Alright, I did already have Malwarebytes, I also have SUPERantispyware, but that's it.
I didn't know which program to use, though i've had many before just wasn't sure which one actually did it's job.
Malwarebytes would scan, then it'd stop and say error send error report. So I ran combofix first, then Malwarebytes, and it worked.
here's the combofix log.
ComboFix 08-04-12.3 - Compaq_Administrator 2008-04-13 19:09:28.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1437 [GMT -5:00]
Running from: C:\Documents and Settings\Compaq_Administrator\Desktop\ComboFix.exe
.
ADS - svchost.exe: deleted 28160 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\All Users\Desktop\Anti Virus Pro spyware remover.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Anti Virus Pro spyware remover
C:\Documents and Settings\All Users\Start Menu\Programs\Anti Virus Pro spyware remover\Register Anti Virus Pro spyware remover.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Anti Virus Pro spyware remover\Start Anti Virus Pro spyware remover.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Anti Virus Pro spyware remover\Uninstall.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe
C:\Documents and Settings\Compaq_Administrator\Application Data\Anti-Virus-Pro.com
C:\Documents and Settings\Compaq_Administrator\Application Data\ASKS~1
C:\Documents and Settings\Compaq_Administrator\Application Data\ASKS~1\?explore.exe
C:\Documents and Settings\Compaq_Administrator\Application Data\ICROSO~1.NET
C:\Documents and Settings\Compaq_Administrator\Application Data\ICROSO~1.NET\?icrosoft.NET\
C:\Documents and Settings\Compaq_Administrator\Application Data\ICROSO~1.NET\rundll.exe
C:\Documents and Settings\Compaq_Administrator\Application Data\Install.dat
C:\Documents and Settings\Compaq_Administrator\Application Data\microsoft\internet explorer\Desktop.htt
C:\Documents and Settings\Compaq_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Anti Virus Pro spyware remover.lnk
C:\Documents and Settings\Compaq_Administrator\Application Data\printer.exe
C:\Documents and Settings\Compaq_Administrator\Desktop\bravesentry.lnk
C:\Documents and Settings\Compaq_Administrator\ftpdll.dll
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\n.ini
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Brave-Sentry
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Brave-Sentry\BraveSentry.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Brave-Sentry\Uninstall.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\findfast.exe
C:\Program Files\AntiVirusPro
C:\Program Files\AntiVirusPro\AntiVirusPro.exe
C:\Program Files\AntiVirusPro\AntiVirusPro.exe.local
C:\Program Files\AntiVirusPro\AntiVirusPro.exe.log
C:\Program Files\AntiVirusPro\Core.dll
C:\Program Files\AntiVirusPro\database.pkg
C:\Program Files\AntiVirusPro\Localization.dll
C:\Program Files\AntiVirusPro\msvcp71.dll
C:\Program Files\AntiVirusPro\msvcr71.dll
C:\Program Files\AntiVirusPro\Uninstall.exe
C:\Program Files\AntiVirusPro\WndSystem.dll
C:\Program Files\bravesentry
C:\Program Files\bravesentry\BraveSentry.exe
C:\Program Files\bravesentry\BraveSentry.lic
C:\Program Files\bravesentry\BraveSentry0.bs
C:\Program Files\bravesentry\BraveSentry0.dll
C:\Program Files\bravesentry\BraveSentry1.bs
C:\Program Files\bravesentry\BraveSentry2.dll
C:\Program Files\bravesentry\BraveSentry3.dll
C:\Program Files\bravesentry\Uninstall.exe
C:\Program Files\cjb
C:\Program Files\cjb\cjb8.exe
C:\Program Files\Common Files\Yazzle1552OinAdmin.exe
C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe
C:\Program Files\iSecurity
C:\Program Files\iSecurity\{32FF2108-1EF0-4ae8-8C23-17C92EAA5DEF}\install.exe
C:\Program Files\iSecurity\iSecurity.dat
C:\Program Files\iSecurity\ucleaner.bmp
C:\Program Files\iSecurity\ucleaneri.bmp
C:\Program Files\iSecurity\udefender.bmp
C:\Program Files\iSecurity\udefenderi.bmp
C:\Program Files\iSecurity\v5\iSecurity.cpl
C:\Program Files\iSecurity\winifixer.bmp
C:\Program Files\iSecurity\winifixeri.bmp
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\outerinfo
C:\Program Files\outerinfo\FF\chrome.manifest
C:\Program Files\outerinfo\FF\components\FF.dll
C:\Program Files\outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\outerinfo\FF\install.rdf
C:\Program Files\outerinfo\Terms.rtf
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive15.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dicy.gz
C:\Program Files\QdrModule\kwdy.gz
C:\Program Files\QdrModule\pckr.dat
C:\Program Files\QdrModule\QdrModule15.exe
C:\Program Files\QdrPack
C:\Program Files\QdrPack\dicts.gz
C:\Program Files\QdrPack\QdrPack15.exe
C:\Program Files\QdrPack\trgts.gz
C:\Program Files\webhancer
C:\Program Files\webhancer\Programs\license.txt
C:\Program Files\webhancer\Programs\readme.txt
C:\Program Files\webhancer\Programs\sporder.dll
C:\Program Files\webhancer\Programs\webhdll.dll
C:\Program Files\webhancer\Programs\whagent.exe
C:\Program Files\webhancer\Programs\whagent.ini
C:\Program Files\webhancer\Programs\whiehlpr.dll
C:\Program Files\webhancer\Programs\whinstaller.exe
C:\WINDOWS\conf.inf
C:\WINDOWS\desktop.html
C:\WINDOWS\Installer\{9bffcd6d-45aa-49bf-835c-bec81c0d191c}
C:\WINDOWS\Installer\{9bffcd6d-45aa-49bf-835c-bec81c0d191c}\zip.dll
C:\WINDOWS\kavir.exe
C:\WINDOWS\ky.sxc
C:\WINDOWS\lfn.exe
C:\WINDOWS\mrofinu1854.exe
C:\WINDOWS\mrofinu27.exe
C:\WINDOWS\mscon.sio
C:\WINDOWS\nivavir.config
C:\WINDOWS\shell.exe
C:\WINDOWS\system32\~.exe
C:\WINDOWS\system32\
000060.exe
C:\WINDOWS\system32\
000080.exe
C:\WINDOWS\system32\
000090.exe
C:\WINDOWS\system32\22405248441.dll
C:\WINDOWS\system32\alt.exe.exe
C:\WINDOWS\system32\BluetoothAuthorizationAgent.exe
C:\WINDOWS\system32\config\56733378.Evt
C:\WINDOWS\system32\dllgh8jkd1q1.exe
C:\WINDOWS\system32\dllgh8jkd1q2.exe
C:\WINDOWS\system32\dllgh8jkd1q5.exe
C:\WINDOWS\system32\dllgh8jkd1q6.exe
C:\WINDOWS\system32\dllgh8jkd1q7.exe
C:\WINDOWS\system32\dllgh8jkd1q8.exe
C:\WINDOWS\system32\drivers\grande48.sys
C:\WINDOWS\system32\drivers\qzphmqbc.dat
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\drivers\Tff23.sys
c:\windows\system32\Drivers\Xfm31.sys
C:\WINDOWS\system32\drivers\YKY42.sys
C:\WINDOWS\system32\duomslht.dll
C:\WINDOWS\system32\ftpdll.dll
C:\WINDOWS\system32\gQBbcMoq.ini
C:\WINDOWS\system32\gQBbcMoq.ini2
C:\WINDOWS\system32\hxccwtaa.ini
C:\WINDOWS\system32\iSecurity.cpl
C:\WINDOWS\system32\khfEWPGw.dll
C:\WINDOWS\system32\kr_done1
C:\WINDOWS\system32\maxpaynow1.exe
C:\WINDOWS\system32\maxpaynowti.exe
C:\WINDOWS\system32\maxpaynowti1.exe
C:\WINDOWS\system32\msdefender.exe
C:\WINDOWS\system32\msram.dll
C:\WINDOWS\system32\n.ini
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\rceu.dll
C:\WINDOWS\system32\shift.exe.exe
C:\WINDOWS\system32\spoolvs.exe
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\thlsmoud.ini
C:\WINDOWS\system32\tkfepsbehgbit.dll
C:\WINDOWS\system32\tuvWmKdE.dll
C:\WINDOWS\system32\vedxg4am1et2.exe
C:\WINDOWS\system32\vedxg6ame4.exe
C:\WINDOWS\system32\vedxga1me4t1.exe
C:\WINDOWS\system32\vedxga3me2.exe
C:\WINDOWS\system32\vedxga4m1et4.exe
C:\WINDOWS\system32\vedxga4me1.exe
C:\WINDOWS\system32\vedxga5me3.exe
C:\WINDOWS\system32\vx.tll
C:\WINDOWS\system32\wGPWEfhk.ini
C:\WINDOWS\system32\wGPWEfhk.ini2
C:\WINDOWS\system32\wind32.exe
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\WLCtrl32.dl_
C:\WINDOWS\system32\WLCtrl32.dll
C:\WINDOWS\system32\wmsdkns.exe
C:\WINDOWS\system32\wowfx.dll
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wsnpoem\audio.dll
C:\WINDOWS\system32\wsnpoem\video.dll
C:\WINDOWS\taskmon.exe
C:\WINDOWS\TEMP\2111024123.exe
C:\WINDOWS\winself.exe
C:\windows\xpupdate.exe
----- BITS: Possible infected sites -----
hxxp://flyvideonetwork.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICF
-------\Legacy_TFF23
-------\Legacy_XFM31
-------\Legacy_YKY42
-------\Service_asc3550p
-------\Service_bxdbhgeo
-------\Service_ccEvtMgr
-------\Service_ccPwdSvc
-------\Service_ccPxySvc
-------\Service_ICF
-------\Service_NISUM
-------\Service_Tff23
-------\Service_Xfm31
-------\Service_YKY42
-------\Service_Yky42
-------\Legacy_bxdbhgeo
-------\Legacy_MSSysInterv1
-------\Legacy_Schedule
-------\bxdbhgeo
-------\MSSysInterv1
-------\Schedule
((((((((((((((((((((((((( Files Created from 2008-03-14 to 2008-04-14 )))))))))))))))))))))))))))))))
.
2008-04-13 19:01 . 2008-04-13 19:01 3,648 --a------ C:\WINDOWS\system32\upluspdi.dll
2008-04-13 18:16 . 2008-04-13 18:16 <DIR> d-------- C:\_OTMoveIt
2008-04-13 17:57 . 2008-04-13 17:57 37,888 -rahs---- C:\WINDOWS\system32\actmoviev.exe
2008-04-13 17:56 . 2008-04-13 17:56 269,334 --a------ C:\WINDOWS\system32\fmpgrqt.bmp
2008-04-13 17:50 . 2008-04-13 17:50 37,888 -rahs---- C:\WINDOWS\system32\a234h.exe
2008-04-13 17:50 . 2008-04-13 17:50 37,888 -rahs---- C:\WINDOWS\system32\
000080o.exe
2008-04-13 17:50 . 2008-04-13 17:50 3,648 --a------ C:\WINDOWS\system32\lgvydlsi.dll
2008-04-13 17:48 . 2008-04-13 17:48 269,334 --a------ C:\WINDOWS\system32\tsbalkfel.bmp
2008-04-13 17:47 . 2008-04-13 17:47 66,864 --ahs---- C:\Documents and Settings\LocalService\cftmon.exe
2008-04-13 17:42 . 2008-04-13 17:42 22,016 --ahs---- C:\WINDOWS\system32\aaaamonj.dll
2008-04-13 17:40 . 2004-08-09 23:00 113,664 --a------ C:\WINDOWS\system32\bihcf.sys
2008-04-13 17:40 . 2008-04-13 17:40 41,984 -rahs---- C:\WINDOWS\system32\1041l.exe
2008-04-13 17:40 . 2008-04-13 17:56 7,168 --a------ C:\WINDOWS\win32ole.dll
2008-04-13 17:39 . 2008-04-13 17:39 37,888 -rahs---- C:\WINDOWS\system32\alrsvcu.exe
2008-04-13 17:39 . 2008-04-13 17:39 37,888 -rahs---- C:\WINDOWS\system32\acelpdecc.exe
2008-04-13 17:39 . 2008-04-13 17:57 32 --a-s---- C:\WINDOWS\system32\2130578575.dat
2008-04-13 17:39 . 2008-04-13 17:39 29 --a------ C:\WINDOWS\system32\ssrfwwpi.tmp
2008-04-13 17:38 . 2008-04-13 17:38 6,672 --a------ C:\WINDOWS\system32\ibudu.dll
2008-04-13 17:38 . 2008-04-13 19:17 2,560 --a------ C:\WINDOWS\system32\itcoe.sys
2008-04-13 17:37 . 2008-04-13 17:37 269,334 --a------ C:\WINDOWS\system32\mtsfilkn.bmp
2008-04-13 17:37 . 2008-04-13 17:56 72,155 --ahs---- C:\Documents and Settings\Compaq_Administrator\cftmon.exe
2008-04-13 17:22 . 2008-04-13 17:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\krmrshwv
2008-04-13 17:22 . 2008-04-13 17:22 196,096 --a------ C:\WINDOWS\zujmnsrs.dll
2008-04-13 17:22 . 2008-04-13 17:22 118,784 --a------ C:\WINDOWS\system32\arcbcnsh.exe
2008-04-13 17:22 . 2008-04-13 17:22 70,144 --a------ C:\WINDOWS\pkjutetg.dll
2008-04-13 17:22 . 2008-04-13 17:22 70,144 --a------ C:\Documents and Settings\All Users\Application Data\ujavgbur.dll
2008-04-13 17:21 . 2008-04-13 17:23 <DIR> d-------- C:\Program Files\Bat
2008-04-13 17:20 . 2008-04-13 17:20 6,656 --a------ C:\WINDOWS\ns.dll
2008-04-12 18:46 . 2008-04-12 18:46 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-12 14:55 . 2008-04-12 14:55 <DIR> d-------- C:\Program Files\CCleaner
2008-04-12 14:41 . 2008-04-12 14:55 <DIR> d-------- C:\Program Files\XoftSpySE
2008-04-12 13:25 . 2008-04-12 13:25 3,370 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-12 13:19 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-12 13:19 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-12 13:19 . 2008-04-12 17:34 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-12 13:19 . 2008-04-12 13:49 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-12 13:19 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-12 13:19 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-12 13:19 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-12 12:47 . 2008-04-13 17:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-04-12 12:46 . 2008-04-12 18:50 <DIR> d-------- C:\WINDOWS\cuawsppw
2008-04-12 12:46 . 2008-04-12 23:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\rubsbwpk
2008-04-12 12:46 . 2008-04-12 12:46 70,144 --a------ C:\WINDOWS\mzcxcjel.dll
2008-04-12 12:46 . 2008-04-12 12:46 70,144 --a------ C:\Documents and Settings\All Users\Application Data\pyvgjupy.dll
2008-04-12 12:44 . 2008-04-12 12:44 6,656 --a------ C:\WINDOWS\ons.dll
2008-04-07 19:59 . 2008-04-07 19:59 402 --a------ C:\WINDOWS\system32\LE347.tmp
2008-04-07 19:59 . 2008-04-07 19:59 402 --a------ C:\WINDOWS\system32\LE24D.tmp
2008-04-07 19:59 . 2008-04-07 19:59 402 --a------ C:\WINDOWS\system32\LE153.tmp
2008-04-07 17:27 . 2008-04-08 07:33 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-07 17:27 . 2008-04-07 17:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-07 17:07 . 2008-04-07 17:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-30 16:10 . 2008-03-30 16:10 <DIR> d-------- C:\Program Files\Screenshot Utility
2008-03-30 08:02 . 2008-03-30 08:02 190,464 --a------ C:\WINDOWS\system32\luapvs.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-13 21:38 --------- d-----w C:\Documents and Settings\Compaq_Administrator\Application Data\LimeWire
2008-04-07 22:56 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-07 22:52 --------- d-----w C:\Program Files\Viewpoint
2008-04-07 22:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-04-07 21:45 --------- d-----w C:\Program Files\Common Files\Real
2008-03-30 03:16 --------- d-----w C:\Program Files\EA GAMES
2008-03-29 18:24 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-03-28 21:39 --------- d-----w C:\Documents and Settings\Compaq_Administrator\Application Data\FileZilla
2008-03-27 23:00 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-03-12 18:33 --------- d-----w C:\Program Files\MMRR Software
2008-03-12 00:23 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-03-12 00:23 --------- d-----w C:\Documents and Settings\Compaq_Administrator\Application Data\Malwarebytes
2008-03-12 00:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-09 17:31 --------- d-----w C:\Program Files\Common Files\Intuit
2008-03-09 17:30 --------- d-----w C:\Program Files\Intuit
2008-03-09 17:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intuit
2008-03-09 17:28 --------- d-----w C:\Program Files\Common Files\SWF Studio
2008-03-06 02:50 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-02-25 22:03 --------- d-----w C:\Program Files\NewSoft
2008-02-25 22:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-25 21:59 --------- d-----w C:\Program Files\DSC Driver
2008-02-20 19:31 --------- d-----w C:\Program Files\LimeWire
2008-02-11 00:08 6,144 ----a-w C:\WINDOWS\ictions.dll
2008-01-26 22:06 5,120 ----a-w C:\WINDOWS\rictions.dll
.
------- Sigcheck -------
2005-03-14 03:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2gdr\tcpip.sys
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\SoftwareDistribution\Download\556eb98436b65a8c1ffae674c83d197f\sp2qfe\tcpip.sys
2005-03-14 02:55 359808 1898df9a9d550da97c2ed41ae3c76a25 C:\WINDOWS\system32\dllcache\tcpip.sys
2005-03-14 02:55 359808 1898df9a9d550da97c2ed41ae3c76a25 C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-04-12_17.23.31.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-13 00:16:39 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-12 23:46:16 6,758,400 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-04-12 23:46:17 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-04-13 00:16:39 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-12 23:46:15 6,758,400 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-04-12 23:46:15 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
- 2004-08-10 04:00:00 1,032,192 ------w C:\WINDOWS\explorer.exe
+ 2004-08-10 04:00:00 1,034,752 ----a-w C:\WINDOWS\explorer.exe
- 2007-09-27 19:52:53 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-13 22:55:58 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-09-27 19:52:53 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-13 22:55:58 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-13 22:55:58 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-08-10 11:00:00 18,688 ----a-w C:\WINDOWS\system32\dllcache\cdaudio.sys
+ 2004-08-10 04:00:00 16,896 ----a-w C:\WINDOWS\system32\ehsjml.dll
+ 2008-04-14 00:18:30 118,784 ----a-w C:\WINDOWS\system32\hmxupqrc.exe
+ 2006-04-14 22:38:05 13,824 ----a-w C:\WINDOWS\system32\icasServ.exe
+ 2004-08-10 04:00:00 32,768 ----a-w C:\WINDOWS\system32\kbl.dll
+ 2004-08-10 04:00:00 77,824 ----a-w C:\WINDOWS\system32\kdzzg.exe
+ 2004-08-10 04:00:00 113,664 ----a-w C:\WINDOWS\system32\lgfitgfqp.drv
- 2004-08-10 04:00:00 13,312 ----a-w C:\WINDOWS\system32\lsass.exe
+ 2004-08-10 04:00:00 14,848 ----a-w C:\WINDOWS\system32\lsass.exe
- 2004-08-10 04:00:00 57,856 ----a-w C:\WINDOWS\system32\spoolsv.exe
+ 2004-08-10 04:00:00 58,880 ----a-w C:\WINDOWS\system32\spoolsv.exe
+ 2004-08-10 04:00:00 113,664 ----a-w C:\WINDOWS\system32\sradgnehcf.sys
- 2004-08-10 04:00:00 14,336 ----a-w C:\WINDOWS\system32\svchost.exe
+ 2008-04-13 22:37:58 17,408 ----a-w C:\WINDOWS\system32\svchost.exe
+ 2008-04-13 22:38:13 26,112 ----a-w C:\WINDOWS\system32\wbem\csrss.exe
- 2004-08-10 04:00:00 502,272 ----a-w C:\WINDOWS\system32\winlogon.exe
+ 2004-08-10 04:00:00 506,368 ----a-w C:\WINDOWS\system32\winlogon.exe
+ 2008-04-14 00:18:33 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_1dc.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2BC7FC20-CFB1-489A-8BFF-4E285C3E1F62}]
C:\WINDOWS\system32\qoMcbBQg.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CF26FAC0-7D4E-46D8-AE64-B277B11443AC}]
2008-03-30 08:02 190464 --a------ C:\WINDOWS\system32\luapvs.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-02-29 17:03 1481968]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54 5674352]
"QdrModule15"="C:\Program Files\QdrModule\QdrModule15.exe" [ ]
"QdrPack15"="C:\Program Files\QdrPack\QdrPack15.exe" [ ]
"Tcu"="C:\Documents and Settings\Compaq_Administrator\Application Data\?asks\?explore.exe" [ ]
"sswwphwe"="C:\WINDOWS\system32\arcbcnsh.exe" [2008-04-13 17:22 118784]
"srcezlqz"="C:\WINDOWS\system32\hmxupqrc.exe" [2008-04-13 19:18 118784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 22:56 64512]
"ftutil2"="rundll32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 22:05 16239616 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:19 77312 C:\WINDOWS\arpwrmsg.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2008-02-26 14:41 14348]
"PCDrProfiler"="" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2008-02-26 14:41 14348]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-26 14:41 14348]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 02:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2008-02-26 14:41 14348]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-09 23:00 33280 C:\WINDOWS\system32\rundll32.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2008-02-26 14:41 14348]
"AntiVirusPro"="C:\Program Files\AntiVirusPro\AntiVirusPro.exe" [ ]
"icasServ"="C:\WINDOWS\system32\icasServ.exe" [2006-04-14 17:38 13824]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"hinhbril"="C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\qkbcrn.sys WLEntryPoint" [ ]
"csrss"="C:\WINDOWS\system32\wbem\csrss.exe" [2008-04-13 17:38 26112]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
Icatch(VI) SnapDetect.lnk - C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe [2008-02-25 16:59:38 65536]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-11-06 19:40:54 815104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"Qo6VtiKILJ"= C:\Documents and Settings\All Users\Application Data\krmrshwv\cvgrudej.exe
"ratgn"= rundll32.exe "C:\WINDOWS\system32\lgfitgfqp.drv" WLEntryPoint
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"DKvupD"= {242949B7-8E83-E31D-5CAB-E61E5BAAA7AD} - C:\WINDOWS\system32\kbl.dll [2004-08-09 23:00 32768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ibudu]
ibudu.dll 2008-04-13 17:38 6672 C:\WINDOWS\system32\ibudu.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\AIM\\aim.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Intuit\\QuickBooks 2006\\QBDBMgrN.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56597:TCP"= 56597:TCP:@xpsp2res.dll,-22005
"48448:TCP"= 48448:TCP:@xpsp2res.dll,-22005
"15607:TCP"= 15607:TCP:@xpsp2res.dll,-22005
"9538:TCP"= 9538:TCP:@xpsp2res.dll,-22005
R1 itcoe;itcoe adapter;C:\WINDOWS\system32\itcoe.sys [2008-04-13 19:17]
S2 ARSVCdmserver;ARSVC ARSVCdmserver;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\4.tmp []
S2 RemoteRegistryNetDDEdsdm;Remote Registry RemoteRegistryNetDDEdsdm;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\10.tmp []
S2 TapiSrvclr_optimization_v2.0.50727_32;Telephony TapiSrvclr_optimization_v2.0.50727_32;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\490411199.exe []
S2 TermServiceMSIServer;Terminal Services TermServiceMSIServer;C:\WINDOWS\system32\alrsvcu.exe [2008-04-13 17:39]
S2 ThemesTrkWks;Themes ThemesTrkWks;C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\C.tmp []
*Newly Created Service* - ARSVCDMSERVER
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-13 19:18:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\system32\drivers\Wfky49.sys 167936 bytes executable
scan completed successfully
hidden files: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Wfky49]
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ARSVCdmserver]
"ImagePath"="C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\4.tmp srv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\RemoteRegistryNetDDEdsdm]
"ImagePath"="C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\10.tmp srv"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ThemesTrkWks]
"ImagePath"="C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\C.tmp srv"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\ibudu.dll
-> C:\WINDOWS\system32\ehsjml.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Bat\X_Bat.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\bak\jusched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2008-04-13 19:20:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-14 00:20:08
ComboFix2.txt 2008-04-12 22:24:00
ComboFix3.txt 2008-04-12 18:45:34
Pre-Run: 124,921,438,208 bytes free
Post-Run: 125,208,006,656 bytes free
.
2007-09-27 20:18:08 --- E O F ---
----------------------------------
and the mbam log.
Malwarebytes' Anti-Malware 1.08
Database version: 471
Scan type: Full Scan (A:\|C:\|D:\|)
Objects scanned: 147120
Time elapsed: 27 minute(s), 42 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 1
Registry Keys Infected: 16
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 88
Memory Processes Infected:
c:\WINDOWS\system32\icasServ.exe (Trojan.Clicker) -> Unloaded process successfully.
C:\WINDOWS\system32\wbem\csrss.exe (Heuristic.Reserved.Word.Exploit) -> Unloaded process successfully.
Memory Modules Infected:
c:\WINDOWS\system32\ehsjml.dll (Trojan.Agent) -> Unloaded module successfully.
Registry Keys Infected:
HKEY_CLASSES_ROOT\AppID\{f663b917-591f-4172-8d87-3d7d729007ca} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bat.batbho (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63f7460b-c831-4142-a4aa-5ec303ec4343} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\bat.batbho.1 (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d279bc2b-a85b-4559-8fd9-ddc55f5d402d} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{b80a3586-caa5-41c8-89bf-e617f0b6cfbf} (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\BATCO (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Batco (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\bat.DLL (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bat (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bat (Adware.Batco) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\IQSoftware (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\luapvs.TCHONGABHO (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\xflock (Malware.Trace) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\icasServ (Trojan.Clicker) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hinhbril (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ratgn (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\{59a40ac9-e67d-4155-b31d-4b7330fcd2d6} (Adware.PurityScan) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\csrss (Heuristic.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer (Adware.SearchEnhancer) -> Quarantined and deleted successfully.
Files Infected:
c:\WINDOWS\system32\ehsjml.dll (Trojan.Agent) -> Delete on reboot.
c:\WINDOWS\system32\icasServ.exe (Trojan.Clicker) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temp\eobmrr.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lgfitgfqp.drv (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Bat\Bat.dll (Adware.Batco) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temp\afjboaknrma.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Administrator\Local Settings\Temp\oiabmetisnk.nls (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Bat\un_BatSetup_15041.exe (Adware.Rabio) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Documents and Settings\Compaq_Administrator\Application Data\printer.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\findfast.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\BraveSentry\BraveSentry0.dll.vir (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\BraveSentry\BraveSentry2.dll.vir (Rogue.Brave.Sentry) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\BraveSentry\BraveSentry3.dll.vir (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\webHancer\Programs\webhdll.dll.vir (Adware.WebHancer) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\webHancer\Programs\whagent.exe.vir (Adware.WebHancer) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\webHancer\Programs\whiehlpr.dll.vir (Adware.WebHancer) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Program Files\webHancer\Programs\whinstaller.exe.vir (Adware.WebHancer) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\desktop.html.vir (Hijacker.Wallpaper) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\shell.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\printer.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\spoolvs.exe.vir (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\vedxga4me1.exe.vir (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP191\A0042043.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP191\A0042044.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP191\A0042045.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP191\A0042046.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP191\A0042047.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\A0042055.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\A0042056.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\A0042057.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\A0042058.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\A0042059.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-10.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-11.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-12.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-13.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-14.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-15.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-16.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-17.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-18.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-19.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-2.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-20.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-21.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-22.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-23.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-24.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-25.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-26.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-27.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-28.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-29.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-3.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-30.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-31.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-32.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-34.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-35.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-36.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-37.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-38.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-39.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-4.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-40.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-41.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-42.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-43.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-44.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-45.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-46.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-47.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-48.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-49.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-5.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-50.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-51.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-52.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-6.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-7.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-8.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP192\snapshot\MFEX-9.DAT (Trojan.Qhost) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bihcf.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sradgnehcf.sys (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\n.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\Bat - Auto Update.lnk (Adware.Batco) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wbem\csrss.exe (Heuristic.Reserved.Word.Exploit) -> Quarantined and deleted successfully.