Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

No Desktop @ all, and Can't right click or bring up Task Manager [


  • This topic is locked This topic is locked

#16
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
and here is the main.text

Deckard's System Scanner v20071014.68
Run by Kent on 2007-10-15 00:12:53
Computer is in Safe Mode with Networking.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Failed to create restore point; computer is in safe mode.


-- Last 5 Restore Point(s) --
38: 2007-10-13 01:05:24 UTC - RP182 - Restore Operation
37: 2007-10-01 19:57:19 UTC - RP181 - Restore Operation
36: 2007-10-01 19:52:51 UTC - RP180 - Restore Operation
35: 2007-10-01 19:43:40 UTC - RP179 - Restore Operation
34: 2007-10-01 19:41:37 UTC - RP178 - Restore Operation


-- First Restore Point --
1: 2007-09-05 10:28:40 UTC - RP145 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.

Percentage of Memory in Use: 77% (more than 75%).
Total Physical Memory: 504 MiB (512 MiB recommended).
System Drive C: has 3.55 GiB (less than 15%) free.


-- HijackThis (run as Kent.exe) ------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:56 AM, on 10/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Kent\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Kent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.apple.com/itunes/download/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3E80EA04-3EBA-40E2-B1C1-58D119F6518a} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {54E6D360-DCF8-4E50-92C9-8792126D2864} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {6B8ADCEE-02B2-475A-803C-F3ADF8B773F8} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {74F932E6-C714-4D49-83DA-C48F9FD61A76} - C:\WINDOWS\system32\fbiugbyy.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A91DB785-7D93-42AE-AC4C-E6F0BD0CA45D} - C:\WINDOWS\AppPatch\natimxl.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {D023390D-0F52-4437-B2FF-58561E3368A5} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {D0329530-48D1-4AD6-AAB6-E90338C13212} - C:\WINDOWS\system32\djqfhsn.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [xcdtggyl] C:\vrjocsqy.bat
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://titanium.full...cweb/awswax.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.ai...AIM.9.5.1.8.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.ritea...PhotoOnline.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://mainstreet.f...perSetupSP1.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Remote Procedure Call (RPC) Se (RPCSEO) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://www.google.com/
O24 - Desktop Component 1: MySpace - http://www.myspace.com/

--
End of file - 9721 bytes

-- File Associations -----------------------------------------------------------

.js - unable to read key
.js - unable to read key


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R0 Vax347b - c:\windows\system32\drivers\vax347b.sys
R0 Vax347s - c:\windows\system32\drivers\vax347s.sys
R0 xcqyangz - c:\windows\system32\drivers\coohlwms.sys
R3 AnyDVD - c:\windows\system32\drivers\anydvd.sys <Not Verified; SlySoft, Inc.; AnyDVD>
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
R3 MarvinBus (Pinnacle Marvin Bus) - c:\windows\system32\drivers\marvinbus.sys <Not Verified; Pinnacle Systems GmbH; Pinnacle Marvin Discrete>
R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>

S1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>
S1 StyleXPHelper - c:\program files\tgtsoft\stylexp\stylexphelper.exe <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver>
S3 pcouffin (VSO Software pcouffin) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S2 Diskeeper - "c:\program files\diskeeper corporation\diskeeper\dkservice.exe" <Not Verified; Diskeeper Corporation; Diskeeper ™ Disk Defragmenter>
S2 PCLEPCI - c:\windows\system32\drivers\pclepci.sys <Not Verified; Pinnacle Systems GmbH; PCLEPCI>
S2 RPCSEO (Remote Procedure Call (RPC) Se) - c:\program files\intel\service <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe
S3 TUWinStylerThemeSvc (TuneUp WinStyler Theme Service) - "c:\program files\tuneup utilities 2006\winstylerthemesvc.exe" <Not Verified; TuneUp Software GmbH; TuneUp Utilities>


-- Device Manager: Disabled ----------------------------------------------------

No disabled devices found.


-- Scheduled Tasks -------------------------------------------------------------

2007-10-13 14:27:06 362 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2007-09-28 21:17:39 388 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job
2007-09-24 17:43:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


-- Files created between 2007-09-15 and 2007-10-15 -----------------------------

2007-10-15 00:01:47 126976 --a------ C:\zip.exe
2007-10-15 00:01:47 60416 --a------ C:\WINDOWS\system32\drivers\wcassojb.sys
2007-10-15 00:01:47 1080 --a------ C:\vrjocsqy.bat
2007-10-15 00:01:47 19814 --a------ C:\reboot.exe
2007-10-15 00:01:47 336 --a------ C:\reboot.bat
2007-10-15 00:01:47 353 --a------ C:\avexport.bat
2007-10-14 18:48:28 75284 --a------ C:\WINDOWS\system32\gelnihsr.exe <Not Verified; ; DDC>
2007-10-14 18:43:06 0 d-------- C:\!KillBox
2007-10-14 14:37:18 75284 --a------ C:\WINDOWS\system32\mbkfwfgn.exe <Not Verified; ; DDC>
2007-10-13 14:37:08 75284 --a------ C:\WINDOWS\system32\guoicais.exe <Not Verified; ; DDC>
2007-10-13 14:29:25 75284 --a------ C:\WINDOWS\system32\dnqnepfw.exe <Not Verified; ; DDC>
2007-10-13 14:04:10 75284 --a------ C:\WINDOWS\system32\jfwrxtrg.exe <Not Verified; ; DDC>
2007-10-13 13:58:34 75284 --a------ C:\WINDOWS\system32\xbpaoyop.exe <Not Verified; ; DDC>
2007-10-13 02:37:07 0 d-------- C:\VundoFix Backups
2007-10-12 23:53:49 75284 --a------ C:\WINDOWS\system32\yhcvvvim.exe <Not Verified; ; DDC>
2007-10-12 23:41:45 0 d-------- C:\Program Files\Trend Micro
2007-10-12 18:55:27 75284 --a------ C:\WINDOWS\system32\hwugjfqh.exe <Not Verified; ; DDC>
2007-10-07 19:40:01 0 d-------- C:\Documents and Settings\Administrator\Application Data\ICAClient
2007-10-03 18:16:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\SendTo
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\My Documents <MYDOCU~1>
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Local Settings <LOCALS~1>
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Favorites <FAVORI~1>
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Cookies
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Application Data <APPLIC~1>
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Application Data\Sonic
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Application Data\Real
2007-10-02 00:14:23 0 d-------- C:\Documents and Settings\New\Application Data\Microsoft
2007-10-02 00:14:22 0 d-------- C:\Documents and Settings\New\Templates <TEMPLA~1>
2007-10-02 00:14:22 1048576 --ah----- C:\Documents and Settings\New\NTUSER.DAT
2007-10-01 18:06:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2007-10-01 13:02:43 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2007-10-01 13:02:27 0 d-------- C:\Documents and Settings\Administrator\Application Data\Opera
2007-10-01 12:56:52 9437184 --a------ C:\Documents and Settings\Kent\ntuser.dat
2007-10-01 08:53:10 548352 -r-hs---- C:\WINDOWS\serivce.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-01 01:29:39 75284 --a------ C:\WINDOWS\system32\oekuilff.exe <Not Verified; ; DDC>
2007-09-30 01:29:20 75284 --a------ C:\WINDOWS\system32\uplkxpkh.exe <Not Verified; ; DDC>
2007-09-29 08:26:14 59392 --a------ C:\WINDOWS\system32\cryptsva.dll
2007-09-29 08:24:59 75284 --a------ C:\WINDOWS\system32\duxgbkrt.exe <Not Verified; ; DDC>
2007-09-28 08:25:37 59392 --a------ C:\WINDOWS\system32\d3dx9_3.dll
2007-09-28 08:24:37 75284 --a------ C:\WINDOWS\system32\malnvsid.exe <Not Verified; ; DDC>
2007-09-27 12:39:16 4736 --a------ C:\WINDOWS\system32\drivers\jmwsmxkv.sys
2007-09-27 12:39:04 59392 --a------ C:\WINDOWS\system32\comaddi.dll
2007-09-27 12:37:56 104447 --a------ C:\WINDOWS\system32\djqfhsn.dll
2007-09-27 12:37:38 75284 --a------ C:\WINDOWS\system32\fktqqvoy.exe <Not Verified; ; DDC>
2007-09-26 14:23:48 17920 --a------ C:\WINDOWS\system32\drivers\coohlwms.sys
2007-09-26 14:22:34 91648 --a------ C:\WINDOWS\system32\cmcfg3.dll
2007-09-26 03:01:15 237568 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2007-09-25 19:45:42 75284 --a------ C:\WINDOWS\system32\turkcmlr.exe <Not Verified; ; DDC>
2007-09-25 16:59:53 75284 --a------ C:\WINDOWS\system32\tdnblsyp.exe <Not Verified; ; DDC>
2007-09-25 16:45:51 0 d-------- C:\Documents and Settings\LocalService\Application Data\Google
2007-09-25 16:45:30 0 dr------- C:\Documents and Settings\LocalService\Favorites <FAVORI~1>
2007-09-25 15:52:44 75284 --a------ C:\WINDOWS\system32\wsentjip.exe <Not Verified; ; DDC>
2007-09-23 21:14:46 75284 --a------ C:\WINDOWS\system32\utyedard.exe <Not Verified; ; DDC>
2007-09-23 21:01:21 75284 --a------ C:\WINDOWS\system32\jtjcfuhd.exe <Not Verified; ; DDC>
2007-09-23 12:16:14 75284 --a------ C:\WINDOWS\system32\jyijuiyu.exe <Not Verified; ; DDC>
2007-09-22 03:01:52 1048576 --a------ C:\Documents and Settings\Administrator\ntuser.dat
2007-09-22 03:01:49 7843840 --a------ C:\Documents and Settings\HP_Owner\ntuser.dat
2007-09-21 21:34:58 75284 --a------ C:\WINDOWS\system32\sfiqjqis.exe <Not Verified; ; DDC>
2007-09-21 13:42:59 75284 --a------ C:\WINDOWS\system32\dihqnfiw.exe <Not Verified; ; DDC>
2007-09-20 18:25:11 75284 --a------ C:\WINDOWS\system32\loytijnr.exe <Not Verified; ; DDC>
2007-09-20 17:41:12 0 d-------- C:\Documents and Settings\HP_Owner\Application Data\Opera
2007-09-20 11:38:47 0 d-------- C:\spoolerlogs
2007-09-18 14:18:44 75284 --a------ C:\WINDOWS\system32\kuvjrgkn.exe <Not Verified; ; DDC>
2007-09-18 12:42:38 75284 --a------ C:\WINDOWS\system32\dniiutqn.exe <Not Verified; ; DDC>
2007-09-18 10:05:27 75284 --a------ C:\WINDOWS\system32\hvtxbfrx.exe <Not Verified; ; DDC>
2007-09-17 13:33:04 75284 --a------ C:\WINDOWS\system32\aajavlmu.exe <Not Verified; ; DDC>
2007-09-17 11:33:18 75284 --a------ C:\WINDOWS\system32\fwynsrdj.exe <Not Verified; ; DDC>
2007-09-16 19:56:23 75284 --a------ C:\WINDOWS\system32\alfemeiy.exe <Not Verified; ; DDC>
2007-09-16 18:26:53 75284 --a------ C:\WINDOWS\system32\dxfdothm.exe <Not Verified; ; DDC>
2007-09-15 18:26:38 75284 --a------ C:\WINDOWS\system32\xetlijiu.exe <Not Verified; ; DDC>
2007-09-15 16:52:48 75284 --a------ C:\WINDOWS\system32\jvhlovxi.exe <Not Verified; ; DDC>
2007-09-15 15:00:10 75284 --a------ C:\WINDOWS\system32\wukmusea.exe <Not Verified; ; DDC>
2007-09-15 11:21:39 75284 --a------ C:\WINDOWS\system32\whmcrvsj.exe <Not Verified; ; DDC>
2007-09-15 05:49:29 75284 --a------ C:\WINDOWS\system32\ipphseug.exe <Not Verified; ; DDC>


-- Find3M Report ---------------------------------------------------------------

2007-10-13 14:26:55 0 d-------- C:\Program Files\Common Files\Symantec Shared
2007-10-13 14:22:03 0 d-------- C:\Documents and Settings\Kent\Application Data\Juniper Networks
2007-10-12 23:46:39 0 d-------- C:\Program Files\Google
2007-10-01 12:50:50 0 d-------- C:\Program Files\Intel
2007-09-30 01:27:48 562688 -----n--- C:\WINDOWS\Intel.DLL
2007-09-25 16:33:05 0 d-------- C:\Program Files\Dartfish
2007-09-25 16:24:52 0 d-------- C:\Program Files\CoffeeCup Software
2007-09-24 11:44:50 0 d-------- C:\Documents and Settings\Kent\Application Data\LimeWire
2007-09-14 16:35:23 75284 --a------ C:\WINDOWS\system32\mkugioqi.exe <Not Verified; ; DDC>
2007-09-14 13:18:51 75284 --a------ C:\WINDOWS\system32\duqoroxt.exe <Not Verified; ; DDC>
2007-09-14 13:07:19 75284 --a------ C:\WINDOWS\system32\jkofxmkh.exe <Not Verified; ; DDC>
2007-09-14 11:49:47 75284 --a------ C:\WINDOWS\system32\gvkdinpk.exe <Not Verified; ; DDC>
2007-09-13 13:43:03 75284 --a------ C:\WINDOWS\system32\alrcwofr.exe <Not Verified; ; DDC>
2007-09-12 13:42:44 75284 --a------ C:\WINDOWS\system32\toeqnomx.exe <Not Verified; ; DDC>
2007-09-12 03:28:28 75284 --a------ C:\WINDOWS\system32\sfbphhvl.exe <Not Verified; ; DDC>
2007-09-11 16:23:49 75284 --a------ C:\WINDOWS\system32\tjjvopsb.exe <Not Verified; ; DDC>
2007-09-11 06:22:15 75284 --a------ C:\WINDOWS\system32\eimwelfo.exe <Not Verified; ; DDC>
2007-09-10 13:20:55 75284 --a------ C:\WINDOWS\system32\qcifeqmt.exe <Not Verified; ; DDC>
2007-09-09 22:20:30 75284 --a------ C:\WINDOWS\system32\unxqjkdq.exe <Not Verified; ; DDC>
2007-09-09 20:50:42 75284 --a------ C:\WINDOWS\system32\gwuhnjwi.exe <Not Verified; ; DDC>
2007-09-09 17:51:57 75284 --a------ C:\WINDOWS\system32\tboikamb.exe <Not Verified; ; DDC>
2007-09-09 17:17:40 75284 --a------ C:\WINDOWS\system32\onphsxqi.exe <Not Verified; ; DDC>
2007-09-09 12:40:28 75284 --a------ C:\WINDOWS\system32\iecpewka.exe <Not Verified; ; DDC>
2007-09-09 11:51:08 75284 --a------ C:\WINDOWS\system32\tfywfoag.exe <Not Verified; ; DDC>
2007-09-08 21:03:54 75284 --a------ C:\WINDOWS\system32\gkgnwigm.exe <Not Verified; ; DDC>
2007-09-08 13:26:17 75284 --a------ C:\WINDOWS\system32\cjhcwyrv.exe <Not Verified; ; DDC>
2007-09-08 11:49:00 75284 --a------ C:\WINDOWS\system32\ijsprjxb.exe <Not Verified; ; DDC>
2007-09-08 06:07:09 75284 --a------ C:\WINDOWS\system32\dhfsqbqr.exe <Not Verified; ; DDC>
2007-09-07 21:12:43 75284 --a------ C:\WINDOWS\system32\fowhurxy.exe <Not Verified; ; DDC>
2007-09-07 10:09:03 75284 --a------ C:\WINDOWS\system32\kqpcevsu.exe <Not Verified; ; DDC>
2007-09-07 04:57:33 75284 --a------ C:\WINDOWS\system32\djyyifwu.exe <Not Verified; ; DDC>
2007-09-06 13:10:27 75284 --a------ C:\WINDOWS\system32\njkocwph.exe <Not Verified; ; DDC>
2007-09-06 05:22:05 75284 --a------ C:\WINDOWS\system32\vkackwdv.exe <Not Verified; ; DDC>
2007-09-05 13:51:14 75284 --a------ C:\WINDOWS\system32\ldhiumsb.exe <Not Verified; ; DDC>
2007-09-05 08:40:02 75284 --a------ C:\WINDOWS\system32\lhvlmcty.exe <Not Verified; ; DDC>
2007-09-05 02:12:23 75284 --a------ C:\WINDOWS\system32\phhisrpb.exe <Not Verified; ; DDC>
2007-09-04 11:26:10 75284 --a------ C:\WINDOWS\system32\vqhjluwh.exe <Not Verified; ; DDC>
2007-09-03 22:08:22 75284 --a------ C:\WINDOWS\system32\eafsegnr.exe <Not Verified; ; DDC>
2007-09-03 10:54:12 75284 --a------ C:\WINDOWS\system32\frsqnevt.exe <Not Verified; ; DDC>
2007-09-03 10:42:50 75284 --a------ C:\WINDOWS\system32\vgmnpblu.exe <Not Verified; ; DDC>
2007-09-02 16:30:33 75284 --a------ C:\WINDOWS\system32\bkdmpwxf.exe <Not Verified; ; DDC>
2007-09-02 15:36:15 75284 --a------ C:\WINDOWS\system32\qxpglalv.exe <Not Verified; ; DDC>
2007-09-02 15:03:16 75284 --a------ C:\WINDOWS\system32\ncgiscci.exe <Not Verified; ; DDC>
2007-09-02 14:32:23 75284 --a------ C:\WINDOWS\system32\eljfonwp.exe <Not Verified; ; DDC>
2007-09-02 14:20:23 75284 --a------ C:\WINDOWS\system32\ejrnjjdk.exe <Not Verified; ; DDC>
2007-09-01 22:56:45 75284 --a------ C:\WINDOWS\system32\mthydijq.exe <Not Verified; ; DDC>
2007-09-01 17:29:20 75284 --a------ C:\WINDOWS\system32\qrfvcjeh.exe <Not Verified; ; DDC>
2007-09-01 15:30:19 75284 --a------ C:\WINDOWS\system32\ejqoohxr.exe <Not Verified; ; DDC>
2007-09-01 14:01:14 75284 --a------ C:\WINDOWS\system32\miglvumo.exe <Not Verified; ; DDC>
2007-09-01 01:08:29 75284 --a------ C:\WINDOWS\system32\bqchjhxr.exe <Not Verified; ; DDC>
2007-08-31 15:38:37 75284 --a------ C:\WINDOWS\system32\jwxnrdnn.exe <Not Verified; ; DDC>
2007-08-31 15:30:16 75284 --a------ C:\WINDOWS\system32\lmddxjam.exe <Not Verified; ; DDC>
2007-08-31 13:39:02 75284 --a------ C:\WINDOWS\system32\kkttfcty.exe <Not Verified; ; DDC>
2007-08-31 10:52:14 75284 --a------ C:\WINDOWS\system32\xbybiely.exe <Not Verified; ; DDC>
2007-08-31 04:28:36 75284 --a------ C:\WINDOWS\system32\repinkly.exe <Not Verified; ; DDC>
2007-08-30 04:28:16 75284 --a------ C:\WINDOWS\system32\wxaljrka.exe <Not Verified; ; DDC>
2007-08-30 03:53:23 75284 --a------ C:\WINDOWS\system32\cmymcveo.exe <Not Verified; ; DDC>
2007-08-30 03:35:04 75284 --a------ C:\WINDOWS\system32\qmpqeifj.exe <Not Verified; ; DDC>
2007-08-30 00:18:18 75284 --a------ C:\WINDOWS\system32\yaowydmt.exe <Not Verified; ; DDC>
2007-08-29 16:56:45 75284 --a------ C:\WINDOWS\system32\egafhqke.exe <Not Verified; ; DDC>
2007-08-29 15:42:47 75284 --a------ C:\WINDOWS\system32\jwqttdqr.exe <Not Verified; ; DDC>
2007-08-28 15:42:31 75284 --a------ C:\WINDOWS\system32\ajftrmrg.exe <Not Verified; ; DDC>
2007-08-22 21:25:38 0 d-------- C:\Documents and Settings\Kent\Application Data\Adobe
2007-08-22 10:02:18 0 d-------- C:\Documents and Settings\Kent\Application Data\U3
2007-08-22 01:00:39 304161 --a------ C:\WINDOWS\system32\qwdwlvis.exe
2007-08-21 10:01:10 304161 --a------ C:\WINDOWS\system32\ufjvjefy.exe
2007-08-15 22:51:20 73 --a------ C:\WINDOWS\sysInf.dat
2007-08-15 08:08:45 75284 --a------ C:\WINDOWS\system32\biwwqgqo.exe <Not Verified; ; DDC>
2007-08-15 04:03:30 0 d-------- C:\Program Files\MSXML 6.0
2007-08-15 03:33:20 75284 --a------ C:\WINDOWS\system32\bxdbtmip.exe <Not Verified; ; DDC>
2007-08-14 18:38:38 75284 --a------ C:\WINDOWS\system32\fdoygvbc.exe <Not Verified; ; DDC>
2007-08-13 18:38:11 75284 --a------ C:\WINDOWS\system32\srnultya.exe <Not Verified; ; DDC>
2007-08-13 15:59:34 75284 --a------ C:\WINDOWS\system32\jvlibgfw.exe <Not Verified; ; DDC>
2007-08-13 09:02:51 75284 --a------ C:\WINDOWS\system32\pwmnfwak.exe <Not Verified; ; DDC>
2007-08-13 08:45:25 75284 --a------ C:\WINDOWS\system32\bujqkwqg.exe <Not Verified; ; DDC>
2007-08-12 10:35:43 75284 --a------ C:\WINDOWS\system32\cwldftju.exe <Not Verified; ; DDC>
2007-08-12 10:35:27 66068 --a------ C:\WINDOWS\system32\dprwiyub.exe
2007-08-12 10:31:50 75284 --a------ C:\WINDOWS\system32\kwpmalnp.exe <Not Verified; ; DDC>
2007-08-12 10:31:23 66068 --a------ C:\WINDOWS\system32\dqyqxsih.exe
2007-08-12 10:26:51 75284 --a------ C:\WINDOWS\system32\jikaqtno.exe <Not Verified; ; DDC>
2007-08-12 10:26:22 66068 --a------ C:\WINDOWS\system32\bcoqflmh.exe
2007-08-12 10:24:41 75284 --a------ C:\WINDOWS\system32\jecbgxdr.exe <Not Verified; ; DDC>
2007-08-12 09:58:37 75284 --a------ C:\WINDOWS\system32\ulmsgbtk.exe <Not Verified; ; DDC>
2007-08-11 09:58:23 75284 --a------ C:\WINDOWS\system32\hgyhvejm.exe <Not Verified; ; DDC>
2007-08-10 13:07:59 120852 --a------ C:\WINDOWS\system32\vicynhrx.dll
2007-08-10 13:07:35 75284 --a------ C:\WINDOWS\system32\pvwlgeya.exe <Not Verified; ; DDC>
2007-08-10 03:33:04 75284 --a------ C:\WINDOWS\system32\nykijyjr.exe <Not Verified; ; DDC>
2007-08-09 18:41:45 75284 --a------ C:\WINDOWS\system32\muvqxvql.exe <Not Verified; ; DDC>
2007-08-09 18:41:16 66068 --a------ C:\WINDOWS\system32\ouldhhks.exe
2007-08-09 18:36:28 75284 --a------ C:\WINDOWS\system32\tvscetsi.exe <Not Verified; ; DDC>
2007-08-09 14:06:50 75284 --a------ C:\WINDOWS\system32\awyrbjcf.exe <Not Verified; ; DDC>
2007-08-08 14:06:22 75284 --a------ C:\WINDOWS\system32\pwcdrrch.exe <Not Verified; ; DDC>
2007-08-08 14:06:08 66068 --a------ C:\WINDOWS\system32\yfsxnsno.exe
2007-08-08 14:01:46 75284 --a------ C:\WINDOWS\system32\vlrnfuhl.exe <Not Verified; ; DDC>
2007-08-08 14:01:39 304161 --a------ C:\WINDOWS\system32\jlsjdadm.exe
2007-08-08 14:01:08 66068 --a------ C:\WINDOWS\system32\dmdnwxoi.exe
2007-08-08 13:56:00 75284 --a------ C:\WINDOWS\system32\wrumtpei.exe <Not Verified; ; DDC>
2007-08-08 13:52:11 66068 --a------ C:\WINDOWS\system32\tfoogfgc.exe
2007-08-08 09:27:43 75284 --a------ C:\WINDOWS\system32\gnuxrand.exe <Not Verified; ; DDC>
2007-08-07 09:27:15 66068 --a------ C:\WINDOWS\system32\jkindolm.exe
2007-08-06 09:27:01 66068 --a------ C:\WINDOWS\system32\idkxgbju.exe
2007-08-05 14:02:33 66068 --a------ C:\WINDOWS\system32\uklialsr.exe
2007-08-05 14:02:00 66068 --a------ C:\WINDOWS\system32\fnubjdka.exe
2007-08-05 12:48:09 66068 --a------ C:\WINDOWS\system32\wlvfywnd.exe
2007-08-04 12:47:49 66068 --a------ C:\WINDOWS\system32\ebeijatl.exe
2007-08-04 12:36:14 66068 --a------ C:\WINDOWS\system32\rysxqegy.exe
2007-08-04 12:30:35 66068 --a------ C:\WINDOWS\system32\xoxsioxg.exe
2007-08-03 22:50:35 66068 --a------ C:\WINDOWS\system32\klgfyife.exe
2007-08-03 22:41:46 66068 --a------ C:\WINDOWS\system32\dfkhgjtq.exe
2007-08-03 18:45:32 121876 --a------ C:\WINDOWS\system32\gfdrqjls.dll
2007-08-03 18:45:18 66068 --a------ C:\WINDOWS\system32\ydsgrmcx.exe
2007-08-03 18:41:13 66068 --a------ C:\WINDOWS\system32\yijjynhs.exe
2007-08-03 17:15:44 66068 --a------ C:\WINDOWS\system32\cqrqdqap.exe
2007-08-03 12:26:07 121876 --a------ C:\WINDOWS\system32\eaykkcoo.dll
2007-08-03 12:26:03 66068 --a------ C:\WINDOWS\system32\aephbyrq.exe
2007-08-03 12:25:41 66068 --a------ C:\WINDOWS\system32\wwqrysnr.exe
2007-08-03 10:15:04 66068 --a------ C:\WINDOWS\system32\qykmjaok.exe
2007-08-03 10:11:11 66068 --a------ C:\WINDOWS\system32\fdtctvap.exe
2007-08-03 10:10:42 66068 --a------ C:\WINDOWS\system32\vondahac.exe
2007-08-03 10:05:09 66068 --a------ C:\WINDOWS\system32\lyqcgfsr.exe
2007-08-03 08:32:30 66068 --a------ C:\WINDOWS\system32\hrbdmqjj.exe
2007-08-03 08:32:03 66068 --a------ C:\WINDOWS\system32\mbjodnlr.exe
2007-08-03 08:24:45 66068 --a------ C:\WINDOWS\system32\qrvtayyi.exe
2007-08-03 08:23:46 66068 --a------ C:\WINDOWS\system32\kijnmjxw.exe
2007-08-02 16:09:47 66068 --a------ C:\WINDOWS\system32\lcgehnrd.exe
2007-08-02 13:32:11 66068 --a------ C:\WINDOWS\system32\kykevwos.exe
2007-08-02 09:26:36 66068 --a------ C:\WINDOWS\system32\kkgidcuq.exe
2007-08-02 09:22:10 66068 --a------ C:\WINDOWS\system32\ysfhjpsm.exe
2007-08-02 09:17:00 66068 --a------ C:\WINDOWS\system32\vxwuwajr.exe
2007-08-02 08:53:56 66068 --a------ C:\WINDOWS\system32\emjwxsbl.exe
2007-08-02 04:07:08 66068 --a------ C:\WINDOWS\system32\fixhllik.exe
2007-08-02 04:06:26 66068 --a------ C:\WINDOWS\system32\huwnoygf.exe
2007-08-01 19:15:03 66068 --a------ C:\WINDOWS\system32\dpxkycfp.exe
2007-08-01 17:55:29 66068 --a------ C:\WINDOWS\system32\bvasruwp.exe
2007-08-01 11:47:41 66068 --a------ C:\WINDOWS\system32\vahpixhy.exe
2007-07-31 11:47:34 125972 --a------ C:\WINDOWS\system32\yfyaphis.dll
2007-07-31 11:47:17 66068 --a------ C:\WINDOWS\system32\yehwhift.exe
2007-07-30 11:46:58 125972 --a------ C:\WINDOWS\system32\kovssvbt.dll
2007-07-30 11:46:49 66068 --a------ C:\WINDOWS\system32\ksruawvt.exe
2007-07-29 11:46:37 66068 --a------ C:\WINDOWS\system32\vmwysees.exe
2007-07-28 11:46:46 125972 --a------ C:\WINDOWS\system32\ppyldnwj.dll
2007-07-28 11:46:26 66068 --a------ C:\WINDOWS\system32\rstparab.exe
2007-07-27 15:14:46 103144 --a------ C:\Documents and Settings\Kent\Application Data\GDIPFONTCACHEV1.DAT
2007-07-27 12:10:27 33 --a------ C:\Documents and Settings\Kent\Application Data\pcouffin.log
2007-07-27 12:10:25 81920 --a------ C:\Documents and Settings\Kent\Application Data\ezpinst.exe
2007-07-27 12:10:24 47360 --a------ C:\Documents and Settings\Kent\Application Data\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
2007-07-27 12:10:24 1144 --a------ C:\Documents and Settings\Kent\Application Data\pcouffin.inf
2007-07-27 12:10:24 7176 --a------ C:\Documents and Settings\Kent\Application Data\pcouffin.cat
2007-07-27 11:45:55 66068 --a------ C:\WINDOWS\system32\cdmpmrvr.exe
2007-07-26 22:41:46 139 --a------ C:\AUTOEXEC.BAT
2007-07-26 11:45:20 66068 --a------ C:\WINDOWS\system32\jsuyyqje.exe
2007-07-26 11:44:03 66068 --a------ C:\WINDOWS\system32\secrtjrg.exe
2007-07-26 03:28:20 66068 --a------ C:\WINDOWS\system32\ohefsopx.exe
2007-07-25 21:54:13 66068 --a------ C:\WINDOWS\system32\lmwlskyy.exe
2007-07-25 19:49:45 66068 --a------ C:\WINDOWS\system32\dxfmfvdu.exe
2007-07-25 17:10:25 66068 --a------ C:\WINDOWS\system32\bsqhnsib.exe
2007-07-24 17:10:08 66068 --a------ C:\WINDOWS\system32\tvxtwwxv.exe
2007-07-23 23:20:46 66068 --a------ C:\WINDOWS\system32\cgnulkci.exe
2007-07-23 22:16:47 66068 --a------ C:\WINDOWS\system32\rjklcuji.exe
2007-07-23 21:12:34 66068 --a------ C:\WINDOWS\system32\jpfeujcl.exe
2007-07-23 20:34:50 66068 --a------ C:\WINDOWS\system32\rgyvwyjr.exe
2007-07-22 13:43:33 66068 --a------ C:\WINDOWS\system32\gjnkhxfk.exe
2007-07-21 22:29:33 66068 --a------ C:\WINDOWS\system32\fainjfeb.exe
2007-07-20 22:29:24 66068 --a------ C:\WINDOWS\system32\dqfmcfti.exe
2007-07-19 22:48:40 66068 --a------ C:\WINDOWS\system32\ljgaiwaw.exe
2007-07-19 04:20:29 66068 --a------ C:\WINDOWS\system32\vuvijarb.exe
2007-07-19 04:12:36 66068 --a------ C:\WINDOWS\system32\jnohlhbk.exe
2007-07-19 03:54:45 66068 --a------ C:\WINDOWS\system32\pmneqbwd.exe
2007-07-19 02:26:33 66068 --a------ C:\WINDOWS\system32\thwsfyyv.exe
2007-07-18 22:25:36 110612 --a------ C:\WINDOWS\system32\fldabjwx.dll
2007-07-18 22:25:18 66068 --a------ C:\WINDOWS\system32\xtqvwniy.exe
2007-07-18 19:17:52 110612 --a------ C:\WINDOWS\system32\vopwnect.dll
2007-07-18 19:17:25 66068 --a------ C:\WINDOWS\system32\pbgtodee.exe
2007-07-17 18:59:45 110612 --a------ C:\WINDOWS\system32\rqehndhr.dll
2007-07-17 18:59:04 66068 --a------ C:\WINDOWS\system32\fivnpekq.exe
2007-07-17 18:54:33 66068 --a------ C:\WINDOWS\system32\clbbdlgj.exe
2007-07-17 11:16:01 66068 --a------ C:\WINDOWS\system32\wlbxrjtx.exe
2007-07-17 09:15:37 66068 --a------ C:\WINDOWS\system32\jmieyhyp.exe
2007-07-17 09:07:59 66068 --a------ C:\WINDOWS\system32\gaiyykeh.exe
2007-07-17 06:00:18 66068 --a------ C:\WINDOWS\system32\kkaosqvr.exe
2007-07-16 10:01:14 66068 --a------ C:\WINDOWS\system32\bmkhidev.exe
2007-07-16 09:00:52 66068 --a------ C:\WINDOWS\system32\gcuxoapo.exe
2007-07-15 14:23:19 66068 --a------ C:\WINDOWS\system32\xtjerxdu.exe


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3E80EA04-3EBA-40E2-B1C1-58D119F6518a}]
C:\WINDOWS\system32\ksqsoelb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54E6D360-DCF8-4E50-92C9-8792126D2864}]
C:\WINDOWS\system32\ksqsoelb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6B8ADCEE-02B2-475A-803C-F3ADF8B773F8}]
C:\WINDOWS\system32\ksqsoelb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74F932E6-C714-4D49-83DA-C48F9FD61A76}]
C:\WINDOWS\system32\fbiugbyy.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A91DB785-7D93-42AE-AC4C-E6F0BD0CA45D}]
C:\WINDOWS\AppPatch\natimxl.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D023390D-0F52-4437-B2FF-58561E3368A5}]
C:\WINDOWS\system32\ksqsoelb.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D0329530-48D1-4AD6-AAB6-E90338C13212}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [09/21/2005 10:24 AM C:\WINDOWS\SOUNDMAN.EXE]
"PS2"="C:\WINDOWS\system32\ps2.exe" [10/25/2004 04:17 PM]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [04/17/2004 12:41 PM]
"AlcxMonitor"="ALCXMNTR.EXE" [09/07/2004 08:47 PM C:\WINDOWS\ALCXMNTR.EXE]
"AlcWzrd"="ALCWZRD.EXE" [09/21/2005 03:32 PM C:\WINDOWS\ALCWZRD.EXE]
"Alcmtr"="ALCMTR.EXE" [05/03/2005 06:43 PM C:\WINDOWS\ALCMTR.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [06/29/2004 05:06 PM C:\WINDOWS\AGRSMMSG.exe]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [01/13/2007 09:47 AM]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [01/13/2007 09:47 AM]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [04/09/2007 05:23 AM]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [10/14/2004 09:54 PM]
"KBD"="C:\HP\KBD\KBD.EXE" [02/02/2005 05:44 PM]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [05/07/1998 04:04 PM]
"HPHUPD06"="c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [06/07/2004 06:53 PM]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [06/07/2004 06:42 PM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" []
"xcdtggyl"="C:\vrjocsqy.bat" [10/15/2007 12:01 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 09:24 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [09/25/2006 08:24 AM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"wininet.dll"=

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\fastload.dll 12/20/2001 10:34 PM 24576 C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\fastload.dll


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"AIM"=C:\Program Files\AIM\aim.exe -cnetwait.odl
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"Aim6"="C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
"Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
"LaunchList"=C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe
"STYLEXP"=C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"THGuard"="C:\Program Files\TrojanHunter 4.5\THGuard.exe"
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"HostManager"=C:\Program Files\Common Files\AOL\1128563132\ee\AOLSoftware.exe
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
"WinampAgent"=C:\Program Files\Winamp\winampa.exe
"msci"=C:\DOCUME~1\HP_Owner\LOCALS~1\Temp\2006621212256_mcinfo.exe /insfin
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"IPHSend"=C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
"DeadAIM"=rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" /STARTUP
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
"Symantec NetDriver Monitor"=C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
"Ulead Quick-Drop"="C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5 Plus\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
"PrintDrive"=rundll32.exe "C:\WINDOWS\system32\svlesekg.dll",setvm
"GPLv3"=rundll32.exe "C:\WINDOWS\system32\acpbapku.dll",realset
"SecurityUpdate"=rundll32.exe C:\WINDOWS\system32\pjditur.dll,TurnOn2
"j6221430"=rundll32 C:\WINDOWS\system32\j6221430.dll sook
"SearchIndexer"=rundll32.exe "C:\WINDOWS\system32\tihcnhpr.dll",sitypnow
"Persistence"=C:\WINDOWS\system32\igfxpers.exe
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe"


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\P]
AutoRun\command- P:\LaunchU3.exe -a




-- End of Deckard's System Scanner: finished at 2007-10-15 00:51:55 ------------
  • 0

Advertisements


#17
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
and here is the extra.txt

Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------

-- System Information ----------------------------------------------------------

Microsoft Windows XP Home Edition (build 2600) SP 2.0
Architecture: X86; Language: English

CPU 0: Intel® Pentium® 4 CPU 3.06GHz
Percentage of Memory in Use: 75%
Physical Memory (total/avail): 503.3 MiB / 124.89 MiB
Pagefile Memory (total/avail): 1229.38 MiB / 1073.07 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1847.98 MiB

C: is Fixed (NTFS) - 142.96 GiB total, 3.55 GiB free.
D: is Fixed (FAT32) - 6.07 GiB total, 0.71 GiB free.
E: is CDROM (No Media)
F: is CDROM (No Media)
G: is CDROM (No Media)
H: is Removable (No Media)
I: is Removable (No Media)
J: is Removable (No Media)
K: is Removable (No Media)
L: is CDROM (No Media)
M: is CDROM (No Media)

\\.\PHYSICALDRIVE0 - ST3160023AS - 149.05 GiB - 2 partitions
\PARTITION0 - Unknown - 6.08 GiB - D:
\PARTITION1 (bootable) - Installable File System - 142.96 GiB - C:

\\.\PHYSICALDRIVE2 - Generic USB CF Reader USB Device

\\.\PHYSICALDRIVE4 - Generic USB MS Reader USB Device

\\.\PHYSICALDRIVE1 - Generic USB SD Reader USB Device

\\.\PHYSICALDRIVE3 - Generic USB SM Reader USB Device



-- Security Center -------------------------------------------------------------

AUOptions is set to notify before download.
Windows Internal Firewall is enabled.

FirstRunDisabled is set.
FirewallDisableNotify is set.

FW: BitDefender Internet Security v10 v7.2 (Softwin) Disabled
AV: BitDefender Internet Security v10 v7.2 (Softwin) Disabled Outdated
AV: Kaspersky Anti-Virus 6.0 v6.0.0.303 (Kaspersky Lab) Disabled

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\\iTunes\\iTunes.exe"="%ProgramFiles%\\iTunes\\iTunes.exe:*:enabled:iTunes"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe:*:Enabled:BackWeb for Pavilion"
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"="C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe:*:Enabled:Earthlink"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
"C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0"
"C:\\Program Files\\interMute\\SpySubtract\\SpySub.exe"="C:\\Program Files\\interMute\\SpySubtract\\SpySub.exe:*:Enabled:SpySubtract"
"C:\\Program Files\\interMute\\SpamSubtract\\SpamSub.exe"="C:\\Program Files\\interMute\\SpamSubtract\\SpamSub.exe:*:Enabled:SpamSubtract"
"C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:*:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:*:Enabled:ActiveSync Application"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares"
"C:\\Documents and Settings\\HP_Owner\\Shared\\PC Games - Unreal Tournament\\Unreal Tournament\\System\\UnrealTournament.exe"="C:\\Documents and Settings\\HP_Owner\\Shared\\PC Games - Unreal Tournament\\Unreal Tournament\\System\\UnrealTournament.exe:*:Enabled:UnrealTournament"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Disabled:Internet Explorer"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\kuntpunisher\\day of defeat source\\hl2.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\kuntpunisher\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\WINDOWS\\system32\\LEXPPS.EXE"="C:\\WINDOWS\\system32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
"C:\\Program Files\\Valve\\Steam\\SteamApps\\mzd3rch1c0\\counter-strike\\hl.exe"="C:\\Program Files\\Valve\\Steam\\SteamApps\\mzd3rch1c0\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Morpheus\\Morpheus.exe"="C:\\Program Files\\Morpheus\\Morpheus.exe:*:Enabled:M5Shell"
"D:\\StubInstaller.exe"="D:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Limewire Shared\\LimeWire\\LimeWire.exe"="C:\\Limewire Shared\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\aolsoftware.exe"="C:\\Program Files\\Common Files\\AOL\\1128563132\\ee\\aolsoftware.exe:*:Enabled:AOL Services"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Games\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe"="C:\\Games\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe:*:Enabled:XTCS Counter-Strike 1.6 Final Release"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Winamp\\winamp.exe"="C:\\Program Files\\Winamp\\winamp.exe:*:Enabled:Winamp"
"C:\\Program Files\\Opera\\Opera.exe"="C:\\Program Files\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\\WINDOWS\\system32\\ewptylnu.exe"="C:\\WINDOWS\\system32\\ewp"
"C:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe"="C:\\Program Files\\Pinnacle\\Studio 11\\programs\\RM.exe:*:Enabled:Render Manager"
"C:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe"="C:\\Program Files\\Pinnacle\\Studio 11\\programs\\Studio.exe:*:Enabled:Studio"
"C:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe"="C:\\Program Files\\Pinnacle\\Studio 11\\programs\\PMSRegisterFile.exe:*:Enabled:PMSRegisterFile"
"C:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe"="C:\\Program Files\\Pinnacle\\Studio 11\\programs\\umi.exe:*:Enabled:umi"


-- Environment Variables -------------------------------------------------------

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Kent\Application Data
CLASSPATH=.;C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=OSCARMAMARIL
ComSpec=C:\WINDOWS\system32\cmd.exe
DEFAULT_CA_NR=CA6
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Kent
LOGONSERVER=\\OSCARMAMARIL
NUMBER_OF_PROCESSORS=1
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\Diskeeper Corporation\Diskeeper\;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\;;C:\PROGRA~1\COMMON~1\MUVEET~1\030625;C:\Program Files\Pinnacle\Shared Files;C:\Program Files\Pinnacle\Shared Files\Filter
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre1.5.0_03\lib\ext\QTJava.zip
SAFEBOOT_OPTION=NETWORK
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Kent\LOCALS~1\Temp
TMP=C:\DOCUME~1\Kent\LOCALS~1\Temp
USERDOMAIN=OSCARMAMARIL
USERNAME=Kent
USERPROFILE=C:\Documents and Settings\Kent
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


-- User Profiles ---------------------------------------------------------------

HP_Owner (admin)
Kent (admin)
Administrator (admin)


-- Add/Remove Programs ---------------------------------------------------------

--> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
--> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
--> C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
--> c:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
--> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
--> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
--> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
--> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
--> C:\WINDOWS\UNRecode.exe /UNINSTALL
--> MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
µTorrent --> "C:\Program Files\uTorrent\uninstall.exe"
3GP Video Converter 3 --> C:\Program Files\ImTOO\3GP Video Converter 3\Uninstall.exe
Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe InDesign CS2 --> msiexec /I{7F4C8163-F259-49A0-A018-2857A90578BC}
Adobe Photoshop CS --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x9
Adobe Reader 7.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
Adobe® Photoshop® Album Starter Edition 3.0 --> MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
Agere Systems PCI Soft Modem --> agrsmdel
AIM "You've Got Pictures" Picture Finder Plugin v9.5.1.8 --> C:\Program Files\Common Files\YGP\Plugins\AIM\9_5_1_8a\YGPInstallerAim.exe /u -d"AIM" -p"AIM" -len-US-AIM
AIM 6.0 --> C:\Program Files\AIM6\uninst.exe
AnyDVD --> "C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD"
AOL Coach Version 1.0(Build:20040229.1 en) --> C:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe
AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM=
AOL Uninstaller (Choose which Products to Remove) --> C:\Program Files\Common Files\AOL\uninstaller.exe
Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
ArcSoft PhotoImpression --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6C5D7191-140A-11D6-B5A0-0050DA208A93}\Setup.exe" -l0x9 -uninst
AVI to MPEG Converter --> C:\PROGRA~1\AVITOM~1\UNWISE.EXE C:\PROGRA~1\AVITOM~1\INSTALL.LOG
AviSynth 2.5 --> "C:\Program Files\AviSynth 2.5\Uninstall.exe"
CC_ccProxyMSI --> MsiExec.exe /I{A398F2DC-D706-4bb2-AC38-5532CD229D08}
CC_ccStart --> MsiExec.exe /I{D6414CC7-F215-467F-88B1-546ED863F35B}
ccCommon --> MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
Citrix Presentation Server Client --> MsiExec.exe /I{B2AE44CB-2AAB-4C08-A54B-D264BD604DA8}
CloneDVD2 --> "C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
Counter-Strike™ --> MsiExec.exe /I{DF5A03CC-D5AA-43D8-B948-D9903F2AF94A}
DartViewer --> MsiExec.exe /X{BBF7D230-8F25-4041-90A9-73FD03BE8640}
dBpowerAMP AAC Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP AAC Codec.dat
dBpowerAMP FLAC Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP FLAC Codec.dat
dBpowerAMP Monkeys Audio Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
dBpowerAMP Mp3 (MPEG Suite 2000 CLI) --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Mp3 (MPEG Suite 2000 CLI).dat
dBpowerAMP Music Converter --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
dBpowerAMP Ogg Vorbis Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Ogg Vorbis Codec.dat
dBpowerAMP Shorten Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Shorten Codec.dat
dBpowerAMP Skin Designer --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Skin Designer.dat
dBpowerAMP Wavpack Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Wavpack Codec.dat
dBpowerAMP WMA V9 Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
dBpowerAMP WMA V9.1 Codec --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP WMA V9.1 Codec.dat
DeadAIM --> MsiExec.exe /I{25AF0BD1-DF07-4447-8E91-28E99617C556}
Diskeeper Professional Premier Edition --> MsiExec.exe /X{D6B79F07-62D1-46C9-A225-625ACC748144}
dMC Power Pack --> "C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dMC Power Pack.dat
Download Accelerator Plus (DAP) --> C:\PROGRA~1\DAP\DAPREMOVE.EXE
DVDx 2.0 --> "C:\Program Files\DVDx\unins000.exe"
eMule Plus 1.2 --> "C:\Program Files\eMule\unins000.exe"
EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
EZ Label Xpress 3.0 Full --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{3902CCB7-9D8D-4BCA-B9B1-20AA26432FBA}
Free Mp3 Wma Converter V 1.4.0 --> "C:\Program Files\Free Audio Pack\unins000.exe"
Half-Life® 2 --> MsiExec.exe /I{D45EC259-4A19-4656-B588-C2C360DD18EA}
Help and Support Additions --> C:\PROGRA~1\HELPAN~1\UNWISE.EXE C:\PROGRA~1\HELPAN~1\INSTALL.LOG
High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Format SDK (KB902344) --> "C:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe"
HP Deskjet Preloaded Printer Drivers --> MsiExec.exe /X{F419D20A-7719-4639-8E30-C073A040D878}
HP Image Zone 4.2.3 --> C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Image Zone Plus 4.2.3 --> C:\Program Files\HP\Digital Imaging\{0D182A5E-AEE0-42ca-BD1D-4EEB2FFA256D}\setup\hpzscr01.exe -datfile hpdscr01.dat
HP Multimedia Keyboard Software --> C:\HP\KBD\Install.exe /remove
HP Organize --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0122362-6333-4DE4-93F6-A5A2F3CC101A}\Setup.exe" UNINSTALL
HP Photosmart Cameras 4.0 --> C:\Program Files\HP\Digital Imaging\{4C04DF1B-6A39-4299-9DD1-1FA60000266E}\setup\hpzscr01.exe -datfile hpiscr01.dat
HP PSC & OfficeJet 4.0 --> "C:\Program Files\HP\Digital Imaging\{A1062847-0846-427A-92A1-BB8251A91E91}\setup\hpzscr01.exe" -datfile hposcr04.dat
HP Software Update --> MsiExec.exe /X{457791C5-D702-4143-A7B2-2744BE9573F2}
HPIZ423 --> MsiExec.exe /X{561A9B4E-2E48-4149-B977-59C7AFF62B52}
Image Resizer Powertoy for Windows XP --> MsiExec.exe /I{1CB92574-96F2-467B-B793-5CEB35C40C29}
ImTOO AVI MPEG Converter --> C:\Program Files\ImTOO\AVI MPEG Converter 3\Uninstall.exe
Intel® Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstall
IntelliMover Data Transfer Demo --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{14589F05-C658-4594-9429-D437BA688686}\Setup.exe" -l0x9
InterVideo DiscLabel --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C3F058C0-A21C-452D-8D99-95B1A45F417D}\setup.exe" REMOVEALL
InterVideo WinDVD Creator --> "C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
InterVideo WinDVD Player --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
iPod for Windows 2006-03-23 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2070F79D-46BC-4EEA-8F02-9B4DCABAE7CB} /l1033
IrfanView (remove only) --> C:\Program Files\IrfanView\iv_uninstall.exe
iTunes --> MsiExec.exe /I{AB90749C-7422-4580-8A7A-66CC5E9E5F98}
J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
Java 2 Runtime Environment, SE v1.4.2_03 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
Kaspersky Anti-Virus 6.0 --> MsiExec.exe /I{75193929-9A52-4CA4-98DE-8C7296940920}
Learn2 Player (Uninstall Only) --> C:\Program Files\Learn2.com\StRunner\stuninst.exe
Lexmark Z700-P700 Series --> C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBLUN5C.EXE -dLexmark Z700-P700 Series
LimeWire PRO 4.12.3 --> "C:\Program Files\LimeWire\uninstall.exe"
Lippincott's Review for NCLEX-PN 6e --> C:\PROGRA~1\LIPPIN~1\LRSNCL~1\UNWISE32.EXE C:\PROGRA~1\LIPPIN~1\LRSNCL~1\INSTALL.LOG
LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
LiveUpdate 2.5 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
LiveUpdate BVRP Software --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -l0x9
Macromedia Extension Manager --> MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}
Magic ISO Maker v5.3 (build 0229) --> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MC Web --> C:\WINDOWS\unvise32.exe C:\uninstal.log
Messenger Plus! 3 --> "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Microsoft ActiveSync 3.8 --> "C:\WINDOWS\ISUNINST.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
Microsoft Base Smart Card Cryptographic Service Provider Package --> "C:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe"
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Expression Web --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall WEBDESIGNER /dll ESETUP.DLL
Microsoft Expression Web --> MsiExec.exe /X{90120000-0026-0000-0000-0000000FF1CE}
Microsoft Expression Web MUI (English) --> MsiExec.exe /X{90120000-0026-0409-0000-0000000FF1CE}
Microsoft Office FrontPage 2003 --> MsiExec.exe /I{90170409-6000-11D3-8CFE-0150048383C9}
Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
Microsoft Office XP Media Content --> MsiExec.exe /I{90300409-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Professional --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0050048383C9}
Microsoft Office XP Web Components --> MsiExec.exe /I{90260409-6000-11D3-8CFE-0050048383C9}
Microsoft Plus! Digital Media Edition Installer --> MsiExec.exe /X{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}
Microsoft Plus! Photo Story 2 LE --> MsiExec.exe /X{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Works --> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
middle_man --> "C:\PROGRA~1\AIM\UninstallMM.exe"
Mihov Image Resizer (remove only) --> "C:\Program Files\Mihov Image Resizer\Uninstall.exe"
mobile PhoneTools --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}\setup.exe" -l0x9
Move Networks Player for Firefox --> "C:\Program Files\Mozilla Firefox\plugins\unins000.exe"
Move Networks Player for Internet Explorer --> "C:\Documents and Settings\Kent\Application Data\Move Networks\ie_bin\unins000.exe"
Mozilla Firefox (2.0.0.6) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe
Mozilla Firefox (2.0.0.7) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN --> C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
MSN Messenger 7.5 --> MsiExec.exe /I{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5}
MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
MSN Toolbar --> C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\mtbs.exe c
MSRedist --> MsiExec.exe /I{FC37ABD0-2108-4beb-B010-1254E0662B5A}
MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Multiple Image Resizer .NET --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A46CD8B-9BBB-4F2D-810C-5C3DAA0E2B20}
muvee autoProducer 3.5 magicMoments - HPD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B103C8A7-D1CC-4B1A-BD41-883F652E097D}\setup.exe" -l0x9
Native Instruments Traktor DJ Studio 3 --> C:\PROGRA~1\NATIVE~1\TRAKTO~1\UNWISE.EXE C:\PROGRA~1\NATIVE~1\TRAKTO~1\INSTALL.LOG
Nero 7 Demo --> MsiExec.exe /I{38E0C491-5230-4373-B62E-F1A6E94B1033}
Norton Internet Security --> MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
Norton Internet Security --> MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
Norton Internet Security --> MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
Norton Internet Security --> MsiExec.exe /I{91AA4B1F-B918-4e0b-A304-F8D4EC5D7726}
Norton Internet Security --> MsiExec.exe /I{C9D599E1-6B68-4a1f-8A4F-A1DB433DB1BF}
Norton Internet Security --> MsiExec.exe /I{E47EE8FB-ACC0-4608-859C-4E2851B18A6A}
Norton Internet Security --> MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
Norton Personal Firewall --> MsiExec.exe /I{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}
Norton Personal Firewall (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{3BD0196C-6553-460c-A0C4-90D8AE5D60D2}.exe /X
Norton Security Center --> MsiExec.exe /X{503AA035-41E2-4858-B31F-1E49AC66C309}
ObjectDock --> C:\PROGRA~1\Stardock\OBJECT~1\UNWISE.EXE C:\PROGRA~1\Stardock\OBJECT~1\INSTALL.LOG
Opera 9.10 --> MsiExec.exe /X{750B9AD1-4C63-4143-94C5-6FB304199BAD}
Photosmart 320,370,7400,8100,8400 Series --> C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\setup\hpzscr01.exe -datfile hphscr01.dat
Pinnacle Instant DVD Recorder --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}\setup.exe" -l0x9 UNINSTALL
PowerCDR Express --> MsiExec.exe /I{9B2B0EAD-2CC7-4589-B3AA-D23BAB724065}
PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"
PS2 --> C:\WINDOWS\system32\ps2.exe uninstall
Python 2.2 combined Win32 extensions --> C:\Python22\Lib\SITE-P~1\UNWISE~1.EXE C:\Python22\Lib\SITE-P~1\w32inst.log
Python 2.2.1 --> C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
QuickTime --> MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
Realtek High Definition Audio Driver --> RtlUpd.exe -r
Registry Mechanic 6.0 --> "C:\Program Files\Registry Mechanic\unins000.exe"
Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
Sonic Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
Sony Ericsson PC Suite 1.20.173 --> MsiExec.exe /I{C5ADA65A-7828-4D85-B071-ECC52B51F794}
Sony Ericsson Themes Creator 3.02 --> C:\Program Files\Sony Ericsson\Themes Creator\Uninstall.exe
Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Steam™ --> MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
Studio 11 --> C:\Program Files\InstallShield Installation Information\{110B1ADF-2EAE-4E8F-B501-D2A1E6D8ED9D}\Setup2.exe -runfromtemp -l0x0009 UNINSTALL -removeonly
StyleXP (remove only) --> "C:\Program Files\TGTSoft\StyleXP\StyleXP-uninstall.exe"
Super Granny from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\3F34F72F-9BB0-4B73-8312-558953ACF56F\Uninstall.exe"
TablePCRT --> MsiExec.exe /X{C46A5F24-B91F-477C-B634-DB99A7D7792A}
Tradewinds from Hewlett-Packard Desktops (remove only) --> "C:\Program Files\WildTangent\Apps\GameChannel\Games\F5215F01-DFC0-475D-A910-6F1AF94E807E\Uninstall.exe"
TrojanHunter 4.5 --> "C:\Program Files\TrojanHunter 4.5\unins000.exe"
TuneUp Utilities 2006 --> MsiExec.exe /I{868D7896-99D4-4513-BC62-2B3AD3E24926}
Ulead DVD MovieFactory 5 Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF164702-AF8B-4F2F-8038-74A4C536866B}\setup.exe" -l0x9
Updates from HP --> C:\WINDOWS\BWUnin-6.3.2.62.exe -AppId 309731
Veoh Player --> C:\Program Files\InstallShield Installation Information\{3D5A72E1-1467-4199-8CF6-12DA8D502A6B}\setup.exe -runfromtemp -l0x0409
ViaDuct 2000 --> C:\WINDOWS\IsUninst.exe -fC:\VIADCT32\Uninst.isu
Video GIF AVI ThumbCell Creater Free Version v1.2 --> "C:\Program Files\Video GIF AVI ThumbCell Creater\unins000.exe"
Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
Virtual DJ - Atomix Productions --> C:\PROGRA~1\VIRTUA~1\UNWISE.EXE C:\PROGRA~1\VIRTUA~1\INSTALL.LOG
Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
WindowBlinds --> C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\UNWISE.EXE C:\PROGRA~1\Stardock\OBJECT~2\WINDOW~1\INSTALL.LOG
Windows Communication Foundation --> MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Imaging Component --> "C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Presentation Foundation --> MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation --> MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
XML Paper Specification Shared Components Pack 1.0 -->
XviD 1.1 final uninstall --> "C:\Program Files\XviD\unins000.exe"
Yahoo! Desktop Login --> MsiExec.exe /I{F9AEEC34-CF00-4CBD-9E36-DF9DC4002685}
Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe


-- Application Event Log -------------------------------------------------------

Event Record #/Type5143 / Error
Event Submitted/Written: 10/14/2007 06:55:56 PM
Event ID/Source: 1015 / Winlogon
Event Description:
A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code 00000000. The machine
must now be restarted.

Event Record #/Type5128 / Error
Event Submitted/Written: 10/13/2007 02:22:05 PM
Event ID/Source: 1008 / MsiInstaller
Event Description:
The installation of C:\WINDOWS\Installer\c044.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Event Record #/Type5127 / Error
Event Submitted/Written: 10/13/2007 02:22:05 PM
Event ID/Source: 1008 / MsiInstaller
Event Description:
The installation of C:\WINDOWS\Installer\c044.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Event Record #/Type5126 / Error
Event Submitted/Written: 10/13/2007 02:22:05 PM
Event ID/Source: 1008 / MsiInstaller
Event Description:
The installation of c:\WINDOWS\Installer\96af7.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Event Record #/Type5125 / Error
Event Submitted/Written: 10/13/2007 02:22:05 PM
Event ID/Source: 1008 / MsiInstaller
Event Description:
The installation of c:\WINDOWS\Installer\96af7.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.



-- Security Event Log ----------------------------------------------------------

No Errors/Warnings found.


-- System Event Log ------------------------------------------------------------

Event Record #/Type93975 / Error
Event Submitted/Written: 10/15/2007 00:11:14 AM
Event ID/Source: 7026 / Service Control Manager
Event Description:
The following boot-start or system-start driver(s) failed to load:
ASPI32
Fips
intelppm
kl1
klif
SCDEmu
StyleXPHelper
SYMTDI

Event Record #/Type93974 / Error
Event Submitted/Written: 10/15/2007 00:10:24 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Event Record #/Type93973 / Error
Event Submitted/Written: 10/15/2007 00:10:02 AM
Event ID/Source: 30013 / ipnathlp
Event Description:
The DHCP allocator has disabled itself on IP address 192.168.1.101,
since the IP address is outside the 192.168.0.0/255.255.255.0 scope
from which addresses are being allocated to DHCP clients.
To enable the DHCP allocator on this IP address,
please change the scope to include the IP address,
or change the IP address to fall within the scope.

Event Record #/Type93972 / Error
Event Submitted/Written: 10/15/2007 00:10:02 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1084" attempting to start the service ALG with arguments ""
in order to run the server:
{D6015EC3-FA16-4813-9CA1-DA204574F5DA}

Event Record #/Type93971 / Error
Event Submitted/Written: 10/15/2007 00:10:02 AM
Event ID/Source: 10005 / DCOM
Event Description:
DCOM got error "%%1058" attempting to start the service upnphost with arguments ""
in order to run the server:
{204810B9-73B2-11D4-BF42-00B0D0118B56}



-- End of Deckard's System Scanner: finished at 2007-10-15 00:51:55 ------------
  • 0

#18
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
sorry again for the attachments
  • 0

#19
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
No problem. :)

1.Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Files to delete:
C:\WINDOWS\system32\gelnihsr.exe 
C:\WINDOWS\system32\mbkfwfgn.exe 
C:\WINDOWS\system32\dnqnepfw.exe 
C:\WINDOWS\system32\jfwrxtrg.exe 
C:\WINDOWS\system32\xbpaoyop.exe 
C:\WINDOWS\system32\yhcvvvim.exe 
C:\WINDOWS\system32\hwugjfqh.exe 
C:\WINDOWS\system32\oekuilff.exe 
C:\WINDOWS\system32\uplkxpkh.exe
C:\WINDOWS\system32\cryptsva.dll
C:\WINDOWS\system32\duxgbkrt.exe 
C:\WINDOWS\system32\malnvsid.exe 
C:\WINDOWS\system32\drivers\jmwsmxkv.sys
C:\WINDOWS\system32\comaddi.dll
C:\WINDOWS\system32\djqfhsn.dll
C:\WINDOWS\system32\drivers\coohlwms.sys
C:\WINDOWS\system32\turkcmlr.exe 
C:\WINDOWS\system32\tdnblsyp.exe 
C:\WINDOWS\system32\wsentjip.exe 
C:\WINDOWS\system32\utyedard.exe 
C:\WINDOWS\system32\jtjcfuhd.exe 
C:\WINDOWS\system32\jyijuiyu.exe 
C:\WINDOWS\system32\sfiqjqis.exe 
C:\WINDOWS\system32\dihqnfiw.exe 
C:\WINDOWS\system32\loytijnr.exe 
C:\WINDOWS\system32\kuvjrgkn.exe 
C:\WINDOWS\system32\dniiutqn.exe 
C:\WINDOWS\system32\hvtxbfrx.exe 
C:\WINDOWS\system32\aajavlmu.exe 
C:\WINDOWS\system32\fwynsrdj.exe 
C:\WINDOWS\system32\alfemeiy.exe 
C:\WINDOWS\system32\dxfdothm.exe 
C:\WINDOWS\system32\xetlijiu.exe 
C:\WINDOWS\system32\jvhlovxi.exe 
C:\WINDOWS\system32\wukmusea.exe 
C:\WINDOWS\system32\whmcrvsj.exe 
C:\WINDOWS\system32\ipphseug.exe 
C:\WINDOWS\system32\mkugioqi.exe 
C:\WINDOWS\system32\duqoroxt.exe 
C:\WINDOWS\system32\jkofxmkh.exe
C:\WINDOWS\system32\gvkdinpk.exe 
C:\WINDOWS\system32\alrcwofr.exe 
C:\WINDOWS\system32\toeqnomx.exe 
C:\WINDOWS\system32\sfbphhvl.exe 
C:\WINDOWS\system32\tjjvopsb.exe 
C:\WINDOWS\system32\eimwelfo.exe 
C:\WINDOWS\system32\qcifeqmt.exe 
C:\WINDOWS\system32\unxqjkdq.exe 
C:\WINDOWS\system32\gwuhnjwi.exe 
C:\WINDOWS\system32\tboikamb.exe 
C:\WINDOWS\system32\onphsxqi.exe 
C:\WINDOWS\system32\iecpewka.exe 
C:\WINDOWS\system32\tfywfoag.exe 
C:\WINDOWS\system32\gkgnwigm.exe
C:\WINDOWS\system32\cjhcwyrv.exe
C:\WINDOWS\system32\ijsprjxb.exe
C:\WINDOWS\system32\dhfsqbqr.exe 
C:\WINDOWS\system32\fowhurxy.exe 
C:\WINDOWS\system32\kqpcevsu.exe 
C:\WINDOWS\system32\djyyifwu.exe 
C:\WINDOWS\system32\njkocwph.exe 
C:\WINDOWS\system32\vkackwdv.exe 
C:\WINDOWS\system32\ldhiumsb.exe 
C:\WINDOWS\system32\lhvlmcty.exe 
C:\WINDOWS\system32\phhisrpb.exe 
C:\WINDOWS\system32\vqhjluwh.exe 
C:\WINDOWS\system32\eafsegnr.exe 
C:\WINDOWS\system32\frsqnevt.exe 
C:\WINDOWS\system32\vgmnpblu.exe 
C:\WINDOWS\system32\bkdmpwxf.exe
C:\WINDOWS\system32\qxpglalv.exe
C:\WINDOWS\system32\ncgiscci.exe
C:\WINDOWS\system32\eljfonwp.exe
C:\WINDOWS\system32\ejrnjjdk.exe 
C:\WINDOWS\system32\mthydijq.exe
C:\WINDOWS\system32\qrfvcjeh.exe
C:\WINDOWS\system32\ejqoohxr.exe
C:\WINDOWS\system32\miglvumo.exe 
C:\WINDOWS\system32\bqchjhxr.exe 
C:\WINDOWS\system32\jwxnrdnn.exe
C:\WINDOWS\system32\lmddxjam.exe
C:\WINDOWS\system32\kkttfcty.exe 
C:\WINDOWS\system32\xbybiely.exe
C:\WINDOWS\system32\repinkly.exe 
C:\WINDOWS\system32\wxaljrka.exe
C:\WINDOWS\system32\cmymcveo.exe
C:\WINDOWS\system32\qmpqeifj.exe 
C:\WINDOWS\system32\yaowydmt.exe
C:\WINDOWS\system32\egafhqke.exe
C:\WINDOWS\system32\jwqttdqr.exe 
C:\WINDOWS\system32\ajftrmrg.exe
C:\WINDOWS\system32\qwdwlvis.exe
C:\WINDOWS\system32\ufjvjefy.exe
C:\WINDOWS\system32\biwwqgqo.exe 
C:\WINDOWS\system32\bxdbtmip.exe 
C:\WINDOWS\system32\fdoygvbc.exe
C:\WINDOWS\system32\srnultya.exe
C:\WINDOWS\system32\jvlibgfw.exe 
C:\WINDOWS\system32\pwmnfwak.exe
C:\WINDOWS\system32\bujqkwqg.exe 
C:\WINDOWS\system32\cwldftju.exe
C:\WINDOWS\system32\dprwiyub.exe
C:\WINDOWS\system32\kwpmalnp.exe
C:\WINDOWS\system32\dqyqxsih.exe
C:\WINDOWS\system32\jikaqtno.exe
C:\WINDOWS\system32\bcoqflmh.exe
C:\WINDOWS\system32\jecbgxdr.exe
C:\WINDOWS\system32\ulmsgbtk.exe
C:\WINDOWS\system32\hgyhvejm.exe 
C:\WINDOWS\system32\vicynhrx.dll
C:\WINDOWS\system32\pvwlgeya.exe 
C:\WINDOWS\system32\nykijyjr.exe 
C:\WINDOWS\system32\muvqxvql.exe
C:\WINDOWS\system32\ouldhhks.exe
C:\WINDOWS\system32\tvscetsi.exe
C:\WINDOWS\system32\awyrbjcf.exe 
C:\WINDOWS\system32\pwcdrrch.exe
C:\WINDOWS\system32\yfsxnsno.exe
C:\WINDOWS\system32\vlrnfuhl.exe
C:\WINDOWS\system32\jlsjdadm.exe
C:\WINDOWS\system32\dmdnwxoi.exe
C:\WINDOWS\system32\wrumtpei.exe
C:\WINDOWS\system32\tfoogfgc.exe
C:\WINDOWS\system32\gnuxrand.exe
C:\WINDOWS\system32\jkindolm.exe
C:\WINDOWS\system32\idkxgbju.exe
C:\WINDOWS\system32\uklialsr.exe
C:\WINDOWS\system32\fnubjdka.exe
C:\WINDOWS\system32\wlvfywnd.exe
C:\WINDOWS\system32\ebeijatl.exe
C:\WINDOWS\system32\rysxqegy.exe
C:\WINDOWS\system32\xoxsioxg.exe
C:\WINDOWS\system32\klgfyife.exe
C:\WINDOWS\system32\dfkhgjtq.exe
C:\WINDOWS\system32\gfdrqjls.dll
C:\WINDOWS\system32\ydsgrmcx.exe
C:\WINDOWS\system32\yijjynhs.exe
C:\WINDOWS\system32\cqrqdqap.exe
C:\WINDOWS\system32\eaykkcoo.dll
C:\WINDOWS\system32\aephbyrq.exe
C:\WINDOWS\system32\wwqrysnr.exe
C:\WINDOWS\system32\qykmjaok.exe
C:\WINDOWS\system32\fdtctvap.exe
C:\WINDOWS\system32\vondahac.exe
C:\WINDOWS\system32\lyqcgfsr.exe
C:\WINDOWS\system32\hrbdmqjj.exe
C:\WINDOWS\system32\mbjodnlr.exe
C:\WINDOWS\system32\qrvtayyi.exe
C:\WINDOWS\system32\kijnmjxw.exe
C:\WINDOWS\system32\lcgehnrd.exe
C:\WINDOWS\system32\kykevwos.exe
C:\WINDOWS\system32\kkgidcuq.exe
C:\WINDOWS\system32\ysfhjpsm.exe
C:\WINDOWS\system32\vxwuwajr.exe
C:\WINDOWS\system32\emjwxsbl.exe
C:\WINDOWS\system32\fixhllik.exe
C:\WINDOWS\system32\huwnoygf.exe
C:\WINDOWS\system32\dpxkycfp.exe
C:\WINDOWS\system32\bvasruwp.exe
C:\WINDOWS\system32\vahpixhy.exe
C:\WINDOWS\system32\yfyaphis.dll
C:\WINDOWS\system32\yehwhift.exe
C:\WINDOWS\system32\kovssvbt.dll
C:\WINDOWS\system32\ksruawvt.exe
C:\WINDOWS\system32\vmwysees.exe
C:\WINDOWS\system32\ppyldnwj.dll
C:\WINDOWS\system32\rstparab.exe
C:\WINDOWS\system32\jsuyyqje.exe
C:\WINDOWS\system32\secrtjrg.exe
C:\WINDOWS\system32\ohefsopx.exe
C:\WINDOWS\system32\lmwlskyy.exe
C:\WINDOWS\system32\dxfmfvdu.exe
C:\WINDOWS\system32\bsqhnsib.exe
C:\WINDOWS\system32\tvxtwwxv.exe
C:\WINDOWS\system32\cgnulkci.exe
C:\WINDOWS\system32\rjklcuji.exe
C:\WINDOWS\system32\jpfeujcl.exe
C:\WINDOWS\system32\rgyvwyjr.exe
C:\WINDOWS\system32\gjnkhxfk.exe
C:\WINDOWS\system32\fainjfeb.exe
C:\WINDOWS\system32\dqfmcfti.exe
C:\WINDOWS\system32\ljgaiwaw.exe
C:\WINDOWS\system32\vuvijarb.exe
C:\WINDOWS\system32\jnohlhbk.exe
C:\WINDOWS\system32\pmneqbwd.exe
C:\WINDOWS\system32\thwsfyyv.exe
C:\WINDOWS\system32\fldabjwx.dll
C:\WINDOWS\system32\xtqvwniy.exe
C:\WINDOWS\system32\vopwnect.dll
C:\WINDOWS\system32\pbgtodee.exe
C:\WINDOWS\system32\rqehndhr.dll
C:\WINDOWS\system32\fivnpekq.exe
C:\WINDOWS\system32\clbbdlgj.exe
C:\WINDOWS\system32\wlbxrjtx.exe
C:\WINDOWS\system32\jmieyhyp.exe
C:\WINDOWS\system32\gaiyykeh.exe
C:\WINDOWS\system32\kkaosqvr.exe
C:\WINDOWS\system32\bmkhidev.exe
C:\WINDOWS\system32\gcuxoapo.exe
C:\WINDOWS\system32\xtjerxdu.exe
C:\WINDOWS\system32\ksqsoelb.dll
C:\WINDOWS\AppPatch\natimxl.dll
C:\WINDOWS\system32\fbiugbyy.dll
C:\WINDOWS\system32\svlesekg.dll
C:\WINDOWS\system32\acpbapku.dll
C:\WINDOWS\system32\pjditur.dll
C:\WINDOWS\system32\j6221430.dll
C:\WINDOWS\system32\tihcnhpr.dll


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
3. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
==========================================
Please run Vundofix again after the Avenger.

Post back with these logs please.
Avenger .txt
Vundofix
New Hijackthis log

  • 0

#20
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
hey kandah,

here is the avenger text:

//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Error: could not create zip file.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fgurygdw

*******************

Script file located at: \??\C:\Documents and Settings\ljjjwpri.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\gelnihsr.exe deleted successfully.
File C:\WINDOWS\system32\mbkfwfgn.exe deleted successfully.
File C:\WINDOWS\system32\dnqnepfw.exe deleted successfully.
File C:\WINDOWS\system32\jfwrxtrg.exe deleted successfully.
File C:\WINDOWS\system32\xbpaoyop.exe deleted successfully.
File C:\WINDOWS\system32\yhcvvvim.exe deleted successfully.
File C:\WINDOWS\system32\hwugjfqh.exe deleted successfully.
File C:\WINDOWS\system32\oekuilff.exe deleted successfully.
File C:\WINDOWS\system32\uplkxpkh.exe deleted successfully.
File C:\WINDOWS\system32\cryptsva.dll deleted successfully.
File C:\WINDOWS\system32\duxgbkrt.exe deleted successfully.
File C:\WINDOWS\system32\malnvsid.exe deleted successfully.


Could not open file C:\WINDOWS\system32\drivers\jmwsmxkv.sys for deletion
Deletion of file C:\WINDOWS\system32\drivers\jmwsmxkv.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\jmwsmxkv.sys
Status: 0xc0000022

File C:\WINDOWS\system32\comaddi.dll deleted successfully.


Could not open file C:\WINDOWS\system32\djqfhsn.dll for deletion
Deletion of file C:\WINDOWS\system32\djqfhsn.dll failed!

Could not process line:
C:\WINDOWS\system32\djqfhsn.dll
Status: 0xc0000022



Could not open file C:\WINDOWS\system32\drivers\coohlwms.sys for deletion
Deletion of file C:\WINDOWS\system32\drivers\coohlwms.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\coohlwms.sys
Status: 0xc0000022

File C:\WINDOWS\system32\turkcmlr.exe deleted successfully.
File C:\WINDOWS\system32\tdnblsyp.exe deleted successfully.
File C:\WINDOWS\system32\wsentjip.exe deleted successfully.
File C:\WINDOWS\system32\utyedard.exe deleted successfully.
File C:\WINDOWS\system32\jtjcfuhd.exe deleted successfully.
File C:\WINDOWS\system32\jyijuiyu.exe deleted successfully.
File C:\WINDOWS\system32\sfiqjqis.exe deleted successfully.
File C:\WINDOWS\system32\dihqnfiw.exe deleted successfully.
File C:\WINDOWS\system32\loytijnr.exe deleted successfully.
File C:\WINDOWS\system32\kuvjrgkn.exe deleted successfully.
File C:\WINDOWS\system32\dniiutqn.exe deleted successfully.
File C:\WINDOWS\system32\hvtxbfrx.exe deleted successfully.
File C:\WINDOWS\system32\aajavlmu.exe deleted successfully.
File C:\WINDOWS\system32\fwynsrdj.exe deleted successfully.
File C:\WINDOWS\system32\alfemeiy.exe deleted successfully.
File C:\WINDOWS\system32\dxfdothm.exe deleted successfully.
File C:\WINDOWS\system32\xetlijiu.exe deleted successfully.
File C:\WINDOWS\system32\jvhlovxi.exe deleted successfully.
File C:\WINDOWS\system32\wukmusea.exe deleted successfully.
File C:\WINDOWS\system32\whmcrvsj.exe deleted successfully.
File C:\WINDOWS\system32\ipphseug.exe deleted successfully.
File C:\WINDOWS\system32\mkugioqi.exe deleted successfully.
File C:\WINDOWS\system32\duqoroxt.exe deleted successfully.
File C:\WINDOWS\system32\jkofxmkh.exe deleted successfully.
File C:\WINDOWS\system32\gvkdinpk.exe deleted successfully.
File C:\WINDOWS\system32\alrcwofr.exe deleted successfully.
File C:\WINDOWS\system32\toeqnomx.exe deleted successfully.
File C:\WINDOWS\system32\sfbphhvl.exe deleted successfully.
File C:\WINDOWS\system32\tjjvopsb.exe deleted successfully.
File C:\WINDOWS\system32\eimwelfo.exe deleted successfully.
File C:\WINDOWS\system32\qcifeqmt.exe deleted successfully.
File C:\WINDOWS\system32\unxqjkdq.exe deleted successfully.
File C:\WINDOWS\system32\gwuhnjwi.exe deleted successfully.
File C:\WINDOWS\system32\tboikamb.exe deleted successfully.
File C:\WINDOWS\system32\onphsxqi.exe deleted successfully.
File C:\WINDOWS\system32\iecpewka.exe deleted successfully.
File C:\WINDOWS\system32\tfywfoag.exe deleted successfully.
File C:\WINDOWS\system32\gkgnwigm.exe deleted successfully.
File C:\WINDOWS\system32\cjhcwyrv.exe deleted successfully.
File C:\WINDOWS\system32\ijsprjxb.exe deleted successfully.
File C:\WINDOWS\system32\dhfsqbqr.exe deleted successfully.
File C:\WINDOWS\system32\fowhurxy.exe deleted successfully.
File C:\WINDOWS\system32\kqpcevsu.exe deleted successfully.
File C:\WINDOWS\system32\djyyifwu.exe deleted successfully.
File C:\WINDOWS\system32\njkocwph.exe deleted successfully.
File C:\WINDOWS\system32\vkackwdv.exe deleted successfully.
File C:\WINDOWS\system32\ldhiumsb.exe deleted successfully.
File C:\WINDOWS\system32\lhvlmcty.exe deleted successfully.
File C:\WINDOWS\system32\phhisrpb.exe deleted successfully.
File C:\WINDOWS\system32\vqhjluwh.exe deleted successfully.
File C:\WINDOWS\system32\eafsegnr.exe deleted successfully.
File C:\WINDOWS\system32\frsqnevt.exe deleted successfully.
File C:\WINDOWS\system32\vgmnpblu.exe deleted successfully.
File C:\WINDOWS\system32\bkdmpwxf.exe deleted successfully.
File C:\WINDOWS\system32\qxpglalv.exe deleted successfully.
File C:\WINDOWS\system32\ncgiscci.exe deleted successfully.
File C:\WINDOWS\system32\eljfonwp.exe deleted successfully.
File C:\WINDOWS\system32\ejrnjjdk.exe deleted successfully.
File C:\WINDOWS\system32\mthydijq.exe deleted successfully.
File C:\WINDOWS\system32\qrfvcjeh.exe deleted successfully.
File C:\WINDOWS\system32\ejqoohxr.exe deleted successfully.
File C:\WINDOWS\system32\miglvumo.exe deleted successfully.
File C:\WINDOWS\system32\bqchjhxr.exe deleted successfully.
File C:\WINDOWS\system32\jwxnrdnn.exe deleted successfully.
File C:\WINDOWS\system32\lmddxjam.exe deleted successfully.
File C:\WINDOWS\system32\kkttfcty.exe deleted successfully.
File C:\WINDOWS\system32\xbybiely.exe deleted successfully.
File C:\WINDOWS\system32\repinkly.exe deleted successfully.
File C:\WINDOWS\system32\wxaljrka.exe deleted successfully.
File C:\WINDOWS\system32\cmymcveo.exe deleted successfully.
File C:\WINDOWS\system32\qmpqeifj.exe deleted successfully.
File C:\WINDOWS\system32\yaowydmt.exe deleted successfully.
File C:\WINDOWS\system32\egafhqke.exe deleted successfully.
File C:\WINDOWS\system32\jwqttdqr.exe deleted successfully.
File C:\WINDOWS\system32\ajftrmrg.exe deleted successfully.
File C:\WINDOWS\system32\qwdwlvis.exe deleted successfully.
File C:\WINDOWS\system32\ufjvjefy.exe deleted successfully.
File C:\WINDOWS\system32\biwwqgqo.exe deleted successfully.
File C:\WINDOWS\system32\bxdbtmip.exe deleted successfully.
File C:\WINDOWS\system32\fdoygvbc.exe deleted successfully.
File C:\WINDOWS\system32\srnultya.exe deleted successfully.
File C:\WINDOWS\system32\jvlibgfw.exe deleted successfully.
File C:\WINDOWS\system32\pwmnfwak.exe deleted successfully.
File C:\WINDOWS\system32\bujqkwqg.exe deleted successfully.
File C:\WINDOWS\system32\cwldftju.exe deleted successfully.
File C:\WINDOWS\system32\dprwiyub.exe deleted successfully.
File C:\WINDOWS\system32\kwpmalnp.exe deleted successfully.
File C:\WINDOWS\system32\dqyqxsih.exe deleted successfully.
File C:\WINDOWS\system32\jikaqtno.exe deleted successfully.
File C:\WINDOWS\system32\bcoqflmh.exe deleted successfully.
File C:\WINDOWS\system32\jecbgxdr.exe deleted successfully.
File C:\WINDOWS\system32\ulmsgbtk.exe deleted successfully.
File C:\WINDOWS\system32\hgyhvejm.exe deleted successfully.
File C:\WINDOWS\system32\vicynhrx.dll deleted successfully.
File C:\WINDOWS\system32\pvwlgeya.exe deleted successfully.
File C:\WINDOWS\system32\nykijyjr.exe deleted successfully.
File C:\WINDOWS\system32\muvqxvql.exe deleted successfully.
File C:\WINDOWS\system32\ouldhhks.exe deleted successfully.
File C:\WINDOWS\system32\tvscetsi.exe deleted successfully.
File C:\WINDOWS\system32\awyrbjcf.exe deleted successfully.
File C:\WINDOWS\system32\pwcdrrch.exe deleted successfully.
File C:\WINDOWS\system32\yfsxnsno.exe deleted successfully.
File C:\WINDOWS\system32\vlrnfuhl.exe deleted successfully.
File C:\WINDOWS\system32\jlsjdadm.exe deleted successfully.
File C:\WINDOWS\system32\dmdnwxoi.exe deleted successfully.
File C:\WINDOWS\system32\wrumtpei.exe deleted successfully.
File C:\WINDOWS\system32\tfoogfgc.exe deleted successfully.
File C:\WINDOWS\system32\gnuxrand.exe deleted successfully.
File C:\WINDOWS\system32\jkindolm.exe deleted successfully.
File C:\WINDOWS\system32\idkxgbju.exe deleted successfully.
File C:\WINDOWS\system32\uklialsr.exe deleted successfully.
File C:\WINDOWS\system32\fnubjdka.exe deleted successfully.
File C:\WINDOWS\system32\wlvfywnd.exe deleted successfully.
File C:\WINDOWS\system32\ebeijatl.exe deleted successfully.
File C:\WINDOWS\system32\rysxqegy.exe deleted successfully.
File C:\WINDOWS\system32\xoxsioxg.exe deleted successfully.
File C:\WINDOWS\system32\klgfyife.exe deleted successfully.
File C:\WINDOWS\system32\dfkhgjtq.exe deleted successfully.
File C:\WINDOWS\system32\gfdrqjls.dll deleted successfully.
File C:\WINDOWS\system32\ydsgrmcx.exe deleted successfully.
File C:\WINDOWS\system32\yijjynhs.exe deleted successfully.
File C:\WINDOWS\system32\cqrqdqap.exe deleted successfully.
File C:\WINDOWS\system32\eaykkcoo.dll deleted successfully.
File C:\WINDOWS\system32\aephbyrq.exe deleted successfully.
File C:\WINDOWS\system32\wwqrysnr.exe deleted successfully.
File C:\WINDOWS\system32\qykmjaok.exe deleted successfully.
File C:\WINDOWS\system32\fdtctvap.exe deleted successfully.
File C:\WINDOWS\system32\vondahac.exe deleted successfully.
File C:\WINDOWS\system32\lyqcgfsr.exe deleted successfully.
File C:\WINDOWS\system32\hrbdmqjj.exe deleted successfully.
File C:\WINDOWS\system32\mbjodnlr.exe deleted successfully.
File C:\WINDOWS\system32\qrvtayyi.exe deleted successfully.
File C:\WINDOWS\system32\kijnmjxw.exe deleted successfully.
File C:\WINDOWS\system32\lcgehnrd.exe deleted successfully.
File C:\WINDOWS\system32\kykevwos.exe deleted successfully.
File C:\WINDOWS\system32\kkgidcuq.exe deleted successfully.
File C:\WINDOWS\system32\ysfhjpsm.exe deleted successfully.
File C:\WINDOWS\system32\vxwuwajr.exe deleted successfully.
File C:\WINDOWS\system32\emjwxsbl.exe deleted successfully.
File C:\WINDOWS\system32\fixhllik.exe deleted successfully.
File C:\WINDOWS\system32\huwnoygf.exe deleted successfully.
File C:\WINDOWS\system32\dpxkycfp.exe deleted successfully.
File C:\WINDOWS\system32\bvasruwp.exe deleted successfully.
File C:\WINDOWS\system32\vahpixhy.exe deleted successfully.
File C:\WINDOWS\system32\yfyaphis.dll deleted successfully.
File C:\WINDOWS\system32\yehwhift.exe deleted successfully.
File C:\WINDOWS\system32\kovssvbt.dll deleted successfully.
File C:\WINDOWS\system32\ksruawvt.exe deleted successfully.
File C:\WINDOWS\system32\vmwysees.exe deleted successfully.
File C:\WINDOWS\system32\ppyldnwj.dll deleted successfully.
File C:\WINDOWS\system32\rstparab.exe deleted successfully.
File C:\WINDOWS\system32\jsuyyqje.exe deleted successfully.
File C:\WINDOWS\system32\secrtjrg.exe deleted successfully.
File C:\WINDOWS\system32\ohefsopx.exe deleted successfully.
File C:\WINDOWS\system32\lmwlskyy.exe deleted successfully.
File C:\WINDOWS\system32\dxfmfvdu.exe deleted successfully.
File C:\WINDOWS\system32\bsqhnsib.exe deleted successfully.
File C:\WINDOWS\system32\tvxtwwxv.exe deleted successfully.
File C:\WINDOWS\system32\cgnulkci.exe deleted successfully.
File C:\WINDOWS\system32\rjklcuji.exe deleted successfully.
File C:\WINDOWS\system32\jpfeujcl.exe deleted successfully.
File C:\WINDOWS\system32\rgyvwyjr.exe deleted successfully.
File C:\WINDOWS\system32\gjnkhxfk.exe deleted successfully.
File C:\WINDOWS\system32\fainjfeb.exe deleted successfully.
File C:\WINDOWS\system32\dqfmcfti.exe deleted successfully.
File C:\WINDOWS\system32\ljgaiwaw.exe deleted successfully.
File C:\WINDOWS\system32\vuvijarb.exe deleted successfully.
File C:\WINDOWS\system32\jnohlhbk.exe deleted successfully.
File C:\WINDOWS\system32\pmneqbwd.exe deleted successfully.
File C:\WINDOWS\system32\thwsfyyv.exe deleted successfully.
File C:\WINDOWS\system32\fldabjwx.dll deleted successfully.
File C:\WINDOWS\system32\xtqvwniy.exe deleted successfully.
File C:\WINDOWS\system32\vopwnect.dll deleted successfully.
File C:\WINDOWS\system32\pbgtodee.exe deleted successfully.
File C:\WINDOWS\system32\rqehndhr.dll deleted successfully.
File C:\WINDOWS\system32\fivnpekq.exe deleted successfully.
File C:\WINDOWS\system32\clbbdlgj.exe deleted successfully.
File C:\WINDOWS\system32\wlbxrjtx.exe deleted successfully.
File C:\WINDOWS\system32\jmieyhyp.exe deleted successfully.
File C:\WINDOWS\system32\gaiyykeh.exe deleted successfully.
File C:\WINDOWS\system32\kkaosqvr.exe deleted successfully.
File C:\WINDOWS\system32\bmkhidev.exe deleted successfully.
File C:\WINDOWS\system32\gcuxoapo.exe deleted successfully.
File C:\WINDOWS\system32\xtjerxdu.exe deleted successfully.


File C:\WINDOWS\system32\ksqsoelb.dll not found!
Deletion of file C:\WINDOWS\system32\ksqsoelb.dll failed!

Could not process line:
C:\WINDOWS\system32\ksqsoelb.dll
Status: 0xc0000034



File C:\WINDOWS\AppPatch\natimxl.dll not found!
Deletion of file C:\WINDOWS\AppPatch\natimxl.dll failed!

Could not process line:
C:\WINDOWS\AppPatch\natimxl.dll
Status: 0xc0000034



File C:\WINDOWS\system32\fbiugbyy.dll not found!
Deletion of file C:\WINDOWS\system32\fbiugbyy.dll failed!

Could not process line:
C:\WINDOWS\system32\fbiugbyy.dll
Status: 0xc0000034



File C:\WINDOWS\system32\svlesekg.dll not found!
Deletion of file C:\WINDOWS\system32\svlesekg.dll failed!

Could not process line:
C:\WINDOWS\system32\svlesekg.dll
Status: 0xc0000034



File C:\WINDOWS\system32\acpbapku.dll not found!
Deletion of file C:\WINDOWS\system32\acpbapku.dll failed!

Could not process line:
C:\WINDOWS\system32\acpbapku.dll
Status: 0xc0000034

File C:\WINDOWS\system32\pjditur.dll deleted successfully.


File C:\WINDOWS\system32\j6221430.dll not found!
Deletion of file C:\WINDOWS\system32\j6221430.dll failed!

Could not process line:
C:\WINDOWS\system32\j6221430.dll
Status: 0xc0000034



File C:\WINDOWS\system32\tihcnhpr.dll not found!
Deletion of file C:\WINDOWS\system32\tihcnhpr.dll failed!

Could not process line:
C:\WINDOWS\system32\tihcnhpr.dll
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.
  • 0

#21
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts

  • 0

#22
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Here is part one of the Vundo fix log:



VundoFix V6.5.9

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 2:37:07 AM 10/13/2007

Listing files found while scanning....

C:\WINDOWS\AppPatch\lxmitan.bak1
C:\WINDOWS\AppPatch\lxmitan.bak2
C:\WINDOWS\AppPatch\lxmitan.ini
C:\WINDOWS\AppPatch\lxmitan.ini2
C:\WINDOWS\AppPatch\lxmitan.tmp
C:\WINDOWS\AppPatch\natimxl.dll
C:\windows\system32\acpbapku.dll
C:\windows\system32\acwtolsv.exe
C:\WINDOWS\system32\addghyqy.dll
C:\windows\system32\adrcadkw.exe
C:\windows\system32\aemodkgp.dll
C:\windows\system32\agsuqaju.dll
C:\windows\system32\ahvioriq.exe
C:\windows\system32\ailutonn.ini
C:\windows\system32\akgkvfhc.dll
C:\windows\system32\aknyefni.ini
C:\windows\system32\amsrrkux.dll
C:\windows\system32\aqqxljwy.exe
C:\windows\system32\aribknrr.ini
C:\windows\system32\atfaivgp.dll
C:\windows\system32\aubyeoxc.exe
C:\windows\system32\avmceuwk.dll
C:\windows\system32\axcxluht.dll
C:\windows\system32\bdatwtft.dll
C:\windows\system32\bdaygvbr.dll
C:\windows\system32\bfbycnuy.ini
C:\windows\system32\bgvilcak.dll
C:\windows\system32\bhbeqeve.dll
C:\windows\system32\bhvhhuuo.dll
C:\windows\system32\biiigmbv.dll
C:\windows\system32\bislqgaj.dll
C:\windows\system32\bkwhtpkd.dll
C:\windows\system32\blpfthqm.dll
C:\windows\system32\bnbtvadw.exe
C:\windows\system32\bnmdyter.dll
C:\windows\system32\bpgexeqp.dll
C:\windows\system32\bqenigew.dll
C:\windows\system32\bqewuvdm.ini
C:\windows\system32\brsfisjt.exe
C:\WINDOWS\system32\bsaamgue.dll
C:\windows\system32\btcbklyn.exe
C:\windows\system32\budliluf.dll
C:\windows\system32\buyuleqq.ini
C:\windows\system32\bviimpqc.dll
C:\windows\system32\bvpdvyjf.dll
C:\windows\system32\bxmsujek.ini
C:\windows\system32\caeefarm.dll
C:\windows\system32\cerfviqi.dll
C:\windows\system32\chfvkgka.ini
C:\windows\system32\chycvihl.exe
C:\windows\system32\ciikmiri.exe
C:\windows\system32\ciulhedm.ini
C:\windows\system32\cjpyquvd.dll
C:\windows\system32\cknmiyrb.exe
C:\windows\system32\cladpptd.dll
C:\windows\system32\clmslsnr.dll
C:\windows\system32\cniaypgi.dll
C:\windows\system32\cosaqpkg.dll
C:\windows\system32\cpqfahbr.dll
C:\windows\system32\cqpmiivb.ini
C:\windows\system32\crlcgcqd.ini
C:\windows\system32\csiofdse.dll
C:\windows\system32\csnxnmio.dll
C:\windows\system32\ctngmihf.dll
C:\windows\system32\ctttoqvh.dll
C:\windows\system32\deigwyfi.dll
C:\windows\system32\dfgwqsjo.ini
C:\windows\system32\djqfhsng.dll
C:\windows\system32\dkihfkur.dll
C:\windows\system32\dkpthwkb.ini
C:\windows\system32\dlfoxmui.dll
C:\windows\system32\dlgkmfyu.dll
C:\windows\system32\dmnucham.dll
C:\windows\system32\dqcgclrc.dll
C:\windows\system32\drkwvoag.ini
C:\WINDOWS\system32\dslerlhn.dll
C:\windows\system32\dvuqypjc.ini
C:\windows\system32\dxunanbl.ini
C:\windows\system32\dywiytig.dll
C:\windows\system32\eiuqpbvn.dll
C:\windows\system32\enjcaheu.dll
C:\windows\system32\ensfydhq.dll
C:\windows\system32\eoqhoktn.exe
C:\windows\system32\eqymbldj.dll
C:\windows\system32\errakvnl.dll
C:\windows\system32\esdfoisc.ini
C:\windows\system32\esfugfly.ini
C:\windows\system32\eugmaasb.ini
C:\windows\system32\euldqxgw.dll
C:\windows\system32\eveqebhb.ini
C:\windows\system32\ewptylnu.exe
C:\windows\system32\eyrkupll.ini
C:\windows\system32\fbcdbjiu.dll
C:\windows\system32\fbxkcgsq.exe
C:\windows\system32\fdbkfvsf.dll
C:\windows\system32\fdxsrvqk.dll
C:\windows\system32\fhimgntc.ini
C:\windows\system32\fjrdxwdn.dll
C:\windows\system32\fjyvdpvb.ini
C:\WINDOWS\system32\fkmbgflq.dll
C:\windows\system32\flhxnxvv.dll
C:\windows\system32\fmbkrvxv.exe
C:\windows\system32\fnlvcfed.dll
C:\WINDOWS\system32\fnxeqfad.dll
C:\windows\system32\frovgrpt.dll
C:\windows\system32\frsxwygn.ini
C:\windows\system32\fscbkeko.dll
C:\windows\system32\fsvfkbdf.ini
C:\windows\system32\fulildub.ini
C:\windows\system32\fysvkjbx.ini
C:\windows\system32\gaovwkrd.dll
C:\windows\system32\gciybsyl.dll
C:\windows\system32\gcqurhak.ini
C:\windows\system32\gcqurhak.tmp
C:\WINDOWS\system32\gcsclypd.dll
C:\windows\system32\gfykahpq.dll
C:\windows\system32\giltdxgm.dll
C:\windows\system32\gkeselvs.ini
C:\windows\system32\glfnmigi.dll
C:\windows\system32\gluvdvqq.ini
C:\windows\system32\gsfqkfri.dll
C:\windows\system32\gunyhspr.ini
C:\WINDOWS\system32\gwnonkhr.dll
C:\windows\system32\gyadonoj.ini
C:\windows\system32\hdwfophq.exe
C:\windows\system32\heuthnha.exe
C:\windows\system32\hhhhpibw.dll
C:\windows\system32\hiltfamr.ini
C:\windows\system32\hnnaufrw.dll
C:\windows\system32\hohmspnl.dll
C:\windows\system32\horfxrsq.dll
C:\windows\system32\hoswuqbo.dll
C:\windows\system32\hrreredl.dll
C:\windows\system32\hsqtcjsu.dll
C:\windows\system32\htjoaqaq.ini
C:\windows\system32\iajjlduw.exe
C:\windows\system32\icykanep.dll
C:\windows\system32\ieftyvus.dll
C:\windows\system32\ieuovclp.dll
C:\windows\system32\ifaoflav.exe
C:\windows\system32\ifgqlhje.dll
C:\windows\system32\ifwhvaai.dll
C:\windows\system32\ifywgied.ini
C:\windows\system32\igllcygc.dll
C:\windows\system32\igpyainc.ini
C:\windows\system32\ihsohnrm.dll
C:\windows\system32\ikvkumrm.ini
C:\windows\system32\ilrljsxg.exe
C:\windows\system32\infeynka.dll
C:\WINDOWS\system32\inwhrkro.dll
C:\windows\system32\iqivfrec.ini
C:\windows\system32\itxuqlou.dll
C:\windows\system32\iwhmbtvt.dll
C:\windows\system32\iyhddkeb.dll
C:\windows\system32\iyshuukb.exe
C:\windows\system32\j6221430.dll
C:\windows\system32\jcdktbkj.ini
C:\windows\system32\jdlbmyqe.ini
C:\windows\system32\jebtjkay.dll
C:\windows\system32\jejaoqkd.dll
C:\windows\system32\jghatdjp.dll
C:\windows\system32\jhtrcyim.dll
C:\windows\system32\jkbtkdcj.dll
C:\windows\system32\jmhbfakf.exe
C:\windows\system32\jmoiwvwl.ini
C:\windows\system32\jnrrdwly.dll
C:\windows\system32\jonodayg.dll
C:\windows\system32\jskmkgkp.dll
C:\windows\system32\jvodcuty.ini
C:\windows\system32\jwhgsyxs.exe
C:\windows\system32\jylpavco.dll
C:\windows\system32\kahruqcg.dll
C:\windows\system32\kcihwisy.exe
C:\windows\system32\kejusmxb.dll
C:\windows\system32\khcdnitx.dll
C:\windows\system32\khpscimk.exe
C:\windows\system32\kivfssyq.ini
C:\windows\system32\kkdppeos.dll
C:\windows\system32\kkrkdbcy.exe
C:\windows\system32\kkwgmlfa.exe
C:\windows\system32\klnwtmdn.exe
C:\windows\system32\kmtmnlws.ini
C:\windows\system32\kowlooit.dll
C:\windows\system32\kqhrisrk.ini
C:\windows\system32\krsirhqk.dll
C:\windows\system32\kvcrgnwv.ini
C:\windows\system32\kwuecmva.ini
C:\windows\system32\lbhatnet.exe
C:\windows\system32\lbiwcabp.exe
C:\windows\system32\lbnanuxd.dll
C:\windows\system32\lcbmesno.ini
C:\windows\system32\lcfuqsju.dll
C:\windows\system32\lcyrxudu.exe
C:\windows\system32\lepsjpcw.ini
C:\windows\system32\ljkqlllo.exe
C:\windows\system32\ljtfswjd.exe
C:\windows\system32\llpukrye.dll
C:\windows\system32\llrapgrn.dll
C:\windows\system32\lnpsmhoh.ini
C:\windows\system32\lnvkarre.ini
C:\windows\system32\loenbcym.dll
C:\windows\system32\lqdemhvy.dll
C:\WINDOWS\system32\lwtgtkut.dll
C:\windows\system32\lwtpgkcu.dll
C:\windows\system32\lwvwiomj.dll
C:\windows\system32\lxjfsemv.dll
C:\windows\system32\lysbyicg.ini
C:\windows\system32\mahcunmd.ini
C:\windows\system32\masybwco.exe
C:\windows\system32\mbxpmepp.dll
C:\windows\system32\mcimrlgc.exe
C:\windows\system32\mcnbfwie.dll
C:\windows\system32\mdehluic.dll
C:\windows\system32\mdvuweqb.dll
C:\windows\system32\mexlftqh.dll
C:\windows\system32\mgvgnpos.ini
C:\windows\system32\mgxdtlig.ini
C:\windows\system32\mihyxqly.ini
C:\windows\system32\mkraeymp.ini
C:\windows\system32\mlwvxgac.exe
C:\windows\system32\mnpmghjf.dll
C:\windows\system32\mophwurc.exe
C:\windows\system32\mqgjuqaf.dll
C:\windows\system32\mrafeeac.ini
C:\windows\system32\mrenjmhu.dll
C:\windows\system32\mrmukvki.dll
C:\windows\system32\mrnhoshi.ini
C:\windows\system32\msnsxuto.dll
C:\windows\system32\muviwcnu.ini
C:\windows\system32\mycbneol.ini
C:\windows\system32\nbmufekj.exe
C:\windows\system32\nctvktxu.ini
C:\windows\system32\neprqfpa.dll
C:\windows\system32\nerhjtdv.dll
C:\windows\system32\nfcgnltx.dll
C:\windows\system32\nfmhdjdd.dll
C:\windows\system32\ngywxsrf.dll
C:\windows\system32\nhswhfet.dll
C:\windows\system32\nkxehunw.dll
C:\windows\system32\nnfglyax.dll
C:\windows\system32\nnotulia.dll
C:\windows\system32\nrgparll.ini
C:\windows\system32\ntfrjcnr.dll
C:\windows\system32\ntpaxikv.dll
C:\windows\system32\nvbpquie.ini
C:\WINDOWS\system32\nwildrsa.dll
C:\windows\system32\obquwsoh.ini
C:\windows\system32\ocvaplyj.ini
C:\windows\system32\odhqyvbx.ini
C:\windows\system32\odtvcief.exe
C:\windows\system32\ojlltdgx.ini
C:\windows\system32\ojsqwgfd.dll
C:\windows\system32\okekbcsf.ini
C:\windows\system32\okuuhbvy.ini
C:\windows\system32\omihkuni.exe
C:\windows\system32\onsembcl.dll
C:\windows\system32\oqblbgtv.ini
C:\windows\system32\oqofjdsw.ini
C:\windows\system32\oqufdnqj.dll
C:\windows\system32\orsdrgyp.exe
C:\windows\system32\otnggppu.ini
C:\windows\system32\oyyyghtp.dll
C:\windows\system32\pbnrmcws.dll
C:\windows\system32\pdasvgwv.dll
C:\windows\system32\penakyci.ini
C:\windows\system32\pgkdomea.ini
C:\windows\system32\pjdtahgj.ini
C:\windows\system32\pjfehklg.dll
C:\windows\system32\pjyelhmh.exe
C:\windows\system32\pkgkmksj.ini
C:\windows\system32\pmyearkm.dll
C:\WINDOWS\system32\pqsqaccy.dll
C:\windows\system32\psgbsbox.ini
C:\windows\system32\ptepukqn.dll
C:\windows\system32\pthgyyyo.ini
C:\windows\system32\pujagftb.dll
C:\windows\system32\pusuaeyf.dll
C:\windows\system32\puuwpjxp.dll
C:\windows\system32\pvugsyeh.exe
C:\windows\system32\pxkufyxr.ini
C:\windows\system32\pxxlhrcx.ini
C:\windows\system32\qaqaojth.dll
C:\windows\system32\qccrdjqw.ini
C:\windows\system32\qgxdfwex.dll
C:\windows\system32\qiboaomi.dll
C:\windows\system32\qlchibiu.dll
C:\windows\system32\qphakyfg.ini
C:\windows\system32\qpnpqajv.exe
C:\windows\system32\qqeluyub.dll
C:\windows\system32\qqvdvulg.dll
C:\windows\system32\qrdduqju.dll
C:\windows\system32\qsrxfroh.ini
C:\windows\system32\qxdiaffo.dll
C:\windows\system32\qykyuovk.dll
C:\windows\system32\qyssfvik.dll
C:\windows\system32\rbhafqpc.ini
C:\windows\system32\rcfhebql.dll
C:\windows\system32\rhsidpes.exe
C:\windows\system32\riamtgrl.dll
C:\windows\system32\ritigmob.exe
C:\windows\system32\rljqurif.dll
C:\windows\system32\rmaftlih.dll
C:\windows\system32\rncjrftn.ini
C:\windows\system32\rohkhwuw.ini
C:\windows\system32\rphaodfv.dll
C:\windows\system32\rpshynug.dll
C:\windows\system32\rqykbswc.dll
C:\windows\system32\rrnkbira.dll
C:\windows\system32\rvrkgyko.exe
C:\windows\system32\rxyfukxp.dll
C:\windows\system32\sfmwgvgt.dll
C:\windows\system32\sopngvgm.dll
C:\windows\system32\spbhrfns.dll
C:\windows\system32\suvytfei.ini
C:\windows\system32\svlesekg.dll
C:\windows\system32\svlsuuja.exe
C:\windows\system32\swbfidwt.dll
C:\windows\system32\swcmrnbp.ini
C:\windows\system32\swlnmtmk.dll
C:\windows\system32\swstvwfj.dll
C:\windows\system32\tbruskkw.dll
C:\windows\system32\tcamoptx.ini
C:\windows\system32\tcaohwtw.dll
C:\windows\system32\tdhxfwqy.dll
C:\windows\system32\tebenhbf.dll
C:\windows\system32\tebqygbe.exe
C:\windows\system32\tefhwshn.ini
C:\windows\system32\tftwtadb.ini
C:\windows\system32\thulxcxa.ini2
C:\windows\system32\thulxcxa.tmp
C:\windows\system32\thvmnauc.dll
C:\windows\system32\tioolwok.ini
C:\windows\system32\tvjqnbnw.dll
C:\windows\system32\uehacjne.ini
C:\windows\system32\uhfudaie.exe
C:\windows\system32\uhmjnerm.ini
C:\windows\system32\uhtcldmg.dll
C:\windows\system32\uibihclq.ini
C:\windows\system32\uidpemoi.dll
C:\windows\system32\uijbdcbf.ini
C:\windows\system32\uisvnbow.ini
C:\windows\system32\uivpxsoy.ini
C:\windows\system32\ujquddrq.ini
C:\windows\system32\ujsqufcl.ini
C:\windows\system32\ukpabpca.ini
C:\windows\system32\ulumgmcy.dll
C:\windows\system32\uncwivum.dll
C:\windows\system32\unyqmhuv.exe
C:\windows\system32\uolquxti.ini
C:\windows\system32\uppggnto.dll
C:\windows\system32\urwciipr.exe
C:\windows\system32\usjctqsh.ini
C:\windows\system32\uxtkvtcn.dll
C:\windows\system32\vbmgiiib.ini
C:\WINDOWS\system32\vcbyourp.dll
C:\windows\system32\vdlorraw.dll
C:\windows\system32\vfdoahpr.ini
C:\windows\system32\vlpshvmd.dll
C:\windows\system32\vmesfjxl.ini
C:\windows\system32\vqpbiuky.dll
C:\windows\system32\vsstxmjj.dll
C:\windows\system32\vtgblbqo.dll
C:\windows\system32\vthuwpoy.dll
C:\windows\system32\vtonufse.exe
C:\windows\system32\vvxnxhlf.ini
C:\windows\system32\vwgljwur.exe
C:\windows\system32\vwgvsadp.ini
C:\windows\system32\vwngrcvk.dll
C:\windows\system32\warroldv.ini
C:\windows\system32\wbiphhhh.ini
C:\windows\system32\wcpjspel.dll
C:\windows\system32\wegineqb.ini
C:\windows\system32\wgxqdlue.ini
C:\windows\system32\wkksurbt.ini
C:\windows\system32\wlqrwqwy.dll
C:\windows\system32\wmnvhedx.dll
C:\windows\system32\wnbnqjvt.ini
C:\windows\system32\wnuhexkn.ini
C:\windows\system32\wobnvsiu.dll
C:\windows\system32\wpltompx.dll
C:\windows\system32\wqjdrccq.dll
C:\windows\system32\wrfuannh.ini
C:\windows\system32\wsdjfoqo.dll
C:\windows\system32\wtwhoact.ini
C:\windows\system32\wuwhkhor.dll
C:\windows\system32\wychgbyy.dll
C:\windows\system32\xaylgfnn.ini
C:\windows\system32\xbjkvsyf.dll
C:\windows\system32\xbvyqhdo.dll
C:\windows\system32\xcaswucc.exe
C:\windows\system32\xcrhlxxp.dll
C:\windows\system32\xewfdxgq.ini
C:\windows\system32\xgcotudx.dll
C:\windows\system32\xgdtlljo.dll
C:\windows\system32\xgndiywd.dll
C:\windows\system32\xkocwcyo.dll
C:\windows\system32\xobsbgsp.dll
C:\windows\system32\xpfsmgdt.dll
C:\windows\system32\xpmotlpw.ini
C:\windows\system32\xpsauhva.dll
C:\windows\system32\xtindchk.ini
C:\windows\system32\xtjlwaag.dll
C:\windows\system32\xtlngcfn.ini
C:\windows\system32\xtpomact.dll
C:\windows\system32\xukrrsma.ini
C:\windows\system32\yakjtbej.ini
C:\windows\system32\yalhpepw.dll
C:\windows\system32\yaygniqg.dll
C:\windows\system32\yinpkbvp.exe
C:\windows\system32\yjevgeym.dll
C:\windows\system32\ylfgufse.dll
C:\windows\system32\ylqxyhim.dll
C:\windows\system32\ylwdrrnj.ini
C:\windows\system32\ymmsiwow.dll
C:\windows\system32\yocjjtrv.exe
C:\windows\system32\yopwuhtv.ini
C:\windows\system32\yosxpviu.dll
C:\windows\system32\ypnigrwj.dll
C:\windows\system32\yqlmcifd.exe
C:\windows\system32\yqwfxhdt.ini
C:\windows\system32\ytucdovj.dll
C:\windows\system32\yuncybfb.dll
C:\windows\system32\yvbhuuko.dll
C:\windows\system32\yviebipn.dll
C:\windows\system32\ywqwrqlw.ini
C:\windows\system32\yybghcyw.ini

Beginning removal...

VundoFix V6.5.10

Checking Java version...

Java version is 1.4.2.3
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.3
Old versions of java are exploitable and should be removed.

Scan started at 6:50:32 PM 10/14/2007

Listing files found while scanning....

C:\WINDOWS\AppPatch\lxmitan.bak1
C:\WINDOWS\AppPatch\lxmitan.bak2
C:\WINDOWS\AppPatch\lxmitan.ini
C:\WINDOWS\AppPatch\lxmitan.ini2
C:\WINDOWS\AppPatch\lxmitan.tmp
C:\WINDOWS\AppPatch\natimxl.dll
C:\windows\system32\acpbapku.dll
C:\windows\system32\acwtolsv.exe
C:\WINDOWS\system32\addghyqy.dll
C:\windows\system32\adrcadkw.exe
C:\windows\system32\aemodkgp.dll
C:\windows\system32\agsuqaju.dll
C:\windows\system32\ahvioriq.exe
C:\windows\system32\ailutonn.ini
C:\windows\system32\akgkvfhc.dll
C:\windows\system32\aknyefni.ini
C:\windows\system32\amsrrkux.dll
C:\windows\system32\aqqxljwy.exe
C:\windows\system32\aribknrr.ini
C:\windows\system32\atfaivgp.dll
C:\windows\system32\aubyeoxc.exe
C:\windows\system32\avmceuwk.dll
C:\windows\system32\axcxluht.dll
C:\windows\system32\bdatwtft.dll
C:\windows\system32\bdaygvbr.dll
C:\windows\system32\bfbycnuy.ini
C:\windows\system32\bgvilcak.dll
C:\windows\system32\bhbeqeve.dll
C:\windows\system32\bhvhhuuo.dll
C:\windows\system32\biiigmbv.dll
C:\windows\system32\bislqgaj.dll
C:\windows\system32\bkwhtpkd.dll
C:\windows\system32\blpfthqm.dll
C:\windows\system32\bnbtvadw.exe
C:\windows\system32\bnmdyter.dll
C:\windows\system32\bpgexeqp.dll
C:\windows\system32\bqenigew.dll
C:\windows\system32\bqewuvdm.ini
C:\windows\system32\brsfisjt.exe
C:\windows\system32\bsaamgue.dll
C:\windows\system32\btcbklyn.exe
C:\windows\system32\budliluf.dll
C:\windows\system32\buyuleqq.ini
C:\windows\system32\bviimpqc.dll
C:\windows\system32\bvpdvyjf.dll
C:\windows\system32\bxmsujek.ini
C:\windows\system32\caeefarm.dll
C:\windows\system32\cerfviqi.dll
C:\windows\system32\chfvkgka.ini
C:\windows\system32\chycvihl.exe
C:\windows\system32\ciikmiri.exe
C:\windows\system32\ciulhedm.ini
C:\windows\system32\cjpyquvd.dll
C:\windows\system32\cknmiyrb.exe
C:\windows\system32\cladpptd.dll
C:\windows\system32\clmslsnr.dll
C:\windows\system32\cniaypgi.dll
C:\windows\system32\cosaqpkg.dll
C:\windows\system32\cpqfahbr.dll
C:\windows\system32\cqpmiivb.ini
C:\windows\system32\crlcgcqd.ini
C:\windows\system32\csiofdse.dll
C:\windows\system32\csnxnmio.dll
C:\windows\system32\ctngmihf.dll
C:\windows\system32\ctttoqvh.dll
C:\windows\system32\deigwyfi.dll
C:\windows\system32\dfgwqsjo.ini
C:\windows\system32\djqfhsng.dll
C:\windows\system32\dkihfkur.dll
C:\windows\system32\dkpthwkb.ini
C:\windows\system32\dlfoxmui.dll
C:\windows\system32\dlgkmfyu.dll
C:\windows\system32\dmnucham.dll
C:\windows\system32\dqcgclrc.dll
C:\windows\system32\drkwvoag.ini
C:\WINDOWS\system32\dslerlhn.dll
C:\windows\system32\dvuqypjc.ini
C:\windows\system32\dxunanbl.ini
C:\windows\system32\dywiytig.dll
C:\windows\system32\eiuqpbvn.dll
C:\windows\system32\enjcaheu.dll
C:\windows\system32\ensfydhq.dll
C:\windows\system32\eoqhoktn.exe
C:\windows\system32\eqymbldj.dll
C:\windows\system32\errakvnl.dll
C:\windows\system32\esdfoisc.ini
C:\windows\system32\esfugfly.ini
C:\windows\system32\eugmaasb.ini
C:\windows\system32\euldqxgw.dll
C:\windows\system32\eveqebhb.ini
C:\windows\system32\ewptylnu.exe
C:\windows\system32\eyrkupll.ini
C:\windows\system32\fbcdbjiu.dll
C:\windows\system32\fbxkcgsq.exe
C:\windows\system32\fdbkfvsf.dll
C:\windows\system32\fdxsrvqk.dll
C:\windows\system32\fhimgntc.ini
C:\windows\system32\fjrdxwdn.dll
C:\windows\system32\fjyvdpvb.ini
C:\WINDOWS\system32\fkmbgflq.dll
C:\windows\system32\flhxnxvv.dll
C:\windows\system32\fmbkrvxv.exe
C:\windows\system32\fnlvcfed.dll
C:\WINDOWS\system32\fnxeqfad.dll
C:\windows\system32\frovgrpt.dll
C:\windows\system32\frsxwygn.ini
C:\windows\system32\fscbkeko.dll
C:\windows\system32\fsvfkbdf.ini
C:\windows\system32\fulildub.ini
C:\windows\system32\fysvkjbx.ini
C:\windows\system32\gaovwkrd.dll
C:\windows\system32\gciybsyl.dll
C:\windows\system32\gcqurhak.ini
C:\windows\system32\gcqurhak.tmp
C:\WINDOWS\system32\gcsclypd.dll
C:\windows\system32\gcxcgljr.ini
C:\windows\system32\gfykahpq.dll
C:\windows\system32\giltdxgm.dll
C:\windows\system32\gkeselvs.ini
C:\windows\system32\glfnmigi.dll
C:\windows\system32\gluvdvqq.ini
C:\windows\system32\gsfqkfri.dll
C:\windows\system32\gtcsqqpi.dll
C:\windows\system32\gunyhspr.ini
C:\windows\system32\gvnotgkx.ini
C:\WINDOWS\system32\gwnonkhr.dll
C:\windows\system32\gyadonoj.ini
C:\windows\system32\hdwfophq.exe
C:\windows\system32\heuthnha.exe
C:\windows\system32\hhhhpibw.dll
C:\windows\system32\hiltfamr.ini
C:\windows\system32\hnnaufrw.dll
C:\windows\system32\hohmspnl.dll
C:\windows\system32\horfxrsq.dll
C:\windows\system32\hoswuqbo.dll
C:\windows\system32\hrreredl.dll
C:\windows\system32\hsqtcjsu.dll
C:\windows\system32\htjoaqaq.ini
C:\windows\system32\hwehwrmj.dll
C:\windows\system32\iajjlduw.exe
C:\windows\system32\icykanep.dll
C:\windows\system32\ieftyvus.dll
C:\windows\system32\ieuovclp.dll
C:\windows\system32\ifaoflav.exe
C:\windows\system32\ifgqlhje.dll
C:\windows\system32\ifwhvaai.dll
C:\windows\system32\ifywgied.ini
C:\windows\system32\igllcygc.dll
C:\windows\system32\igpyainc.ini
C:\windows\system32\ihsohnrm.dll
C:\windows\system32\ikvkumrm.ini
C:\windows\system32\ilrljsxg.exe
C:\windows\system32\infeynka.dll
C:\WINDOWS\system32\inwhrkro.dll
C:\windows\system32\ipqqsctg.ini
C:\windows\system32\iqivfrec.ini
C:\windows\system32\itxuqlou.dll
C:\windows\system32\iwhmbtvt.dll
C:\windows\system32\iyhddkeb.dll
C:\windows\system32\iyshuukb.exe
C:\windows\system32\j6221430.dll
C:\windows\system32\jcdktbkj.ini
C:\windows\system32\jdlbmyqe.ini
C:\windows\system32\jebtjkay.dll
C:\windows\system32\jejaoqkd.dll
C:\windows\system32\jghatdjp.dll
C:\windows\system32\jhtrcyim.dll
C:\windows\system32\jkbtkdcj.dll
C:\windows\system32\jmhbfakf.exe
C:\windows\system32\jmoiwvwl.ini
C:\windows\system32\jmrwhewh.ini
C:\windows\system32\jndvxvoj.dll
C:\windows\system32\jnrrdwly.dll
C:\windows\system32\jonodayg.dll
C:\windows\system32\jovxvdnj.ini
C:\windows\system32\jskmkgkp.dll
C:\windows\system32\jvodcuty.ini
C:\windows\system32\jwhgsyxs.exe
C:\windows\system32\jylpavco.dll
C:\windows\system32\kahruqcg.dll
C:\windows\system32\kcihwisy.exe
C:\windows\system32\kejusmxb.dll
C:\windows\system32\khcdnitx.dll
C:\windows\system32\khpscimk.exe
C:\windows\system32\kivfssyq.ini
C:\windows\system32\kkdppeos.dll
C:\windows\system32\kkrkdbcy.exe
C:\windows\system32\kkwgmlfa.exe
C:\windows\system32\klnwtmdn.exe
C:\windows\system32\kmtmnlws.ini
C:\windows\system32\kowlooit.dll
C:\windows\system32\kqhrisrk.ini
C:\windows\system32\krsirhqk.dll
C:\windows\system32\kvcrgnwv.ini
C:\windows\system32\kwuecmva.ini
C:\windows\system32\lbhatnet.exe
C:\windows\system32\lbiwcabp.exe
C:\windows\system32\lbnanuxd.dll
C:\windows\system32\lcbmesno.ini
C:\windows\system32\lcfuqsju.dll
C:\windows\system32\lcyrxudu.exe
C:\windows\system32\lepsjpcw.ini
C:\windows\system32\ljkqlllo.exe
C:\windows\system32\ljtfswjd.exe
C:\windows\system32\llpukrye.dll
C:\windows\system32\llrapgrn.dll
C:\windows\system32\lnpsmhoh.ini
C:\windows\system32\lnvkarre.ini
C:\windows\system32\loenbcym.dll
C:\windows\system32\lqdemhvy.dll
C:\WINDOWS\system32\lwtgtkut.dll
C:\windows\system32\lwtpgkcu.dll
C:\windows\system32\lwvwiomj.dll
C:\windows\system32\lxjfsemv.dll
C:\windows\system32\lysbyicg.ini
C:\windows\system32\mahcunmd.ini
C:\windows\system32\masybwco.exe
C:\windows\system32\mbxpmepp.dll
C:\windows\system32\mcimrlgc.exe
C:\windows\system32\mcnbfwie.dll
C:\windows\system32\mdehluic.dll
C:\windows\system32\mdvuweqb.dll
C:\windows\system32\mexlftqh.dll
C:\windows\system32\mgvgnpos.ini
C:\windows\system32\mgxdtlig.ini
C:\windows\system32\mihyxqly.ini
C:\windows\system32\mkraeymp.ini
C:\windows\system32\mlwvxgac.exe
C:\windows\system32\mnpmghjf.dll
C:\windows\system32\mophwurc.exe
C:\windows\system32\mqgjuqaf.dll
C:\windows\system32\mrafeeac.ini
C:\windows\system32\mrenjmhu.dll
C:\windows\system32\mrmukvki.dll
C:\windows\system32\mrnhoshi.ini
C:\windows\system32\msnsxuto.dll
C:\windows\system32\muviwcnu.ini
C:\windows\system32\mycbneol.ini
C:\windows\system32\nbmufekj.exe
C:\windows\system32\nctvktxu.ini
C:\windows\system32\neprqfpa.dll
C:\windows\system32\nerhjtdv.dll
C:\windows\system32\nfcgnltx.dll
C:\windows\system32\nfmhdjdd.dll
C:\windows\system32\ngywxsrf.dll
C:\windows\system32\nhswhfet.dll
C:\windows\system32\nkxehunw.dll
C:\windows\system32\nnfglyax.dll
C:\windows\system32\nnotulia.dll
C:\windows\system32\nrgparll.ini
C:\windows\system32\ntfrjcnr.dll
C:\windows\system32\ntpaxikv.dll
C:\windows\system32\nvbpquie.ini
C:\WINDOWS\system32\nwildrsa.dll
C:\windows\system32\obquwsoh.ini
C:\windows\system32\ocvaplyj.ini
C:\windows\system32\odhqyvbx.ini
C:\windows\system32\odtvcief.exe
C:\windows\system32\ojlltdgx.ini
C:\windows\system32\ojsqwgfd.dll
C:\windows\system32\okekbcsf.ini
C:\windows\system32\okuuhbvy.ini
C:\windows\system32\omihkuni.exe
C:\windows\system32\onsembcl.dll
C:\windows\system32\oqblbgtv.ini
C:\windows\system32\oqofjdsw.ini
C:\windows\system32\oqufdnqj.dll
C:\windows\system32\orsdrgyp.exe
C:\windows\system32\otnggppu.ini
C:\windows\system32\oyyyghtp.dll
C:\windows\system32\pbnrmcws.dll
C:\windows\system32\pdasvgwv.dll
C:\windows\system32\penakyci.ini
C:\windows\system32\pgkdomea.ini
C:\windows\system32\pjdtahgj.ini
C:\windows\system32\pjfehklg.dll
C:\windows\system32\pjyelhmh.exe
C:\windows\system32\pkgkmksj.ini
C:\windows\system32\pmyearkm.dll
C:\WINDOWS\system32\pqsqaccy.dll
C:\windows\system32\psgbsbox.ini
C:\windows\system32\ptepukqn.dll
C:\windows\system32\pthgyyyo.ini
C:\windows\system32\pujagftb.dll
C:\windows\system32\pusuaeyf.dll
C:\windows\system32\puuwpjxp.dll
C:\windows\system32\pvugsyeh.exe
C:\windows\system32\pxkufyxr.ini
C:\windows\system32\pxxlhrcx.ini
C:\windows\system32\qaqaojth.dll
C:\windows\system32\qccrdjqw.ini
C:\windows\system32\qgxdfwex.dll
C:\windows\system32\qiboaomi.dll
C:\windows\system32\qlchibiu.dll
C:\windows\system32\qphakyfg.ini
C:\windows\system32\qpnpqajv.exe
C:\windows\system32\qqeluyub.dll
C:\windows\system32\qqvdvulg.dll
C:\windows\system32\qrdduqju.dll
C:\windows\system32\qsrxfroh.ini
C:\windows\system32\qxdiaffo.dll
C:\windows\system32\qykyuovk.dll
C:\windows\system32\qyssfvik.dll
C:\windows\system32\rbhafqpc.ini
C:\windows\system32\rcfhebql.dll
C:\windows\system32\rhsidpes.exe
C:\windows\system32\riamtgrl.dll
C:\windows\system32\ritigmob.exe
C:\windows\system32\rjlgcxcg.dll
C:\windows\system32\rljqurif.dll
C:\windows\system32\rmaftlih.dll
C:\windows\system32\rncjrftn.ini
C:\windows\system32\rohkhwuw.ini
C:\windows\system32\rphaodfv.dll
C:\windows\system32\rphnchit.ini
C:\windows\system32\rpshynug.dll
C:\windows\system32\rqykbswc.dll
C:\windows\system32\rrnkbira.dll
C:\windows\system32\rvrkgyko.exe
C:\windows\system32\rxyfukxp.dll
C:\windows\system32\sfmwgvgt.dll
C:\windows\system32\sopngvgm.dll
C:\windows\system32\spbhrfns.dll
C:\windows\system32\suvytfei.ini
C:\windows\system32\svlesekg.dll
C:\windows\system32\svlsuuja.exe
C:\windows\system32\swbfidwt.dll
C:\windows\system32\swcmrnbp.ini
C:\windows\system32\swlnmtmk.dll
C:\windows\system32\swstvwfj.dll
C:\windows\system32\tbruskkw.dll
C:\windows\system32\tcamoptx.ini
C:\windows\system32\tcaohwtw.dll
C:\windows\system32\tdhxfwqy.dll
C:\windows\system32\tebenhbf.dll
C:\windows\system32\tebqygbe.exe
C:\windows\system32\tefhwshn.ini
C:\windows\system32\tftwtadb.ini
C:\windows\system32\thulxcxa.ini2
C:\windows\system32\thulxcxa.tmp
C:\windows\system32\thvmnauc.dll
C:\windows\system32\tihcnhpr.dll
C:\windows\system32\tioolwok.ini
C:\windows\system32\tvjqnbnw.dll
C:\windows\system32\uehacjne.ini
C:\windows\system32\uhfudaie.exe
C:\windows\system32\uhmjnerm.ini
C:\windows\system32\uhtcldmg.dll
C:\windows\system32\uibihclq.ini
C:\windows\system32\uidpemoi.dll
C:\windows\system32\uijbdcbf.ini
C:\windows\system32\uisvnbow.ini
C:\windows\system32\uivpxsoy.ini
C:\windows\system32\ujquddrq.ini
C:\windows\system32\ujsqufcl.ini
C:\windows\system32\ukpabpca.ini
C:\windows\system32\ulumgmcy.dll
C:\windows\system32\uncwivum.dll
C:\windows\system32\unyqmhuv.exe
C:\windows\system32\uolquxti.ini
C:\windows\system32\uppggnto.dll
C:\windows\system32\urwciipr.exe
C:\windows\system32\usjctqsh.ini
C:\windows\system32\uxtkvtcn.dll
C:\windows\system32\vbmgiiib.ini
C:\WINDOWS\system32\vcbyourp.dll
C:\windows\system32\vdlorraw.dll
C:\windows\system32\vfdoahpr.ini
C:\windows\system32\vlpshvmd.dll
C:\windows\system32\vmesfjxl.ini
C:\windows\system32\vqpbiuky.dll
C:\windows\system32\vsstxmjj.dll
C:\windows\system32\vtgblbqo.dll
C:\windows\system32\vthuwpoy.dll
C:\windows\system32\vtonufse.exe
C:\windows\system32\vvxnxhlf.ini
C:\windows\system32\vwgljwur.exe
C:\windows\system32\vwgvsadp.ini
C:\windows\system32\vwngrcvk.dll
C:\windows\system32\warroldv.ini
C:\windows\system32\wbiphhhh.ini
C:\windows\system32\wcpjspel.dll
C:\windows\system32\wegineqb.ini
C:\windows\system32\wgxqdlue.ini
C:\windows\system32\wkksurbt.ini
C:\windows\system32\wlqrwqwy.dll
C:\windows\system32\wmnvhedx.dll
C:\windows\system32\wnbnqjvt.ini
C:\windows\system32\wnuhexkn.ini
C:\windows\system32\wobnvsiu.dll
C:\windows\system32\wpltompx.dll
C:\windows\system32\wqjdrccq.dll
C:\windows\system32\wrfuannh.ini
C:\windows\system32\wsdjfoqo.dll
C:\windows\system32\wtwhoact.ini
C:\windows\system32\wuwhkhor.dll
C:\windows\system32\wychgbyy.dll
C:\windows\system32\xaylgfnn.ini
C:\windows\system32\xbjkvsyf.dll
C:\windows\system32\xbvyqhdo.dll
C:\windows\system32\xcaswucc.exe
C:\windows\system32\xcrhlxxp.dll
C:\windows\system32\xewfdxgq.ini
C:\windows\system32\xgcotudx.dll
C:\windows\system32\xgdtlljo.dll
C:\windows\system32\xgndiywd.dll
C:\windows\system32\xgygmwky.ini
C:\WINDOWS\system32\xkgtonvg.dll
C:\windows\system32\xkocwcyo.dll
C:\windows\system32\xobsbgsp.dll
C:\windows\system32\xpfsmgdt.dll
C:\windows\system32\xpmotlpw.ini
C:\windows\system32\xpsauhva.dll
C:\windows\system32\xtindchk.ini
C:\windows\system32\xtjlwaag.dll
C:\windows\system32\xtlngcfn.ini
C:\windows\system32\xtpomact.dll
C:\windows\system32\xukrrsma.ini
C:\windows\system32\yakjtbej.ini
C:\windows\system32\yalhpepw.dll
C:\windows\system32\yaygniqg.dll
C:\windows\system32\yinpkbvp.exe
C:\windows\system32\yjevgeym.dll
C:\windows\system32\ykwmgygx.dll
C:\windows\system32\ylfgufse.dll
C:\windows\system32\ylqxyhim.dll
C:\windows\system32\ylwdrrnj.ini
C:\windows\system32\ymmsiwow.dll
C:\windows\system32\yocjjtrv.exe
C:\windows\system32\yopwuhtv.ini
C:\windows\system32\yosxpviu.dll
C:\windows\system32\ypnigrwj.dll
C:\windows\system32\yqlmcifd.exe
C:\windows\system32\yqwfxhdt.ini
C:\windows\system32\ytucdovj.dll
C:\windows\system32\yuncybfb.dll
C:\windows\system32\yvbhuuko.dll
C:\windows\system32\yviebipn.dll
C:\windows\system32\ywqwrqlw.ini
C:\windows\system32\yybghcyw.ini
  • 0

#23
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
Here is part 2 of Vundofix log:


Beginning removal...

Attempting to delete C:\WINDOWS\AppPatch\lxmitan.bak1
C:\WINDOWS\AppPatch\lxmitan.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\AppPatch\lxmitan.bak2
C:\WINDOWS\AppPatch\lxmitan.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\AppPatch\lxmitan.ini
C:\WINDOWS\AppPatch\lxmitan.ini Has been deleted!

Attempting to delete C:\WINDOWS\AppPatch\lxmitan.ini2
C:\WINDOWS\AppPatch\lxmitan.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\AppPatch\lxmitan.tmp
C:\WINDOWS\AppPatch\lxmitan.tmp Has been deleted!

Attempting to delete C:\WINDOWS\AppPatch\natimxl.dll
C:\WINDOWS\AppPatch\natimxl.dll Could not be deleted.

Attempting to delete C:\windows\system32\acpbapku.dll
C:\windows\system32\acpbapku.dll Has been deleted!

Attempting to delete C:\windows\system32\acwtolsv.exe
C:\windows\system32\acwtolsv.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\addghyqy.dll
C:\WINDOWS\system32\addghyqy.dll Has been deleted!

Attempting to delete C:\windows\system32\adrcadkw.exe
C:\windows\system32\adrcadkw.exe Has been deleted!

Attempting to delete C:\windows\system32\aemodkgp.dll
C:\windows\system32\aemodkgp.dll Has been deleted!

Attempting to delete C:\windows\system32\agsuqaju.dll
C:\windows\system32\agsuqaju.dll Has been deleted!

Attempting to delete C:\windows\system32\ahvioriq.exe
C:\windows\system32\ahvioriq.exe Has been deleted!

Attempting to delete C:\windows\system32\ailutonn.ini
C:\windows\system32\ailutonn.ini Has been deleted!

Attempting to delete C:\windows\system32\akgkvfhc.dll
C:\windows\system32\akgkvfhc.dll Has been deleted!

Attempting to delete C:\windows\system32\aknyefni.ini
C:\windows\system32\aknyefni.ini Has been deleted!

Attempting to delete C:\windows\system32\amsrrkux.dll
C:\windows\system32\amsrrkux.dll Has been deleted!

Attempting to delete C:\windows\system32\aqqxljwy.exe
C:\windows\system32\aqqxljwy.exe Has been deleted!

Attempting to delete C:\windows\system32\aribknrr.ini
C:\windows\system32\aribknrr.ini Has been deleted!

Attempting to delete C:\windows\system32\atfaivgp.dll
C:\windows\system32\atfaivgp.dll Has been deleted!

Attempting to delete C:\windows\system32\aubyeoxc.exe
C:\windows\system32\aubyeoxc.exe Has been deleted!

Attempting to delete C:\windows\system32\avmceuwk.dll
C:\windows\system32\avmceuwk.dll Has been deleted!

Attempting to delete C:\windows\system32\axcxluht.dll
C:\windows\system32\axcxluht.dll Has been deleted!

Attempting to delete C:\windows\system32\bdatwtft.dll
C:\windows\system32\bdatwtft.dll Has been deleted!

Attempting to delete C:\windows\system32\bdaygvbr.dll
C:\windows\system32\bdaygvbr.dll Has been deleted!

Attempting to delete C:\windows\system32\bfbycnuy.ini
C:\windows\system32\bfbycnuy.ini Has been deleted!

Attempting to delete C:\windows\system32\bgvilcak.dll
C:\windows\system32\bgvilcak.dll Has been deleted!

Attempting to delete C:\windows\system32\bhbeqeve.dll
C:\windows\system32\bhbeqeve.dll Has been deleted!

Attempting to delete C:\windows\system32\bhvhhuuo.dll
C:\windows\system32\bhvhhuuo.dll Has been deleted!

Attempting to delete C:\windows\system32\biiigmbv.dll
C:\windows\system32\biiigmbv.dll Has been deleted!

Attempting to delete C:\windows\system32\bislqgaj.dll
C:\windows\system32\bislqgaj.dll Has been deleted!

Attempting to delete C:\windows\system32\bkwhtpkd.dll
C:\windows\system32\bkwhtpkd.dll Has been deleted!

Attempting to delete C:\windows\system32\blpfthqm.dll
C:\windows\system32\blpfthqm.dll Has been deleted!

Attempting to delete C:\windows\system32\bnbtvadw.exe
C:\windows\system32\bnbtvadw.exe Has been deleted!

Attempting to delete C:\windows\system32\bnmdyter.dll
C:\windows\system32\bnmdyter.dll Has been deleted!

Attempting to delete C:\windows\system32\bpgexeqp.dll
C:\windows\system32\bpgexeqp.dll Has been deleted!

Attempting to delete C:\windows\system32\bqenigew.dll
C:\windows\system32\bqenigew.dll Has been deleted!

Attempting to delete C:\windows\system32\bqewuvdm.ini
C:\windows\system32\bqewuvdm.ini Has been deleted!

Attempting to delete C:\windows\system32\brsfisjt.exe
C:\windows\system32\brsfisjt.exe Has been deleted!

Attempting to delete C:\windows\system32\bsaamgue.dll
C:\windows\system32\bsaamgue.dll Has been deleted!

Attempting to delete C:\windows\system32\btcbklyn.exe
C:\windows\system32\btcbklyn.exe Has been deleted!

Attempting to delete C:\windows\system32\budliluf.dll
C:\windows\system32\budliluf.dll Has been deleted!

Attempting to delete C:\windows\system32\buyuleqq.ini
C:\windows\system32\buyuleqq.ini Has been deleted!

Attempting to delete C:\windows\system32\bviimpqc.dll
C:\windows\system32\bviimpqc.dll Has been deleted!

Attempting to delete C:\windows\system32\bvpdvyjf.dll
C:\windows\system32\bvpdvyjf.dll Has been deleted!

Attempting to delete C:\windows\system32\bxmsujek.ini
C:\windows\system32\bxmsujek.ini Has been deleted!

Attempting to delete C:\windows\system32\caeefarm.dll
C:\windows\system32\caeefarm.dll Has been deleted!

Attempting to delete C:\windows\system32\cerfviqi.dll
C:\windows\system32\cerfviqi.dll Has been deleted!

Attempting to delete C:\windows\system32\chfvkgka.ini
C:\windows\system32\chfvkgka.ini Has been deleted!

Attempting to delete C:\windows\system32\chycvihl.exe
C:\windows\system32\chycvihl.exe Has been deleted!

Attempting to delete C:\windows\system32\ciikmiri.exe
C:\windows\system32\ciikmiri.exe Has been deleted!

Attempting to delete C:\windows\system32\ciulhedm.ini
C:\windows\system32\ciulhedm.ini Has been deleted!

Attempting to delete C:\windows\system32\cjpyquvd.dll
C:\windows\system32\cjpyquvd.dll Has been deleted!

Attempting to delete C:\windows\system32\cknmiyrb.exe
C:\windows\system32\cknmiyrb.exe Has been deleted!

Attempting to delete C:\windows\system32\cladpptd.dll
C:\windows\system32\cladpptd.dll Has been deleted!

Attempting to delete C:\windows\system32\clmslsnr.dll
C:\windows\system32\clmslsnr.dll Has been deleted!

Attempting to delete C:\windows\system32\cniaypgi.dll
C:\windows\system32\cniaypgi.dll Has been deleted!

Attempting to delete C:\windows\system32\cosaqpkg.dll
C:\windows\system32\cosaqpkg.dll Has been deleted!

Attempting to delete C:\windows\system32\cpqfahbr.dll
C:\windows\system32\cpqfahbr.dll Has been deleted!

Attempting to delete C:\windows\system32\cqpmiivb.ini
C:\windows\system32\cqpmiivb.ini Has been deleted!

Attempting to delete C:\windows\system32\crlcgcqd.ini
C:\windows\system32\crlcgcqd.ini Has been deleted!

Attempting to delete C:\windows\system32\csiofdse.dll
C:\windows\system32\csiofdse.dll Has been deleted!

Attempting to delete C:\windows\system32\csnxnmio.dll
C:\windows\system32\csnxnmio.dll Has been deleted!

Attempting to delete C:\windows\system32\ctngmihf.dll
C:\windows\system32\ctngmihf.dll Has been deleted!

Attempting to delete C:\windows\system32\ctttoqvh.dll
C:\windows\system32\ctttoqvh.dll Has been deleted!

Attempting to delete C:\windows\system32\deigwyfi.dll
C:\windows\system32\deigwyfi.dll Has been deleted!

Attempting to delete C:\windows\system32\dfgwqsjo.ini
C:\windows\system32\dfgwqsjo.ini Has been deleted!

Attempting to delete C:\windows\system32\djqfhsng.dll
C:\windows\system32\djqfhsng.dll Has been deleted!

Attempting to delete C:\windows\system32\dkihfkur.dll
C:\windows\system32\dkihfkur.dll Has been deleted!

Attempting to delete C:\windows\system32\dkpthwkb.ini
C:\windows\system32\dkpthwkb.ini Has been deleted!

Attempting to delete C:\windows\system32\dlfoxmui.dll
C:\windows\system32\dlfoxmui.dll Has been deleted!

Attempting to delete C:\windows\system32\dlgkmfyu.dll
C:\windows\system32\dlgkmfyu.dll Has been deleted!

Attempting to delete C:\windows\system32\dmnucham.dll
C:\windows\system32\dmnucham.dll Has been deleted!

Attempting to delete C:\windows\system32\dqcgclrc.dll
C:\windows\system32\dqcgclrc.dll Has been deleted!

Attempting to delete C:\windows\system32\drkwvoag.ini
C:\windows\system32\drkwvoag.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\dslerlhn.dll
C:\WINDOWS\system32\dslerlhn.dll Has been deleted!

Attempting to delete C:\windows\system32\dvuqypjc.ini
C:\windows\system32\dvuqypjc.ini Has been deleted!

Attempting to delete C:\windows\system32\dxunanbl.ini
C:\windows\system32\dxunanbl.ini Has been deleted!

Attempting to delete C:\windows\system32\dywiytig.dll
C:\windows\system32\dywiytig.dll Has been deleted!

Attempting to delete C:\windows\system32\eiuqpbvn.dll
C:\windows\system32\eiuqpbvn.dll Has been deleted!

Attempting to delete C:\windows\system32\enjcaheu.dll
C:\windows\system32\enjcaheu.dll Has been deleted!

Attempting to delete C:\windows\system32\ensfydhq.dll
C:\windows\system32\ensfydhq.dll Has been deleted!

Attempting to delete C:\windows\system32\eoqhoktn.exe
C:\windows\system32\eoqhoktn.exe Has been deleted!

Attempting to delete C:\windows\system32\eqymbldj.dll
C:\windows\system32\eqymbldj.dll Has been deleted!

Attempting to delete C:\windows\system32\errakvnl.dll
C:\windows\system32\errakvnl.dll Has been deleted!

Attempting to delete C:\windows\system32\esdfoisc.ini
C:\windows\system32\esdfoisc.ini Has been deleted!

Attempting to delete C:\windows\system32\esfugfly.ini
C:\windows\system32\esfugfly.ini Has been deleted!

Attempting to delete C:\windows\system32\eugmaasb.ini
C:\windows\system32\eugmaasb.ini Has been deleted!

Attempting to delete C:\windows\system32\euldqxgw.dll
C:\windows\system32\euldqxgw.dll Has been deleted!

Attempting to delete C:\windows\system32\eveqebhb.ini
C:\windows\system32\eveqebhb.ini Has been deleted!

Attempting to delete C:\windows\system32\ewptylnu.exe
C:\windows\system32\ewptylnu.exe Has been deleted!

Attempting to delete C:\windows\system32\eyrkupll.ini
C:\windows\system32\eyrkupll.ini Has been deleted!

Attempting to delete C:\windows\system32\fbcdbjiu.dll
C:\windows\system32\fbcdbjiu.dll Has been deleted!

Attempting to delete C:\windows\system32\fbxkcgsq.exe
C:\windows\system32\fbxkcgsq.exe Has been deleted!

Attempting to delete C:\windows\system32\fdbkfvsf.dll
C:\windows\system32\fdbkfvsf.dll Has been deleted!

Attempting to delete C:\windows\system32\fdxsrvqk.dll
C:\windows\system32\fdxsrvqk.dll Has been deleted!

Attempting to delete C:\windows\system32\fhimgntc.ini
C:\windows\system32\fhimgntc.ini Has been deleted!

Attempting to delete C:\windows\system32\fjrdxwdn.dll
C:\windows\system32\fjrdxwdn.dll Has been deleted!

Attempting to delete C:\windows\system32\fjyvdpvb.ini
C:\windows\system32\fjyvdpvb.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\fkmbgflq.dll
C:\WINDOWS\system32\fkmbgflq.dll Has been deleted!

Attempting to delete C:\windows\system32\flhxnxvv.dll
C:\windows\system32\flhxnxvv.dll Has been deleted!

Attempting to delete C:\windows\system32\fmbkrvxv.exe
C:\windows\system32\fmbkrvxv.exe Has been deleted!

Attempting to delete C:\windows\system32\fnlvcfed.dll
C:\windows\system32\fnlvcfed.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fnxeqfad.dll
C:\WINDOWS\system32\fnxeqfad.dll Has been deleted!

Attempting to delete C:\windows\system32\frovgrpt.dll
C:\windows\system32\frovgrpt.dll Has been deleted!

Attempting to delete C:\windows\system32\frsxwygn.ini
C:\windows\system32\frsxwygn.ini Has been deleted!

Attempting to delete C:\windows\system32\fscbkeko.dll
C:\windows\system32\fscbkeko.dll Has been deleted!

Attempting to delete C:\windows\system32\fsvfkbdf.ini
C:\windows\system32\fsvfkbdf.ini Has been deleted!

Attempting to delete C:\windows\system32\fulildub.ini
C:\windows\system32\fulildub.ini Has been deleted!

Attempting to delete C:\windows\system32\fysvkjbx.ini
C:\windows\system32\fysvkjbx.ini Has been deleted!

Attempting to delete C:\windows\system32\gaovwkrd.dll
C:\windows\system32\gaovwkrd.dll Has been deleted!

Attempting to delete C:\windows\system32\gciybsyl.dll
C:\windows\system32\gciybsyl.dll Has been deleted!

Attempting to delete C:\windows\system32\gcqurhak.ini
C:\windows\system32\gcqurhak.ini Has been deleted!

Attempting to delete C:\windows\system32\gcqurhak.tmp
C:\windows\system32\gcqurhak.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\gcsclypd.dll
C:\WINDOWS\system32\gcsclypd.dll Has been deleted!

Attempting to delete C:\windows\system32\gcxcgljr.ini
C:\windows\system32\gcxcgljr.ini Has been deleted!

Attempting to delete C:\windows\system32\gfykahpq.dll
C:\windows\system32\gfykahpq.dll Has been deleted!

Attempting to delete C:\windows\system32\giltdxgm.dll
C:\windows\system32\giltdxgm.dll Has been deleted!

Attempting to delete C:\windows\system32\gkeselvs.ini
C:\windows\system32\gkeselvs.ini Has been deleted!

Attempting to delete C:\windows\system32\glfnmigi.dll
C:\windows\system32\glfnmigi.dll Has been deleted!

Attempting to delete C:\windows\system32\gluvdvqq.ini
C:\windows\system32\gluvdvqq.ini Has been deleted!

Attempting to delete C:\windows\system32\gsfqkfri.dll
C:\windows\system32\gsfqkfri.dll Has been deleted!

Attempting to delete C:\windows\system32\gtcsqqpi.dll
C:\windows\system32\gtcsqqpi.dll Has been deleted!

Attempting to delete C:\windows\system32\gunyhspr.ini
C:\windows\system32\gunyhspr.ini Has been deleted!

Attempting to delete C:\windows\system32\gvnotgkx.ini
C:\windows\system32\gvnotgkx.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\gwnonkhr.dll
C:\WINDOWS\system32\gwnonkhr.dll Has been deleted!

Attempting to delete C:\windows\system32\gyadonoj.ini
C:\windows\system32\gyadonoj.ini Has been deleted!

Attempting to delete C:\windows\system32\hdwfophq.exe
C:\windows\system32\hdwfophq.exe Has been deleted!

Attempting to delete C:\windows\system32\heuthnha.exe
C:\windows\system32\heuthnha.exe Has been deleted!

Attempting to delete C:\windows\system32\hhhhpibw.dll
C:\windows\system32\hhhhpibw.dll Has been deleted!

Attempting to delete C:\windows\system32\hiltfamr.ini
C:\windows\system32\hiltfamr.ini Has been deleted!

Attempting to delete C:\windows\system32\hnnaufrw.dll
C:\windows\system32\hnnaufrw.dll Has been deleted!

Attempting to delete C:\windows\system32\hohmspnl.dll
C:\windows\system32\hohmspnl.dll Has been deleted!

Attempting to delete C:\windows\system32\horfxrsq.dll
C:\windows\system32\horfxrsq.dll Has been deleted!

Attempting to delete C:\windows\system32\hoswuqbo.dll
C:\windows\system32\hoswuqbo.dll Has been deleted!

Attempting to delete C:\windows\system32\hrreredl.dll
C:\windows\system32\hrreredl.dll Has been deleted!

Attempting to delete C:\windows\system32\hsqtcjsu.dll
C:\windows\system32\hsqtcjsu.dll Has been deleted!

Attempting to delete C:\windows\system32\htjoaqaq.ini
C:\windows\system32\htjoaqaq.ini Has been deleted!

Attempting to delete C:\windows\system32\hwehwrmj.dll
C:\windows\system32\hwehwrmj.dll Has been deleted!

Attempting to delete C:\windows\system32\iajjlduw.exe
C:\windows\system32\iajjlduw.exe Has been deleted!

Attempting to delete C:\windows\system32\icykanep.dll
C:\windows\system32\icykanep.dll Has been deleted!

Attempting to delete C:\windows\system32\ieftyvus.dll
C:\windows\system32\ieftyvus.dll Has been deleted!

Attempting to delete C:\windows\system32\ieuovclp.dll
C:\windows\system32\ieuovclp.dll Has been deleted!

Attempting to delete C:\windows\system32\ifaoflav.exe
C:\windows\system32\ifaoflav.exe Has been deleted!

Attempting to delete C:\windows\system32\ifgqlhje.dll
C:\windows\system32\ifgqlhje.dll Has been deleted!

Attempting to delete C:\windows\system32\ifwhvaai.dll
C:\windows\system32\ifwhvaai.dll Has been deleted!

Attempting to delete C:\windows\system32\ifywgied.ini
C:\windows\system32\ifywgied.ini Has been deleted!

Attempting to delete C:\windows\system32\igllcygc.dll
C:\windows\system32\igllcygc.dll Has been deleted!

Attempting to delete C:\windows\system32\igpyainc.ini
C:\windows\system32\igpyainc.ini Has been deleted!

Attempting to delete C:\windows\system32\ihsohnrm.dll
C:\windows\system32\ihsohnrm.dll Has been deleted!

Attempting to delete C:\windows\system32\ikvkumrm.ini
C:\windows\system32\ikvkumrm.ini Has been deleted!

Attempting to delete C:\windows\system32\ilrljsxg.exe
C:\windows\system32\ilrljsxg.exe Has been deleted!

Attempting to delete C:\windows\system32\infeynka.dll
C:\windows\system32\infeynka.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\inwhrkro.dll
C:\WINDOWS\system32\inwhrkro.dll Has been deleted!

Attempting to delete C:\windows\system32\ipqqsctg.ini
C:\windows\system32\ipqqsctg.ini Has been deleted!

Attempting to delete C:\windows\system32\iqivfrec.ini
C:\windows\system32\iqivfrec.ini Has been deleted!

Attempting to delete C:\windows\system32\itxuqlou.dll
C:\windows\system32\itxuqlou.dll Has been deleted!

Attempting to delete C:\windows\system32\iwhmbtvt.dll
C:\windows\system32\iwhmbtvt.dll Has been deleted!

Attempting to delete C:\windows\system32\iyhddkeb.dll
C:\windows\system32\iyhddkeb.dll Has been deleted!

Attempting to delete C:\windows\system32\iyshuukb.exe
C:\windows\system32\iyshuukb.exe Has been deleted!

Attempting to delete C:\windows\system32\j6221430.dll
C:\windows\system32\j6221430.dll Has been deleted!

Attempting to delete C:\windows\system32\jcdktbkj.ini
C:\windows\system32\jcdktbkj.ini Has been deleted!

Attempting to delete C:\windows\system32\jdlbmyqe.ini
C:\windows\system32\jdlbmyqe.ini Has been deleted!

Attempting to delete C:\windows\system32\jebtjkay.dll
C:\windows\system32\jebtjkay.dll Has been deleted!

Attempting to delete C:\windows\system32\jejaoqkd.dll
C:\windows\system32\jejaoqkd.dll Has been deleted!

Attempting to delete C:\windows\system32\jghatdjp.dll
C:\windows\system32\jghatdjp.dll Has been deleted!

Attempting to delete C:\windows\system32\jhtrcyim.dll
C:\windows\system32\jhtrcyim.dll Has been deleted!

Attempting to delete C:\windows\system32\jkbtkdcj.dll
C:\windows\system32\jkbtkdcj.dll Has been deleted!

Attempting to delete C:\windows\system32\jmhbfakf.exe
C:\windows\system32\jmhbfakf.exe Has been deleted!

Attempting to delete C:\windows\system32\jmoiwvwl.ini
C:\windows\system32\jmoiwvwl.ini Has been deleted!

Attempting to delete C:\windows\system32\jmrwhewh.ini
C:\windows\system32\jmrwhewh.ini Has been deleted!

Attempting to delete C:\windows\system32\jndvxvoj.dll
C:\windows\system32\jndvxvoj.dll Has been deleted!

Attempting to delete C:\windows\system32\jnrrdwly.dll
C:\windows\system32\jnrrdwly.dll Has been deleted!

Attempting to delete C:\windows\system32\jonodayg.dll
C:\windows\system32\jonodayg.dll Has been deleted!

Attempting to delete C:\windows\system32\jovxvdnj.ini
C:\windows\system32\jovxvdnj.ini Has been deleted!

Attempting to delete C:\windows\system32\jskmkgkp.dll
C:\windows\system32\jskmkgkp.dll Has been deleted!

Attempting to delete C:\windows\system32\jvodcuty.ini
C:\windows\system32\jvodcuty.ini Has been deleted!

Attempting to delete C:\windows\system32\jwhgsyxs.exe
C:\windows\system32\jwhgsyxs.exe Has been deleted!

Attempting to delete C:\windows\system32\jylpavco.dll
C:\windows\system32\jylpavco.dll Has been deleted!

Attempting to delete C:\windows\system32\kahruqcg.dll
C:\windows\system32\kahruqcg.dll Has been deleted!

Attempting to delete C:\windows\system32\kcihwisy.exe
C:\windows\system32\kcihwisy.exe Has been deleted!

Attempting to delete C:\windows\system32\kejusmxb.dll
C:\windows\system32\kejusmxb.dll Has been deleted!

Attempting to delete C:\windows\system32\khcdnitx.dll
C:\windows\system32\khcdnitx.dll Has been deleted!

Attempting to delete C:\windows\system32\khpscimk.exe
C:\windows\system32\khpscimk.exe Has been deleted!

Attempting to delete C:\windows\system32\kivfssyq.ini
C:\windows\system32\kivfssyq.ini Has been deleted!

Attempting to delete C:\windows\system32\kkdppeos.dll
C:\windows\system32\kkdppeos.dll Has been deleted!

Attempting to delete C:\windows\system32\kkrkdbcy.exe
C:\windows\system32\kkrkdbcy.exe Has been deleted!

Attempting to delete C:\windows\system32\kkwgmlfa.exe
C:\windows\system32\kkwgmlfa.exe Has been deleted!

Attempting to delete C:\windows\system32\klnwtmdn.exe
C:\windows\system32\klnwtmdn.exe Has been deleted!

Attempting to delete C:\windows\system32\kmtmnlws.ini
C:\windows\system32\kmtmnlws.ini Has been deleted!

Attempting to delete C:\windows\system32\kowlooit.dll
C:\windows\system32\kowlooit.dll Has been deleted!

Attempting to delete C:\windows\system32\kqhrisrk.ini
C:\windows\system32\kqhrisrk.ini Has been deleted!

Attempting to delete C:\windows\system32\krsirhqk.dll
C:\windows\system32\krsirhqk.dll Has been deleted!

Attempting to delete C:\windows\system32\kvcrgnwv.ini
C:\windows\system32\kvcrgnwv.ini Has been deleted!

Attempting to delete C:\windows\system32\kwuecmva.ini
C:\windows\system32\kwuecmva.ini Has been deleted!

Attempting to delete C:\windows\system32\lbhatnet.exe
C:\windows\system32\lbhatnet.exe Has been deleted!

Attempting to delete C:\windows\system32\lbiwcabp.exe
C:\windows\system32\lbiwcabp.exe Has been deleted!

Attempting to delete C:\windows\system32\lbnanuxd.dll
C:\windows\system32\lbnanuxd.dll Has been deleted!

Attempting to delete C:\windows\system32\lcbmesno.ini
C:\windows\system32\lcbmesno.ini Has been deleted!

Attempting to delete C:\windows\system32\lcfuqsju.dll
C:\windows\system32\lcfuqsju.dll Has been deleted!

Attempting to delete C:\windows\system32\lcyrxudu.exe
C:\windows\system32\lcyrxudu.exe Has been deleted!

Attempting to delete C:\windows\system32\lepsjpcw.ini
C:\windows\system32\lepsjpcw.ini Has been deleted!

Attempting to delete C:\windows\system32\ljkqlllo.exe
C:\windows\system32\ljkqlllo.exe Has been deleted!

Attempting to delete C:\windows\system32\ljtfswjd.exe
C:\windows\system32\ljtfswjd.exe Has been deleted!

Attempting to delete C:\windows\system32\llpukrye.dll
C:\windows\system32\llpukrye.dll Has been deleted!

Attempting to delete C:\windows\system32\llrapgrn.dll
C:\windows\system32\llrapgrn.dll Has been deleted!

Attempting to delete C:\windows\system32\lnpsmhoh.ini
C:\windows\system32\lnpsmhoh.ini Has been deleted!

Attempting to delete C:\windows\system32\lnvkarre.ini
C:\windows\system32\lnvkarre.ini Has been deleted!

Attempting to delete C:\windows\system32\loenbcym.dll
C:\windows\system32\loenbcym.dll Has been deleted!

Attempting to delete C:\windows\system32\lqdemhvy.dll
C:\windows\system32\lqdemhvy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\lwtgtkut.dll
C:\WINDOWS\system32\lwtgtkut.dll Has been deleted!

Attempting to delete C:\windows\system32\lwtpgkcu.dll
C:\windows\system32\lwtpgkcu.dll Has been deleted!

Attempting to delete C:\windows\system32\lwvwiomj.dll
C:\windows\system32\lwvwiomj.dll Has been deleted!

Attempting to delete C:\windows\system32\lxjfsemv.dll
C:\windows\system32\lxjfsemv.dll Has been deleted!

Attempting to delete C:\windows\system32\lysbyicg.ini
C:\windows\system32\lysbyicg.ini Has been deleted!

Attempting to delete C:\windows\system32\mahcunmd.ini
C:\windows\system32\mahcunmd.ini Has been deleted!

Attempting to delete C:\windows\system32\masybwco.exe
C:\windows\system32\masybwco.exe Has been deleted!

Attempting to delete C:\windows\system32\mbxpmepp.dll
C:\windows\system32\mbxpmepp.dll Has been deleted!

Attempting to delete C:\windows\system32\mcimrlgc.exe
C:\windows\system32\mcimrlgc.exe Has been deleted!

Attempting to delete C:\windows\system32\mcnbfwie.dll
C:\windows\system32\mcnbfwie.dll Has been deleted!

Attempting to delete C:\windows\system32\mdehluic.dll
C:\windows\system32\mdehluic.dll Has been deleted!

Attempting to delete C:\windows\system32\mdvuweqb.dll
C:\windows\system32\mdvuweqb.dll Has been deleted!

Attempting to delete C:\windows\system32\mexlftqh.dll
C:\windows\system32\mexlftqh.dll Has been deleted!

Attempting to delete C:\windows\system32\mgvgnpos.ini
C:\windows\system32\mgvgnpos.ini Has been deleted!

Attempting to delete C:\windows\system32\mgxdtlig.ini
C:\windows\system32\mgxdtlig.ini Has been deleted!

Attempting to delete C:\windows\system32\mihyxqly.ini
C:\windows\system32\mihyxqly.ini Has been deleted!

Attempting to delete C:\windows\system32\mkraeymp.ini
C:\windows\system32\mkraeymp.ini Has been deleted!

Attempting to delete C:\windows\system32\mlwvxgac.exe
C:\windows\system32\mlwvxgac.exe Has been deleted!

Attempting to delete C:\windows\system32\mnpmghjf.dll
C:\windows\system32\mnpmghjf.dll Has been deleted!

Attempting to delete C:\windows\system32\mophwurc.exe
C:\windows\system32\mophwurc.exe Has been deleted!

Attempting to delete C:\windows\system32\mqgjuqaf.dll
C:\windows\system32\mqgjuqaf.dll Has been deleted!

Attempting to delete C:\windows\system32\mrafeeac.ini
C:\windows\system32\mrafeeac.ini Has been deleted!

Attempting to delete C:\windows\system32\mrenjmhu.dll
C:\windows\system32\mrenjmhu.dll Has been deleted!

Attempting to delete C:\windows\system32\mrmukvki.dll
C:\windows\system32\mrmukvki.dll Has been deleted!

Attempting to delete C:\windows\system32\mrnhoshi.ini
C:\windows\system32\mrnhoshi.ini Has been deleted!

Attempting to delete C:\windows\system32\msnsxuto.dll
C:\windows\system32\msnsxuto.dll Has been deleted!

Attempting to delete C:\windows\system32\muviwcnu.ini
C:\windows\system32\muviwcnu.ini Has been deleted!

Attempting to delete C:\windows\system32\mycbneol.ini
C:\windows\system32\mycbneol.ini Has been deleted!

Attempting to delete C:\windows\system32\nbmufekj.exe
C:\windows\system32\nbmufekj.exe Has been deleted!

Attempting to delete C:\windows\system32\nctvktxu.ini
C:\windows\system32\nctvktxu.ini Has been deleted!

Attempting to delete C:\windows\system32\neprqfpa.dll
C:\windows\system32\neprqfpa.dll Has been deleted!

Attempting to delete C:\windows\system32\nerhjtdv.dll
C:\windows\system32\nerhjtdv.dll Has been deleted!

Attempting to delete C:\windows\system32\nfcgnltx.dll
C:\windows\system32\nfcgnltx.dll Has been deleted!

Attempting to delete C:\windows\system32\nfmhdjdd.dll
C:\windows\system32\nfmhdjdd.dll Has been deleted!

Attempting to delete C:\windows\system32\ngywxsrf.dll
C:\windows\system32\ngywxsrf.dll Has been deleted!

Attempting to delete C:\windows\system32\nhswhfet.dll
C:\windows\system32\nhswhfet.dll Has been deleted!

Attempting to delete C:\windows\system32\nkxehunw.dll
C:\windows\system32\nkxehunw.dll Has been deleted!

Attempting to delete C:\windows\system32\nnfglyax.dll
C:\windows\system32\nnfglyax.dll Has been deleted!

Attempting to delete C:\windows\system32\nnotulia.dll
C:\windows\system32\nnotulia.dll Has been deleted!

Attempting to delete C:\windows\system32\nrgparll.ini
C:\windows\system32\nrgparll.ini Has been deleted!

Attempting to delete C:\windows\system32\ntfrjcnr.dll
C:\windows\system32\ntfrjcnr.dll Has been deleted!

Attempting to delete C:\windows\system32\ntpaxikv.dll
C:\windows\system32\ntpaxikv.dll Has been deleted!

Attempting to delete C:\windows\system32\nvbpquie.ini
C:\windows\system32\nvbpquie.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\nwildrsa.dll
C:\WINDOWS\system32\nwildrsa.dll Has been deleted!

Attempting to delete C:\windows\system32\obquwsoh.ini
C:\windows\system32\obquwsoh.ini Has been deleted!

Attempting to delete C:\windows\system32\ocvaplyj.ini
C:\windows\system32\ocvaplyj.ini Has been deleted!

Attempting to delete C:\windows\system32\odhqyvbx.ini
C:\windows\system32\odhqyvbx.ini Has been deleted!

Attempting to delete C:\windows\system32\odtvcief.exe
C:\windows\system32\odtvcief.exe Has been deleted!

Attempting to delete C:\windows\system32\ojlltdgx.ini
C:\windows\system32\ojlltdgx.ini Has been deleted!

Attempting to delete C:\windows\system32\ojsqwgfd.dll
C:\windows\system32\ojsqwgfd.dll Has been deleted!

Attempting to delete C:\windows\system32\okekbcsf.ini
C:\windows\system32\okekbcsf.ini Has been deleted!

Attempting to delete C:\windows\system32\okuuhbvy.ini
C:\windows\system32\okuuhbvy.ini Has been deleted!

Attempting to delete C:\windows\system32\omihkuni.exe
C:\windows\system32\omihkuni.exe Has been deleted!

Attempting to delete C:\windows\system32\onsembcl.dll
C:\windows\system32\onsembcl.dll Has been deleted!

Attempting to delete C:\windows\system32\oqblbgtv.ini
C:\windows\system32\oqblbgtv.ini Has been deleted!

Attempting to delete C:\windows\system32\oqofjdsw.ini
C:\windows\system32\oqofjdsw.ini Has been deleted!

Attempting to delete C:\windows\system32\oqufdnqj.dll
C:\windows\system32\oqufdnqj.dll Has been deleted!

Attempting to delete C:\windows\system32\orsdrgyp.exe
C:\windows\system32\orsdrgyp.exe Has been deleted!

Attempting to delete C:\windows\system32\otnggppu.ini
C:\windows\system32\otnggppu.ini Has been deleted!

Attempting to delete C:\windows\system32\oyyyghtp.dll
C:\windows\system32\oyyyghtp.dll Has been deleted!

Attempting to delete C:\windows\system32\pbnrmcws.dll
C:\windows\system32\pbnrmcws.dll Has been deleted!

Attempting to delete C:\windows\system32\pdasvgwv.dll
C:\windows\system32\pdasvgwv.dll Has been deleted!

Attempting to delete C:\windows\system32\penakyci.ini
C:\windows\system32\penakyci.ini Has been deleted!

Attempting to delete C:\windows\system32\pgkdomea.ini
C:\windows\system32\pgkdomea.ini Has been deleted!

Attempting to delete C:\windows\system32\pjdtahgj.ini
C:\windows\system32\pjdtahgj.ini Has been deleted!

Attempting to delete C:\windows\system32\pjfehklg.dll
C:\windows\system32\pjfehklg.dll Has been deleted!

Attempting to delete C:\windows\system32\pjyelhmh.exe
C:\windows\system32\pjyelhmh.exe Has been deleted!

Attempting to delete C:\windows\system32\pkgkmksj.ini
C:\windows\system32\pkgkmksj.ini Has been deleted!

Attempting to delete C:\windows\system32\pmyearkm.dll
C:\windows\system32\pmyearkm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pqsqaccy.dll
C:\WINDOWS\system32\pqsqaccy.dll Has been deleted!

Attempting to delete C:\windows\system32\psgbsbox.ini
C:\windows\system32\psgbsbox.ini Has been deleted!

Attempting to delete C:\windows\system32\ptepukqn.dll
C:\windows\system32\ptepukqn.dll Has been deleted!

Attempting to delete C:\windows\system32\pthgyyyo.ini
C:\windows\system32\pthgyyyo.ini Has been deleted!

Attempting to delete C:\windows\system32\pujagftb.dll
C:\windows\system32\pujagftb.dll Has been deleted!

Attempting to delete C:\windows\system32\pusuaeyf.dll
C:\windows\system32\pusuaeyf.dll Has been deleted!

Attempting to delete C:\windows\system32\puuwpjxp.dll
C:\windows\system32\puuwpjxp.dll Has been deleted!

Attempting to delete C:\windows\system32\pvugsyeh.exe
C:\windows\system32\pvugsyeh.exe Has been deleted!

Attempting to delete C:\windows\system32\pxkufyxr.ini
C:\windows\system32\pxkufyxr.ini Has been deleted!

Attempting to delete C:\windows\system32\pxxlhrcx.ini
C:\windows\system32\pxxlhrcx.ini Has been deleted!

Attempting to delete C:\windows\system32\qaqaojth.dll
C:\windows\system32\qaqaojth.dll Has been deleted!

Attempting to delete C:\windows\system32\qccrdjqw.ini
C:\windows\system32\qccrdjqw.ini Has been deleted!

Attempting to delete C:\windows\system32\qgxdfwex.dll
C:\windows\system32\qgxdfwex.dll Has been deleted!

Attempting to delete C:\windows\system32\qiboaomi.dll
C:\windows\system32\qiboaomi.dll Has been deleted!

Attempting to delete C:\windows\system32\qlchibiu.dll
C:\windows\system32\qlchibiu.dll Has been deleted!

Attempting to delete C:\windows\system32\qphakyfg.ini
C:\windows\system32\qphakyfg.ini Has been deleted!

Attempting to delete C:\windows\system32\qpnpqajv.exe
C:\windows\system32\qpnpqajv.exe Has been deleted!

Attempting to delete C:\windows\system32\qqeluyub.dll
C:\windows\system32\qqeluyub.dll Has been deleted!

Attempting to delete C:\windows\system32\qqvdvulg.dll
C:\windows\system32\qqvdvulg.dll Has been deleted!

Attempting to delete C:\windows\system32\qrdduqju.dll
C:\windows\system32\qrdduqju.dll Has been deleted!

Attempting to delete C:\windows\system32\qsrxfroh.ini
C:\windows\system32\qsrxfroh.ini Has been deleted!

Attempting to delete C:\windows\system32\qxdiaffo.dll
C:\windows\system32\qxdiaffo.dll Has been deleted!

Attempting to delete C:\windows\system32\qykyuovk.dll
C:\windows\system32\qykyuovk.dll Has been deleted!

Attempting to delete C:\windows\system32\qyssfvik.dll
C:\windows\system32\qyssfvik.dll Has been deleted!

Attempting to delete C:\windows\system32\rbhafqpc.ini
C:\windows\system32\rbhafqpc.ini Has been deleted!

Attempting to delete C:\windows\system32\rcfhebql.dll
C:\windows\system32\rcfhebql.dll Has been deleted!

Attempting to delete C:\windows\system32\rhsidpes.exe
C:\windows\system32\rhsidpes.exe Has been deleted!

Attempting to delete C:\windows\system32\riamtgrl.dll
C:\windows\system32\riamtgrl.dll Has been deleted!

Attempting to delete C:\windows\system32\ritigmob.exe
C:\windows\system32\ritigmob.exe Has been deleted!

Attempting to delete C:\windows\system32\rjlgcxcg.dll
C:\windows\system32\rjlgcxcg.dll Has been deleted!

Attempting to delete C:\windows\system32\rljqurif.dll
C:\windows\system32\rljqurif.dll Has been deleted!

Attempting to delete C:\windows\system32\rmaftlih.dll
C:\windows\system32\rmaftlih.dll Has been deleted!

Attempting to delete C:\windows\system32\rncjrftn.ini
C:\windows\system32\rncjrftn.ini Has been deleted!

Attempting to delete C:\windows\system32\rohkhwuw.ini
C:\windows\system32\rohkhwuw.ini Has been deleted!

Attempting to delete C:\windows\system32\rphaodfv.dll
C:\windows\system32\rphaodfv.dll Has been deleted!

Attempting to delete C:\windows\system32\rphnchit.ini
C:\windows\system32\rphnchit.ini Has been deleted!

Attempting to delete C:\windows\system32\rpshynug.dll
C:\windows\system32\rpshynug.dll Has been deleted!

Attempting to delete C:\windows\system32\rqykbswc.dll
C:\windows\system32\rqykbswc.dll Has been deleted!

Attempting to delete C:\windows\system32\rrnkbira.dll
C:\windows\system32\rrnkbira.dll Has been deleted!

Attempting to delete C:\windows\system32\rvrkgyko.exe
C:\windows\system32\rvrkgyko.exe Has been deleted!

Attempting to delete C:\windows\system32\rxyfukxp.dll
C:\windows\system32\rxyfukxp.dll Has been deleted!

Attempting to delete C:\windows\system32\sfmwgvgt.dll
C:\windows\system32\sfmwgvgt.dll Has been deleted!

Attempting to delete C:\windows\system32\sopngvgm.dll
C:\windows\system32\sopngvgm.dll Has been deleted!

Attempting to delete C:\windows\system32\spbhrfns.dll
C:\windows\system32\spbhrfns.dll Has been deleted!

Attempting to delete C:\windows\system32\suvytfei.ini
C:\windows\system32\suvytfei.ini Has been deleted!

Attempting to delete C:\windows\system32\svlesekg.dll
C:\windows\system32\svlesekg.dll Has been deleted!

Attempting to delete C:\windows\system32\svlsuuja.exe
C:\windows\system32\svlsuuja.exe Has been deleted!

Attempting to delete C:\windows\system32\swbfidwt.dll
C:\windows\system32\swbfidwt.dll Has been deleted!

Attempting to delete C:\windows\system32\swcmrnbp.ini
C:\windows\system32\swcmrnbp.ini Has been deleted!

Attempting to delete C:\windows\system32\swlnmtmk.dll
C:\windows\system32\swlnmtmk.dll Has been deleted!

Attempting to delete C:\windows\system32\swstvwfj.dll
C:\windows\system32\swstvwfj.dll Has been deleted!

Attempting to delete C:\windows\system32\tbruskkw.dll
C:\windows\system32\tbruskkw.dll Has been deleted!

Attempting to delete C:\windows\system32\tcamoptx.ini
C:\windows\system32\tcamoptx.ini Has been deleted!

Attempting to delete C:\windows\system32\tcaohwtw.dll
C:\windows\system32\tcaohwtw.dll Has been deleted!

Attempting to delete C:\windows\system32\tdhxfwqy.dll
C:\windows\system32\tdhxfwqy.dll Has been deleted!

Attempting to delete C:\windows\system32\tebenhbf.dll
C:\windows\system32\tebenhbf.dll Has been deleted!

Attempting to delete C:\windows\system32\tebqygbe.exe
C:\windows\system32\tebqygbe.exe Has been deleted!

Attempting to delete C:\windows\system32\tefhwshn.ini
C:\windows\system32\tefhwshn.ini Has been deleted!

Attempting to delete C:\windows\system32\tftwtadb.ini
C:\windows\system32\tftwtadb.ini Has been deleted!

Attempting to delete C:\windows\system32\thulxcxa.ini2
C:\windows\system32\thulxcxa.ini2 Has been deleted!

Attempting to delete C:\windows\system32\thulxcxa.tmp
C:\windows\system32\thulxcxa.tmp Has been deleted!

Attempting to delete C:\windows\system32\thvmnauc.dll
C:\windows\system32\thvmnauc.dll Has been deleted!

Attempting to delete C:\windows\system32\tihcnhpr.dll
C:\windows\system32\tihcnhpr.dll Has been deleted!

Attempting to delete C:\windows\system32\tioolwok.ini
C:\windows\system32\tioolwok.ini Has been deleted!

Attempting to delete C:\windows\system32\tvjqnbnw.dll
C:\windows\system32\tvjqnbnw.dll Has been deleted!

Attempting to delete C:\windows\system32\uehacjne.ini
C:\windows\system32\uehacjne.ini Has been deleted!

Attempting to delete C:\windows\system32\uhfudaie.exe
C:\windows\system32\uhfudaie.exe Has been deleted!

Attempting to delete C:\windows\system32\uhmjnerm.ini
C:\windows\system32\uhmjnerm.ini Has been deleted!

Attempting to delete C:\windows\system32\uhtcldmg.dll
C:\windows\system32\uhtcldmg.dll Has been deleted!

Attempting to delete C:\windows\system32\uibihclq.ini
C:\windows\system32\uibihclq.ini Has been deleted!

Attempting to delete C:\windows\system32\uidpemoi.dll
C:\windows\system32\uidpemoi.dll Has been deleted!

Attempting to delete C:\windows\system32\uijbdcbf.ini
C:\windows\system32\uijbdcbf.ini Has been deleted!

Attempting to delete C:\windows\system32\uisvnbow.ini
C:\windows\system32\uisvnbow.ini Has been deleted!

Attempting to delete C:\windows\system32\uivpxsoy.ini
C:\windows\system32\uivpxsoy.ini Has been deleted!

Attempting to delete C:\windows\system32\ujquddrq.ini
C:\windows\system32\ujquddrq.ini Has been deleted!

Attempting to delete C:\windows\system32\ujsqufcl.ini
C:\windows\system32\ujsqufcl.ini Has been deleted!

Attempting to delete C:\windows\system32\ukpabpca.ini
C:\windows\system32\ukpabpca.ini Has been deleted!

Attempting to delete C:\windows\system32\ulumgmcy.dll
C:\windows\system32\ulumgmcy.dll Has been deleted!

Attempting to delete C:\windows\system32\uncwivum.dll
C:\windows\system32\uncwivum.dll Has been deleted!

Attempting to delete C:\windows\system32\unyqmhuv.exe
C:\windows\system32\unyqmhuv.exe Has been deleted!

Attempting to delete C:\windows\system32\uolquxti.ini
C:\windows\system32\uolquxti.ini Has been deleted!

Attempting to delete C:\windows\system32\uppggnto.dll
C:\windows\system32\uppggnto.dll Has been deleted!

Attempting to delete C:\windows\system32\urwciipr.exe
C:\windows\system32\urwciipr.exe Has been deleted!

Attempting to delete C:\windows\system32\usjctqsh.ini
C:\windows\system32\usjctqsh.ini Has been deleted!

Attempting to delete C:\windows\system32\uxtkvtcn.dll
C:\windows\system32\uxtkvtcn.dll Has been deleted!

Attempting to delete C:\windows\system32\vbmgiiib.ini
C:\windows\system32\vbmgiiib.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\vcbyourp.dll
C:\WINDOWS\system32\vcbyourp.dll Has been deleted!

Attempting to delete C:\windows\system32\vdlorraw.dll
C:\windows\system32\vdlorraw.dll Has been deleted!

Attempting to delete C:\windows\system32\vfdoahpr.ini
C:\windows\system32\vfdoahpr.ini Has been deleted!

Attempting to delete C:\windows\system32\vlpshvmd.dll
C:\windows\system32\vlpshvmd.dll Has been deleted!

Attempting to delete C:\windows\system32\vmesfjxl.ini
C:\windows\system32\vmesfjxl.ini Has been deleted!

Attempting to delete C:\windows\system32\vqpbiuky.dll
C:\windows\system32\vqpbiuky.dll Has been deleted!

Attempting to delete C:\windows\system32\vsstxmjj.dll
C:\windows\system32\vsstxmjj.dll Has been deleted!

Attempting to delete C:\windows\system32\vtgblbqo.dll
C:\windows\system32\vtgblbqo.dll Has been deleted!

Attempting to delete C:\windows\system32\vthuwpoy.dll
C:\windows\system32\vthuwpoy.dll Has been deleted!

Attempting to delete C:\windows\system32\vtonufse.exe
C:\windows\system32\vtonufse.exe Has been deleted!

Attempting to delete C:\windows\system32\vvxnxhlf.ini
C:\windows\system32\vvxnxhlf.ini Has been deleted!

Attempting to delete C:\windows\system32\vwgljwur.exe
C:\windows\system32\vwgljwur.exe Has been deleted!

Attempting to delete C:\windows\system32\vwgvsadp.ini
C:\windows\system32\vwgvsadp.ini Has been deleted!

Attempting to delete C:\windows\system32\vwngrcvk.dll
C:\windows\system32\vwngrcvk.dll Has been deleted!

Attempting to delete C:\windows\system32\warroldv.ini
C:\windows\system32\warroldv.ini Has been deleted!

Attempting to delete C:\windows\system32\wbiphhhh.ini
C:\windows\system32\wbiphhhh.ini Has been deleted!

Attempting to delete C:\windows\system32\wcpjspel.dll
C:\windows\system32\wcpjspel.dll Has been deleted!

Attempting to delete C:\windows\system32\wegineqb.ini
C:\windows\system32\wegineqb.ini Has been deleted!

Attempting to delete C:\windows\system32\wgxqdlue.ini
C:\windows\system32\wgxqdlue.ini Has been deleted!

Attempting to delete C:\windows\system32\wkksurbt.ini
C:\windows\system32\wkksurbt.ini Has been deleted!

Attempting to delete C:\windows\system32\wlqrwqwy.dll
C:\windows\system32\wlqrwqwy.dll Has been deleted!

Attempting to delete C:\windows\system32\wmnvhedx.dll
C:\windows\system32\wmnvhedx.dll Has been deleted!

Attempting to delete C:\windows\system32\wnbnqjvt.ini
C:\windows\system32\wnbnqjvt.ini Has been deleted!

Attempting to delete C:\windows\system32\wnuhexkn.ini
C:\windows\system32\wnuhexkn.ini Has been deleted!

Attempting to delete C:\windows\system32\wobnvsiu.dll
C:\windows\system32\wobnvsiu.dll Has been deleted!

Attempting to delete C:\windows\system32\wpltompx.dll
C:\windows\system32\wpltompx.dll Has been deleted!

Attempting to delete C:\windows\system32\wqjdrccq.dll
C:\windows\system32\wqjdrccq.dll Has been deleted!

Attempting to delete C:\windows\system32\wrfuannh.ini
C:\windows\system32\wrfuannh.ini Has been deleted!

Attempting to delete C:\windows\system32\wsdjfoqo.dll
C:\windows\system32\wsdjfoqo.dll Has been deleted!

Attempting to delete C:\windows\system32\wtwhoact.ini
C:\windows\system32\wtwhoact.ini Has been deleted!

Attempting to delete C:\windows\system32\wuwhkhor.dll
C:\windows\system32\wuwhkhor.dll Has been deleted!

Attempting to delete C:\windows\system32\wychgbyy.dll
C:\windows\system32\wychgbyy.dll Has been deleted!

Attempting to delete C:\windows\system32\xaylgfnn.ini
C:\windows\system32\xaylgfnn.ini Has been deleted!

Attempting to delete C:\windows\system32\xbjkvsyf.dll
C:\windows\system32\xbjkvsyf.dll Has been deleted!

Attempting to delete C:\windows\system32\xbvyqhdo.dll
C:\windows\system32\xbvyqhdo.dll Has been deleted!

Attempting to delete C:\windows\system32\xcaswucc.exe
C:\windows\system32\xcaswucc.exe Has been deleted!

Attempting to delete C:\windows\system32\xcrhlxxp.dll
C:\windows\system32\xcrhlxxp.dll Has been deleted!

Attempting to delete C:\windows\system32\xewfdxgq.ini
C:\windows\system32\xewfdxgq.ini Has been deleted!

Attempting to delete C:\windows\system32\xgcotudx.dll
C:\windows\system32\xgcotudx.dll Has been deleted!

Attempting to delete C:\windows\system32\xgdtlljo.dll
C:\windows\system32\xgdtlljo.dll Has been deleted!

Attempting to delete C:\windows\system32\xgndiywd.dll
C:\windows\system32\xgndiywd.dll Has been deleted!

Attempting to delete C:\windows\system32\xgygmwky.ini
C:\windows\system32\xgygmwky.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xkgtonvg.dll
C:\WINDOWS\system32\xkgtonvg.dll Has been deleted!

Attempting to delete C:\windows\system32\xkocwcyo.dll
C:\windows\system32\xkocwcyo.dll Has been deleted!

Attempting to delete C:\windows\system32\xobsbgsp.dll
C:\windows\system32\xobsbgsp.dll Has been deleted!

Attempting to delete C:\windows\system32\xpfsmgdt.dll
C:\windows\system32\xpfsmgdt.dll Has been deleted!

Attempting to delete C:\windows\system32\xpmotlpw.ini
C:\windows\system32\xpmotlpw.ini Has been deleted!

Attempting to delete C:\windows\system32\xpsauhva.dll
C:\windows\system32\xpsauhva.dll Has been deleted!

Attempting to delete C:\windows\system32\xtindchk.ini
C:\windows\system32\xtindchk.ini Has been deleted!

Attempting to delete C:\windows\system32\xtjlwaag.dll
C:\windows\system32\xtjlwaag.dll Has been deleted!

Attempting to delete C:\windows\system32\xtlngcfn.ini
C:\windows\system32\xtlngcfn.ini Has been deleted!

Attempting to delete C:\windows\system32\xtpomact.dll
C:\windows\system32\xtpomact.dll Has been deleted!

Attempting to delete C:\windows\system32\xukrrsma.ini
C:\windows\system32\xukrrsma.ini Has been deleted!

Attempting to delete C:\windows\system32\yakjtbej.ini
C:\windows\system32\yakjtbej.ini Has been deleted!

Attempting to delete C:\windows\system32\yalhpepw.dll
C:\windows
  • 0

#24
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
and here is the Latest HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:15 AM, on 10/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\fixthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.apple.com/itunes/download/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3E80EA04-3EBA-40E2-B1C1-58D119F6518a} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {54E6D360-DCF8-4E50-92C9-8792126D2864} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {6B8ADCEE-02B2-475A-803C-F3ADF8B773F8} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {74F932E6-C714-4D49-83DA-C48F9FD61A76} - C:\WINDOWS\system32\fbiugbyy.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A91DB785-7D93-42AE-AC4C-E6F0BD0CA45D} - C:\WINDOWS\AppPatch\natimxl.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {D023390D-0F52-4437-B2FF-58561E3368A5} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {D0329530-48D1-4AD6-AAB6-E90338C13212} - C:\WINDOWS\system32\djqfhsn.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://titanium.full...cweb/awswax.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.ai...AIM.9.5.1.8.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.ritea...PhotoOnline.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://mainstreet.f...perSetupSP1.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Remote Procedure Call (RPC) Se (RPCSEO) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://www.google.com/
O24 - Desktop Component 1: MySpace - http://www.myspace.com/

--
End of file - 9674 bytes
  • 0

#25
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
thanks alot again for helping me out.
  • 0

Advertisements


#26
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome. :)

We will have to have something else to help clean up some of these files.

First download AVG Anti-Spyware from HERE and save that file to your desktop. (This will install and run in Safe Mode)
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
=================================================
After that Double click on the Avast icon on your desktop.
Let it go through the memory scan then it will open to a Mp3 type interface.
At the top left hand corner will be a small button like this ->

After that Click on this button -> .
Let it run at next reboot.
When it finds the files choose whatever number says to move it to the chest.
===================================================
After reboot
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan.
(It is okay if it does not save a report.)
==============================
After AVg antispyware runs reboot again and
rerun Vundofix again.
Let it remove what it finds and after it runs and completes Double click on Vundo fix again and Right click on the white box and select Add More Files.
Paste in this line ->C:\WINDOWS\system32\djqfhsn.dll and then choose remove Vundo.
Let it run and then post back with the Vundofix logs and a new Hijackthis log
also AVG log if you get one.
  • 0

#27
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
I don't have Avast on my desktop. I think I deleted it, after a Blue error screen came up after I installed it after I rebooted the computer. So what should I do?
  • 0

#28
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Try going to Start>All programs>Avast.

There should be a startup folder with the icon in it.

The blue screen is more than likely from the infection.

If you still cannot get it to work then just go on to running AVG anstispyware>then Vundofix.

Edited by kahdah, 17 October 2007 - 03:00 AM.

  • 0

#29
ksanmamaril

ksanmamaril

    Member

  • Topic Starter
  • Member
  • PipPip
  • 37 posts
hey Kahdah.

Here is the new Vundofix text:

Scan started at 12:36:18 AM 10/18/2007

Listing files found while scanning....

No infected files were found.

=============================================================

and here is the New HiJackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:42:02 AM, on 10/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\fixthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.apple.com/itunes/download/
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3E80EA04-3EBA-40E2-B1C1-58D119F6518a} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {54E6D360-DCF8-4E50-92C9-8792126D2864} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {6B8ADCEE-02B2-475A-803C-F3ADF8B773F8} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {74F932E6-C714-4D49-83DA-C48F9FD61A76} - C:\WINDOWS\system32\fbiugbyy.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A91DB785-7D93-42AE-AC4C-E6F0BD0CA45D} - C:\WINDOWS\AppPatch\natimxl.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {D023390D-0F52-4437-B2FF-58561E3368A5} - C:\WINDOWS\system32\ksqsoelb.dll (file missing)
O2 - BHO: (no name) - {D0329530-48D1-4AD6-AAB6-E90338C13212} - C:\WINDOWS\system32\djqfhsn.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - http://titanium.full...cweb/awswax.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.h...staller_gmn.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} (AIM UPF Control) - http://pictures06.ai...AIM.9.5.1.8.cab
O16 - DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} (Rite Aid One Hour Photo Online Control) - https://photos.ritea...PhotoOnline.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart...ploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://mainstreet.f...perSetupSP1.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCLEPCI - Pinnacle Systems GmbH - C:\WINDOWS\system32\drivers\pclepci.sys
O23 - Service: Remote Procedure Call (RPC) Se (RPCSEO) - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O24 - Desktop Component 0: (no name) - http://www.google.com/
O24 - Desktop Component 1: MySpace - http://www.myspace.com/

--
End of file - 9953 bytes




=============================================================

I would post an AVG log but it did not save one.
  • 0

#30
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Please submit the following files to one of these online file scanners.

C:\WINDOWS\system32\djqfhsn.dll
Jotti File Scan
VirusTotal File Scan
This will produce a report after the scan is complete, please copy and paste those results in your next post.
==================================
Open notepad and copy what is in the codebox below:
regedit /e look.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System"
start notepad look.txt

Save this as look.bat , choose to save as *all files and place it on your desktop.
It should look like this:
Doubleclick on it and notepad should open.

Please paste the contents of look.txt in your next reply.

=======================================
After that can you do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
==================================
Please post back with these logs:
Virus file submission
Look.txt
Kaspersky log

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP