Jump to content


- - - - -

More win32 problems


  • Please log in to reply
48 replies to this topic

#1 Guest_Guest_tektok3_*_*

Guest_Guest_tektok3_*_*
  • Guests

Posted 05 September 2005 - 10:43 AM

I am having win32 problems, as well as the smartsecurity desktop. Also, I have cox internet and am using their firewall, antivirus, etc. What do you think of the coxware? The smartsecurity desktop showed up after I started using the package from cox, and I wonder if it downloaded with the cox stuff. Should I get rid of the cox stuff, and use something else?

Here is my log:

Logfile of HijackThis v1.99.1
Scan saved at 11:37:08 AM, on 9/5/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\cox\applications\app\CurtainsSysSvcNt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\atldi32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\atlxm32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\lexpps.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\gjegs.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\AUserInit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {BD9CF1BA-C149-7FD6-0BF4-CE2A97CF0E4F} - C:\WINDOWS\sdklz32.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [InstaFinderK] C:\Program Files\INSTAFINK\InstaFinderK_inst.exe
O4 - HKLM\..\Run: [explorer.exe] C:\WINDOWS\explorer.exe
O4 - HKLM\..\Run: [d3ty32.exe] C:\WINDOWS\system32\d3ty32.exe
O4 - HKLM\..\Run: [ntrd.exe] C:\WINDOWS\ntrd.exe
O4 - HKLM\..\Run: [mfcya32.exe] C:\WINDOWS\mfcya32.exe
O4 - HKLM\..\Run: [netkg32.exe] C:\WINDOWS\system32\netkg32.exe
O4 - HKLM\..\Run: [mfcgo32.exe] C:\WINDOWS\system32\mfcgo32.exe
O4 - HKLM\..\Run: [ieui32.exe] C:\WINDOWS\ieui32.exe
O4 - HKLM\..\Run: [d3hq32.exe] C:\WINDOWS\d3hq32.exe
O4 - HKLM\..\Run: [ipbf32.exe] C:\WINDOWS\system32\ipbf32.exe
O4 - HKLM\..\Run: [appwg32.exe] C:\WINDOWS\appwg32.exe
O4 - HKLM\..\Run: [cruu.exe] C:\WINDOWS\system32\cruu.exe
O4 - HKLM\..\Run: [d3ne.exe] C:\WINDOWS\system32\d3ne.exe
O4 - HKLM\..\Run: [sdkqp.exe] C:\WINDOWS\system32\sdkqp.exe
O4 - HKLM\..\Run: [d3mr32.exe] C:\WINDOWS\system32\d3mr32.exe
O4 - HKLM\..\Run: [atltm32.exe] C:\WINDOWS\atltm32.exe
O4 - HKLM\..\Run: [crfq32.exe] C:\WINDOWS\system32\crfq32.exe
O4 - HKLM\..\Run: [sdkzd32.exe] C:\WINDOWS\sdkzd32.exe
O4 - HKLM\..\Run: [sdksi.exe] C:\WINDOWS\sdksi.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1124573388\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [atlxm32.exe] C:\WINDOWS\atlxm32.exe
O4 - HKLM\..\Run: [apida.exe] C:\WINDOWS\apida.exe
O4 - HKLM\..\Run: [javajm32.exe] C:\WINDOWS\system32\javajm32.exe
O4 - HKLM\..\Run: [winpl.exe] C:\WINDOWS\system32\winpl.exe
O4 - HKLM\..\Run: [systf32.exe] C:\WINDOWS\system32\systf32.exe
O4 - HKLM\..\Run: [sdkpm.exe] C:\WINDOWS\system32\sdkpm.exe
O4 - HKLM\..\Run: [appws32.exe] C:\WINDOWS\system32\appws32.exe
O4 - HKLM\..\Run: [Upp] C:\WINDOWS\Qab.exe
O4 - HKLM\..\Run: [Shell] open32.exe
O4 - HKLM\..\Run: [Systemos Restart] Rundll32.exe pifn.dll, DllRegisterServer
O4 - HKLM\..\Run: [Mbg] C:\WINDOWS\System32\Ohg.exe
O4 - HKLM\..\Run: [Tgv] C:\WINDOWS\System32\Ted.exe
O4 - HKLM\..\Run: [Etc] C:\WINDOWS\Sea.exe
O4 - HKLM\..\Run: [Noh] C:\WINDOWS\Cri.exe
O4 - HKLM\..\Run: [Nlq] C:\WINDOWS\Hft.exe
O4 - HKLM\..\Run: [Dfl] C:\WINDOWS\System32\Uuj.exe
O4 - HKLM\..\Run: [Epm] C:\WINDOWS\Uni.exe
O4 - HKLM\..\Run: [Gai] C:\WINDOWS\System32\Sgf.exe
O4 - HKLM\..\Run: [Nbh] C:\WINDOWS\Hpr.exe
O4 - HKLM\..\Run: [Dig] C:\WINDOWS\Rer.exe
O4 - HKLM\..\Run: [Hrp] C:\WINDOWS\System32\Cci.exe
O4 - HKLM\..\Run: [Vic] C:\WINDOWS\System32\Poo.exe
O4 - HKLM\..\Run: [Mit] C:\WINDOWS\Ljt.exe
O4 - HKLM\..\Run: [Jji] C:\WINDOWS\Ilc.exe
O4 - HKLM\..\Run: [Thd] C:\WINDOWS\Rkm.exe
O4 - HKLM\..\Run: [Cfn] C:\WINDOWS\System32\Ecc.exe
O4 - HKLM\..\Run: [Qpt] C:\WINDOWS\System32\Nqr.exe
O4 - HKLM\..\Run: [Qob] C:\WINDOWS\Eom.exe
O4 - HKLM\..\Run: [Duc] C:\WINDOWS\Elr.exe
O4 - HKLM\..\Run: [Alp] C:\WINDOWS\Dre.exe
O4 - HKLM\..\Run: [Mog] C:\WINDOWS\System32\Alk.exe
O4 - HKLM\..\Run: [Nmp] C:\WINDOWS\Nnl.exe
O4 - HKLM\..\Run: [Dmg] C:\WINDOWS\System32\Srs.exe
O4 - HKLM\..\Run: [Hoi] C:\WINDOWS\System32\Fuh.exe
O4 - HKLM\..\Run: [Ruk] C:\WINDOWS\Hvq.exe
O4 - HKLM\..\Run: [Pad] C:\WINDOWS\System32\Bun.exe
O4 - HKLM\..\Run: [Tti] C:\WINDOWS\Lua.exe
O4 - HKLM\..\Run: [Mvk] C:\WINDOWS\Udn.exe
O4 - HKLM\..\Run: [Hcr] C:\WINDOWS\System32\Uel.exe
O4 - HKLM\..\Run: [Dsi] C:\WINDOWS\Sha.exe
O4 - HKLM\..\Run: [Cnr] C:\WINDOWS\System32\Erc.exe
O4 - HKLM\..\Run: [Gcs] C:\WINDOWS\System32\Utn.exe
O4 - HKLM\..\Run: [Mom] C:\WINDOWS\System32\Bah.exe
O4 - HKLM\..\Run: [Vou] C:\WINDOWS\System32\Svn.exe
O4 - HKLM\..\Run: [Ifa] C:\WINDOWS\System32\Jea.exe
O4 - HKLM\..\Run: [Imu] C:\WINDOWS\System32\Ama.exe
O4 - HKLM\..\Run: [Bgm] C:\WINDOWS\System32\Ppu.exe
O4 - HKLM\..\Run: [Lfr] C:\WINDOWS\System32\Tnl.exe
O4 - HKLM\..\Run: [Jcc] C:\WINDOWS\System32\Ega.exe
O4 - HKLM\..\Run: [Ebg] C:\WINDOWS\Dai.exe
O4 - HKLM\..\Run: [Ctj] C:\WINDOWS\System32\Nll.exe
O4 - HKLM\..\Run: [Buu] C:\WINDOWS\Abv.exe
O4 - HKLM\..\Run: [Dgg] C:\WINDOWS\Rmf.exe
O4 - HKLM\..\Run: [Blb] C:\WINDOWS\System32\Lci.exe
O4 - HKLM\..\Run: [Qme] C:\WINDOWS\System32\Dku.exe
O4 - HKLM\..\Run: [Cqk] C:\WINDOWS\System32\Nvb.exe
O4 - HKLM\..\Run: [Kig] C:\WINDOWS\System32\Tom.exe
O4 - HKLM\..\Run: [Lor] C:\WINDOWS\System32\Cuj.exe
O4 - HKLM\..\Run: [Bds] C:\WINDOWS\System32\Eij.exe
O4 - HKLM\..\Run: [Vmk] C:\WINDOWS\Vaf.exe
O4 - HKLM\..\Run: [Bvr] C:\WINDOWS\Cof.exe
O4 - HKLM\..\Run: [Ufb] C:\WINDOWS\System32\Vni.exe
O4 - HKLM\..\Run: [Gtn] C:\WINDOWS\Ibu.exe
O4 - HKLM\..\Run: [Jsv] C:\WINDOWS\System32\Ovf.exe
O4 - HKLM\..\Run: [Rhv] C:\WINDOWS\Qko.exe
O4 - HKLM\..\Run: [Alq] C:\WINDOWS\Maj.exe
O4 - HKLM\..\Run: [Vor] C:\WINDOWS\System32\Bes.exe
O4 - HKLM\..\Run: [Pcd] C:\WINDOWS\Ijs.exe
O4 - HKLM\..\Run: [Cfb] C:\WINDOWS\Pkm.exe
O4 - HKLM\..\Run: [Ugm] C:\WINDOWS\System32\Upp.exe
O4 - HKLM\..\Run: [Fbk] C:\WINDOWS\Use.exe
O4 - HKLM\..\Run: [Gom] C:\WINDOWS\Ncn.exe
O4 - HKLM\..\Run: [Uci] C:\WINDOWS\System32\Tca.exe
O4 - HKLM\..\Run: [Rnq] C:\WINDOWS\System32\Jpe.exe
O4 - HKLM\..\Run: [Api] C:\WINDOWS\Jlr.exe
O4 - HKLM\..\Run: [Qov] C:\WINDOWS\Tqi.exe
O4 - HKLM\..\Run: [Iin] C:\WINDOWS\System32\Ncm.exe
O4 - HKLM\..\Run: [Tjj] C:\WINDOWS\System32\Ppe.exe
O4 - HKLM\..\Run: [Ahe] C:\WINDOWS\System32\Plc.exe
O4 - HKLM\..\Run: [Nhn] C:\WINDOWS\Fdh.exe
O4 - HKLM\..\Run: [Rln] C:\WINDOWS\System32\Irp.exe
O4 - HKLM\..\Run: [Cqr] C:\WINDOWS\Onl.exe
O4 - HKLM\..\Run: [Cni] C:\WINDOWS\Sgc.exe
O4 - HKLM\..\Run: [Rmt] C:\WINDOWS\Bfe.exe
O4 - HKLM\..\Run: [Aua] C:\WINDOWS\System32\Ljg.exe
O4 - HKLM\..\Run: [Gba] C:\WINDOWS\System32\Dql.exe
O4 - HKLM\..\Run: [Qok] C:\WINDOWS\System32\Rrj.exe
O4 - HKLM\..\Run: [Iuu] C:\WINDOWS\Tjm.exe
O4 - HKLM\..\Run: [Lfo] C:\WINDOWS\Qsl.exe
O4 - HKLM\..\Run: [Kdm] C:\WINDOWS\Chf.exe
O4 - HKLM\..\Run: [Qjb] C:\WINDOWS\System32\Eap.exe
O4 - HKLM\..\Run: [Hnp] C:\WINDOWS\Cks.exe
O4 - HKLM\..\Run: [Ucm] C:\WINDOWS\System32\Tug.exe
O4 - HKLM\..\Run: [Vek] C:\WINDOWS\Rpt.exe
O4 - HKLM\..\Run: [Qvn] C:\WINDOWS\System32\Pgf.exe
O4 - HKLM\..\Run: [Shh] C:\WINDOWS\Hnb.exe
O4 - HKLM\..\Run: [Qsh] C:\WINDOWS\Gmv.exe
O4 - HKLM\..\Run: [Hul] C:\WINDOWS\System32\Oma.exe
O4 - HKLM\..\Run: [Pih] C:\WINDOWS\System32\Ace.exe
O4 - HKLM\..\Run: [mfcuc.exe] C:\WINDOWS\mfcuc.exe
O4 - HKLM\..\Run: [Nle] C:\WINDOWS\Ofo.exe
O4 - HKLM\..\Run: [Acj] C:\WINDOWS\System32\Dps.exe
O4 - HKLM\..\Run: [Jlj] C:\WINDOWS\Sft.exe
O4 - HKLM\..\Run: [Sdv] C:\WINDOWS\Ikg.exe
O4 - HKLM\..\RunOnce: [atldi32.exe] C:\WINDOWS\atldi32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Upp] C:\WINDOWS\Qab.exe
O4 - HKCU\..\Run: [xservice] C:\DOCUME~1\Owner\LOCALS~1\Temp\temp25.exe
O4 - HKCU\..\Run: [Mbg] C:\WINDOWS\System32\Ohg.exe
O4 - HKCU\..\Run: [Tgv] C:\WINDOWS\System32\Ted.exe
O4 - HKCU\..\Run: [Etc] C:\WINDOWS\Sea.exe
O4 - HKCU\..\Run: [Noh] C:\WINDOWS\Cri.exe
O4 - HKCU\..\Run: [Nlq] C:\WINDOWS\Hft.exe
O4 - HKCU\..\Run: [Dfl] C:\WINDOWS\System32\Uuj.exe
O4 - HKCU\..\Run: [Epm] C:\WINDOWS\Uni.exe
O4 - HKCU\..\Run: [Gai] C:\WINDOWS\System32\Sgf.exe
O4 - HKCU\..\Run: [Nbh] C:\WINDOWS\Hpr.exe
O4 - HKCU\..\Run: [Dig] C:\WINDOWS\Rer.exe
O4 - HKCU\..\Run: [Hrp] C:\WINDOWS\System32\Cci.exe
O4 - HKCU\..\Run: [Vic] C:\WINDOWS\System32\Poo.exe
O4 - HKCU\..\Run: [Mit] C:\WINDOWS\Ljt.exe
O4 - HKCU\..\Run: [winservice] C:\WINDOWS\services\svchost.exe
O4 - HKCU\..\Run: [Jji] C:\WINDOWS\Ilc.exe
O4 - HKCU\..\Run: [Thd] C:\WINDOWS\Rkm.exe
O4 - HKCU\..\Run: [Cfn] C:\WINDOWS\System32\Ecc.exe
O4 - HKCU\..\Run: [Qpt] C:\WINDOWS\System32\Nqr.exe
O4 - HKCU\..\Run: [Qob] C:\WINDOWS\Eom.exe
O4 - HKCU\..\Run: [Duc] C:\WINDOWS\Elr.exe
O4 - HKCU\..\Run: [Alp] C:\WINDOWS\Dre.exe
O4 - HKCU\..\Run: [Mog] C:\WINDOWS\System32\Alk.exe
O4 - HKCU\..\Run: [Nmp] C:\WINDOWS\Nnl.exe
O4 - HKCU\..\Run: [Dmg] C:\WINDOWS\System32\Srs.exe
O4 - HKCU\..\Run: [Hoi] C:\WINDOWS\System32\Fuh.exe
O4 - HKCU\..\Run: [Ruk] C:\WINDOWS\Hvq.exe
O4 - HKCU\..\Run: [Pad] C:\WINDOWS\System32\Bun.exe
O4 - HKCU\..\Run: [Tti] C:\WINDOWS\Lua.exe
O4 - HKCU\..\Run: [Mvk] C:\WINDOWS\Udn.exe
O4 - HKCU\..\Run: [Hcr] C:\WINDOWS\System32\Uel.exe
O4 - HKCU\..\Run: [Dsi] C:\WINDOWS\Sha.exe
O4 - HKCU\..\Run: [Cnr] C:\WINDOWS\System32\Erc.exe
O4 - HKCU\..\Run: [Gcs] C:\WINDOWS\System32\Utn.exe
O4 - HKCU\..\Run: [Mom] C:\WINDOWS\System32\Bah.exe
O4 - HKCU\..\Run: [Vou] C:\WINDOWS\System32\Svn.exe
O4 - HKCU\..\Run: [Ifa] C:\WINDOWS\System32\Jea.exe
O4 - HKCU\..\Run: [Imu] C:\WINDOWS\System32\Ama.exe
O4 - HKCU\..\Run: [Bgm] C:\WINDOWS\System32\Ppu.exe
O4 - HKCU\..\Run: [Lfr] C:\WINDOWS\System32\Tnl.exe
O4 - HKCU\..\Run: [Jcc] C:\WINDOWS\System32\Ega.exe
O4 - HKCU\..\Run: [Ebg] C:\WINDOWS\Dai.exe
O4 - HKCU\..\Run: [Ctj] C:\WINDOWS\System32\Nll.exe
O4 - HKCU\..\Run: [Buu] C:\WINDOWS\Abv.exe
O4 - HKCU\..\Run: [Dgg] C:\WINDOWS\Rmf.exe
O4 - HKCU\..\Run: [Blb] C:\WINDOWS\System32\Lci.exe
O4 - HKCU\..\Run: [Qme] C:\WINDOWS\System32\Dku.exe
O4 - HKCU\..\Run: [Cqk] C:\WINDOWS\System32\Nvb.exe
O4 - HKCU\..\Run: [Kig] C:\WINDOWS\System32\Tom.exe
O4 - HKCU\..\Run: [Lor] C:\WINDOWS\System32\Cuj.exe
O4 - HKCU\..\Run: [Bds] C:\WINDOWS\System32\Eij.exe
O4 - HKCU\..\Run: [Vmk] C:\WINDOWS\Vaf.exe
O4 - HKCU\..\Run: [Bvr] C:\WINDOWS\Cof.exe
O4 - HKCU\..\Run: [Ufb] C:\WINDOWS\System32\Vni.exe
O4 - HKCU\..\Run: [Gtn] C:\WINDOWS\Ibu.exe
O4 - HKCU\..\Run: [Jsv] C:\WINDOWS\System32\Ovf.exe
O4 - HKCU\..\Run: [Rhv] C:\WINDOWS\Qko.exe
O4 - HKCU\..\Run: [Alq] C:\WINDOWS\Maj.exe
O4 - HKCU\..\Run: [Vor] C:\WINDOWS\System32\Bes.exe
O4 - HKCU\..\Run: [Pcd] C:\WINDOWS\Ijs.exe
O4 - HKCU\..\Run: [Cfb] C:\WINDOWS\Pkm.exe
O4 - HKCU\..\Run: [Ugm] C:\WINDOWS\System32\Upp.exe
O4 - HKCU\..\Run: [Fbk] C:\WINDOWS\Use.exe
O4 - HKCU\..\Run: [Gom] C:\WINDOWS\Ncn.exe
O4 - HKCU\..\Run: [Uci] C:\WINDOWS\System32\Tca.exe
O4 - HKCU\..\Run: [Rnq] C:\WINDOWS\System32\Jpe.exe
O4 - HKCU\..\Run: [Api] C:\WINDOWS\Jlr.exe
O4 - HKCU\..\Run: [Qov] C:\WINDOWS\Tqi.exe
O4 - HKCU\..\Run: [Iin] C:\WINDOWS\System32\Ncm.exe
O4 - HKCU\..\Run: [Tjj] C:\WINDOWS\System32\Ppe.exe
O4 - HKCU\..\Run: [Ahe] C:\WINDOWS\System32\Plc.exe
O4 - HKCU\..\Run: [Nhn] C:\WINDOWS\Fdh.exe
O4 - HKCU\..\Run: [Rln] C:\WINDOWS\System32\Irp.exe
O4 - HKCU\..\Run: [Cqr] C:\WINDOWS\Onl.exe
O4 - HKCU\..\Run: [Cni] C:\WINDOWS\Sgc.exe
O4 - HKCU\..\Run: [Rmt] C:\WINDOWS\Bfe.exe
O4 - HKCU\..\Run: [Aua] C:\WINDOWS\System32\Ljg.exe
O4 - HKCU\..\Run: [Gba] C:\WINDOWS\System32\Dql.exe
O4 - HKCU\..\Run: [Qok] C:\WINDOWS\System32\Rrj.exe
O4 - HKCU\..\Run: [Iuu] C:\WINDOWS\Tjm.exe
O4 - HKCU\..\Run: [Lfo] C:\WINDOWS\Qsl.exe
O4 - HKCU\..\Run: [Kdm] C:\WINDOWS\Chf.exe
O4 - HKCU\..\Run: [Qjb] C:\WINDOWS\System32\Eap.exe
O4 - HKCU\..\Run: [Hnp] C:\WINDOWS\Cks.exe
O4 - HKCU\..\Run: [Ucm] C:\WINDOWS\System32\Tug.exe
O4 - HKCU\..\Run: [Vek] C:\WINDOWS\Rpt.exe
O4 - HKCU\..\Run: [Qvn] C:\WINDOWS\System32\Pgf.exe
O4 - HKCU\..\Run: [Shh] C:\WINDOWS\Hnb.exe
O4 - HKCU\..\Run: [Qsh] C:\WINDOWS\Gmv.exe
O4 - HKCU\..\Run: [Hul] C:\WINDOWS\System32\Oma.exe
O4 - HKCU\..\Run: [Pih] C:\WINDOWS\System32\Ace.exe
O4 - HKCU\..\Run: [Nle] C:\WINDOWS\Ofo.exe
O4 - HKCU\..\Run: [Acj] C:\WINDOWS\System32\Dps.exe
O4 - HKCU\..\Run: [Jlj] C:\WINDOWS\Sft.exe
O4 - HKCU\..\Run: [Sdv] C:\WINDOWS\Ikg.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: WindowsUpdate23452[1].exe
O4 - Startup: winupdate07503810[1].exe
O4 - Startup: winupdate19698025[1].exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {D7811076-5F96-4C6C-B50E-1403311C1D3A} - C:\WINDOWS\System32\wldr.dll (file missing) (HKCU)
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.horse-active.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.horse-active.net (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - Trusted IP range: 64.62.171.156
O15 - Trusted IP range: 64.62.171.156 (HKLM)
O16 - DPF: {42B4A4BC-E46F-2B93-417D-7F1E6F6F1EBA} - http://63.219.178.91/1/rdgUS990.exe
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://fastconnectk...flowActiveX.CAB
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Network Security Service (NSS) ( 11F#`I) - Unknown owner - C:\WINDOWS\sysay32.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Curtains for Windows System Service (CurtainsSysSvc) - Authentium, Inc. - c:\program files\cox\applications\app\CurtainsSysSvcNt.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common files\WinTools\WToolsS.exe (file missing)

#2 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 10:45 AM

Oops. I didn't log in. That was me.

#3 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 11:06 AM

HI again tektok3

You have a few problems on your computer, we should be able to rid you of all of them

But
Can you do the following for me first please

Open Hijackthis>>Open Misc Tools Section>>Open Uninstall Manager
Click the SAVE LIST button
Save the list to desktop and then copy and paste back here the contents

Can you also do the following
==Download and save WinPFind.zip
UNZIP the contents to your desktop or a folder
Open the WinPFind folder you extracted to desktop
Double click on WinPFind.exe
Then click Start Scan
This could take some time as it will scan your drive
Go to the WinPFind folder
Locate WinPFind.txt in the WinPfind folder

Post the results of the WindPFind.txt

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#4 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 01:10 PM

Okie-dokie. Here is my SAVE LIST list from Hijackthis. I will post the WinPFind stuff as soon as it finishes scanning. Thank you!

3D Home Architect Home Design Deluxe 6
3D Home Architect® Deluxe 3.0
Ad-aware 6 Personal
Adobe Download Manager 1.2 (Remove Only)
Adobe Reader 6.0.1
Adware Away v2.2
Ahead Nero Burning ROM
AOL Explorer
AOL Instant Messenger
aspi
Avery DesignPro
Blackhawk Striker from Compaq (remove only)
Bounce Symphony from Compaq (remove only)
CCHelp
CCScore
CleanUp!
Compaq Connections
Compaq Instant Support
Compaq Organize
Cox High Speed Internet security software
CR2
Dell Photo Printer 720
DjVu Browser Plug-in 4.1
Documents To Go
ESSAdpt
ESSANUP
ESSBrwr
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSTUTOR
ESSvpaht
ESSvpot
Excavation from Compaq (remove only)
First Step Guide
Google Earth
green label Print It 3
Handmark 4.0Student for Palm OS
Handmark PDA Money for palmOne
HijackThis 1.99.1
Home Search Assistent
HP Deskjet Preloaded Printer Drivers
HP Photo & Imaging 3.1
HP Photo and Imaging 2.0 - Photosmart Cameras
HP PSC & OfficeJet 3.0
HP Software Update
ImageMixer VCD2
Intel® Extreme Graphics Driver
IntelliMover Data Transfer Demo
InterActual Player
Internet Explorer Q831167
InterVideo WinDVD Player
iPod Updater 2004-11-15
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Kodak EasyShare software
KSU
Learn2 Player (Uninstall Only)
LingvoSoft Talking Dictionary (English<->Persian (Farsi)) for Palm OS
LiveUpdate 2.6 (Symantec Corporation)
Logitech Pocket Digital
Macromedia Flash Player
Memories Disc Creator 2.0
MGI PhotoSuite 4 (Remove Only)
Microsoft .NET Framework 1.1
Microsoft Data Access Components KB870669
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office Standard Edition 2003
Microsoft Plus! Digital Media Edition
Microsoft Works 7.0
MSN Music Assistant
MUSICMATCH Jukebox
Norton WMI Update
Notifier
NVIDIA GART Driver
Offer Optimizer
Orbital from Compaq (remove only)
OTtBP
Otto from Compaq (remove only)
Outlook Express Q837009
Overball from Compaq (remove only)
Pacific Poker
Palm Desktop
PartyPoker.net
PCDLNCH
PC-Doctor for Windows
Photosmart 140,240,7200,7600,7700,7900 Series
Planet Poker
Polar Bowler from Compaq (remove only)
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2004
QuickTime
RealOne Player
RecordNow!
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
Screen2 Screen Saver
Search Assistant
Search Extender
SFR
SFR2
Shopping Wizard
Shopping Wizard
Slyder from Compaq (remove only)
Software for your PC!
Sonic Update Manager
Sony USB Driver
SpamSubtract
Spybot - Search & Destroy 1.3
Symantec Network Driver Update
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
WeatherBug
Web Search Tools Error Search
WildTangent Web Driver
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player Hotfix [See wm828026 for more information]
Windows open32 update
Windows SR 2.0
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB833407
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB837001
Windows XP Hotfix - KB840374
Windows XP Hotfix (SP2) [See Q329048 for more information]
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q328310
Windows XP Hotfix (SP2) Q329112
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329441
Windows XP Hotfix (SP2) Q329909
Windows XP Hotfix (SP2) Q331953
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q810565
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q811493
Windows XP Hotfix (SP2) Q811789
Windows XP Hotfix (SP2) Q814033
Windows XP Hotfix (SP2) Q814995
Windows XP Hotfix (SP2) Q815021
Windows XP Hotfix (SP2) Q815485
Windows XP Hotfix (SP2) Q817287
Windows XP Hotfix (SP2) Q817606
WinTools for Internet Explorer [v2]
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Messenger Explorer Bar
Yahoo! Photos Easy Upload Tool 1v3
Yahoo! Toolbar

#5 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 01:38 PM

Here are the results of the WinPFind.txt


WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

Windows OS and Versions
Product Name: Microsoft Windows XP Current Build: Service Pack 1 Current Build Number: 2600
Internet Explorer Version: 6.0.2800.1106

Checking Selected Standard Folders

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
UPX! 4/26/2004 1:45:52 PM 6656 C:\WINDOWS\services.exe

Checking %System% folder...
FSG! 9/1/2005 10:42:32 PM 8833 C:\WINDOWS\SYSTEM32\1010781.exe
FSG! 9/4/2005 2:54:38 AM 8833 C:\WINDOWS\SYSTEM32\32101625.exe
UPX! 4/26/2004 1:28:28 PM 3072 C:\WINDOWS\SYSTEM32\arpa.exe
UPX! 7/23/2004 1:32:52 PM 9728 C:\WINDOWS\SYSTEM32\authz.exe
PEC2 8/29/2002 6:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PTech 4/29/2004 2:35:00 AM H 3066522 C:\WINDOWS\SYSTEM32\kyf.dat
UPX! 8/22/2001 6:00:00 PM 86030 C:\WINDOWS\SYSTEM32\msdjgk.dll
UPX! 8/22/2001 6:00:00 PM 218624 C:\WINDOWS\SYSTEM32\mseggo.gif
Umonitor 8/29/2002 6:00:00 AM 631808 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 8/29/2002 6:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...
UPX! 4/26/2004 2:04:54 AM 6656 C:\WINDOWS\SYSTEM32\drivers\csrss.exe
aspack 12/10/2004 10:30:48 AM R 707176 C:\WINDOWS\SYSTEM32\drivers\css-dvp.sys

Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/5/2005 12:34:16 PM S 2048 C:\WINDOWS\bootstat.dat
8/4/2005 11:24:20 AM H 30202 C:\WINDOWS\fiz2
7/17/2005 8:25:22 AM H 15515 C:\WINDOWS\log0.txt
8/8/2005 11:38:06 AM H 10277 C:\WINDOWS\log1.txt
8/6/2005 8:22:38 AM H 10363 C:\WINDOWS\log2.txt
8/4/2005 11:24:22 AM H 65680 C:\WINDOWS\MEMORY.DMP
9/1/2005 1:11:56 AM H 54156 C:\WINDOWS\QTFont.qfn
8/25/2005 8:33:52 AM HS 48680 C:\WINDOWS\winnt.bmp
8/5/2005 5:27:00 AM HS 48680 C:\WINDOWS\winnt256.bmp
9/5/2005 12:34:18 PM H 6 C:\WINDOWS\Tasks\SA.DAT

Checking for CPL files...
Microsoft Corporation 8/29/2002 6:00:00 AM 66048 C:\WINDOWS\SYSTEM32\access.cpl
Realtek Semiconductor Corp. 2/17/2004 5:49:14 AM 14193152 C:\WINDOWS\SYSTEM32\ALSNDMGR.CPL
Microsoft Corporation 8/29/2002 6:00:00 AM 578560 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 129024 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 150016 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation 4/7/2003 8:14:30 AM 94208 C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Ahead Software AG 5/26/2003 4:12:14 AM 57344 C:\WINDOWS\SYSTEM32\ImageDrive.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 292352 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 121856 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 65536 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 10/11/2003 4:52:00 AM 53352 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 559616 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 256000 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
NVIDIA Corporation 8/19/2003 3:56:00 AM 143360 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 109056 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 9/23/2004 6:57:40 PM 323072 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 268288 C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 90112 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 8/3/2004 2:03:24 PM 167704 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 66048 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 578560 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 129024 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 150016 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 292352 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 121856 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 65536 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 559616 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 256000 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 36864 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 109056 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 147456 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 268288 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 8/29/2002 6:00:00 AM 90112 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Realtek Semiconductor Corp. 2/17/2004 5:49:14 AM 14193152 C:\WINDOWS\SYSTEM32\DRVSTORE\Alcxwdm_cfb7d3fc0ab7f7a3133a6c25509eaf3479108975\ALSNDMGR.CPL
Intel Corporation 4/7/2003 8:14:30 AM 94208 C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\igfxcpl.cpl
Realtek Semiconductor Corp. 9/12/2003 8:24:20 PM 10435584 C:\WINDOWS\SYSTEM32\ReinstallBackups\0014\DriverFiles\ALSNDMGR.CPL

Checking Selected Startup Folders

Checking files in %ALLUSERSPROFILE%\Startup folder...
9/17/2004 10:28:00 PM 1562 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dataviz Messenger.lnk
10/11/2003 4:16:08 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini

Checking files in %ALLUSERSPROFILE%\Application Data folder...
10/10/2003 9:10:12 PM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
10/11/2003 5:35:18 AM 534 C:\Documents and Settings\All Users\Application Data\hpzinstall.log

Checking files in %USERPROFILE%\Startup folder...
10/11/2003 4:16:08 AM HS 84 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop.ini
9/17/2004 11:14:26 PM 1315 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\HotSync Manager.lnk
11/7/2004 1:13:28 PM 0 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\WindowsUpdate23452[1].exe
UPX! 3/4/2005 3:24:56 AM 9216 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\winupdate07503810[1].exe
UPX! 2/18/2005 8:59:22 PM 8704 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\winupdate19698025[1].exe
6/17/2004 12:21:22 AM 938 C:\Documents and Settings\Owner\Start Menu\Programs\Startup\WKCALREM.LNK

Checking files in %USERPROFILE%\Application Data folder...
10/10/2003 9:10:12 PM HS 62 C:\Documents and Settings\Owner\Application Data\desktop.ini
9/21/2004 9:27:20 PM 0 C:\Documents and Settings\Owner\Application Data\dm.ini
6/16/2004 9:33:44 PM 37 C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
4/26/2005 11:02:10 PM 284 C:\Documents and Settings\Owner\Application Data\ViewerApp.dat

Checking Selected Registry Keys

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD9CF1BA-C149-7FD6-0BF4-CE2A97CF0E4F}
Class = C:\WINDOWS\sdklz32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = &Yahoo! Companion : C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINDOWS\System32\msdxm.ocx

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\WINDOWS\System32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
ButtonText = Messenger :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
ButtonText = Research :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D7811076-5F96-4C6C-B50E-1403311C1D3A}
ButtonText = Microsoft AntiSpyware helper :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{F4430FE8-2638-42e5-B849-800749B94EED}
ButtonText = PartyPoker.net : C:\Program Files\PartyPoker.net\partypokernet.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{4528BBE0-4E08-11D5-AD55-00010333D0AD}
&Yahoo! Messenger = C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}
&Research = C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = &Yahoo! Companion : C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
NeroCheck C:\WINDOWS\system32\NeroCheck.exe
SSC_UserPrompt C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
WildTangent CDA RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
iTunesHelper C:\Program Files\iTunes\iTunesHelper.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
ViewMgr C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
InstaFinderK C:\Program Files\INSTAFINK\InstaFinderK_inst.exe
explorer.exe C:\WINDOWS\explorer.exe
d3ty32.exe C:\WINDOWS\system32\d3ty32.exe
ntrd.exe C:\WINDOWS\ntrd.exe
mfcya32.exe C:\WINDOWS\mfcya32.exe
netkg32.exe C:\WINDOWS\system32\netkg32.exe
mfcgo32.exe C:\WINDOWS\system32\mfcgo32.exe
ieui32.exe C:\WINDOWS\ieui32.exe
d3hq32.exe C:\WINDOWS\d3hq32.exe
ipbf32.exe C:\WINDOWS\system32\ipbf32.exe
appwg32.exe C:\WINDOWS\appwg32.exe
cruu.exe C:\WINDOWS\system32\cruu.exe
d3ne.exe C:\WINDOWS\system32\d3ne.exe
sdkqp.exe C:\WINDOWS\system32\sdkqp.exe
d3mr32.exe C:\WINDOWS\system32\d3mr32.exe
atltm32.exe C:\WINDOWS\atltm32.exe
crfq32.exe C:\WINDOWS\system32\crfq32.exe
sdkzd32.exe C:\WINDOWS\sdkzd32.exe
sdksi.exe C:\WINDOWS\sdksi.exe
HostManager C:\Program Files\Common Files\AOL\1124573388\ee\AOLHostManager.exe
atlxm32.exe C:\WINDOWS\atlxm32.exe
apida.exe C:\WINDOWS\apida.exe
javajm32.exe C:\WINDOWS\system32\javajm32.exe
winpl.exe C:\WINDOWS\system32\winpl.exe
systf32.exe C:\WINDOWS\system32\systf32.exe
sdkpm.exe C:\WINDOWS\system32\sdkpm.exe
appws32.exe C:\WINDOWS\system32\appws32.exe
AuthConsoleStart
Upp C:\WINDOWS\Qab.exe
Shell open32.exe
Systemos Restart Rundll32.exe pifn.dll, DllRegisterServer
Mbg C:\WINDOWS\System32\Ohg.exe
Tgv C:\WINDOWS\System32\Ted.exe
Etc C:\WINDOWS\Sea.exe
Noh C:\WINDOWS\Cri.exe
Nlq C:\WINDOWS\Hft.exe
Dfl C:\WINDOWS\System32\Uuj.exe
Epm C:\WINDOWS\Uni.exe
Gai C:\WINDOWS\System32\Sgf.exe
Nbh C:\WINDOWS\Hpr.exe
Dig C:\WINDOWS\Rer.exe
Hrp C:\WINDOWS\System32\Cci.exe
Vic C:\WINDOWS\System32\Poo.exe
Mit C:\WINDOWS\Ljt.exe
Jji C:\WINDOWS\Ilc.exe
Thd C:\WINDOWS\Rkm.exe
Cfn C:\WINDOWS\System32\Ecc.exe
Qpt C:\WINDOWS\System32\Nqr.exe
Qob C:\WINDOWS\Eom.exe
Duc C:\WINDOWS\Elr.exe
Alp C:\WINDOWS\Dre.exe
Mog C:\WINDOWS\System32\Alk.exe
Nmp C:\WINDOWS\Nnl.exe
Dmg C:\WINDOWS\System32\Srs.exe
Hoi C:\WINDOWS\System32\Fuh.exe
Ruk C:\WINDOWS\Hvq.exe
Pad C:\WINDOWS\System32\Bun.exe
Tti C:\WINDOWS\Lua.exe
Mvk C:\WINDOWS\Udn.exe
Hcr C:\WINDOWS\System32\Uel.exe
Dsi C:\WINDOWS\Sha.exe
Cnr C:\WINDOWS\System32\Erc.exe
Gcs C:\WINDOWS\System32\Utn.exe
Mom C:\WINDOWS\System32\Bah.exe
Vou C:\WINDOWS\System32\Svn.exe
Ifa C:\WINDOWS\System32\Jea.exe
Imu C:\WINDOWS\System32\Ama.exe
Bgm C:\WINDOWS\System32\Ppu.exe
Lfr C:\WINDOWS\System32\Tnl.exe
Jcc C:\WINDOWS\System32\Ega.exe
Ebg C:\WINDOWS\Dai.exe
Ctj C:\WINDOWS\System32\Nll.exe
Buu C:\WINDOWS\Abv.exe
Dgg C:\WINDOWS\Rmf.exe
Blb C:\WINDOWS\System32\Lci.exe
Qme C:\WINDOWS\System32\Dku.exe
Cqk C:\WINDOWS\System32\Nvb.exe
Kig C:\WINDOWS\System32\Tom.exe
Lor C:\WINDOWS\System32\Cuj.exe
Bds C:\WINDOWS\System32\Eij.exe
Vmk C:\WINDOWS\Vaf.exe
Bvr C:\WINDOWS\Cof.exe
Ufb C:\WINDOWS\System32\Vni.exe
Gtn C:\WINDOWS\Ibu.exe
Jsv C:\WINDOWS\System32\Ovf.exe
Rhv C:\WINDOWS\Qko.exe
Alq C:\WINDOWS\Maj.exe
Vor C:\WINDOWS\System32\Bes.exe
Pcd C:\WINDOWS\Ijs.exe
Cfb C:\WINDOWS\Pkm.exe
Ugm C:\WINDOWS\System32\Upp.exe
Fbk C:\WINDOWS\Use.exe
Gom C:\WINDOWS\Ncn.exe
Uci C:\WINDOWS\System32\Tca.exe
Rnq C:\WINDOWS\System32\Jpe.exe
Api C:\WINDOWS\Jlr.exe
Qov C:\WINDOWS\Tqi.exe
Iin C:\WINDOWS\System32\Ncm.exe
Tjj C:\WINDOWS\System32\Ppe.exe
Ahe C:\WINDOWS\System32\Plc.exe
Nhn C:\WINDOWS\Fdh.exe
Rln C:\WINDOWS\System32\Irp.exe
Cqr C:\WINDOWS\Onl.exe
Cni C:\WINDOWS\Sgc.exe
Rmt C:\WINDOWS\Bfe.exe
Aua C:\WINDOWS\System32\Ljg.exe
Gba C:\WINDOWS\System32\Dql.exe
Qok C:\WINDOWS\System32\Rrj.exe
Iuu C:\WINDOWS\Tjm.exe
Lfo C:\WINDOWS\Qsl.exe
Kdm C:\WINDOWS\Chf.exe
Qjb C:\WINDOWS\System32\Eap.exe
Hnp C:\WINDOWS\Cks.exe
Ucm C:\WINDOWS\System32\Tug.exe
Vek C:\WINDOWS\Rpt.exe
Qvn C:\WINDOWS\System32\Pgf.exe
Shh C:\WINDOWS\Hnb.exe
Qsh C:\WINDOWS\Gmv.exe
Hul C:\WINDOWS\System32\Oma.exe
Pih C:\WINDOWS\System32\Ace.exe
mfcuc.exe C:\WINDOWS\mfcuc.exe
Nle C:\WINDOWS\Ofo.exe
Acj C:\WINDOWS\System32\Dps.exe
Jlj C:\WINDOWS\Sft.exe
Sdv C:\WINDOWS\Ikg.exe
Pbq C:\WINDOWS\System32\Mev.exe
Rjr C:\WINDOWS\System32\Vgn.exe
Jns C:\WINDOWS\Dvn.exe
Meq C:\WINDOWS\Nsm.exe
Qiv C:\WINDOWS\System32\Sdk.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
atldi32.exe C:\WINDOWS\atldi32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background
MoneyAgent "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
AIM C:\Program Files\AIM\aim.exe -cnetwait.odl
Weather C:\Program Files\AWS\WeatherBug\Weather.exe 1
Yahoo! Pager C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
Upp C:\WINDOWS\Qab.exe
xservice C:\DOCUME~1\Owner\LOCALS~1\Temp\temp25.exe
Mbg C:\WINDOWS\System32\Ohg.exe
Tgv C:\WINDOWS\System32\Ted.exe
Etc C:\WINDOWS\Sea.exe
Noh C:\WINDOWS\Cri.exe
Nlq C:\WINDOWS\Hft.exe
Dfl C:\WINDOWS\System32\Uuj.exe
Epm C:\WINDOWS\Uni.exe
Gai C:\WINDOWS\System32\Sgf.exe
Nbh C:\WINDOWS\Hpr.exe
Dig C:\WINDOWS\Rer.exe
Hrp C:\WINDOWS\System32\Cci.exe
Vic C:\WINDOWS\System32\Poo.exe
Mit C:\WINDOWS\Ljt.exe
winservice C:\WINDOWS\services\svchost.exe
Jji C:\WINDOWS\Ilc.exe
Thd C:\WINDOWS\Rkm.exe
Cfn C:\WINDOWS\System32\Ecc.exe
Qpt C:\WINDOWS\System32\Nqr.exe
Qob C:\WINDOWS\Eom.exe
Duc C:\WINDOWS\Elr.exe
Alp C:\WINDOWS\Dre.exe
Mog C:\WINDOWS\System32\Alk.exe
Nmp C:\WINDOWS\Nnl.exe
Dmg C:\WINDOWS\System32\Srs.exe
Hoi C:\WINDOWS\System32\Fuh.exe
Ruk C:\WINDOWS\Hvq.exe
Pad C:\WINDOWS\System32\Bun.exe
Tti C:\WINDOWS\Lua.exe
Mvk C:\WINDOWS\Udn.exe
Hcr C:\WINDOWS\System32\Uel.exe
Dsi C:\WINDOWS\Sha.exe
Cnr C:\WINDOWS\System32\Erc.exe
Gcs C:\WINDOWS\System32\Utn.exe
Mom C:\WINDOWS\System32\Bah.exe
Vou C:\WINDOWS\System32\Svn.exe
Ifa C:\WINDOWS\System32\Jea.exe
Imu C:\WINDOWS\System32\Ama.exe
Bgm C:\WINDOWS\System32\Ppu.exe
Lfr C:\WINDOWS\System32\Tnl.exe
Jcc C:\WINDOWS\System32\Ega.exe
Ebg C:\WINDOWS\Dai.exe
Ctj C:\WINDOWS\System32\Nll.exe
Buu C:\WINDOWS\Abv.exe
Dgg C:\WINDOWS\Rmf.exe
Blb C:\WINDOWS\System32\Lci.exe
Qme C:\WINDOWS\System32\Dku.exe
Cqk C:\WINDOWS\System32\Nvb.exe
Kig C:\WINDOWS\System32\Tom.exe
Lor C:\WINDOWS\System32\Cuj.exe
Bds C:\WINDOWS\System32\Eij.exe
Vmk C:\WINDOWS\Vaf.exe
Bvr C:\WINDOWS\Cof.exe
Ufb C:\WINDOWS\System32\Vni.exe
Gtn C:\WINDOWS\Ibu.exe
Jsv C:\WINDOWS\System32\Ovf.exe
Rhv C:\WINDOWS\Qko.exe
Alq C:\WINDOWS\Maj.exe
Vor C:\WINDOWS\System32\Bes.exe
Pcd C:\WINDOWS\Ijs.exe
Cfb C:\WINDOWS\Pkm.exe
Ugm C:\WINDOWS\System32\Upp.exe
Fbk C:\WINDOWS\Use.exe
Gom C:\WINDOWS\Ncn.exe
Uci C:\WINDOWS\System32\Tca.exe
Rnq C:\WINDOWS\System32\Jpe.exe
Api C:\WINDOWS\Jlr.exe
Qov C:\WINDOWS\Tqi.exe
Iin C:\WINDOWS\System32\Ncm.exe
Tjj C:\WINDOWS\System32\Ppe.exe
Ahe C:\WINDOWS\System32\Plc.exe
Nhn C:\WINDOWS\Fdh.exe
Rln C:\WINDOWS\System32\Irp.exe
Cqr C:\WINDOWS\Onl.exe
Cni C:\WINDOWS\Sgc.exe
Rmt C:\WINDOWS\Bfe.exe
Aua C:\WINDOWS\System32\Ljg.exe
Gba C:\WINDOWS\System32\Dql.exe
Qok C:\WINDOWS\System32\Rrj.exe
Iuu C:\WINDOWS\Tjm.exe
Lfo C:\WINDOWS\Qsl.exe
Kdm C:\WINDOWS\Chf.exe
Qjb C:\WINDOWS\System32\Eap.exe
Hnp C:\WINDOWS\Cks.exe
Ucm C:\WINDOWS\System32\Tug.exe
Vek C:\WINDOWS\Rpt.exe
Qvn C:\WINDOWS\System32\Pgf.exe
Shh C:\WINDOWS\Hnb.exe
Qsh C:\WINDOWS\Gmv.exe
Hul C:\WINDOWS\System32\Oma.exe
Pih C:\WINDOWS\System32\Ace.exe
Nle C:\WINDOWS\Ofo.exe
Acj C:\WINDOWS\System32\Dps.exe
Jlj C:\WINDOWS\Sft.exe
Sdv C:\WINDOWS\Ikg.exe
Pbq C:\WINDOWS\System32\Mev.exe
Rjr C:\WINDOWS\System32\Vgn.exe
Jns C:\WINDOWS\Dvn.exe
Meq C:\WINDOWS\Nsm.exe
Qiv C:\WINDOWS\System32\Sdk.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 0


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoViewContextMenu 2


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
Key KY/Pkx,Rc
Hint rats
FileName0 C:\WINDOWS\System32\RSACi.rat

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default
Allow_Unknowns 0
PleaseMom 1
Enabled 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\.Default\http://www.rsac.org/ratingsv01.html
l 0
n 0
s 0
v 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings\PICSRules\.Default
NumSys 0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop
NoChangingWallpaper 0
NoComponents 0
NoAddingComponents 0
NoDeletingComponents 0
NoEditingComponents 0
NoHTMLWallPaper 0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 255
_NoDriveTypeAutoRun 0
NoActiveDesktop 0
ClassicShell 0
ForceActiveDesktopOn 1
NoViewContextMenu 2

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
Wallpaper C:\WINDOWS\desktop.html
disableregistrytools 0
disabletaskmgr 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\System32\AUserInit.exe
Shell = Explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
= igfxsrvc.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


Scan Complete
WinPFind v1.3.5 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/5/2005 2:32:05 PM

#6 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 02:56 PM

Good work, you have some work to do, but you should be looking a lot better after you try some fixes
I'll leave the manual fixes with Hijackthis later, I need you to run some tools first and I'll supply a couple registry fixes

Please download the following tools
First Access your Add/Remove programs and remove
Ad-aware 6 Personal
After you have done that, let's get you the latest version
Download and InstallAd-Aware SE Personal 1.06
Open Ad-Aware, ensure to click the check for updates now link and Connect to download the latest updates
When installing ad-aware may prompt to update, allow it but Don't run a scan yet

==Download and UNZIP to desktop or a folder
HSFIX.zip
HSFix directory will be created
We'll need this later
If Command's AV interferes with this download, you will have to disable it

==Download and UNZIP to the desktop or a folder
~Link Removed~
So you now have Deldomains.inf extracted
We'll need this later

==Download and Unzip The Hoster to a folder
We'll need this later

==Download smitRem.exe and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.
We'll need this later

==Download and then Install
Ewido Security Suite

When installing, under "Additional Options" Uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We'll fix that later
From the main ewido screen, click on Update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
If for some reason the Updater won't work can you manually download the
Updates from this link after you have Ewido installed
http://www.ewido.net...wnload/updates/

==Download and UNZIP to desktop or a folder
CWSServiceremove.zip
So you now have Cwsserviceremove.reg on your desktop or a folder
We'll need this later

==Download and UNZIP to desktop or a folder fix.zip
So you now have fix.reg extracted
[attachment=330:attachment] We'll need this later

==Create a New folder on your desktop, call it Aboutbuster
(Right click an empty spot on the desktop and select NEW>>FOLDER)
Download to desktop About:Buster
by RubbeR Ducky
Unzip it to that new folder
*Open the AboutBuster folder you unzipped the contents too
*Double click to run About:Buster.exe
*Click the UPDATE button, and allow to update
*Close out AboutBuster for now, we'll need it later

Download and save to desktop or folder
CWShredder.exe
Run this later

You have a bit of work ahead of you,
Please Print this out or save these instructions to a Notepad file and save it to your Desktop

RESTART your Computer in SAFE MODE
You can do this by tapping the F8 key as the system is restarting, just before Windows loads, or use the link
I supplied for a more detailed explanation

Go to START>>>RUN>>>type in services.msc
Hit OK
In the next window, look on the right hand side for this service
name---- Network Security Service (NSS)

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Disabled

Do the same thing for this one too
WinTools for IE service

Access your Add/Remove programs and remove the following if you can
If you can't remain in safe mode and carry on with instructions
There are other nasties in your add/remove programs, just try removing the following for now
WinTools for Internet Explorer [v2]
Viewpoint Manager (Remove Only)
Viewpoint Media Player
Viewpoint Toolbar (Remove Only)
WeatherBug
<-remove this if you didn't intentionally install it
Web Search Tools Error Search
WildTangent Web Driver
Windows open32 update
Windows SR 2.0


Stay in safe mode
Set Windows To Show Hidden Files and Folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Uncheck the Hide Extensions for known file types
* Click Yes to confirm.
* Click OK.

Find and delete the following folders if found
C:\Program Files\Common files\WinTools <-folder
C:\Program Files\INSTAFINK <-folder
C:\Program Files\AWS <-folder if Weatherbug was removed

==Navigate to the HSFix directory>>Open the folder, ensure you unzipped this
and double-click on HSFix.bat.
* It will produce a log file, located here: C:\hslog.txt. <--we'll need this later

==Open the Aboutbuster folder and Run About:buster.exe
Click the Begin Removal button
Can you please run this scan twice
When it's done it will produce a log in the Aboutbuster folder called
Ab logfile.txt
I'll need to see the log later

Double click on cwsserviceremove.reg and allow to add or merge to the registry

Open the SmitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

Go to start > control panel > Display properties > Desktop > Customize Desktop... > Web tab > uncheck everything you find in there.
Exclude "My Current Home Page" if selected
Click OK>> Apply>>OK

==Open Ewido Security Suite
Give it time to load
Click on the Scanner button on the left menu
Click on the Settings button on the right
Select "Scan Every File"
OK it and then click on the "Complete System Scan"
*If Ewido finds something it will prompt you with "Infected Object found"
Ensure the following are Selected
*1. Perform Action = Remove
*2. Create Encrypted Backup in Quarantine (Recommended)
*3. Perform action with all infections
Then click OK
When Ewido has finished it's scan click the "Save Report" button
Save the report to desktop
Exit Ewido

Open Ad-Aware
Click START
Click the radio button to Perform a Full system scan then click NEXT
When it's finished scanning
At this point you should either right click on the screen and and choose the "Select All" Objects option or individually put a checkmark in each objects checkbox
click on the Next button. Ad-Aware SE will now present you with a confirmation box as to whether or not you would like to remove the objects you have just selected. Press the "OK" button

Double click on fix.reg and allow to add or merge to the registry

Run CWShredder.exe and click the FIX button, let it finish

RESTART your computer to Normal mode

Back in Windows

==Right Click on DelDomains.inf>>Choose Install from the menu bar
This will delete all your Trusted and Ranges entries

==Open Hoster and
Press "Restore Original Hosts" and press "OK".
Then Exit

==Access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the Security tab | Custom Level
Check ActiveX security settings:
Make sure that the following settings are correct:
o Download signed ActiveX controls (Prompt)
o Download unsigned ActiveX controls (Disable)
o Initialize and script ActiveX controls not marked as safe (Disable)
o Script ActiveX controls marked safe for scripting (Prompt)

From my signature below please run a free online virus scan at Panda's
Choose to scan "MyComputer"
When the scan is done, if anything is found it will give you a choice to Save a Report
Please save the report to desktop or a folder

I need to see some logs, Please try and supply all of them

The Report from Panda's
The Report from Ewidos
The Ab logfile.txt from About:Buster
C:\hslog.txt from HSFix
Also run Hijackthis again and post a fresh log

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#7 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 03:53 PM

Oooookiedokie. I downloaded everything EXCEPT: The link you gave me said I wasn't authorized to download DelDomains.zip - so I didn't get that one. I downloaded Ewido to my computer, but I couldn't install it. An error popup kept coming up that said the installer I am using is corrupted or incomplete, and it might be because of a virus. I already have About: Buster (3.0.0.0) and CWShredder (1.59.0.1). Should I uninstall them & download new versions, or leave them as is?

Thanks again!

#8 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 03:58 PM

Remove your versions of CWShredder and About:Buster
and get the ones I posted

I uploaded DelDomains for you, please download it from here
[attachment=331:attachment]

Ewido is legitimate
Please allow to install if your AV is interfering

Or try redownload Ewido from this link
http://www.ewido.net/en/

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#9 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 04:10 PM

Both of the downloads worked this time. I'll follow the rest of the instructions, now, and hopefully come back w/ plenty of logs!

#10 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:31 PM

Alllllright, here we go! I'm not sure if the Delldomains thing worked. My right-click is still disabled, so I clicked on "install" from the File menu. It didn't seem to do much. Is this what's supposed to happen? Also, I must've just zoned out because I didn't see your "Remove your versions of CWShredder and About:Buster and get the ones I posted" at the top of the page until just now, and used the old ones. Do I need to get the new ones, & run it again?

Here are my logs:

Activescan:

Incident Status Location

Adware:adware/tvmedia No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\tvmcwrd.dll
Spyware:spyware/whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Adware:adware/navipromo No disinfected C:\WINDOWS\SYSTEM32\sdkdp32.exe
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM32\DRIVERS\csrss.exe
Adware:adware/ipinsight No disinfected C:\WINDOWS\INF\alchem.inf
Adware:adware/spywad No disinfected C:\WINDOWS\popup.html
Adware:adware/sidesearch No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\Lycos
Adware:adware/ncase No disinfected C:\WINDOWS\SYSTEM32\FLEOK
Adware:adware/wintools No disinfected Windows Registry
Adware:Adware/KeenValue No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq15D.tmp\remove.exe
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab[mySetp.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[a.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2a79b1dc-4864bd19.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-4e66bbdf-62b618be.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6a66635c-7d6532a4.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7106e536-674b7a91.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-771ffd62-53cc9b3e.zip[Dummy.class]
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0044868.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0044869.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0045867.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0045868.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046867.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046868.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046884.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046885.dll
Virus:Trj/Horst.D Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046916.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0047261.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0048261.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0048312.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP313\A0048380.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP313\A0048425.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049060.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049061.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049062.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049063.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049064.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049065.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049066.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049067.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049069.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049070.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049072.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049073.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049074.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049075.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049076.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049077.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049078.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049080.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049081.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049085.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049086.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049087.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049088.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049089.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049090.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049091.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049094.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049095.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049096.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049098.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049099.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049100.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049101.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049102.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049103.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049104.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049105.exe
Adware:Adware/SaveNow No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049106.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049107.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049111.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049112.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049113.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049114.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049115.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049116.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049118.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049119.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049120.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049121.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049122.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049123.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049124.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049125.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049126.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049127.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049128.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049130.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049131.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049132.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049133.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049134.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049135.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049136.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049138.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049139.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049140.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049141.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049143.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049144.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049145.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049146.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049147.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049148.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049150.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049151.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049154.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049156.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049157.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049158.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049159.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049160.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049161.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049162.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049163.exe
Adware:Adware/SaveNow No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049164.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049165.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049166.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049167.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049168.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049169.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049179.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049180.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049181.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049183.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049184.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049185.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049186.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049187.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049189.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049190.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049193.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049194.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049195.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049196.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049197.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049198.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049199.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049200.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049201.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049202.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049203.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049204.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049205.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049206.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049207.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049209.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049211.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049212.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049213.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049214.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049215.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049216.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049217.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049218.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049219.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049220.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049223.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049224.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049225.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049226.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049227.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049228.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049229.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049230.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049233.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049234.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049235.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049236.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049238.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049239.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049240.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049241.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049243.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049244.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049245.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049246.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049247.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049249.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049250.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049251.exe
Adware:Adware/eZula No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049252.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049253.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049254.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049255.exe
Virus:Trj/Downloader.EIY

#11 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 08:34 PM

Yup, you need the newer version of CWShredder and AboutBuster

Please reboot back into safe mode and run those 2 updated versions again

Do what you can and post back all required log

P.S. The updated AboutBuster was an important step

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#12 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:35 PM

I'm not sure that worked, so let me post the Panda log again:



Incident Status Location

Adware:adware/tvmedia No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\tvmcwrd.dll
Spyware:spyware/whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Adware:adware/navipromo No disinfected C:\WINDOWS\SYSTEM32\sdkdp32.exe
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM32\DRIVERS\csrss.exe
Adware:adware/ipinsight No disinfected C:\WINDOWS\INF\alchem.inf
Adware:adware/spywad No disinfected C:\WINDOWS\popup.html
Adware:adware/sidesearch No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\Lycos
Adware:adware/ncase No disinfected C:\WINDOWS\SYSTEM32\FLEOK
Adware:adware/wintools No disinfected Windows Registry
Adware:Adware/KeenValue No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq15D.tmp\remove.exe
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab[mySetp.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[a.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2a79b1dc-4864bd19.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-4e66bbdf-62b618be.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6a66635c-7d6532a4.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7106e536-674b7a91.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-771ffd62-53cc9b3e.zip[Dummy.class]
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0044868.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0044869.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0045867.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0045868.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046867.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046868.dll
Virus:Trj/Dropper.DV Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046884.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046885.dll
Virus:Trj/Horst.D Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0046916.exe
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0047261.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0048261.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\Fifoed\A0048312.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP313\A0048380.dll
Virus:Trj/Pidspro.A Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP313\A0048425.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049060.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049061.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049062.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049063.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049064.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049065.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049066.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049067.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049069.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049070.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049072.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049073.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049074.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049075.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049076.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049077.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049078.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049080.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049081.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049085.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049086.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049087.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049088.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049089.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049090.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049091.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049094.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049095.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049096.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049098.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049099.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049100.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049101.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049102.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049103.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049104.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049105.exe
Adware:Adware/SaveNow No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049106.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049107.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049111.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049112.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049113.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049114.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049115.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049116.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049118.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049119.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049120.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049121.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049122.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049123.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049124.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049125.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049126.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049127.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049128.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049130.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049131.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049132.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049133.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049134.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049135.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049136.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049138.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049139.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049140.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049141.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049143.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049144.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049145.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049146.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049147.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049148.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049150.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049151.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049154.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049156.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049157.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049158.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049159.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049160.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049161.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049162.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049163.exe
Adware:Adware/SaveNow No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049164.dll
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049165.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049166.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049167.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049168.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049169.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049179.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049180.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049181.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049183.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049184.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049185.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049186.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049187.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049189.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049190.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049193.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049194.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049195.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049196.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049197.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049198.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049199.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049200.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049201.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049202.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049203.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049204.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049205.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049206.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049207.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049209.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049211.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049212.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049213.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049214.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049215.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049216.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049217.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049218.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049219.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049220.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049223.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049224.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049225.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049226.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049227.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049228.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049229.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049230.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049233.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049234.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049235.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049236.exe
Virus:Trj/Agent.ALD Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049238.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049239.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049240.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049241.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049243.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049244.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049245.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049246.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049247.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049249.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049250.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049251.exe
Adware:Adware/eZula No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049252.exe
Adware:Adware/SearchAid No disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049253.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049254.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049255.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049256.exe
Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049257.exe

#13 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:36 PM

Rats. So do I need to do the whole thing again, or just run the 2 programs?

#14 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:37 PM

Ok. Will do.

#15 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 08:38 PM

Can you do me a favor please

In the Panda log, can you remove any references of bad files in your System Volume Information folders
They look like this as an example

Virus:Trj/Downloader.EIY Disinfected C:\System Volume Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049064.exe

But post back the Panda report with everything else included, or was that the WHOLE report?

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#16 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:50 PM

Here is the Panda log w/o the sys volume info. Now I am going to run Shredder & About Buster in safe mode. I'll be back in a bit.


Status Location

Adware:adware/tvmedia No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\tvmcwrd.dll
Spyware:spyware/whazit No disinfected C:\WINDOWS\SYSTEM32\fiz1
Adware:adware/navipromo No disinfected C:\WINDOWS\SYSTEM32\sdkdp32.exe
Adware:adware/portalscan No disinfected C:\WINDOWS\SYSTEM32\DRIVERS\csrss.exe
Adware:adware/ipinsight No disinfected C:\WINDOWS\INF\alchem.inf
Adware:adware/spywad No disinfected C:\WINDOWS\popup.html
Adware:adware/sidesearch No disinfected C:\DOCUMENTS AND SETTINGS\OWNER\APPLICATION DATA\Lycos
Adware:adware/ncase No disinfected C:\WINDOWS\SYSTEM32\FLEOK
Adware:adware/wintools No disinfected Windows Registry
Adware:Adware/KeenValue No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq15D.tmp\remove.exe
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab
Adware:Adware/MyWay No disinfected C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\Quarantine\Quarantine\ppq16D.tmp\mysearch.cab[mySetp.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[a.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\a.jar-7bb6a5c5-1b79ee9b.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2a79b1dc-4864bd19.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-4e66bbdf-62b618be.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-6a66635c-7d6532a4.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-7106e536-674b7a91.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-771ffd62-53cc9b3e.zip[Dummy.class]
Information\_restore{BC9F3C70-F33F-48FB-93C7-198E1A9B1607}\RP315\A0049168.exe

Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Abi.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Amu.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Bft.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Dsg.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Fbc.html
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\alchem.inf
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Kkt.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Laa.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Mmm.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Nng.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\popup.html
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Rod.html
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\aeglbaopdibq.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\bjicnldhdnbn.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\bnfgcldgpcme.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ciknhlklinjp.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\daiaqdpaojnj.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\eaelgqiigamd.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ejblejooeifi.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\gfnogidnocgh.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ifpcqflglkdo.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ijhggeffnkbe.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\inkffokdphle.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\kacoaifepdcj.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\kanhmcqkknok.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\lfalicfdkmpd.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\lfohbpoiehqq.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\lhcpkfmcgjka.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\mlfpplgqiodp.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ojjnpofbmkho.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\ondbappdcqmg.exe
Virus:Trj/Horst.D Disinfected C:\WINDOWS\services\svchost.exe
Possible Virus. No disinfected C:\WINDOWS\services.exe
Possible Virus. No disinfected C:\WINDOWS\system32\drivers\csrss.exe
Possible Virus. No disinfected C:\WINDOWS\system32\inetsrv\services.exe
Spyware:Spyware/Omi No disinfected C:\WINDOWS\system32\msfdje.gif
Virus:Trj/Pidspro.A Disinfected C:\WINDOWS\system32\ntmain.dll
Virus:Trj/Dropper.DV Disinfected C:\WINDOWS\system32\open32_uninstall.exe
Possible Virus. No disinfected C:\WINDOWS\system32\pifn.dll
Possible Virus. No disinfected C:\WINDOWS\system32\wbem\svchost.exe
Spyware:Spyware/Slimield No disinfected C:\WINDOWS\Tip.html

#17 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 08:54 PM

How do I uninstall About:Buster & CWShredder? I can't seem to find an uninstall for them either in the control panel or in the programs.

#18 guestolo

guestolo

    Site Donator

  • Admin
  • PipPipPipPipPipPipPip
  • 16,247 posts

Posted 05 September 2005 - 08:58 PM

Both old versions of CWShredder and About Buster can be manually deleted
If you find it difficult to delete right now, don't worry about it
Just carry on
But use the newer versions of each

Do you want to post your own logs from FRST?
Follow the instructions posted Click Here


#19 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 09:16 PM

Okay! Thanks!

#20 tektok3

tektok3

    Journeyman

  • Members
  • PipPip
  • 36 posts

Posted 05 September 2005 - 09:45 PM

My Ewidos log is REALLY long. How should I paste it in?

Here is my About:Buster Log:


AboutBuster 5.0 reference file 31
Scan started on [9/5/2005] at [10:21:58 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\A5W.INI:oxglnn
Removed Stream! C:\WINDOWS\A5W.INI:preodj
Removed Stream! C:\WINDOWS\abamo.log:risjjc
Removed Stream! C:\WINDOWS\amkrd.log:rqzkji
Removed Stream! C:\WINDOWS\arwal.dat:wwnyld
Removed Stream! C:\WINDOWS\aurl.dat:gwuaak
Removed Stream! C:\WINDOWS\aurl.dat:liesav
Removed Stream! C:\WINDOWS\bbckl.txt:jibzum
Removed Stream! C:\WINDOWS\bjwrm.log:lgniou
Removed Stream! C:\WINDOWS\bjwrm.log:umnejb
Removed Stream! C:\WINDOWS\Blue Lace 16.bmp:qaqzow
Removed Stream! C:\WINDOWS\bootstat.dat:nshoeq
Removed Stream! C:\WINDOWS\bqvop.log:mnfrdl
Removed Stream! C:\WINDOWS\brpgf.txt:fsauga
Removed Stream! C:\WINDOWS\btojm.txt:ecckrj
Removed Stream! C:\WINDOWS\cgjag.txt:lxlzlb
Removed Stream! C:\WINDOWS\clock.avi:fbbrhd
Removed Stream! C:\WINDOWS\Coffee Bean.bmp:stmgcl
Removed Stream! C:\WINDOWS\comsetup.log:ztuive
Removed Stream! C:\WINDOWS\control.ini:kufteo
Removed Stream! C:\WINDOWS\cswwe.dat:batldo
Removed Stream! C:\WINDOWS\ctybv.txt:dmqyyy
Removed Stream! C:\WINDOWS\dahotfix.log:bfgoyj
Removed Stream! C:\WINDOWS\dellstat.ini:pleklb
Removed Stream! C:\WINDOWS\desktop.ini:tbdyxq
Removed Stream! C:\WINDOWS\DHCPUPG.LOG:szexqi
Removed Stream! C:\WINDOWS\DHCPUPG.LOG:ufztst
Removed Stream! C:\WINDOWS\DirectX.log:uwgytl
Removed Stream! C:\WINDOWS\DjVuDoc.ico:hlxqnl
Removed Stream! C:\WINDOWS\DjVuDoc.ico:mcweza
Removed Stream! C:\WINDOWS\dlmxz.txt:qoxwwt
Removed Stream! C:\WINDOWS\dlzpq.log:kawcks
Removed Stream! C:\WINDOWS\dmwwz.dat:apankh
Removed Stream! C:\WINDOWS\dokml.log:euojtl
Removed Stream! C:\WINDOWS\dphja.log:ewanht
Removed Stream! C:\WINDOWS\dphja.log:flyrvt
Removed Stream! C:\WINDOWS\DPINST.LOG:hwlzft
Removed Stream! C:\WINDOWS\DPINST.LOG:ydiqaz
Removed Stream! C:\WINDOWS\DtcInstall.log:bpahtg
Removed Stream! C:\WINDOWS\ehjjp.log:koexlk
Removed Stream! C:\WINDOWS\ehjjp.log:sqosbg
Removed Stream! C:\WINDOWS\emepi.dat:irwlxq
Removed Stream! C:\WINDOWS\eqdsr.txt:uqiihx
Removed Stream! C:\WINDOWS\eReg.dat:pmgwfg
Removed Stream! C:\WINDOWS\EReg072.dat:khqcck
Removed Stream! C:\WINDOWS\EReg072.dat:rgwuaq
Removed Stream! C:\WINDOWS\explorer.scf:kpzgbd
Removed Stream! C:\WINDOWS\exzpx.dat:knyvqf
Removed Stream! C:\WINDOWS\FeatherTexture.bmp:dnialq
Removed Stream! C:\WINDOWS\friwu.log:vvfruh
Removed Stream! C:\WINDOWS\fsmal.txt:mvznfn
Removed Stream! C:\WINDOWS\fsmal.txt:tpokai
Removed Stream! C:\WINDOWS\fwoxj.dat:nwpxwr
Removed Stream! C:\WINDOWS\fwshu.dat:nwpxwr
Removed Stream! C:\WINDOWS\gaevg.txt:wklxrz
Removed Stream! C:\WINDOWS\ggeju.txt:gxikqc
Removed Stream! C:\WINDOWS\gkefn.dat:svoomm
Removed Stream! C:\WINDOWS\gqkoo.log:fvrthp
Removed Stream! C:\WINDOWS\Greenstone.bmp:kvybow
Removed Stream! C:\WINDOWS\hamfj.log:mapryz
Removed Stream! C:\WINDOWS\hdaqz.log:bkzvxn
Removed Stream! C:\WINDOWS\HPHins01.dat:tljjry
Removed Stream! C:\WINDOWS\hphmdl01.dat:qgxmec
Removed Stream! C:\WINDOWS\hphmdl01.dat:yxgpxi
Removed Stream! C:\WINDOWS\hqtqa.txt:jzqsym
Removed Stream! C:\WINDOWS\idcub.dat:iyzcrt
Removed Stream! C:\WINDOWS\iis6.log:baafso
Removed Stream! C:\WINDOWS\iis6.log:bzritd
Removed Stream! C:\WINDOWS\ilhsd.log:qpyiub
Removed Stream! C:\WINDOWS\imsins.log:mgvxtq
Removed Stream! C:\WINDOWS\iobon.txt:iqjnod
Removed Stream! C:\WINDOWS\ixlgm.txt:uubwjr
Removed Stream! C:\WINDOWS\jbgws.dat:mvlbdt
Removed Stream! C:\WINDOWS\jdibe.log:xwdvxp
Removed Stream! C:\WINDOWS\jdnmb.log:adqifa
Removed Stream! C:\WINDOWS\jdnmb.log:qkzrkm
Removed Stream! C:\WINDOWS\jdwjm.txt:cfjitq
Removed Stream! C:\WINDOWS\jjots.txt:avfqah
Removed Stream! C:\WINDOWS\jptwv.log:vfrxeq
Removed Stream! C:\WINDOWS\KB821557.log:fhocvt
Removed Stream! C:\WINDOWS\KB821557.log:ilswfx
Removed Stream! C:\WINDOWS\KB823182.log:qofdzi
Removed Stream! C:\WINDOWS\KB823559.log:hjbbud
Removed Stream! C:\WINDOWS\KB824105.log:lwqbxu
Removed Stream! C:\WINDOWS\KB824141.log:lkmfqq
Removed Stream! C:\WINDOWS\KB824146.log:lwtacn
Removed Stream! C:\WINDOWS\KB828035.log:edjmnk
Removed Stream! C:\WINDOWS\KB828741.log:qstsyx
Removed Stream! C:\WINDOWS\KB835732.log:dmtvto
Removed Stream! C:\WINDOWS\KB839643-DirectX9Uninst.log:gmivpn
Removed Stream! C:\WINDOWS\KB840374.log:aiikdq
Removed Stream! C:\WINDOWS\KB840374.log:auylpp
Removed Stream! C:\WINDOWS\kkrsw.dat:pprnzh
Removed Stream! C:\WINDOWS\kxqym.txt:pqaafr
Removed Stream! C:\WINDOWS\kxvxe.txt:idlbmm
Removed Stream! C:\WINDOWS\kxvxe.txt:lkldzd
Removed Stream! C:\WINDOWS\kxvxe.txt:twsfov
Removed Stream! C:\WINDOWS\log.bak.txt:xhokjz
Removed Stream! C:\WINDOWS\log.bak.txt:zjnhtl
Removed Stream! C:\WINDOWS\log0.txt:teouiz
Removed Stream! C:\WINDOWS\log0.txt:uulfmz
Removed Stream! C:\WINDOWS\log0.txt:viyico
Removed Stream! C:\WINDOWS\log1.txt:cmzvfg
Removed Stream! C:\WINDOWS\log2.txt:cehkjt
Removed Stream! C:\WINDOWS\log3.txt:jylibv
Removed Stream! C:\WINDOWS\log4.txt:oxqojm
Removed Stream! C:\WINDOWS\LUINSTALL.LOG:angedk
Removed Stream! C:\WINDOWS\marker_2.bin:iarvfm
Removed Stream! C:\WINDOWS\marker_2.bin:jlrzpy
Removed Stream! C:\WINDOWS\mcrtu.txt:gxjtdo
Removed Stream! C:\WINDOWS\mhrxy.log:hqbfdq
Removed Stream! C:\WINDOWS\msdfmap.ini:gwfmyd
Removed Stream! C:\WINDOWS\msgsocm.log:ziivwv
Removed Stream! C:\WINDOWS\msoffice.ini:kjkifs
Removed Stream! C:\WINDOWS\mtgzn.dat:awlxsb
Removed Stream! C:\WINDOWS\mtgzn.dat:cvabfz
Removed Stream! C:\WINDOWS\mwhyc.txt:hwtsqy
Removed Stream! C:\WINDOWS\mWinXp.txt:bqdqeb
Removed Stream! C:\WINDOWS\mWinXp.txt:pegkya
Removed Stream! C:\WINDOWS\mWinXpD.txt:ntdoqz
Removed Stream! C:\WINDOWS\mWinXpD2.txt:ovaieg
Removed Stream! C:\WINDOWS\mwokv.txt:nodmbu
Removed Stream! C:\WINDOWS\mxcog.dat:vgjwzr
Removed Stream! C:\WINDOWS\nero.INI:cwhhct
Removed Stream! C:\WINDOWS\netdet.ini:oarcem
Removed Stream! C:\WINDOWS\netdet.ini:xfdiok
Removed Stream! C:\WINDOWS\nfgiq.log:mkhbao
Removed Stream! C:\WINDOWS\nfgiq.log:swmmtq
Removed Stream! C:\WINDOWS\nfkqs.dat:jclinm
Removed Stream! C:\WINDOWS\nggtu.log:pymnno
Removed Stream! C:\WINDOWS\nikid.log:zcuubh
Removed Stream! C:\WINDOWS\Nng.html:iolbil
Removed Stream! C:\WINDOWS\nsreg.dat:hzfaqz
Removed Stream! C:\WINDOWS\nszxj.txt:idpeyv
Removed Stream! C:\WINDOWS\ntbtlog.txt:cvenpx
Removed Stream! C:\WINDOWS\ntdtcsetup.log:zkjpsw
Removed Stream! C:\WINDOWS\ntemq.txt:sqeklb
Removed Stream! C:\WINDOWS\nzrvf.dat:krafnh
Removed Stream! C:\WINDOWS\ocgen.log:lirlgk
Removed Stream! C:\WINDOWS\ocmsn.log:bwdntp
Removed Stream! C:\WINDOWS\ODBC.INI:gsqjsm
Removed Stream! C:\WINDOWS\ODBC.INI:oiurur
Removed Stream! C:\WINDOWS\ODBCINST.INI:djkqau
Removed Stream! C:\WINDOWS\odmiq.dat:moyhhx
Removed Stream! C:\WINDOWS\OEWABLog.txt:cayflz
Removed Stream! C:\WINDOWS\OEWABLog.txt:culmdp
Removed Stream! C:\WINDOWS\OEWABLog.txt:zxynag
Removed Stream! C:\WINDOWS\oewbn.txt:vjhyaq
Removed Stream! C:\WINDOWS\oewbn.txt:ytipvx
Removed Stream! C:\WINDOWS\opsvu.txt:ubqknk
Removed Stream! C:\WINDOWS\orun32.ini:gkadct
Removed Stream! C:\WINDOWS\orun32.ini:sqjsuq
Removed Stream! C:\WINDOWS\orun32.ini:zjxjqe
Removed Stream! C:\WINDOWS\orun32.isu:fmpywa
Removed Stream! C:\WINDOWS\oskns.log:ihcgoh
Removed Stream! C:\WINDOWS\ouiua.dat:cxzorf
Removed Stream! C:\WINDOWS\ovqlb.txt:lszwfs
Removed Stream! C:\WINDOWS\patch.log:gkzqss
Removed Stream! C:\WINDOWS\pdcjd.txt:wtcobf
Removed Stream! C:\WINDOWS\pfbur.log:ardbfm
Removed Stream! C:\WINDOWS\pfbur.log:ydrvuc
Removed Stream! C:\WINDOWS\pjtgf.txt:gxfyhl
Removed Stream! C:\WINDOWS\PlusDMESetup.log:gqmoem
Removed Stream! C:\WINDOWS\PlusDMESetup.log:ssnozw
Removed Stream! C:\WINDOWS\PlusDMESetup.log:zzspbt
Removed Stream! C:\WINDOWS\pnwvc.log:ehazre
Removed Stream! C:\WINDOWS\poqpf.dat:baulik
Removed Stream! C:\WINDOWS\poqpf.dat:zypdjw
Removed Stream! C:\WINDOWS\PowerReg.dat:zblngr
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:btrgwm
Removed Stream! C:\WINDOWS\pvcwd.dat:fvohhd
Removed Stream! C:\WINDOWS\pvcwd.dat:rzijdg
Removed Stream! C:\WINDOWS\pwzpd.log:nzdbos
Removed Stream! C:\WINDOWS\Q323255.log:qxrolq
Removed Stream! C:\WINDOWS\Q323255.log:tafydu
Removed Stream! C:\WINDOWS\Q323255.log:tuklyx
Removed Stream! C:\WINDOWS\Q327979.log:effugc
Removed Stream! C:\WINDOWS\Q328310.log:gaogju
Removed Stream! C:\WINDOWS\Q329048.log:bxvlmn
Removed Stream! C:\WINDOWS\Q329048.log:dbicuw
Removed Stream! C:\WINDOWS\Q329048.log:jyktna
Removed Stream! C:\WINDOWS\Q329048.log:znacvu
Removed Stream! C:\WINDOWS\Q329112.log:kaviqo
Removed Stream! C:\WINDOWS\Q329115.log:yagllf
Removed Stream! C:\WINDOWS\Q329170.log:uyoqoy
Removed Stream! C:\WINDOWS\q329256.log:hgcadp
Removed Stream! C:\WINDOWS\Q329390.log:evmaew
Removed Stream! C:\WINDOWS\Q329834.log:mygwia
Removed Stream! C:\WINDOWS\Q329909.log:aoebki
Removed Stream! C:\WINDOWS\Q329909.log:jrwkde
Removed Stream! C:\WINDOWS\Q331958.log:uvgvje
Removed Stream! C:\WINDOWS\Q331958.log:zxnoqh
Removed Stream! C:\WINDOWS\Q810565.log:dfodwy
Removed Stream! C:\WINDOWS\Q810577.log:kppges
Removed Stream! C:\WINDOWS\Q811493.log:jbpprk
Removed Stream! C:\WINDOWS\Q811630.log:sprljf
Removed Stream! C:\WINDOWS\Q811630.log:zftojb
Removed Stream! C:\WINDOWS\Q811789.log:xuvtqr
Removed Stream! C:\WINDOWS\Q814033.log:bbzulm
Removed Stream! C:\WINDOWS\Q814995.log:kqkqdq
Removed Stream! C:\WINDOWS\Q814995.log:oyzwsk
Removed Stream! C:\WINDOWS\Q814995.log:qfodyo
Removed Stream! C:\WINDOWS\Q815021.log:cnvzaz
Removed Stream! C:\WINDOWS\Q815021Uninst.log:gybsjp
Removed Stream! C:\WINDOWS\Q815021Uninst.log:punylc
Removed Stream! C:\WINDOWS\Q815485.log:druvgs
Removed Stream! C:\WINDOWS\Q815485.log:wjfwyl
Removed Stream! C:\WINDOWS\Q817287.log:hcwkum
Removed Stream! C:\WINDOWS\Q817606.log:ivglne
Removed Stream! C:\WINDOWS\Q828026.log:qafvpl
Removed Stream! C:\WINDOWS\qdvmn.log:aorqho
Removed Stream! C:\WINDOWS\qeuei.dat:ramdgc
Removed Stream! C:\WINDOWS\qtxlh.dat:pycrnz
Removed Stream! C:\WINDOWS\QUICKEN.INI:cynehf
Removed Stream! C:\WINDOWS\QuickInstall.INI:fkaimw
Removed Stream! C:\WINDOWS\QuickInstall.INI:xrxydm
Removed Stream! C:\WINDOWS\qujju.dat:izvxpc
Removed Stream! C:\WINDOWS\qyuwr.log:dvbmfk
Removed Stream! C:\WINDOWS\rbqwa.txt:xlkogy
Removed Stream! C:\WINDOWS\REGLOCS.OLD:mbdqbk
Removed Stream! C:\WINDOWS\regopt.log:qgjkcp
Removed Stream! C:\WINDOWS\rfvzi.log:wdcfhg
Removed Stream! C:\WINDOWS\Rhododendron.bmp:bgcpwa
Removed Stream! C:\WINDOWS\Rhododendron.bmp:nrypez
Removed Stream! C:\WINDOWS\rjglm.log:bmchnk
Removed Stream! C:\WINDOWS\rjglm.log:qqfsnx
Removed Stream! C:\WINDOWS\rjygy.txt:ivamsx
Removed Stream! C:\WINDOWS\roait.dat:bwsrna
Removed Stream! C:\WINDOWS\rsrdk.dat:ajnjxv
Removed Stream! C:\WINDOWS\rsrdk.dat:peulbq
Removed Stream! C:\WINDOWS\ruagb.dat:gojeko
Removed Stream! C:\WINDOWS\Run32A50.mch:pfprwe
Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:fugyxb
Removed Stream! C:\WINDOWS\sb_affiliate.ini:bxkmgt
Removed Stream! C:\WINDOWS\SchedLgU.Txt:hefyeb
Removed Stream! C:\WINDOWS\Screen2.scr:lkycti
Removed Stream! C:\WINDOWS\Screen2.scr:xvydrl
Removed Stream! C:\WINDOWS\setupact.log:etpdic
Removed Stream! C:\WINDOWS\setupapi.log:peurxx
Removed Stream! C:\WINDOWS\setuperr.log:txbcoi
Removed Stream! C:\WINDOWS\setuplog.txt:rtznke
Removed Stream! C:\WINDOWS\slmll.log:wmjklh
Removed Stream! C:\WINDOWS\smscfg.ini:axnwaa
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:kbyjjj
Removed Stream! C:\WINDOWS\Spyware Begone Setup Log.txt:ofbqnj
Removed Stream! C:\WINDOWS\sqmfe.log:nkdary
Removed Stream! C:\WINDOWS\sxcvb.txt:pifniy
Removed Stream! C:\WINDOWS\sys32_app.dat:bcpxhz
Removed Stream! C:\WINDOWS\sys32_app.dat:oydgrv
Removed Stream! C:\WINDOWS\system.ini:bmlpxa
Removed Stream! C:\WINDOWS\system.ini:gnwsha
Removed Stream! C:\WINDOWS\tcfkh.log:cqyxwb
Removed Stream! C:\WINDOWS\teewo.txt:ajqyfl
Removed Stream! C:\WINDOWS\teony.dat:gzvttg
Removed Stream! C:\WINDOWS\tmdmi.txt:mrjqso
Removed Stream! C:\WINDOWS\tmsok.dat:idelul
Removed Stream! C:\WINDOWS\tsoc.log:sexrwv
Removed Stream! C:\WINDOWS\uencv.dat:twpthq
Removed Stream! C:\WINDOWS\ukksy.dat:zqecil
Removed Stream! C:\WINDOWS\ulhkp.log:qkembf
Removed Stream! C:\WINDOWS\unnns.dat:ewpoua
Removed Stream! C:\WINDOWS\UPGRADE.TXT:dvvmbf
Removed Stream! C:\WINDOWS\uypll.txt:aamlkk
Removed Stream! C:\WINDOWS\uypll.txt:owhtwk
Removed Stream! C:\WINDOWS\uysao.txt:vsaazi
Removed Stream! C:\WINDOWS\uzxrl.log:ovijcz
Removed Stream! C:\WINDOWS\vb.ini:sbwreu
Removed Stream! C:\WINDOWS\vbaddin.ini:khfvfe
Removed Stream! C:\WINDOWS\vcgsm.log:mifrbq
Removed Stream! C:\WINDOWS\vdjcf.txt:fhygjq
Removed Stream! C:\WINDOWS\viassary-hp.reg:thqnbs
Removed Stream! C:\WINDOWS\vmuninst.log:tcguwo
Removed Stream! C:\WINDOWS\vmuninst.log:zptuqu
Removed Stream! C:\WINDOWS\wbgxy.txt:sqdzse
Removed Stream! C:\WINDOWS\wiaservc.log:jyesty
Removed Stream! C:\WINDOWS\Windows Update.log:viaybd
Removed Stream! C:\WINDOWS\WindowsUpdate.log:hvrfqo
Removed Stream! C:\WINDOWS\WindowsUpdate.log:xvxhsd
Removed Stream! C:\WINDOWS\wininit.ini:sakdsk
Removed Stream! C:\WINDOWS\winnt.bmp:aglnlx
Removed Stream! C:\WINDOWS\winnt256.bmp:eqthyn
Removed Stream! C:\WINDOWS\WINNT32.LOG:jzcdop
Removed Stream! C:\WINDOWS\WINNT32.LOG:yazmtr
Removed Stream! C:\WINDOWS\wjfwy.log:betouu
Removed Stream! C:\WINDOWS\wjfwy.log:npqvkc
Removed Stream! C:\WINDOWS\wmsetup.log:ylufcm
Removed Stream! C:\WINDOWS\wmsetup10.log:ixirpy
Removed Stream! C:\WINDOWS\wmsetup10.log:otmirp
Removed Stream! C:\WINDOWS\WMSysPrx.prx:qcidxh
Removed Stream! C:\WINDOWS\WMSysPrx.prx:qmfsew
Removed Stream! C:\WINDOWS\wnpod.dat:jckwqe
Removed Stream! C:\WINDOWS\wntlq.txt:dxppzw
Removed Stream! C:\WINDOWS\wntlq.txt:gufnts
Removed Stream! C:\WINDOWS\wsdu.log:aimuzn
Removed Stream! C:\WINDOWS\wsdu.log:wyautg
Removed Stream! C:\WINDOWS\wzklj.txt:oyszvj
Removed Stream! C:\WINDOWS\xkhgh.dat:zbjeft
Removed Stream! C:\WINDOWS\xpsp1hfm.log:oxdtyf
Removed Stream! C:\WINDOWS\yacs.log:obgnzj
Removed Stream! C:\WINDOWS\ybfii.log:jzpenm
Removed Stream! C:\WINDOWS\ybfii.log:lkpfva
Removed Stream! C:\WINDOWS\ybipy.dat:yypmva
Removed Stream! C:\WINDOWS\yebzn.txt:yylmrz
Removed Stream! C:\WINDOWS\ygxds.dat:gbzstt
Removed Stream! C:\WINDOWS\ygxds.dat:rzzrpc
Removed Stream! C:\WINDOWS\ynrdp.txt:vmlwmx
Removed Stream! C:\WINDOWS\zfqbr.log:nmekoh
Removed Stream! C:\WINDOWS\zigai.txt:hpuvxq
Removed Stream! C:\WINDOWS\zlipv.log:izydjs
Removed Stream! C:\WINDOWS\zurxv.dat:zifart
Removed Stream! C:\WINDOWS\_default.pif:atizhu
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:aetiuq
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:alqjgu
------------------------------------------------
Removed File! : C:\Windows\arskm.dat
Removed File! : C:\Windows\arwal.dat
Removed File! : C:\Windows\cldoh.dat
Removed File! : C:\Windows\cswwe.dat
Removed File! : C:\Windows\fdgrf.dat
Removed File! : C:\Windows\fwshu.dat
Removed File! : C:\Windows\fyjpq.dat
Removed File! : C:\Windows\gxikq.dat
Removed File! : C:\Windows\hezqs.dat
Removed File! : C:\Windows\igkqu.dat
Removed File! : C:\Windows\ksmfj.dat
Removed File! : C:\Windows\lkojo.dat
Removed File! : C:\Windows\mbdqb.dat
Removed File! : C:\Windows\mxcog.dat
Removed File! : C:\Windows\nnlaq.dat
Removed File! : C:\Windows\qovwl.dat
Removed File! : C:\Windows\qujju.dat
Removed File! : C:\Windows\rmymz.dat
Removed File! : C:\Windows\roait.dat
Removed File! : C:\Windows\ruagb.dat
Removed File! : C:\Windows\tmsok.dat
Removed File! : C:\Windows\ttsko.dat
Removed File! : C:\Windows\unnns.dat
Removed File! : C:\Windows\vazfb.dat
Removed File! : C:\Windows\vqomg.dat
Removed File! : C:\Windows\wbdbh.dat
Removed File! : C:\Windows\wnpod.dat
Removed File! : C:\Windows\xkhgh.dat
Removed File! : C:\Windows\ybipy.dat
Removed File! : C:\Windows\System32\asjbl.dat
Removed File! : C:\Windows\System32\bikbd.dat
Removed File! : C:\Windows\System32\bmkkh.dat
Removed File! : C:\Windows\System32\byrjo.dat
Removed File! : C:\Windows\System32\ceqme.dat
Removed File! : C:\Windows\System32\dbons.dat
Removed File! : C:\Windows\System32\ddjlz.dat
Removed File! : C:\Windows\System32\dimkl.dat
Removed File! : C:\Windows\System32\dkvgf.dat
Removed File! : C:\Windows\System32\dooqp.dat
Removed File! : C:\Windows\System32\eakwn.dat
Removed File! : C:\Windows\System32\eqast.dat
Removed File! : C:\Windows\System32\flmau.dat
Removed File! : C:\Windows\System32\hnjgb.dat
Removed File! : C:\Windows\System32\ilrmj.dat
Removed File! : C:\Windows\System32\iwyex.dat
Removed File! : C:\Windows\System32\jhhav.dat
Removed File! : C:\Windows\System32\jracz.dat
Removed File! : C:\Windows\System32\kkkjn.dat
Removed File! : C:\Windows\System32\kobfz.dat
Removed File! : C:\Windows\System32\ludkg.dat
Removed File! : C:\Windows\System32\lzdeb.dat
Removed File! : C:\Windows\System32\mabyc.dat
Removed File! : C:\Windows\System32\mrxia.dat
Removed File! : C:\Windows\System32\ovnxo.dat
Removed File! : C:\Windows\System32\pbtxi.dat
Removed File! : C:\Windows\System32\pwigz.dat
Removed File! : C:\Windows\System32\qumpy.dat
Removed File! : C:\Windows\System32\rnisx.dat
Removed File! : C:\Windows\System32\snclv.dat
Removed File! : C:\Windows\System32\tlhkf.dat
Removed File! : C:\Windows\System32\twpth.dat
Removed File! : C:\Windows\System32\txtnj.dat
Removed File! : C:\Windows\System32\vjitv.dat
Removed File! : C:\Windows\System32\vksxk.dat
Removed File! : C:\Windows\System32\wdkeb.dat
Removed File! : C:\Windows\System32\wlgng.dat
Removed File! : C:\Windows\System32\wyyss.dat
Removed File! : C:\Windows\System32\xdgut.dat
Removed File! : C:\Windows\System32\xovtf.dat
Removed File! : C:\Windows\System32\xswhd.dat
Removed File! : C:\Windows\System32\xuxbt.dat
Removed File! : C:\Windows\System32\ygtmu.dat
Removed File! : C:\Windows\System32\yzdzh.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 10:23:04 PM


AboutBuster 5.0 reference file 31
Scan started on [9/5/2005] at [10:23:33 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\aurl.dat:ovcvgi
Removed Stream! C:\WINDOWS\bbckl.txt:ohnfqf
Removed Stream! C:\WINDOWS\bjwrm.log:urxjkn
Removed Stream! C:\WINDOWS\bqvop.log:urbjbw
Removed Stream! C:\WINDOWS\bqvop.log:zwngcu
Removed Stream! C:\WINDOWS\clock.avi:xrmdsr
Removed Stream! C:\WINDOWS\dahotfix.log:cvvszb
Removed Stream! C:\WINDOWS\dmwwz.dat:ioibzv
Removed Stream! C:\WINDOWS\eReg.dat:ymiwxv
Removed Stream! C:\WINDOWS\ggeju.txt:pwrkin
Removed Stream! C:\WINDOWS\iis6.log:yogusq
Removed Stream! C:\WINDOWS\jdwjm.txt:woeofd
Removed Stream! C:\WINDOWS\KB821557.log:tvywcr
Removed Stream! C:\WINDOWS\KB824105.log:mkzhkz
Removed Stream! C:\WINDOWS\KB824141.log:qdxtsq
Removed Stream! C:\WINDOWS\KB824141.log:voxurc
Removed Stream! C:\WINDOWS\KB828035.log:iepznb
Removed Stream! C:\WINDOWS\KB828035.log:kljqrl
Removed Stream! C:\WINDOWS\KB835732.log:ennudu
Removed Stream! C:\WINDOWS\KB835732.log:huggvn
Removed Stream! C:\WINDOWS\KB835732.log:olpqnd
Removed Stream! C:\WINDOWS\KB839643-DirectX9Uninst.log:vmminy
Removed Stream! C:\WINDOWS\log2.txt:jqcwsw
Removed Stream! C:\WINDOWS\log3.txt:mvesgb
Removed Stream! C:\WINDOWS\log3.txt:njrner
Removed Stream! C:\WINDOWS\log4.txt:unsazi
Removed Stream! C:\WINDOWS\marker_2.bin:xbbhxo
Removed Stream! C:\WINDOWS\mhrxy.log:izbzjw
Removed Stream! C:\WINDOWS\mtgzn.dat:zwyrao
Removed Stream! C:\WINDOWS\mWinXp.txt:qbkwgb
Removed Stream! C:\WINDOWS\mWinXpD.txt:sxwknl
Removed Stream! C:\WINDOWS\nero.INI:heqpak
Removed Stream! C:\WINDOWS\netdet.ini:xtmmkd
Removed Stream! C:\WINDOWS\nsreg.dat:lxerna
Removed Stream! C:\WINDOWS\nsreg.dat:vdvtbf
Removed Stream! C:\WINDOWS\nszxj.txt:msjbth
Removed Stream! C:\WINDOWS\ntemq.txt:sriztf
Removed Stream! C:\WINDOWS\nzrvf.dat:osjkhx
Removed Stream! C:\WINDOWS\nzrvf.dat:ygxbhj
Removed Stream! C:\WINDOWS\ocgen.log:tngbfm
Removed Stream! C:\WINDOWS\ocmsn.log:dixtgg
Removed Stream! C:\WINDOWS\ocmsn.log:jzfarx
Removed Stream! C:\WINDOWS\ocmsn.log:olkzmr
Removed Stream! C:\WINDOWS\ODBC.INI:ovcrse
Removed Stream! C:\WINDOWS\orun32.isu:vqtjcc
Removed Stream! C:\WINDOWS\orun32.isu:wkuwdf
Removed Stream! C:\WINDOWS\patch.log:iqkvdk
Removed Stream! C:\WINDOWS\patch.log:krbxws
Removed Stream! C:\WINDOWS\patch.log:wcanre
Removed Stream! C:\WINDOWS\Prairie Wind.bmp:mvwuns
Removed Stream! C:\WINDOWS\Q327979.log:rcwsac
Removed Stream! C:\WINDOWS\Q328310.log:iyaasu
Removed Stream! C:\WINDOWS\Q329112.log:mvtvcu
Removed Stream! C:\WINDOWS\q329256.log:rydfbc
Removed Stream! C:\WINDOWS\Q329390.log:hnmnhx
Removed Stream! C:\WINDOWS\Q329390.log:qbzzfp
Removed Stream! C:\WINDOWS\Q811493.log:nwzadg
Removed Stream! C:\WINDOWS\Q811493.log:rygutr
Removed Stream! C:\WINDOWS\Q814033.log:fxrffq
Removed Stream! C:\WINDOWS\Q814995.log:rgetdl
Removed Stream! C:\WINDOWS\Q815021.log:qtauuf
Removed Stream! C:\WINDOWS\Q815485.log:xaninj
Removed Stream! C:\WINDOWS\Q817287.log:uooncj
Removed Stream! C:\WINDOWS\Q817606.log:jhwyfw
Removed Stream! C:\WINDOWS\Q817606.log:yztyea
Removed Stream! C:\WINDOWS\QUICKEN.INI:lcyvlt
Removed Stream! C:\WINDOWS\REGLOCS.OLD:qkzwrx
Removed Stream! C:\WINDOWS\REGLOCS.OLD:uygjkp
Removed Stream! C:\WINDOWS\Rhododendron.bmp:tkcoye
Removed Stream! C:\WINDOWS\rsrdk.dat:xnwmut
Removed Stream! C:\WINDOWS\Run32A50.mch:tsekuh
Removed Stream! C:\WINDOWS\Santa Fe Stucco.bmp:wzeplh
Removed Stream! C:\WINDOWS\sb_affiliate.ini:fsjcgc
Removed Stream! C:\WINDOWS\SchedLgU.Txt:lswyos
Removed Stream! C:\WINDOWS\setupapi.log:qwrjlv
Removed Stream! C:\WINDOWS\smscfg.ini:myuhit
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:rsaxbf
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:vjsupv
Removed Stream! C:\WINDOWS\sqmfe.log:syfbuk
Removed Stream! C:\WINDOWS\sys32_app.dat:zobcir
Removed Stream! C:\WINDOWS\system.ini:iixski
Removed Stream! C:\WINDOWS\system.ini:ndzlnp
Removed Stream! C:\WINDOWS\ulhkp.log:xfyvsm
Removed Stream! C:\WINDOWS\UPGRADE.TXT:hpscll
Removed Stream! C:\WINDOWS\uzxrl.log:uhmmzf
Removed Stream! C:\WINDOWS\vdjcf.txt:hoaowk
Removed Stream! C:\WINDOWS\wiaservc.log:mhbsvd
Removed Stream! C:\WINDOWS\Windows Update.log:wcsapk
Removed Stream! C:\WINDOWS\Windows Update.log:zaryyz
Removed Stream! C:\WINDOWS\winnt.bmp:csaway
Removed Stream! C:\WINDOWS\winnt256.bmp:fkczib
Removed Stream! C:\WINDOWS\wmsetup10.log:xrdmsx
Removed Stream! C:\WINDOWS\xpsp1hfm.log:rywzlb
Removed Stream! C:\WINDOWS\xpsp1hfm.log:sccjzv
Removed Stream! C:\WINDOWS\xpsp1hfm.log:tjfaty
Removed Stream! C:\WINDOWS\xpsp1hfm.log:uafnkj
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:cahuww
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:cskqlk
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:ggpqnp
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:gsebqf
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:iojwba
Removed Stream! C:\WINDOWS\{F08B228D-74AF-4061-9A05-3E0C671873D6}.dat:jcidyy
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 10:23:59 PM