This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] A little help PLEASE!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First, let me say that this site is a fantastic resource for all us computer novices out there who get attacked by these stupid IT terrorists out there. I can't tell you how much I appreciate people like yourselves who take the time to help us with our problems. That said…I have beengetting pop-ups ever since I cisited a site while doing research for work. I noticed that a program, winbuyer, tried to install itself. I was able to get rid of it using Spyware Doctor, but I am still getting pop-ups. The majority of these are entitled "Set the Trend" or some annoying ad about "Wall St.". My pop-up setting show starsdoor as an accepted site, and no matter how many times I delete it, it always comes back. I ran Hijack and this is the log that came up. Please help me!!!!

Logfile of HijackThis v1.99.1
Scan saved at 9:13:03 AM, on 1/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\TightVNC\WinVNC .exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr .exe
C:\WINDOWS\system32\52545A5C5B5A5D.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Gateway Utilities\GWInkMonitor .exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sports Interaction Poker\Sports Interaction Poker.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DNA\btdna .exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\DNA\btdna .exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by TransIT Solutions
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhf.exe
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [A4A6ACAEADACAFAE] 52545A5C5B5A5D.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna .exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com/
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O17 - HKLM\Software\..\Telephony: DomainName = ExpressLeasing.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
Hi morrison0880 and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Make sure to make a backup of any data that you have created, such as documents, pictures, music, ect… before we begin the fix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~

It appears to be the new file infecting Vundo trojan. Many of your .exe (program files) have likely been infected and may not work. We may be able to get at least some if not all of them back but you may need to re-install some programs after we're done.

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hello IndiGenus,
Thanks for your quick reply. Computer is now running a good deal faster, although I've still got some pop-ups (dayam them!!!)
Here is the log that popped up.
ComboFix 08-01-31.4 - RRH 2008-01-31 9:20:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.194 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe
C:\Program Files\Gateway Utilities\GWInkMonitor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\tn3
C:\WINDOWS\asks~1
C:\WINDOWS\b103.exe
C:\WINDOWS\b116.exe
C:\WINDOWS\b122.exe
C:\WINDOWS\b128.exe
C:\WINDOWS\b138.exe
C:\WINDOWS\b143.exe
C:\WINDOWS\b149.exe
C:\WINDOWS\b151.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
C:\WINDOWS\system32\e9
C:\WINDOWS\system32\e9\farstadcom2.exe
C:\WINDOWS\system32\fhkmp.ini
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\p2
C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\pmkhf.exe
C:\WINDOWS\system32\RCX12.tmp
C:\WINDOWS\system32\RCX16.tmp
C:\WINDOWS\system32\RCX17.tmp
C:\WINDOWS\system32\RCX18.tmp
C:\WINDOWS\system32\RCX1A.tmp
C:\WINDOWS\system32\RCX20.tmp
C:\WINDOWS\system32\RCX21.tmp
C:\WINDOWS\system32\RCX23.tmp
C:\WINDOWS\system32\RCX26.tmp
C:\WINDOWS\system32\RCX3E.tmp
C:\WINDOWS\system32\RCX4F.tmp
C:\WINDOWS\system32\RCX54.tmp
C:\WINDOWS\system32\RCX61.tmp
C:\WINDOWS\system32\RCX6B.tmp
C:\WINDOWS\system32\RCX6C.tmp
C:\WINDOWS\system32\RCX7E.tmp
C:\WINDOWS\system32\RCX81.tmp
C:\WINDOWS\system32\RCX82.tmp
C:\WINDOWS\system32\RCXA5.tmp
C:\WINDOWS\system32\RCXCC.tmp
C:\WINDOWS\system32\RCXF3.tmp
C:\WINDOWS\system32\t8
C:\WINDOWS\system32\wcpisvtr32.exe
C:\WINDOWS\system32\ymbols~1
C:\WINDOWS\system32\ymbols~1\?ymbols\
C:\WINDOWS\system32\ystem~1
C:\WINDOWS\system32\z4
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-31 09:28 . 2008-01-31 09:28 d——– C:\Temp\tn3
2008-01-31 09:08 . 980 C:\WINDOWS\system32\LexFiles.usr
2008-01-31 09:05 . 2008-01-31 09:05 100 –a—— C:\WINDOWS\system32\ikhcore.cfg
2008-01-28 14:49 . 2008-01-28 14:49 d——– C:\VundoFix Backups
2008-01-28 12:14 . 2008-01-30 13:48 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-25 17:57 . 2007-10-10 18:55 6,065,664 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-25 17:57 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-25 17:57 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-25 17:57 . 2007-10-10 18:55 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-25 17:57 . 2007-10-10 18:55 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-25 17:57 . 2007-10-10 18:55 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-25 17:57 . 2007-10-10 18:55 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-25 17:57 . 2007-10-10 18:55 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-25 17:57 . 2007-10-10 05:59 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-25 17:55 . 2007-08-13 18:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-25 17:46 . 2008-01-25 17:46 d——– C:\cbb9336be4f83b9c6961ea5c
2008-01-25 15:10 . 2008-01-31 09:05 167,545 –a—— C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-25 10:19 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-25 10:19 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-25 10:19 . 2007-12-10 14:53 41,864 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-25 10:19 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-01-25 10:18 . 2008-01-31 09:25 d——– C:\Program Files\Spyware Doctor
2008-01-25 10:18 . 2008-01-25 10:18 d——– C:\Program Files\Google
2008-01-25 10:18 . 2008-01-25 10:18 d——– C:\Documents and Settings\rrh\Application Data\PC Tools
2008-01-25 10:02 . 2008-01-31 09:28 d——– C:\Program Files\DNA
2008-01-25 10:02 . 2008-01-25 14:31 d——– C:\Documents and Settings\rrh\Application Data\DNA
2008-01-25 10:02 . 2008-01-25 10:27 d——– C:\Documents and Settings\rrh\Application Data\BitTorrent
2008-01-25 09:49 . 2008-01-25 09:54 d——– C:\Program Files\SpywareRemover
2008-01-25 09:49 . 2008-01-25 09:50 d——– C:\Documents and Settings\rrh\Application Data\SpywareRemover
2008-01-24 14:27 . 2008-01-24 14:27 d——– C:\WINDOWS\SchCache
2008-01-17 15:39 . 2008-01-30 17:49 d——– C:\Program Files\Sports Interaction Poker
2008-01-16 14:23 . 2008-01-16 14:24 d——– C:\Temp\Ryuan1
2008-01-15 12:52 . 2008-01-25 09:20 371,200 –a—— C:\WINDOWS\mrofinu1000106.exe.tmp
2008-01-15 12:52 . 2008-01-25 10:39 371,200 –a—— C:\WINDOWS\mrofinu.exe.tmp
2008-01-15 12:44 . 2008-01-15 12:44 d——– C:\WINDOWS\system32\D8DAE0E2E1E0E3
2008-01-15 12:44 . 2007-12-14 07:40 120,832 –a—— C:\WINDOWS\system32\52545A5C5B5A5D.exe
2008-01-14 15:20 . 2008-01-14 15:20 d——– C:\Documents and Settings\rrh\Application Data\Symantec
2008-01-14 13:26 . 2008-01-25 14:59 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2008-01-14 10:21 . 2008-01-14 10:21 d——– C:\Program Files\Yahoo!
2008-01-14 10:21 . 2008-01-14 10:21 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-14 09:09 . 2008-01-14 09:09 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-11 18:08 . 2008-01-14 09:35 16 –a—— C:\WINDOWS\system32\coh.cache
2008-01-11 17:45 . 2008-01-15 10:00 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 17:43 . 2008-01-15 10:08 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-11 17:38 . 2008-01-14 09:05 d——– C:\WINDOWS\SxsCaPendDel
2008-01-11 15:03 . 2008-01-11 15:03 d——– C:\Program Files\Enigma Software Group
2008-01-11 14:05 . 2008-01-31 09:25 d——– C:\Program Files\Windows Defender
2008-01-11 12:47 . 2008-01-31 09:15 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-11 11:32 . 2008-01-11 11:32 d——– C:\Program Files\TMW Systems, Inc
2008-01-11 09:31 . 2008-01-31 09:25 d——– C:\Program Files\Dot1XCfg
2008-01-11 09:29 . 2008-01-22 16:10 d–hs—- C:\WINDOWS\QUdDIEFzc29jaWF0ZQ
2008-01-11 09:28 . 2008-01-11 15:29 d——– C:\WINDOWS\system32\vt8
2008-01-11 09:28 . 2008-01-11 15:28 d——– C:\WINDOWS\system32\mp2
2008-01-11 09:28 . 2008-01-11 10:17 d——– C:\WINDOWS\system32\ez4
2008-01-11 09:28 . 2008-01-11 09:28 d——– C:\WINDOWS\system32\che9
2008-01-11 09:28 . 2008-01-11 09:28 86,016 –a—— C:\WINDOWS\system32\drivers\seriall.sys
2008-01-11 09:27 . 2008-01-25 14:26 d——– C:\WINDOWS\system32\edcA01
2008-01-11 09:27 . 2008-01-31 09:28 d——– C:\Temp
2008-01-07 08:31 . 2007-11-28 09:49 d——– C:\Documents and Settings\rrh\Application Data\Interstar Technologies
2008-01-07 08:30 . 2007-11-30 14:38 d——– C:\Documents and Settings\rrh\WINDOWS
2008-01-07 08:30 . 2007-12-10 15:25 d——– C:\Documents and Settings\rrh\Application Data\Windows Desktop Search
2008-01-07 08:30 . 2007-12-05 11:39 d——– C:\Documents and Settings\rrh\Application Data\TransCore
2008-01-05 02:02 . 2007-07-09 08:09 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-04 11:22 . 2008-01-04 11:23 d——– C:\WordLoadConfirmation
2008-01-04 09:12 . 2008-01-04 09:12 d——– C:\WINDOWS\provisioning
2008-01-04 09:12 . 2008-01-04 09:12 d——– C:\WINDOWS\peernet
2008-01-04 09:10 . 2008-01-04 09:10 d——– C:\WINDOWS\ServicePackFiles
2008-01-04 09:02 . 2008-01-04 09:02 d——– C:\WINDOWS\EHome
2007-12-26 15:33 . 2008-01-31 09:12 10,485,814 –a—— C:\WINDOWS\BGInfo.bmp
2007-12-10 15:33 . 2007-12-10 15:33 d——– C:\WINDOWS\Sun
2007-12-06 11:36 . 2007-12-07 12:22 d——– C:\Documents and Settings\rrh\Application Data\AdobeUM
2007-12-06 11:17 . 2007-12-06 11:17 d——– C:\Program Files\Common Files\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 14:25 ——— d—–w C:\Program Files\TightVNC
2008-01-31 14:25 ——— d—–w C:\Program Files\Gateway Utilities
2008-01-25 19:04 ——— d—–w C:\Program Files\tmwmaster
2007-11-30 20:08 ——— d—–w C:\Program Files\Dell_HostCD
2007-11-29 15:07 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-29 15:07 ——— d—–w C:\Program Files\Microsoft ActiveSync
.
—-a-w		   335,872 2008-01-31 14:05:59  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			84,640 2008-01-14 17:30:09  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   149,184 2008-01-14 17:30:13  C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz .exe
—-a-w		   820,872 2008-01-14 14:29:14  C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw .exe
—-a-w		   286,528 2008-01-30 18:49:03  C:\Program Files\DNA\btdna  .exe
—-a-w		   286,528 2008-01-31 14:25:22  C:\Program Files\DNA\btdna .exe
—-a-w			61,440 2008-01-31 14:06:02  C:\Program Files\Dot1XCfg\Dot1XCfg .exe
—-a-w		   847,872 2008-01-11 20:06:16  C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
—-a-w		   303,180 2008-01-31 14:05:58  C:\Program Files\Gateway Utilities\GWInkMonitor .exe
—-a-w		   171,448 2008-01-25 20:13:25  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
—-a-w			86,016 2008-01-31 14:05:57  C:\Program Files\Intel\NCS\PROSet\PRONoMgr .exe
—-a-w		 1,103,752 2008-01-31 14:14:31  C:\Program Files\Spyware Doctor\pctsTray .exe
—-a-w		   589,824 2008-01-31 14:05:33  C:\Program Files\TightVNC\WinVNC .exe
—-a-w		   866,584 2008-01-31 14:06:01  C:\Program Files\Windows Defender\MSASCui .exe
—-a-w			15,360 2008-01-30 18:48:46  C:\WINDOWS\system32\ctfmon .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9fb42e13-cc98-429d-9a85-4081ec1bd961}]
C:\WINDOWS\system32\bkfgkty.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dot1XCfg"="C:\Program Files\Dot1XCfg\Dot1XCfg.exe" [ ]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-01-31 09:28 286528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [ ]
"ATIModeChange"="Ati2mdxx.exe" [2007-10-15 15:02 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Gateway Ink Monitor"="C:\Program Files\Gateway Utilities\GWInkMonitor.exe" [ ]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [ ]
"A4A6ACAEADACAFAE"="52545A5C5B5A5D.exe" [2007-12-14 07:40 120832 C:\WINDOWS\system32\52545A5C5B5A5D.exe]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStartupSound"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxuspm]
byxuspm.dll

R1 seriall;seriall;C:\WINDOWS\system32\drivers\seriall.sys [2008-01-11 09:28]

.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 08:00:01 C:\WINDOWS\Tasks\SpywareRemover Scheduled Scan.job"
- C:\Program Files\SpywareRemover\SpywareRemover.exe
- C:\Program Files\SpywareRemover
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 09:28:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\52545A5C5B5A5D.exe
C:\Program Files\DNA\btdna.exe
.
**************************************************************************
.
Completion time: 2008-01-31 9:30:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 14:29:51
.
2008-01-30 03:58:20 — E O F —
This is one very badly infected machine. One thing to note. All of the .exe/program files in the RenV section of the script were infected by the new Vundo file infecter. You may need to re-install or repair some of those programs.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\LexFiles.usr
C:\WINDOWS\system32\ikhcore.cfg
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\mrofinu1000106.exe.tmp
C:\WINDOWS\mrofinu.exe.tmp
C:\WINDOWS\system32\52545A5C5B5A5D.exe
C:\WINDOWS\system32\drivers\seriall.sys
C:\WINDOWS\system32\bkfgkty.dll
C:\WINDOWS\system32\byxuspm.dll

Folder::
C:\Temp\tn3
C:\WINDOWS\system32\D8DAE0E2E1E0E3
C:\Program Files\Dot1XCfg
C:\WINDOWS\QUdDIEFzc29jaWF0ZQ
C:\WINDOWS\system32\vt8
C:\WINDOWS\system32\mp2
C:\WINDOWS\system32\ez4
C:\WINDOWS\system32\che9
C:\WINDOWS\system32\edcA01
C:\Temp

Driver::
seriall

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9fb42e13-cc98-429d-9a85-4081ec1bd961}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dot1XCfg"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"A4A6ACAEADACAFAE"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byxuspm]

RenV::
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz .exe
C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw .exe
C:\Program Files\DNA\btdna  .exe
C:\Program Files\DNA\btdna .exe
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
C:\Program Files\Gateway Utilities\GWInkMonitor .exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr .exe
C:\Program Files\Spyware Doctor\pctsTray .exe
C:\Program Files\TightVNC\WinVNC .exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\WINDOWS\system32\ctfmon .exe


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Here are the logs, ComboFix first
ComboFix 08-01-31.4 - RRH 2008-01-31 12:32:23.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.230 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\rrh\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\mrofinu.exe.tmp
C:\WINDOWS\mrofinu1000106.exe.tmp
C:\WINDOWS\system32\52545A5C5B5A5D.exe
C:\WINDOWS\system32\bkfgkty.dll
C:\WINDOWS\system32\byxuspm.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\seriall.sys
C:\WINDOWS\system32\ikhcore.cfg
C:\WINDOWS\system32\LexFiles.usr
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\seriall.sys
C:\Program Files\Dot1XCfg
C:\Program Files\Dot1XCfg\Dot1XCfg .exe
C:\Program Files\Dot1XCfg\Dot1XCfg.exe.lzma
C:\Temp
C:\Temp\Ryuan1\tepU.log
C:\temp\tn3
C:\WINDOWS\mrofinu.exe.tmp
C:\WINDOWS\mrofinu1000106.exe.tmp
C:\WINDOWS\QUdDIEFzc29jaWF0ZQ
C:\WINDOWS\system32\52545A5C5B5A5D.exe
C:\WINDOWS\system32\che9
C:\WINDOWS\system32\che9\farstadcom2.exe
C:\WINDOWS\system32\D8DAE0E2E1E0E3
C:\WINDOWS\system32\D8DAE0E2E1E0E3\2A2C3234333235
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\seriall.sys
C:\WINDOWS\system32\edcA01
C:\WINDOWS\system32\ez4
C:\WINDOWS\system32\ikhcore.cfg
C:\WINDOWS\system32\LexFiles.usr
C:\WINDOWS\system32\mp2
C:\WINDOWS\system32\vt8

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_SERIALL
——-\seriall


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-28 14:49 . 2008-01-28 14:49 d——– C:\VundoFix Backups
2008-01-28 12:14 . 2008-01-30 13:48 15,360 –a—— C:\WINDOWS\system32\ctfmon .exe
2008-01-25 17:57 . 2007-10-10 18:55 6,065,664 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-25 17:57 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-25 17:57 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-25 17:57 . 2007-10-10 18:55 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-25 17:57 . 2007-10-10 18:55 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-25 17:57 . 2007-10-10 18:55 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-25 17:57 . 2007-10-10 18:55 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-25 17:57 . 2007-10-10 18:55 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-25 17:57 . 2007-10-10 05:59 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-25 17:55 . 2007-08-13 18:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-01-25 17:46 . 2008-01-25 17:46 d——– C:\cbb9336be4f83b9c6961ea5c
2008-01-25 10:19 . 2007-12-10 14:53 81,288 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-25 10:19 . 2007-12-10 14:53 66,952 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-25 10:19 . 2007-12-10 14:53 41,864 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-25 10:19 . 2007-12-10 14:53 29,576 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-01-25 10:18 . 2008-01-31 09:25 d——– C:\Program Files\Spyware Doctor
2008-01-25 10:18 . 2008-01-25 10:18 d——– C:\Program Files\Google
2008-01-25 10:18 . 2008-01-25 10:18 d——– C:\Documents and Settings\rrh\Application Data\PC Tools
2008-01-25 10:02 . 2008-01-31 09:28 d——– C:\Program Files\DNA
2008-01-25 10:02 . 2008-01-31 12:34 d——– C:\Documents and Settings\rrh\Application Data\DNA
2008-01-25 10:02 . 2008-01-25 10:27 d——– C:\Documents and Settings\rrh\Application Data\BitTorrent
2008-01-25 09:49 . 2008-01-25 09:54 d——– C:\Program Files\SpywareRemover
2008-01-25 09:49 . 2008-01-25 09:50 d——– C:\Documents and Settings\rrh\Application Data\SpywareRemover
2008-01-24 14:27 . 2008-01-24 14:27 d——– C:\WINDOWS\SchCache
2008-01-17 15:39 . 2008-01-31 12:31 d——– C:\Program Files\Sports Interaction Poker
2008-01-14 15:20 . 2008-01-14 15:20 d——– C:\Documents and Settings\rrh\Application Data\Symantec
2008-01-14 13:26 . 2008-01-25 14:59 d——– C:\Documents and Settings\All Users\Symantec Temporary Files
2008-01-14 10:21 . 2008-01-14 10:21 d——– C:\Program Files\Yahoo!
2008-01-14 10:21 . 2008-01-14 10:21 d——– C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-14 09:09 . 2008-01-14 09:09 d——– C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-01-11 18:08 . 2008-01-14 09:35 16 –a—— C:\WINDOWS\system32\coh.cache
2008-01-11 17:45 . 2008-01-15 10:00 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-11 17:43 . 2008-01-15 10:08 d——– C:\Program Files\Common Files\Symantec Shared
2008-01-11 17:38 . 2008-01-14 09:05 d——– C:\WINDOWS\SxsCaPendDel
2008-01-11 15:03 . 2008-01-11 15:03 d——– C:\Program Files\Enigma Software Group
2008-01-11 14:05 . 2008-01-31 09:25 d——– C:\Program Files\Windows Defender
2008-01-11 12:47 . 2008-01-31 09:15 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-11 11:32 . 2008-01-11 11:32 d——– C:\Program Files\TMW Systems, Inc
2008-01-07 08:31 . 2007-11-28 09:49 d——– C:\Documents and Settings\rrh\Application Data\Interstar Technologies
2008-01-07 08:30 . 2007-11-30 14:38 d——– C:\Documents and Settings\rrh\WINDOWS
2008-01-07 08:30 . 2007-12-10 15:25 d——– C:\Documents and Settings\rrh\Application Data\Windows Desktop Search
2008-01-07 08:30 . 2007-12-05 11:39 d——– C:\Documents and Settings\rrh\Application Data\TransCore
2008-01-05 02:02 . 2007-07-09 08:09 584,192 —–c— C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-01-04 11:22 . 2008-01-04 11:23 d——– C:\WordLoadConfirmation
2008-01-04 09:12 . 2008-01-04 09:12 d——– C:\WINDOWS\provisioning
2008-01-04 09:12 . 2008-01-04 09:12 d——– C:\WINDOWS\peernet
2008-01-04 09:10 . 2008-01-04 09:10 d——– C:\WINDOWS\ServicePackFiles
2008-01-04 09:02 . 2008-01-04 09:02 d——– C:\WINDOWS\EHome
2007-12-26 15:33 . 2008-01-31 09:29 10,485,814 –a—— C:\WINDOWS\BGInfo.bmp
2007-12-10 15:33 . 2007-12-10 15:33 d——– C:\WINDOWS\Sun
2007-12-06 11:36 . 2007-12-07 12:22 d——– C:\Documents and Settings\rrh\Application Data\AdobeUM
2007-12-06 11:17 . 2007-12-06 11:17 d——– C:\Program Files\Common Files\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 14:25 ——— d—–w C:\Program Files\TightVNC
2008-01-31 14:25 ——— d—–w C:\Program Files\Gateway Utilities
2008-01-25 19:04 ——— d—–w C:\Program Files\tmwmaster
2007-11-30 20:08 ——— d—–w C:\Program Files\Dell_HostCD
2007-11-29 15:07 ——— d—–w C:\Program Files\Microsoft.NET
2007-11-29 15:07 ——— d—–w C:\Program Files\Microsoft ActiveSync
.
—-a-w		   335,872 2008-01-31 14:05:59  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
—-a-w			84,640 2008-01-14 17:30:09  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w		   149,184 2008-01-14 17:30:13  C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz .exe
—-a-w		   820,872 2008-01-14 14:29:14  C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw .exe
—-a-w		   286,528 2008-01-30 18:49:03  C:\Program Files\DNA\btdna  .exe
—-a-w		   286,528 2008-01-31 14:25:22  C:\Program Files\DNA\btdna .exe
—-a-w		   847,872 2008-01-11 20:06:16  C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
—-a-w		   303,180 2008-01-31 14:05:58  C:\Program Files\Gateway Utilities\GWInkMonitor .exe
—-a-w		   171,448 2008-01-25 20:13:25  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
—-a-w			86,016 2008-01-31 14:05:57  C:\Program Files\Intel\NCS\PROSet\PRONoMgr .exe
—-a-w		 1,103,752 2008-01-31 14:14:31  C:\Program Files\Spyware Doctor\pctsTray .exe
—-a-w		   589,824 2008-01-31 14:05:33  C:\Program Files\TightVNC\WinVNC .exe
—-a-w		   866,584 2008-01-31 14:06:01  C:\Program Files\Windows Defender\MSASCui .exe
—-a-w			15,360 2008-01-30 18:48:46  C:\WINDOWS\system32\ctfmon .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-01-31 09:28 286528]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [ ]
"ATIModeChange"="Ati2mdxx.exe" [2007-10-15 15:02 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [ ]
"Gateway Ink Monitor"="C:\Program Files\Gateway Utilities\GWInkMonitor.exe" [ ]
"WinVNC"="C:\Program Files\TightVNC\WinVNC.exe" [ ]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [ ]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStartupSound"= 1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2008-01-31 08:00:01 C:\WINDOWS\Tasks\SpywareRemover Scheduled Scan.job"
- C:\Program Files\SpywareRemover\SpywareRemover.exe
- C:\Program Files\SpywareRemover
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 12:36:12
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

C:\WINDOWS\system32\LexFiles.usr 788 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\DNA\btdna.exe
.
**************************************************************************
.
Completion time: 2008-01-31 12:37:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 17:37:22
ComboFix2.txt 2008-01-31 14:30:12
.
2008-01-30 03:58:20 — E O F —



HiJack This log

Logfile of HijackThis v1.99.1
Scan saved at 12:40, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\Explorer.EXE
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com/
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O17 - HKLM\Software\..\Telephony: DomainName = ExpressLeasing.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
OK looks like we got much of the actual infection. But those exe files may still be an issue here. Do me a favor and try some of those programs like Windows Defender, Spyware Doctor, Spyhunter, ect… and let me know if they run.

Also, don't see any antivirus program. Though it looks like you had Norton on here at one time? Correct or no? You should install an AV ASAP. There are a few good free for home use ones.

Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. Here is a list of some free and evaluation versions to try: AVG AntiVirus
Avast Antivirus Home Version–Free
Antivir Personal - Free

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Let's do some more scans:

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG


  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.


Restart into normal mode and post the AVG Log and a new HJT Log. Also how are things now
Here are the scans, with AVG First

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 13:54 2008-01-31

+ Scan result:



C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009243.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020479.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021748.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\Program Files\SpywareRemover -> Adware.SpywareRemover : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg .exe.vir -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0008280.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009263.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010261.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011321.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012327.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013410.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013475.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014484.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015475.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017918.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018330.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019278.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019805.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019848.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019987.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020409.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020496.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020546.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021598.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021649.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021709.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021769.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021812.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021854.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021898.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021934.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021999.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022058.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022100.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024057.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024107.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024160.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025235.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025286.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026281.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028286.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029287.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029356.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029403.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030415.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030681.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030741.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030807.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030887.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030951.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0031007.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037081.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038068.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP218\A0038236.exe -> Downloader.Adload.pr : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b138.exe.vir -> Downloader.Agent.cbx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019865.exe -> Downloader.Agent.cbx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038129.exe -> Downloader.Agent.cbx : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir -> Downloader.Agent.erf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021917.exe -> Downloader.Agent.erf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038127.exe -> Downloader.Agent.erf : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b116.exe.vir -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b128.exe.vir -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021959.exe -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038126.exe -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038128.exe -> Downloader.Agent.ezc : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b151.exe.vir -> Downloader.Agent.fjn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021952.exe -> Downloader.Agent.fjn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038132.exe -> Downloader.Agent.fjn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP169\A0008270.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP169\A0008275.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009257.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009282.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010297.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011341.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013404.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013443.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013496.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015468.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017916.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018325.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019264.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019347.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019841.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019868.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020410.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020477.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021742.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021745.exe -> Downloader.Agent.gwh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021746.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021761.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021791.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021836.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021850.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021887.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021918.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021993.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0022022.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022092.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022120.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022126.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025310.exe -> Downloader.Agent.hql : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022131.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024080.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024082.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024084.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024100.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024141.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024181.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024205.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025257.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025311.exe -> Downloader.Agent.hvx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP195\A0022025.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\52545A5C5B5A5D.exe.vir -> Downloader.VB.chy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP218\A0038238.exe -> Downloader.VB.chy : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\DNA\btdna.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Gateway Utilities\GWInkMonitor.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Intel\NCS\PROSet\PRONoMgr.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Spyware Doctor\pctsTray.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\TightVNC\WinVNC.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Windows Defender\MSASCui.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\mrofinu.exe.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\mrofinu1000106.exe.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX12.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX16.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX17.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX18.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX1A.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX20.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX21.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX23.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX26.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX3E.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX4F.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX54.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX61.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX6B.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX6C.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX7E.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX81.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCX82.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCXA5.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCXCC.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\RCXF3.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\ctfmon.exe.tmp.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\pmkhf.exe.vir -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009251.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009252.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009253.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009254.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009256.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0009258.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010250.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010252.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010253.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010254.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010255.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010258.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010298.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011309.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011311.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011312.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011313.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011314.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011315.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0011317.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012315.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012317.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012318.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012319.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012320.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0012321.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013398.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013399.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013401.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013402.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013403.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0013405.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013438.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013439.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013440.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013441.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013442.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP172\A0013445.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013463.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013464.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013466.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013467.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013468.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013469.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013470.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP173\A0013497.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP175\A0013514.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP175\A0013539.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014473.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014475.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014476.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014477.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014478.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP178\A0014479.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015461.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015463.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015464.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015466.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015467.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015471.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015712.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0015834.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017907.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017909.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017910.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017911.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017915.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0017938.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018071.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018204.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018239.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018319.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018320.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018321.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018323.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018324.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0018326.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019258.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019260.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019261.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019262.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019263.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019269.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019512.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019655.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019696.rbf -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019793.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019794.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019796.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019797.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019798.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019799.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019800.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019835.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019836.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019837.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019839.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019840.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019842.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019925.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019926.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019928.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019929.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019930.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019931.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0019932.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020400.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020402.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020403.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020404.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020405.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020484.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020488.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020489.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020492.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020493.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020523.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020535.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020538.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020539.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020540.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020541.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP180\A0020542.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021585.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021586.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021588.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021589.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021590.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP183\A0021592.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021622.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021623.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021624.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021625.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021626.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021627.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021628.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021638.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021639.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021640.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021643.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021645.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP184\A0021646.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021671.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021672.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021673.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021674.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021675.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021677.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021678.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021698.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021699.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021701.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021702.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021703.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP185\A0021704.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021735.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021736.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021743.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021755.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021757.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021758.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021759.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021760.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021762.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021764.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021799.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021800.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021802.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021803.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021804.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021805.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021806.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021807.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021842.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021843.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021844.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021845.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021847.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP187\A0021851.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021882.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021883.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021884.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021885.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021886.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021888.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP189\A0021890.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021922.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021923.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021925.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021926.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021927.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021928.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP192\A0021929.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021986.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021988.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021990.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021991.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021992.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0021994.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP194\A0022023.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022034.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022035.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022045.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022047.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022048.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022049.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022050.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022052.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP196\A0022053.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022086.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022087.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022089.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022090.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022091.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022093.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP198\A0022095.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024044.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024045.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024047.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024048.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024049.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024050.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024051.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024052.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024095.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024096.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024097.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024098.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024099.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024101.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP200\A0024142.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024147.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024149.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024150.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024151.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024152.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024154.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024155.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP202\A0024182.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024200.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024201.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024202.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024203.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024204.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024206.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0024207.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025221.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025222.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025224.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025225.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025226.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025227.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025228.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025230.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025259.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025270.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025272.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025274.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025276.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025279.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025280.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025281.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025282.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025284.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026277.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026278.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026282.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026283.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026284.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026285.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026288.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026289.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0026291.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028271.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028272.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028274.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028275.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028276.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028277.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028278.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028279.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0028281.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029272.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029273.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029274.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029275.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029276.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029277.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029278.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029279.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029280.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029281.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029342.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029343.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029344.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029345.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029346.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029347.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029348.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029351.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029352.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029379.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029386.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029406.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029409.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029410.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029411.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029413.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029414.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029415.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0029417.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030400.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030402.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030403.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030404.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030405.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030406.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030407.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0030408.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP211\A0030635.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030654.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030658.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030659.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030660.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030662.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030663.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030666.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030721.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030725.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030728.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030729.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030730.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030731.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030733.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030735.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030740.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030772.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030781.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030786.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030793.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030794.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030796.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030797.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030798.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030800.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030801.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP213\A0030811.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030850.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030852.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030853.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030854.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030855.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030857.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030860.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030869.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030872.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030874.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030875.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030876.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030877.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030879.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030884.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP214\A0030918.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030925.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030926.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030928.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030929.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030930.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030931.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030932.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030933.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030935.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP215\A0030943.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030981.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030988.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030991.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030992.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030993.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030994.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030996.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0030999.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0031051.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037062.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037066.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037067.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037068.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037069.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037070.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037071.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037073.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0037078.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038058.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038069.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038073.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038074.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038075.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038076.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038077.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP216\A0038078.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038113.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038115.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038116.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038117.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038118.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038119.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038120.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038134.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038135.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038136.exe -> Dropper.Agent.dgo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP179\A0020476.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP186\A0021741.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP204\A0025312.exe -> Not-A-Virus.Adware.PurityScan : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\b103.exe.vir -> Not-A-Virus.Adware.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038125.exe -> Not-A-Virus.Adware.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010295.dll -> Not-A-Virus.Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP170\A0010287.exe -> Trojan.Agent.dwb : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINDOWS\system32\wcpisvtr32.exe.vir -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{6222E92D-114C-4493-B9FA-CD6A92529E0D}\RP217\A0038124.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end




Logfile of HijackThis v1.99.1
Scan saved at 14:01, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\mstsc.exe
C:\PROGRA~1\MICROS~3\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\SYSTEM32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Gateway Ink Monitor] "C:\Program Files\Gateway Utilities\GWInkMonitor.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com/
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O17 - HKLM\Software\..\Telephony: DomainName = ExpressLeasing.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ExpressLeasing.local
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)
Okay let's try this for your programs.

  • Download RenV.exe by sUBs to your desktop
  • Double click on it to run it
  • It will search your system drive looking for any modified .exe file and will produce a log for you.
  • Please attach this report to your reply (Do not copy and paste)
Open Notepad and copy/paste the text from the codebox into a blank file.

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cfgwiz .exe
C:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\SymCuw .exe
C:\Program Files\DNA\btdna  .exe
C:\Program Files\DNA\btdna .exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3 .exe
C:\Program Files\Gateway Utilities\GWInkMonitor .exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier .exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr .exe
C:\Program Files\Spyware Doctor\pctsTray .exe
C:\Program Files\TightVNC\WinVNC .exe
C:\Program Files\Windows Defender\MSASCui .exe
C:\WINDOWS\system32\ctfmon .exe

Save the file on your desktop and name it Log.txt.

Drag the Log.txt file onto RenV.exe (like you did with CFScript.txt) and attach the resulting report to your reply.
Looks like the only one we can't get is Spyware Doctor. Have you tried the other programs that weren't working? You may need to re-install or repair install them.

Let's do another scan too:

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
Hey Indi. I will be away from my computer for the rest of the night. Using someone elses right now, so I will check in again first thing in the morning. One question though. What do you mean by "the only one we can't get is Spyware Doctor"? Are we trying to get rid of it? Are we trying to restore it? Im' afraid I don't quite follow. BTW, thank you so much for your help on this. My computer is pretty much back to where it was before those bastards crapped on my hard drive. I appreciate everything you are doing, and I'm sure everyone else you uys have helped are just as thankful as I am. Peace out, talk to you tomorrow.

What do you mean by "the only one we can't get is Spyware Doctor"?

Oh sorry, yes, I mean to restore it. As you can see it was the only one left in the last log you posted. Sometimes the programs cannot be restored, they need to be re-installed/repaired.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI