Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Devastating attack(HJK Log) [CLOSED]


  • This topic is locked This topic is locked

#1
Jackler

Jackler

    Member

  • Member
  • PipPip
  • 94 posts
This got really bad, really fast. I dont know what the [bleep] happened, as nothing has been recently downloaded, but be it spyware, adware, or a virus, my computer has been taken over. My antivirus programs are encountering "internal errors" as many other programs are, windows explorer is shutting itself down, apperantly the admin has denied access to taskmanager, ect. Its f'in insane. Not to mention this impossible surge of spam and ads. In just writing this, ive closed 21 Internet explorers so far.

Its made the computer near inaccesible. My logs below.

Please help, this is insane...
  • 0

Advertisements


#2
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
Logfile of HijackThis v1.99.1
Scan saved at 5:53:44 PM, on 7/25/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\UGF0cmljayBDb3J6aW5l\command.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\kqjdylh.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\unoucb.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lwfyc.exe
C:\WINDOWS\System32\lwfyc.exe
C:\WINDOWS\System32\lwfyc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\kybrdef_7.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\System32\winlog.exe
C:\WINDOWS\kqjdylhA.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\windows\system32\ondsregl.exe
C:\WINDOWS\cfg32.exe
C:\nwnmef_7.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\ipwins\ipwins.exe
C:\Program Files\Common Files\{C091F94C-0702-1033-0729-020310150001}\Update.exe
C:\Program Files\PSHope\PSHope.exe
C:\Windows\xpupdate.exe
C:\Documents and Settings\Molly\Local Settings\Application Data\0c9b35c1.exe
C:\Program Files\System Files\System.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\mwinopez.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\BraveSentry\BraveSentry.exe
C:\DOCUME~1\Molly\LOCALS~1\Temp\12535\60711.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\BearShare\BearShare.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Documents and Settings\Molly\Desktop\f4f\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalo...asp?si=20065&k=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalo...asp?si=20065&k=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Kristens Sexxy
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\lwfyc.exe
F2 - REG:system.ini: UserInit=userinit.exe,vrldmgh.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [siri] c:\program files\zz\spolv.exe
O4 - HKLM\..\Run: [defender] C:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdef_7.exe
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\System32\mptft.exe
O4 - HKLM\..\Run: [Hhl7RfpJ] "C:\WINDOWS\System32\ssn6tuu.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [uesmcy] C:\WINDOWS\System32\unoucb.exe reg_run
O4 - HKLM\..\Run: [kqjdylhA] C:\WINDOWS\kqjdylhA.exe
O4 - HKLM\..\Run: [cnhe2efd] RUNDLL32.EXE w24be037.dll,n 001e2efc0000000324be037
O4 - HKLM\..\Run: [{1F-F9-94-4C-ZN}] C:\windows\system32\ondsregl.exe CORN003
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmef_7.exe
O4 - HKLM\..\Run: [w0034e02.dll] RUNDLL32.EXE w0034e02.dll,I2 001e2efc00034e02
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\System32\mwinopez.exe CORN003
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\testtestt.exe
O4 - HKLM\..\Run: [0c9b35c1.exe] C:\WINDOWS\System32\0c9b35c1.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\testtestt.exe
O4 - HKLM\..\RunServices: [SystemTools] C:\WINDOWS\System32\testtestt.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [siri] c:\program files\zz\spolv.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [qbynd] C:\WINDOWS\System32\unoucb.exe reg_run
O4 - HKCU\..\Run: [rfwr] C:\PROGRA~1\COMMON~1\rfwr\rfwrm.exe
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [0c9b35c1.exe] C:\Documents and Settings\Molly\Local Settings\Application Data\0c9b35c1.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\mwinopez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: nuavi.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: AltaVista Search - file://C:\Program Files\ALTAVISTA Toolbar\Cache\SelectedContextSearch.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate - file://C:\Program Files\ALTAVISTA Toolbar\Cache\SelectedContextTranslation.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Molly\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: &Gucci Messenger - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Documents and Settings\Molly\Desktop\pppenguin102\Gucci5.5\Gucci5.5\YPager (file missing)
O9 - Extra 'Tools' menuitem: &Gucci Messenger - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Documents and Settings\Molly\Desktop\pppenguin102\Gucci5.5\Gucci5.5\YPager (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} -
O16 - DPF: {4E7BD74F-2B8D-469E-92EA-EC65A294AE31} (AltaVista Toolbar) - http://toolbar.altav...ab?r=1113115026
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1126157728437
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.co...loadControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.co...aploader_v6.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://h20179.www2.h...er/SysQuery.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\anipdlxx.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\g4040edqeh0e0.dll (file missing)
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\kt28l7fu1.dll (file missing)
O21 - SSODL: DCOM Server 2234 - {2C1CD3D7-86AC-4068-93BC-A02304BB2234} - C:\WINDOWS\System32\2234_27.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_27.dll
O21 - SSODL: PcwABIfevU - {C091F94D-6A3B-53E7-23CF-1B2AA9DEFF78} - C:\WINDOWS\System32\fugyu.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi258437.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\UGF0cmljayBDb3J6aW5l\command.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\kqjdylh.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)
  • 0

#3
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
bump
  • 0

#4
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
That's a mess.

1. Update ewido to the latest definition files.
  • On the left hand side of the main screen click update.
  • Then click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.
(the status bar at the bottom will display ("Update successful")
[*]Exit Ewido, do not run the scan yet!
[/list]If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

2. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

4. Once in Safe Mode, Open Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.

5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • In the scriptline to execute field type or paste c:\bfu\alcanshorty.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log.
  • 0

#5
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
bump
  • 0

#6
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Do not bump your topic - follow the instructions that you have been provided with.
  • 0

#7
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
I apologize about the bumps, I made the first one and didnt even notice the header that said not to. The second my gf did while I was at work to try and help me out. I told her she got me in trouble bc of that,lol. Nevertheless, sorry.

Anyhow, not much luck with that..Ewido found and removed 50 infections, alot of which were trogan downloaders, but the Brute Force proggie failed to remove a single thing. I checked a few of the locations that it tried to remove, and the folders are there, but they "say" they're empty, yet they cant be deleted. And, Im still getting alot of ads/popups, and to top that, Windows Explorer keeps encountering problems and has to close. Ugh, pain in the arse..Im leaving this comp in safe mode till I get further instruction,hehe. It took 3 hours for ewido to scan. Anyhow, the post below contains both reports from Ewido and Brute Force. Thank you for taking the time to help me, and once again, sorry for the seemingly rude bump that ignored your sincere post.
  • 0

#8
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:32:54 PM, 7/26/2006
+ Report-Checksum: 4652D097

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{3F143C3A-1457-6CCA-03A7-7AA23B61E40F} -> Spyware.JKSearch : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Euroclick : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Addynamix : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Falkag : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@findwhat[1].txt -> Spyware.Cookie.Findwhat : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Valuead : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Adjuggler : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned without backup
C:\Documents and Settings\Administrator\Cookies\administrator@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temp\qvxt2.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temp\vx2.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temp\vx6.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temp\vxt4.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\6F4EJSPC\AppWrap[1].exe -> Spyware.AdURL : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\AS1GMDPL\AppWrap[1].exe -> Spyware.AdURL : Cleaned without backup
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\AS1GMDPL\AppWrap[2].exe -> Spyware.Zestyfind : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\molly@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\molly@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\molly@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned without backup
C:\Documents and Settings\Molly\Cookies\[email protected][2].txt -> Spyware.Cookie.Adserver : Cleaned without backup
C:\Documents and Settings\Molly\Local Settings\Temp\qvxt2.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Molly\Local Settings\Temp\vx6.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Documents and Settings\Molly\Local Settings\Temp\vxt4.game -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\Installer3.exe -> Spyware.Look2Me : Cleaned without backup
C:\warebundlenewer.exe -> Spyware.Look2Me : Cleaned without backup
C:\WINDOWS\iconu.exe -> Spyware.Zestyfind : Cleaned without backup
C:\WINDOWS\system32\AUNBHO(2).dll -> Spyware.Hijacker.Generic : Cleaned without backup
C:\WINDOWS\system32\AUNBHO(3).dll -> Spyware.Hijacker.Generic : Cleaned without backup
C:\WINDOWS\system32\qvxgamet2.exe -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\WINDOWS\system32\vxgame2.exe -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\WINDOWS\system32\vxgame6.exe -> TrojanDownloader.Small.aqu : Cleaned without backup
C:\WINDOWS\system32\vxgamet4.exe -> TrojanDownloader.Small.aqu : Cleaned without backup


