dll Infected: Trojan.Win32.BHO.rg skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344124.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344125.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344126.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344127.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344129.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344130.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344131.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344132.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344137.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344141.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344142.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344143.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344144.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344145.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344147.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344148.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344149.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344151.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344152.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344156.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344160.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344161.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344162.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344163.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.al skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344165.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344168.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344169.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344170.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344173.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344174.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344175.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344176.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344178.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344179.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344182.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344185.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344186.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344187.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344188.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344194.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344197.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344198.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344201.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344206.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344208.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344209.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344210.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344212.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344214.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344215.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344216.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344218.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344219.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344220.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344221.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344223.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344228.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344229.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344231.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344233.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344237.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344239.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344240.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344241.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344245.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.al skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344246.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344247.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344249.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344251.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344253.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344257.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344258.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344261.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344262.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344263.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344265.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344266.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344267.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344268.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344269.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344270.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344271.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344273.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344274.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344276.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344278.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344280.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344281.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344284.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344285.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344286.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ag skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344288.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344290.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ag skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344291.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344294.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344295.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344296.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344297.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344298.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344300.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344303.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344304.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344305.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344307.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344310.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344311.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344312.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344313.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344314.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344316.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344317.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344324.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344325.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344326.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344327.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344328.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344329.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344331.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344332.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344335.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.agh skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344336.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344337.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344338.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.i skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344342.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344343.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344345.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344348.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344349.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344350.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344351.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344352.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344354.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344357.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344358.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344360.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344362.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344363.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344364.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344369.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344371.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344372.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344373.dll Infected: Trojan.Win32.BHO.rg skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344374.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344375.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344376.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344377.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344378.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344381.dll Infected: Trojan.Win32.BHO.rd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344383.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344384.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.acd skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344385.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344386.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344387.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aps skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344389.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344390.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344392.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.h skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344393.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344395.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344396.dll Infected: Trojan.Win32.BHO.zo skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344398.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344400.dll Infected: Trojan.Win32.BHO.re skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP41\A0344402.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.ae skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP42\A0344413.dll Infected: Backdoor.Win32.Agent.dlj skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP44\A0344454.dll Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP45\A0344598.dll Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP49\A0344924.dll Infected: not-a-virus:AdWare.Win32.Comet.c skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345259.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345260.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345261.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.bkm skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345262.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345263.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP51\A0345264.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.aku skipped
C:\System Volume Information\_restore{10D4B4EE-7C0B-4339-9C74-3091462FA969}\RP53\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\MEMORY.DMP Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{E34E2E1C-77F6-4A64-9949-1DFE76219E29}.crmlog Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system\explorer.VI0 Infected: Virus.Win32.Hidrag.a skipped
C:\WINDOWS\system\explorer.VI1 Infected: Virus.Win32.Hidrag.a skipped
C:\WINDOWS\system\explorer.VI2 Infected: Virus.Win32.Hidrag.a skipped
C:\WINDOWS\system\explorer.VI3 Infected: Virus.Win32.Hidrag.a skipped
C:\WINDOWS\system\explorer.VIR Infected: Virus.Win32.Hidrag.a skipped
C:\WINDOWS\system\mirc.ini Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\mirc.VI0 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\mirc.VI1 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\mirc.VI2 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\mirc.VI3 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\mirc.VIR Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\script.VI0 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\script.VI1 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\script.VI2 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\script.VI3 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\script.VIR Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\sup.VI0 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\sup.VI1 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\sup.VI2 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\sup.VI3 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\sup.VIR Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\postcards.gif\svchost.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
C:\WINDOWS\system\servers.VI0 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\servers.VI1 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\servers.VI2 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\servers.VI3 Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system\servers.VIR Infected: Backdoor.IRC.Zapchast skipped
C:\WINDOWS\system32\1024\ldBAF7.tmp Infected: not-virus:Hoax.Win32.Renos.dv skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ect.exe Infected: Trojan.Win32.Baglet.a skipped
C:\WINDOWS\system32\erl.VIR Infected: Trojan.Win32.Glieder.gen skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\myBarSp.exe Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\WINDOWS\system32\Q\hpC22B.VIR Infected: Trojan-Downloader.Win32.Zlob.ku skipped
C:\WINDOWS\system32\Q\ldEDB9.VIR Infected: Trojan-Downloader.Win32.Zlob.kt skipped
C:\WINDOWS\system32\spool\PRINTERS\00004.SPL Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 1:35:28 PM, on 12/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\clipsrv.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dmadmin.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\PCPOWE~1\PopUp.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?6b8a232acf344492a03be3fa32720f5c
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?6b8a232acf344492a03be3fa32720f5c
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.skinnyski.com
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1) -
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…363/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B1A4037E-165A-48A9-BCDD-02057B03780C}: NameServer = 4.2.2.2,4.2.2.4
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OfficeScan RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\OfficeScan NT\ntrtscan.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: OfficeScan Listener (tmlisten) - Unknown owner - C:\Program Files\OfficeScan NT\tmlisten.exe
Hi

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.
Hi Scotty,

Here's the SDFix log file - thanks again…


SDFix: Version 1.120

Run by [removed] on 12/28/2007 Fri at 08:00 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system\aliases.ini - Deleted
C:\WINDOWS\system\control.ini - Deleted
C:\WINDOWS\system\fullname.txt - Deleted
C:\WINDOWS\system\ident.txt - Deleted
C:\WINDOWS\system\mirc.ico - Deleted
C:\WINDOWS\system\mirc.ini - Deleted
C:\WINDOWS\system\remote.ini - Deleted
C:\WINDOWS\system\script.ini - Deleted
C:\WINDOWS\system\sup.bat - Deleted
C:\WINDOWS\system\sup.reg - Deleted
C:\WINDOWS\system\users.ini - Deleted



Folder C:\WINDOWS\system\download - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1333.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-28 08:21:48
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Atari\RollerCoaster Tycoon?3]
"Order"=hex:08,00,00,00,02,00,00,00,48,03,00,00,01,00,00,00,06,00,00,00,8c,..
[HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\Program Files\Atari\RollerCoaster Tycoon?3\RCT3.exe?"="RollerCoaster Tycoon\xae 3"

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Fri 26 Dec 2003 196 A.SHR — "C:\BOOT.BAK"
Sat 24 Apr 2004 37 A..H. — "C:\WINDOWS\wnwtuf.exe.tmp"
Fri 14 May 2004 51,200 ..SHR — "C:\Program Files\DominateGame\Setup.exe"
Wed 1 Nov 2006 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 3 Oct 2006 20,480 …H. — "C:\Documents and Settings\Greg\My Documents\~WRL3429.tmp"
Fri 10 Feb 2006 19,456 …H. — "C:\Documents and Settings\Paul\My Documents\~WRL2060.tmp"
Fri 10 Feb 2006 19,456 …H. — "C:\Documents and Settings\Paul\My Documents\~WRL2463.tmp"
Fri 27 Sep 1996 198,144 A..H. — "C:\Program Files\DreamWorks Interactive\Horrorland\setup95.exe"
Wed 6 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Tue 3 Oct 2006 19,456 …H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Word\~WRL0005.tmp"
Tue 3 Oct 2006 19,456 …H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Word\~WRL0019.tmp"
Tue 3 Oct 2006 20,480 …H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Word\~WRL0627.tmp"
Tue 3 Oct 2006 20,480 …H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Word\~WRL0815.tmp"
Sat 8 Dec 2007 20,480 …H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Word\~WRL0003.tmp"
Sat 20 Jan 2007 19,968 …H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 2 May 2007 428,544 …H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Word\~WRL0198.tmp"
Thu 30 Dec 2004 20,480 …H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Word\~WRL1225.tmp"
Thu 30 Dec 2004 21,504 …H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Word\~WRL2892.tmp"
Tue 14 Feb 2006 19,968 …H. — "C:\Documents and Settings\Paul\Application Data\Microsoft\Word\~WRL0005.tmp"
Tue 14 Feb 2006 19,456 …H. — "C:\Documents and Settings\Paul\Application Data\Microsoft\Word\~WRL0355.tmp"
Tue 14 Feb 2006 499,200 …H. — "C:\Documents and Settings\Paul\Application Data\Microsoft\Word\~WRL1385.tmp"
Sat 4 Aug 2007 6,838 A..H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Office\Shortcut Bar\Off4F8.tmp"
Thu 5 Aug 2004 8,246 A..H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Office\Shortcut Bar\Off4F8h.tmp"
Thu 5 Aug 2004 8,246 A..H. — "C:\Documents and Settings\Greg\Application Data\Microsoft\Office\Shortcut Bar\Off4F8s.tmp"
Sun 4 Dec 2005 6,838 A..H. — "C:\Documents and Settings\Owner\Application Data\Microsoft\Office\Shortcut Bar\Off4.tmp"
Fri 18 Feb 2005 6,838 A..H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Office\Shortcut Bar\Off3.tmp"
Thu 5 Aug 2004 8,246 A..H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Office\Shortcut Bar\Off3h.tmp"
Thu 5 Aug 2004 8,246 A..H. — "C:\Documents and Settings\Pam\Application Data\Microsoft\Office\Shortcut Bar\Off3s.tmp"

Finished!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI