Here ya go cotty many thanks for your help
Malwarebytes' Anti-Malware 1.10
Database version: 598
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 111376
Time elapsed: 22 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM6314b10c (Trojan.Agent) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\vwhfxvxv.exe (Trojan.Downloader) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcbyyx.dll.vir (Trojan.Vundo) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\nnnnono.dll.vir (Trojan.Vundo) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\qomjijk.dll.vir (Trojan.Vundo) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqnnnm.dll.vir (Trojan.Vundo) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\wvUoMdax.dll.vir (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP348\A0054443.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054614.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054616.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054617.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054619.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054620.dll (Trojan.Vundo) -> No action taken.
ComboFix 08-04-06.1 - Owner 2008-04-07 22:10:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1431 [GMT 8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM6314b10c.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bcnoprki.dll
C:\WINDOWS\system32\byXOfCVP.dll
C:\WINDOWS\system32\cs.dat
C:\WINDOWS\system32\DcJiknpo.ini
C:\WINDOWS\system32\DcJiknpo.ini2
C:\WINDOWS\system32\ddcbyyx.dll
C:\WINDOWS\system32\dNTEdMoq.ini
C:\WINDOWS\system32\dNTEdMoq.ini2
C:\WINDOWS\system32\duis.txt
C:\WINDOWS\system32\GhNVvyay.ini
C:\WINDOWS\system32\GhNVvyay.ini2
C:\WINDOWS\system32\iycuknqx.dll
C:\WINDOWS\system32\LVvEKRqr.ini
C:\WINDOWS\system32\LVvEKRqr.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\nnnnono.dll
C:\WINDOWS\system32\ppqtDMoq.ini
C:\WINDOWS\system32\ppqtDMoq.ini2
C:\WINDOWS\system32\ps1.dat
C:\WINDOWS\system32\PVCfOXyb.ini
C:\WINDOWS\system32\PVCfOXyb.ini2
C:\WINDOWS\system32\qomjijk.dll
C:\WINDOWS\system32\rc.dat
C:\WINDOWS\system32\TDgPrtwa.ini
C:\WINDOWS\system32\TDgPrtwa.ini2
C:\WINDOWS\system32\ttixaueo.dll
C:\WINDOWS\system32\urqnnnm.dll
C:\WINDOWS\system32\wvUoMdax.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_SZKG5
((((((((((((((((((((((((( Files Created from 2008-03-07 to 2008-04-07 )))))))))))))))))))))))))))))))
.
2008-04-07 21:11 . 2008-04-07 21:11 d——– C:\Deckard
2008-04-07 13:16 . 2008-04-07 13:16 d——– C:\Documents and Settings\All Users\Application Data\SITEguard
2008-04-07 13:15 . 2008-04-07 13:15 d——– C:\Program Files\Common Files\iS3
2008-04-07 13:15 . 2008-04-07 13:24 d——– C:\Documents and Settings\All Users\Application Data\STOPzilla!
2008-04-07 13:02 . 2008-04-07 16:09 d——– C:\VundoFix Backups
2008-04-07 12:38 . 2008-04-07 12:38 d——– C:\Program Files\Trend Micro
2008-04-07 11:02 . 2008-04-07 11:02 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-04-07 11:02 . 2008-04-07 11:02 d——– C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-04-07 11:02 . 2008-04-07 11:02 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-03 09:35 . 2008-04-03 09:35 d——– C:\Documents and Settings\Owner\Application Data\Grisoft
2008-04-03 09:35 . 2007-05-30 20:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-03 09:29 . 2008-04-07 18:20 268 –ah—– C:\sqmdata19.sqm
2008-04-03 09:29 . 2008-04-07 18:20 244 –ah—– C:\sqmnoopt19.sqm
2008-04-03 09:13 . 2008-04-03 09:25 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-03 08:46 . 2008-04-07 16:59 268 –ah—– C:\sqmdata18.sqm
2008-04-03 08:46 . 2008-04-07 16:59 244 –ah—– C:\sqmnoopt18.sqm
2008-04-02 10:34 . 2008-04-07 16:32 268 –ah—– C:\sqmdata17.sqm
2008-04-02 10:34 . 2008-04-07 16:32 244 –ah—– C:\sqmnoopt17.sqm
2008-04-02 09:53 . 2008-04-02 09:53 d——– C:\Program Files\Windows Defender
2008-04-02 09:34 . 2008-04-07 14:55 268 –ah—– C:\sqmdata16.sqm
2008-04-02 09:34 . 2008-04-07 14:55 244 –ah—– C:\sqmnoopt16.sqm
2008-04-02 09:27 . 2008-04-02 09:31 d——– C:\Program Files\Microsoft Silverlight
2008-04-01 16:18 . 2008-04-07 13:17 268 –ah—– C:\sqmdata15.sqm
2008-04-01 16:18 . 2008-04-07 13:17 244 –ah—– C:\sqmnoopt15.sqm
2008-04-01 08:30 . 2008-04-07 10:26 268 –ah—– C:\sqmdata14.sqm
2008-04-01 08:30 . 2008-04-07 10:26 244 –ah—– C:\sqmnoopt14.sqm
2008-03-31 09:52 . 2008-03-31 09:52 d——– C:\Documents and Settings\Owner\Application Data\skypePM
2008-03-31 09:52 . 2008-03-31 09:52 32 –a—— C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-31 09:51 . 2008-03-31 09:51 d——– C:\Program Files\Common Files\Skype
2008-03-30 17:15 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-03-30 17:15 . 2007-07-30 19:19 207,736 –a—— C:\WINDOWS\system32\muweb.dll
2008-03-30 17:15 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-03-30 16:39 . 2008-04-07 12:43 d——– C:\Documents and Settings\Owner\Application Data\AVG7
2008-03-30 16:39 . 2008-03-30 16:39 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-30 16:39 . 2008-04-03 09:34 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-30 16:39 . 2008-03-30 16:41 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-03-30 11:26 . 2008-03-30 16:34 10,752 –a—— C:\WINDOWS\DCEBoot.exe
2008-03-30 11:22 . 2008-03-30 11:22 6,144 –a—— C:\vwhfxvxv.exe
2008-03-29 06:37 . 2008-03-29 06:37 d——– C:\Documents and Settings\Owner\Application Data\deskPDF
2008-03-29 06:34 . 2008-03-29 06:35 d——– C:\Program Files\Docudesk
2008-03-29 06:34 . 2008-03-21 12:13 18,790 –a—— C:\WINDOWS\system32\ddmon.dll
2008-03-19 19:27 . 2008-03-30 11:31 d——– C:\Documents and Settings\Owner\Application Data\iPhoneRingToneMaker
2008-03-19 10:04 . 2008-03-19 13:01 d——– C:\fts2008
2008-03-17 19:25 . 2008-04-06 23:22 208 –ah—– C:\sqmdata13.sqm
2008-03-17 19:25 . 2008-04-06 23:22 172 –ah—– C:\sqmnoopt13.sqm
2008-03-17 00:17 . 2008-04-06 16:05 244 –ah—– C:\sqmnoopt12.sqm
2008-03-17 00:17 . 2008-04-06 16:05 232 –ah—– C:\sqmdata12.sqm
2008-03-16 14:05 . 2008-04-06 15:43 268 –ah—– C:\sqmdata11.sqm
2008-03-16 14:05 . 2008-04-06 15:43 244 –ah—– C:\sqmnoopt11.sqm
2008-03-16 00:56 . 2008-04-06 09:21 268 –ah—– C:\sqmdata10.sqm
2008-03-16 00:56 . 2008-04-06 09:21 244 –ah—– C:\sqmnoopt10.sqm
2008-03-14 23:34 . 2008-04-05 23:39 268 –ah—– C:\sqmdata09.sqm
2008-03-14 23:34 . 2008-04-05 23:39 244 –ah—– C:\sqmnoopt09.sqm
2008-03-13 22:12 . 2008-04-05 07:23 268 –ah—– C:\sqmdata08.sqm
2008-03-13 22:12 . 2008-04-05 07:23 244 –ah—– C:\sqmnoopt08.sqm
2008-03-11 22:47 . 2008-04-04 21:30 268 –ah—– C:\sqmdata07.sqm
2008-03-11 22:47 . 2008-04-04 21:30 244 –ah—– C:\sqmnoopt07.sqm
2008-03-10 23:39 . 2008-04-04 08:17 268 –ah—– C:\sqmdata06.sqm
2008-03-10 23:39 . 2008-04-04 08:17 244 –ah—– C:\sqmnoopt06.sqm
2008-03-07 08:06 . 2008-03-07 08:06 d——– C:\WINDOWS\Sun
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-07 13:08 ——— d—–w C:\Program Files\Steam
2008-04-07 06:46 ——— d—–w C:\Documents and Settings\Owner\Application Data\Vso
2008-04-02 00:41 ——— d—–w C:\Documents and Settings\Owner\Application Data\Skype
2008-03-30 08:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\Trend Micro
2008-03-14 14:21 ——— d—–w C:\Documents and Settings\Owner\Application Data\Apple Computer
2008-03-06 04:36 ——— d—–w C:\Program Files\Java
2008-03-06 04:34 ——— d—–w C:\Program Files\Common Files\Java
2008-03-04 12:32 ——— dcsh–w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-04 12:32 ——— d—–w C:\Program Files\Windows Live
2008-03-04 12:31 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-26 00:50 ——— d—–w C:\Program Files\Common Files\Adobe
2008-02-25 10:34 ——— d—–w C:\Program Files\iTunes
2008-02-25 10:33 ——— d—–w C:\Program Files\iPod
2008-02-25 10:32 ——— d—–w C:\Program Files\QuickTime
2008-02-15 01:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\IncrediMail
2008-02-15 01:26 ——— d—–w C:\Documents and Settings\All Users\Application Data\IM
2007-08-27 16:44 87,608 —-a-w C:\Documents and Settings\Owner\Application Data\inst.exe
2007-08-27 16:44 47,360 —-a-w C:\Documents and Settings\Owner\Application Data\pcouffin.sys
2007-05-22 23:15 6,751,232 —-a-w C:\Program Files\NETGEAR WPN311 Wireless Adapter.msi
2007-05-22 23:15 4,107 —-a-w C:\Program Files\
0x0409.ini
2002-09-11 14:26 63,730 —-a-w C:\Program Files\viewsonicinstruct_xp.pdf
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{185552D6-25CA-42DD-BC78-BD6C03AD33CF}]
C:\WINDOWS\system32\awtrPgDT.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{64E9656A-DAF2-4524-BCA6-A8258A4DC10C}]
C:\WINDOWS\system32\qoMDtqpp.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A900664E-9AA5-488F-AE9A-BA59834EB65C}]
C:\WINDOWS\system32\yayvVNhG.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B496564D-A43B-43C1-9959-06950911B3C9}]
C:\WINDOWS\system32\opnkiJcD.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB6D0BC7-ADD9-416D-B0F7-5C7AA09BE877}]
C:\WINDOWS\system32\rqRKEvVL.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F11EB52C-9683-4DBC-B393-8C468748C74D}]
C:\WINDOWS\system32\qoMdETNd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 20:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-16 10:07 68856]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-03-29 05:22 1271032]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 10:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 18:07 843776]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-04-10 09:19 729088]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidTool.exe" [2006-06-02 16:45 385024]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 22:57 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-05-18 11:29 49152]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"pdfFactory Pro Dispatcher v3"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis3a.exe" [2007-09-25 17:32 507904]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 15:44 101136 C:\WINDOWS\KHALMNPR.Exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35 90112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-31 22:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 12:10 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 21:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 03:25 144784]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-30 16:39 579072]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 17:25 6731312]
"BM6314b10c"="C:\WINDOWS\system32\ysdqcmua.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-02-28 20:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-30 16:39 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart17.exe [2006-03-05 04:43:54 11000]
EPSON Status Monitor 3 Environment Check(2).lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2007-09-11 18:03:47 131584]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-10 09:33:54 688128]
NETGEAR WPN311 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN311\wlancfg5.exe [2006-12-04 11:57:38 1503232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Sony\\Media Manager for PSP 2.0\\MediaManager.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\l151x86.sys [2007-12-19 16:53]
.
Contents of the 'Scheduled Tasks' folder
"2008-03-31 11:06:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-04-07 14:17:44 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-07 22:15:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2008-04-07 22:18:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-07 14:18:29
Pre-Run: 285,305,901,056 bytes free
Post-Run: 285,530,292,224 bytes free
.
2008-03-30 09:25:29 — E O F —
Malwarebytes' Anti-Malware 1.10
Database version: 598
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 111376
Time elapsed: 22 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM6314b10c (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\vwhfxvxv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\ddcbyyx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\nnnnono.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\qomjijk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\urqnnnm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\wvUoMdax.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP348\A0054443.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054614.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054616.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054617.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054619.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{16BF058A-2732-42ED-9DD5-09E9C28FC981}\RP351\A0054620.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
Hope this ok
marty