::Report End
  • 0

#9
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
BFU v1.00.9
Windows XP SP1 (WinNT 5.01.2600 SP1)
Script started at 8:40:28 PM, on 7/26/2006

Option Unload Explorer: Yes
Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)
Failed: ServiceStop Network Monitor (operation failed)
Failed: ServiceStop cmdService (operation failed)
Failed: RegDelValue HKCU\System\CurrentControlSet\Control\Lsa|p2pnetwork (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\OLE|p2pnetwork (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\OLE|winlog (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations|LowRiskFileTypes (key not found)
Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|CU1 (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|CU2 (key not found)
Failed: RegDelValue HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices|services32 (key not found)
Option pause between commands: 300 ms
Option pause between commands: 50 ms
Failed: FolderDelete C:\Program Files\MsConfigs (folder not found)
Failed: FolderDelete C:\Program Files\winupdates (folder not found)
Failed: FolderDelete C:\Program Files\winupdate (folder not found)
Failed: FolderDelete C:\Program Files\winsupdater (folder not found)
Failed: FolderDelete C:\Program Files\MsUpdate (folder not found)
Failed: FolderDelete C:\Program Files\MsMovies (folder not found)
Failed: FolderDelete C:\Program Files\wmplayer (folder not found)
Failed: FileDelete C:\Program Files\Common Files\Windows\mc-*-*.exe (operation failed)
Failed: FileDelete C:\Program Files\Common Files\Download\mc-*-*.exe (operation failed)
Failed: FileDelete C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~DFFD89.tmp (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\History (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\Temporary Internet Files (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER469.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER46F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER474.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER479.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER47E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER484.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER489.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER48D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER490.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER494.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER498.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER49E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4A1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4A4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4A7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4AA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4AE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4B9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4BA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4BC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4BE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4BF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4C1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4C3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4C5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4C6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4C9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4CA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4CC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4CE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4D0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4D3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4D5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4D7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4D9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4DC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4DD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4DF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4E2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4E3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4E6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4E8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4EA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4EC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4EE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4F0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4F2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4F4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4F6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4F8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4FB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4FD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER4FF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER502.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER504.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER505.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER506.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER507.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER508.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER509.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER50F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER510.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER511.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER512.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER513.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER514.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER515.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER516.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER517.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER518.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER519.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER51F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER520.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER521.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER522.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER523.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER524.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER525.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER526.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER527.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER528.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER529.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER52A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER52B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER58F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER590.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER591.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER592.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER593.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER594.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER595.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER596.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER597.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER598.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER599.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER59F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5A9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5AF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5B9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5BF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5C9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5CF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5D9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5DF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5E9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5EA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5EB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5EC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5ED.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5EE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5EF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5F9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER5FF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER600.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER601.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER602.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER603.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER604.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER605.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER606.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER607.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER608.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER609.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER60F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER610.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER611.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER612.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER613.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER614.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER615.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER616.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER617.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER618.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER619.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER61F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER620.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER621.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER622.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER623.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER624.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER625.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER626.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER627.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER628.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER629.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER62F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER630.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER631.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER632.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER633.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER634.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER635.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER636.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER637.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER638.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER639.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER63F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER640.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER641.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER642.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER643.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER644.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER645.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER646.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER647.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER648.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER649.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER64F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER650.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER651.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER652.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER653.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER654.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER655.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER656.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER657.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER658.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER659.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER65F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER660.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER661.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER662.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER663.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER664.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER665.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER666.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER667.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER668.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER669.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER66F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER670.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER671.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER672.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER673.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER674.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER675.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER676.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER677.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER678.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER679.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER67F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER680.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER681.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER682.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER683.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER684.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER685.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER686.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER687.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER688.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER689.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER68F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER690.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER691.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER692.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER693.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER694.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER695.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER696.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER697.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER698.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER699.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER69F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6A9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6AF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6B9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6BF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6C9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6CF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6D9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6DF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6E9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6EA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6EB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6EC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6ED.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6EE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6EF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6F9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER6FF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER700.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER701.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER702.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER703.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER704.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER705.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER706.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER707.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER708.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER709.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER70F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER710.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER711.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER712.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER713.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER714.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER715.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER716.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER717.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER718.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER719.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER71F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER720.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER721.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER722.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER723.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER724.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER725.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER726.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER727.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER728.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER729.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER72F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER730.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER731.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER732.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER733.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER734.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER735.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER736.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER737.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER738.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER739.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER73F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER740.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER741.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER742.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER743.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER744.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER745.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER746.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER747.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER748.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER749.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER74F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER750.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER751.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER752.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER753.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER754.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER755.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER756.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER757.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER758.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER759.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER75F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER760.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER761.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER762.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER763.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER764.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER765.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER766.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER767.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER768.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER769.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER76F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER770.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER771.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER772.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER773.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER774.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER775.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER776.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER777.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER778.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER779.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER77F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER780.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER781.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER782.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER783.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER784.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER785.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER786.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER787.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER788.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER789.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER78F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER790.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER791.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER792.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER793.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER794.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER795.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER796.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER797.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER798.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER799.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79A.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79B.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79C.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79D.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79E.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER79F.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A8.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7A9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7AF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7B9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7BF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C4.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7C9.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CA.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CB.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CC.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CD.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CE.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7CF.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D0.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D1.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D2.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D3.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D5.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D6.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D7.tmp.dir00 (operation failed)
Failed: FolderDelete C:\WINDOWS\Temp\WER7D8.
  • 0

#10
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
OK, we can do it manually. Could you post a new HJT log?
  • 0

Advertisements


#11
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
Logfile of HijackThis v1.99.1
Scan saved at 7:05:14 AM, on 7/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\System32\aspi261717.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\unoucb.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\lwfyc.exe
C:\WINDOWS\System32\lwfyc.exe
C:\WINDOWS\System32\lwfyc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\kqjdylhA.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\0c9b35c1.exe
C:\Program Files\Common Files\{C091F94C-0702-1033-0729-020310150001}\Update.exe
C:\Program Files\PSHope\PSHope.exe
C:\Program Files\System Files\System.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\kqjdylh.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Molly\Desktop\f4f\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.fin...siteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.fin...siteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalo...asp?si=20065&k=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Kristens Sexxy
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\lwfyc.exe
F2 - REG:system.ini: UserInit=userinit.exe,vrldmgh.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Steganos Internet Anonym - {00000000-5736-4205-0008-f7ed0776fb27} - c:\program files\steganos internet anonym 2006\sia2006iep.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Optical Mouse\mouse32a.exe
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [siri] c:\program files\zz\spolv.exe
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\System32\mptft.exe
O4 - HKLM\..\Run: [Hhl7RfpJ] "C:\WINDOWS\System32\ssn6tuu.exe"
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [uesmcy] C:\WINDOWS\System32\unoucb.exe reg_run
O4 - HKLM\..\Run: [kqjdylhA] C:\WINDOWS\kqjdylhA.exe
O4 - HKLM\..\Run: [cnhe2efd] RUNDLL32.EXE w24be037.dll,n 001e2efc0000000324be037
O4 - HKLM\..\Run: [{1F-F9-94-4C-ZN}] C:\windows\system32\ondsregl.exe CORN003
O4 - HKLM\..\Run: [w0034e02.dll] RUNDLL32.EXE w0034e02.dll,I2 001e2efc00034e02
O4 - HKLM\..\Run: [0c9b35c1.exe] C:\WINDOWS\System32\0c9b35c1.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [siri] c:\program files\zz\spolv.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [qbynd] C:\WINDOWS\System32\unoucb.exe reg_run
O4 - HKCU\..\Run: [rfwr] C:\PROGRA~1\COMMON~1\rfwr\rfwrm.exe
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [0c9b35c1.exe] C:\Documents and Settings\Molly\Local Settings\Application Data\0c9b35c1.exe
O4 - Startup: Mopy Points Collector.lnk = C:\MOPYFISH\GETPOINT.EXE
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\mwinopez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: nuavi.exe
O4 - Global Startup: opoz.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: AltaVista Search - file://C:\Program Files\ALTAVISTA Toolbar\Cache\SelectedContextSearch.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate - file://C:\Program Files\ALTAVISTA Toolbar\Cache\SelectedContextTranslation.htm
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\System32\dmonwv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Molly\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: &Gucci Messenger - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Documents and Settings\Molly\Desktop\pppenguin102\Gucci5.5\Gucci5.5\YPager (file missing)
O9 - Extra 'Tools' menuitem: &Gucci Messenger - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Documents and Settings\Molly\Desktop\pppenguin102\Gucci5.5\Gucci5.5\YPager (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} -
O16 - DPF: {4E7BD74F-2B8D-469E-92EA-EC65A294AE31} (AltaVista Toolbar) - http://toolbar.altav...ab?r=1113115026
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1126157728437
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.co...loadControl.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.co...aploader_v6.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://h20179.www2.h...er/SysQuery.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O20 - Winlogon Notify: ShellScrap - C:\WINDOWS\system32\hr8005lme.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\g4040edqeh0e0.dll (file missing)
O21 - SSODL: DCOM Server 2234 - {2C1CD3D7-86AC-4068-93BC-A02304BB2234} - C:\WINDOWS\System32\2234_28.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_28.dll
O21 - SSODL: PcwABIfevU - {C091F94D-6A3B-53E7-23CF-1B2AA9DEFF78} - C:\WINDOWS\System32\fugyu.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi261717.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\System32\CTsvcCDA.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\kqjdylh.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\System32\MsPMSPSv.exe (file missing)
  • 0

#12
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
  • Download qoofix.bat (rightclick on this link and choose save as, if using IE save target as)
  • Place qoofix.bat in your C:\BFU - folder. (Important!)
  • Doubleclick qooFix.bat, Close all browsers and explorer folders.
  • Choose option 1 (Qoolfix autofix) and follow the prompts.
  • Please be patient, it will take about five minutes.
  • After the PC has restarted please post another hijackthis log.

Edited by Daemon, 27 July 2006 - 12:52 PM.

  • 0

#13
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
I couldnt download the file. It said the site/file coulld not be found.
  • 0

#14
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Apologies:

http://www.malwarebytes.org/Qoofix.zip or
http://www.besttechi...ools/Qoofix.zip
  • 0

#15
Jackler

Jackler

    Member

  • Topic Starter
  • Member
  • PipPip
  • 94 posts
Qoofix v1.02 by http://www.malwarebytes.org
Scan started on [7/27/2006] at [8:24:24 PM]
-------------------------------------------------------------
Terminated module: bunusjr.dll found in Qoofix.exe (892)
Terminated module: bunusjr.dll found in rundll32.exe (1468)
Terminated module: bunusjr.dll found in explorer.exe (1684)
Terminated module: bunusjr.dll found in lwfyc.exe (1692)
Terminated module: bunusjr.dll found in lwfyc.exe (1728)
Terminated module: bunusjr.dll found in lwfyc.exe (1736)
Terminated module: bunusjr.dll found in unoucb.exe (1744)
-------------------------------------------------------------
C:\WINDOWS\System32\akdxn.dat will be deleted on reboot!
C:\WINDOWS\System32\bunusjr.dll will be deleted on reboot!
C:\WINDOWS\System32\lwfyc.exe will be deleted on reboot!
C:\WINDOWS\System32\unoucb.exe will be deleted on reboot!
C:\WINDOWS\System32\vrldmgh.exe will be deleted on reboot!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nuavi.exe will be deleted on reboot!
C:\WINDOWS\unwn.exe will be deleted on reboot!
C:\WINDOWS\System32\dmonwv.dll will be deleted on reboot!
User prompted NO to reboot, please reboot manually...
-------------------------------------------------------------
Scan COMPLETED SUCCESSFULLY on [7/27/2006] at [8:28:36 PM]

Note: Some registry keys may have been removed.


-----------------------------------------------------------------------------------
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP