Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

1 more HiJackThis Log.../Smitfraud infection[RESOLVED]


  • This topic is locked This topic is locked

#1
Poppapope

Poppapope

    Member

  • Member
  • PipPip
  • 11 posts
Expert help required please....

I've gone thru the steps required before posting a HiJack-log not once but twice. The Trend Micro virus scan revealed one trojan virus which couldn't be removed because it was being used. However, Norton AV 2005 (installed on my system) didn't reveal any trojans, but that could be an error on my part. I've also tried Symantec's tutorial on how to remove the "Joke.Smitfraudiod" virus, but that didn't seem to work.

Still can't change my background settings from the light grey background in place now, sometimes bluescreens show up with info on spyware etc etc and there's this annoying warning sign on the bottom right of my screen. Plus my browser's been hi-jacked.

I'd be extremely grateful for any help you could give me. You guys deserve all the credit you probably won't recieve!

Logfile of HijackThis v1.99.1
Scan saved at 17:06:29, on 2005-04-27
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\Program\Norton AntiVirus\navapsvc.exe
D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\Program\Delade filer\Symantec Shared\ccApp.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\WINNT\system32\internat.exe
D:\winnt\ewxdfwb.exe
D:\Program\Internet Explorer\iexplore.exe
D:\downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINNT\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DI2] "D:\DOCUME~1\PÅVEN\LOKALA~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [etbrun] D:\winnt\system32\elitekts32.exe
O4 - HKLM\..\Run: [Security iGuard] D:\Program\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [TUh9PM] D:\WINNT\pojtdaoy.exe
O4 - HKLM\..\Run: [ccApp] "D:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [dsd] D:\WINNT\dsd.exe
O4 - HKLM\..\Run: [rs7S36g] gejnv.exe
O4 - HKLM\..\Run: [saap] c:\program files\180search assistant\saap.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] D:\WINNT\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ycaumky] d:\winnt\ewxdfwb.exe
O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe
O4 - HKCU\..\Run: [Opmo] D:\WINNT\system32\iias.exe
O4 - HKCU\..\Run: [Adxk] D:\WINNT\system32\w?nspool.exe
O4 - HKCU\..\Run: [klmmrts] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ntcuthh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [synhwhf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xtmmyti] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [deltndl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [svqquiq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gwsavtd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [unbevfl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xijeedh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [oxkokcf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [aqspvco] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [tuypcud] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gjmpjsw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ubogeuw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gqtgmkb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [qxqbjan] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kearnog] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [pjlcvqb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [uyirwfj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [lnbkikj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [fkrujhn] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [dehrsam] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [cepevfb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [btyaaec] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [roqjddh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [wmtpvvb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ugyrswr] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [dakqwfm] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [mfhurcx] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [pcjgvjf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [orfbfjd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [itmpsbq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [hfvukuo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [irlhaeh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [iknfafk] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [sshtgye] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ogbvycc] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [boiapeq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [rbnqdjm] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [balpwwo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [uwcevmn] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ebawqas] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [tyvrxay] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [lyqrtvk] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xkaqsey] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ylutqwo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [cqnxmuf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [frvsfxd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [adktlsl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [plswgfo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kymwcrw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [mbhyjxu] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kbfqiyj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [fisxppv] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ytowjmd] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [rpqsrqo] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [nfswdxc] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [utkgfwn] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [ieytnvk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hoendrc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [snhvawe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gurwyrq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iudehmt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wsnnbhc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hohhudx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wsliskg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [edwrfmh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rwtdusf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [knfgcei] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [egjhoca] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mddnnti] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xfvpdsb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nbtfduk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [twjppnj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aBo2RWMml] wua_mtf.exe
O4 - HKCU\..\Run: [ceppqya] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hlsjphw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [peaebgn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xwsvjlb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ingaavb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lqefvnu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kthmkes] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ramqaee] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wkstqwn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [viuoptq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qdxghaa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pjahytk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [oihiqpi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aeqtljw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wlwlljx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [buljybe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xjcvins] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ugmmlcj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dlalfhw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jmsggpe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pqqnikk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [icndpuo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [oeidcxg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nonyfbd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nspvjpm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [audibey] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [towqjva] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jubaeie] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wgckbgh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vltobla] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xjspkuv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omnatuc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ahwedoc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jdbsbge] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tckxthj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lbtthvg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xlmfbmh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jlvtepm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lqljchp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yddfqap] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wyxhuba] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [obyounb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bumexbc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [smshnug] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nfkrcys] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xueqvom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xtnxiwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uwcjrwy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [csuytgq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uubbvjx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [frnidgv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jkvawck] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bxvvpwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fjcixfb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [moldgjm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yjglyph] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cjjyoox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jiampwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ytiaoru] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dpivehh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lkyfwqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nghdfgv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xyypxqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wvaluvt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [frygftc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jrkjhig] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [garsowd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [guxflfi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwrhgyl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ipvjvvi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tvphrpr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fshfeby] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [siaokqh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mqxghox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ijbqstq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yxcacdp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mujcgqd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vvloexb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwksiiv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [masnnyt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bourqhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [owhqbmp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [arhpgur] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [italcjl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gxqnvpp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ycnclrs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dutpdqk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wqccmdt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wnffkrc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kqrbqkg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yqiyxwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tkdbcrh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [odysquy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [usoejxn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jxufgmy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vacfmei] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwepkyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ibxvrom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tnvulha] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xkyouuy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qkirafb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [juebwrf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [akksrlg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tjyboiw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dyqvsem] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xondsnm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bnxjomg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [foowvqb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [muaoipf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [giiowlf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iapwsyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sijiuyc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jncvbca] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tmxwcqj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xgxogjh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mbpcjxs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gjddcqc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jynlvsc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qcofwec] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fdrjjuv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ivixumr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [chtrnnh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xaulyvy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xemgupi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bcnfevf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sdbynok] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ioxnhvb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [phhyuov] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hoccjun] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kfyuyhp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [goeotxo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lnsklhh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [osgfais] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wvcapre] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atvlsic] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eynldhi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yqrqhfy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jkyadhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bdujmvr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rnxogni] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yxjktaa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttvaogw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [unjtylx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lgcmeup] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ukvnjko] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [etyohjo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nhjuaot] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lycqlmv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ccrnngl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kxywcdt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qykutot] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dvccmfd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yfityts] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mbyhtgx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fxapjgx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kgvfiix] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wehblae] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pblxxkx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [clfbfkn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [thjnxep] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sroyedh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dmcgydo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xfgtaqn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [axkqsll] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gvjtbtl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mvbuqso] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wpclvyy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gpngjoj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omiswsi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ocrwsbw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hlmawob] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yhdbyep] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lhuegiu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [juilduf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [affvwpd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [smhxlsh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jhoyefw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vfpveht] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rctfsil] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xljcjcs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iexurwi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ihxajvt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ueemjty] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dylhbbh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ptypgoj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bxibivp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mrkuebg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jcsyyjr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gpgwvxq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aertebv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fktlkeg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atjyigh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mlrrxaq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [emdlxwm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [huvibkw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atmkhla] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qayphck] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cewftxy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cspxfme] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cqvqdyl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hrycnwl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qrhdadm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cucrjsp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rklmxhc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [veupshb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gijrrsn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cywammw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yypxqdk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ioyvhtb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [flicnjt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ldotuqa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [brjthvk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nbsiikn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qmvrcdh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dtxqoxl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wcgfljl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iyhojfe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kddkgvw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rvtsokx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dmcxhno] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [svnrxkw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rpylwhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [onbpmih] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ktnpskr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [njuwfum] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mafwgqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cxamvmw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [biobyqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dtmfcgc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tknfcpf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eidlgda] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ysobisg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wugaodj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uqrgqge] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [axxhvqx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wviiitl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hegtjup] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [unsvpbo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lbjfbna] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uvaxfsj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fuywvmo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [umvwkwp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fckwybh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bfmbtii] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qifrmsc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bfhbblt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xaxxkkh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ivelijv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mlnbefv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mfyywbq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yfbfcud] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hmyodvu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ynponnf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tqreffk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [edpsjiy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eqjdclx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ydmoqeu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hcqgote] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fmasuha] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dfpgyom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gutidjd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wjgcwmj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aunqrke] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nrybieq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hpbxlcm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pocargn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttrtjxu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ssogotk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cbdxqdj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [stngove] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vvyvcfl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [donqrmy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tvugefa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lndcdgn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [obfdcal] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mrguofc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xwttjfj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omfocox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rjudfxs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [shfsopb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rdfqwji] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lxnswka] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttlmmwg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sjstmqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [apdxqqh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nuojibt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jujgfxx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vwrhqli] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [esowhyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cdcouuo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yplrkry] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kgttndr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sdrvfun] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dfpitju] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [utcpncn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [orqppxu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rdorbsk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [thwniif] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lkdkhij] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tlcfjrd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wwtrfqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ytaklpm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fcelimj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cuqbxod] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cuxewuj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hylufee] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ideijnu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ocwbhev] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [jfjfnjh] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [ylhbrjl] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [ieyvwim] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [xtgqstr] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [mpxiabl] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [efekcvj] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [gufixbi] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [jpdopyv] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [mmwsjvf] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [qdfahba] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [jpfgsnd] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [pdvpenj] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [lfpdsdv] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [wkwbhpx] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [lngshhc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [yeyqpvi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [buhgbuw] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vkqrnme] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [okgavil] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ilnaayn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wjpkqur] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gvovlxb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mjmrbml] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bakcevp] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wstuchm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sbyvlud] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ugakchn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ocumsxv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mkagbko] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vhwgnst] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pjkitug] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hdiqbnv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nagywxh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [psjoapb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mfgrqib] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [cylqtka] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [swtmshq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [olwqvsu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fcmvoci] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ypgerwv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rbnrnba] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jbwchud] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ichuabd] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ftbnbmg] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [aulawaj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fsmamff] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [npfmovq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [smbwbvc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [urimyvq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [favldyh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [umogwlq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sssgqyh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pkxgoio] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kypfjjh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ktgknnn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tmqyuwe] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nplnwxr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ubrshbe] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [uxtuwfj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bfxsxgy] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qiyfgkt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xkhqjni] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ysqolht] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [adncpcu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sqyhinl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nxnvpoq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hmcrjii] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kvfwsiy] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nhdhqmh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tqyjoug] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ghavjbb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jppqcbi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xlluida] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [oswneim] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bfjhylt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [disfssk] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ukafiej] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kkkvkhf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wmrsxgv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [truhiwk] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bsfirsr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [eskfppf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hjfghhl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rmeeijs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [uqnclun] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vsiexuj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wxylgbu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qtvltbt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fsilpox] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ujnedup] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kekjucw] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [afercmc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hgbglep] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [csyquwo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gegukwt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rpvoplv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hvxaift] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kedytql] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rbtmefn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pggmvtj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [efpfqqa] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [apbeuvb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [oifggaf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kmbtuel] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ptlaygu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ksgdswh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xbrmifs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sigpwbo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [dpypatx] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tmfosnb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [aidoape] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gblenno] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [serlcoo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [enuhfkc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bkbevrh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qyhtbjs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nhafusl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vosgrho] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qnwbepo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [neogxbx] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [caykjxo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ybgvaeu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bxnhvki] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tkhxcxl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [txsqlqu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jtjlgac] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kxgiuwj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [yyelvjs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pypbjgm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fnfikaf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [khtkmxr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tqpptyr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gvnqufm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [exwsucc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nxajsst] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rtsmmbi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mbsgggl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sdkchpw] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [wvhekai] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [jvarhpf] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [kapmvcv] d:\winnt\enhtapa.exe
O4 - HKCU\..\Run: [cbacktm] d:\winnt\enhtapa.exe
O4 - HKCU\..\Run: [derunqp] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ygcovxv] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [nwfgvow] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gyrsqfb] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [jytpvjs] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [keqgoik] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [iyvkbtc] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [skwjaum] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [acbaepw] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [algusdq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yjcdock] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [qqehqkl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [kggtlsi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [mdpbkrb] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [otlcuqd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [oetfgyh] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [pspdlmu] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [vunuwqn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gkpwwtn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [hfxhmkd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yjmohdr] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [jpjgjuq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [grfgyvq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [sykfdhi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [uxoospk] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ydyjnrl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [taxskoi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [foyriqq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gbodxjx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [agewgbl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yrhlgka] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ofweqnp] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [vajbugl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ytwonxx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ftwohtf] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [srrftmu] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [rgaauqr] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [koxofvc] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ypfovsg] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [paqolnn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [dfwqrhx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ravmxmf] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gvegbxt] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [buughmd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [xxwgdbl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [dvfieoy] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [wcavler] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [wilidju] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [amchekx] d:\winnt\cpvvptm.exe
O4 - HKCU\..\Run: [jcwivmk] d:\winnt\shcybvt.exe
O4 - HKCU\..\Run: [obcumrt] d:\winnt\shcybvt.exe
O4 - HKCU\..\Run: [teuegdn] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [dlmrahc] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [rswaoed] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [urwgewj] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [hmkwbsk] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [mywqpki] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [lxislbj] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [xwdcsqo] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [adumqen] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [iufymnm] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qqvhqgy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ypgcfyy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [lfunpbu] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [uqocmpf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nreflis] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gppvtxa] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [uxypftn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ihkccsn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nqulgms] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [blflssk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fmtjtwp] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [oarskdf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fhklqqv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nswoaqc] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gpubhcf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [spllcpv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [pnbprds] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [toojsjh] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ismlvvy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [appyrej] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [mgtiqth] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [eykwxux] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [shrbgyb] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [vqslifv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [evnlyvs] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [berexox] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fmkomww] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [veaufqv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [unsqcxf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [aschbdv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [elaosyd] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [xjyleyj] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [npopkju] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [xqxkcbe] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [hfruqkj] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [mvtgpyn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qkjchrn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [iujbjtu] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [wsujrcn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qwxswdl] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [bbhribk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [hwuwglc] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [tptrndn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ntuwphd] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [netmftl] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gjgufna] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [oofghlv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qtmycpk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [tsqrtdm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gvydaco] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wdmkusf] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [eahmftf] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [btaxcku] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [pyqdnko] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [dipvdsg] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [pntyaan] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [rcyqvso] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [khtuvif] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [bthkrls] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [qawhubg] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [cdvsgko] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [hsfmpwm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [hnfsbpc] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gxixjrn] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [nimoxnm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wybtwvo] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [lscdukr] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [acpxdnk] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wabuljp] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wihqgbc] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [xravifs] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [phbgfew] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [baktlki] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [nkliict] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [ukbfcxl] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gqfqwst] d:\winnt\bqccqyj.exe
O4 - HKCU\..\Run: [fmeoxvb] d:\winnt\bqccqyj.exe
O4 - HKCU\..\Run: [uicsqef] d:\winnt\cssrlqo.exe
O4 - HKCU\..\Run: [wmglvgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cgxpyjq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vmawilt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tehoqxo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qesgwfi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aedgevs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vsccpqg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bmcwkfe] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vbcvyih] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [arodimb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [thxuhnc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xcfwacw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [huhdgmg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sjxorkt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gushjjs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lllhltv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tgggijw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jvuuhpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ncqrirj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [udlllfo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxlbckh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mvclyan] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dwhkfpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aguxxru] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [piqjugg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ygeydvk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ckhquif] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yfuhwos] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cvbspyv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qlqgfru] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ekmvbwq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qluxtii] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mtvoyje] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sshhbyk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wxgfipt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tjwbvxj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pnwdfqs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bhisgcq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [eebmfce] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [syvncgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oaubiqq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gcbuvif] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [apsnfpb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tffdgrn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [domyyls] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pwsxlwh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ayndoie] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rnhgnnv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oppmifl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [titsntw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jktxkyr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ojlncrr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rwubmpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxmaefm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dswbayu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ybvphfs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qaanvrc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lgmoarb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vnnivfv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lbmubir] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxargqt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sjlkpfn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lnhdjmx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kenenue] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uojwbte] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [luavxre] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oaiqpip] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cevagfc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ulxiuiv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xfxpkir] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uftrqkw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dryjgoy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dlcdxmi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jncfeam] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [awbhyvu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [feonxnh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [poxtyok] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wrvdlvg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yswqjja] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dwqpwdg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qrjbcyu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bathpuo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hdcpvwu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hcsgfjs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ipqtwlw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nvuliio] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vtjynvl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dcweavt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vwcxiid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ggmrwvb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fludtxx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ijjfnlc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ialikxq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uvoygwo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [suyixiu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yagybgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tiecotx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fieuyqh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ohijetl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hxuurfm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pjhhbcc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uoxxsxs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lbwglau] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nhptyid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dxmkbjk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [plpxxdf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hwgwlpb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [evtoflq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vkloluc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bxchagf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ojttywy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ktkvvik] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mcorscg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wvmcoyo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pyiyjtn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gtpcgta] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wravjxq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [liuwcuh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ogdutsm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lerctvg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qqcygud] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [htpycdh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [iybabvs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [egnbeyd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qtuvvxv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xemceuf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bpenrwp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qhoailm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [muueeyn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hhewwdn] d:\winnt\rqocxfp.exe<
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Welcome to GTG.

Whoa that's a long one. Is that yur whole HijackThis log? You seem to be missing the bottom part there.

OK, let's fix up the wallpaper problem first:

Do you also have the wallpaper problem? If you do, do this also:

Right click on http://www.greyknigh...pairDesktop.reg and download that file. Double click on it and click on Yes when it asks you if you want to merge it into the registry. Once that's done, restart your computer.

Login as usual and now right click on your Desktop and go to Properties. Next go to Desktop tab->Customize Desktop button->Web tab. Uncheck everything listed there. Then delete all the entries listed except for 'My Current Home Page'. Click OK and OK.


Now, I want you to restart and run a new HijackThis scan. Make sure to give us the FULL log since this one seems to be incomplete.
  • 0

#3
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
OK, I've split this log file into two since I suspect there is a limit to the number of characters that fit in one post (?). Yes, my browser's been hi-jacked. My default homepage is w-find.com. Thanks for your time, btw :tazz: Part two of the log file will be posted right after I post this.

Logfile of HijackThis v1.99.1
Scan saved at 17:18:22, on 2005-04-28
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\Program\Norton AntiVirus\navapsvc.exe
D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\Program\Delade filer\Symantec Shared\ccApp.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\WINNT\system32\internat.exe
D:\winnt\ewxdfwb.exe
D:\Program\Internet Explorer\iexplore.exe
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINNT\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DI2] "D:\DOCUME~1\PÅVEN\LOKALA~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [etbrun] D:\winnt\system32\elitekts32.exe
O4 - HKLM\..\Run: [Security iGuard] D:\Program\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [TUh9PM] D:\WINNT\pojtdaoy.exe
O4 - HKLM\..\Run: [ccApp] "D:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [dsd] D:\WINNT\dsd.exe
O4 - HKLM\..\Run: [rs7S36g] gejnv.exe
O4 - HKLM\..\Run: [saap] c:\program files\180search assistant\saap.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] D:\WINNT\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ycaumky] d:\winnt\ewxdfwb.exe
O4 - HKCU\..\Run: [WindowsFY] C:\wp.exe
O4 - HKCU\..\Run: [Opmo] D:\WINNT\system32\iias.exe
O4 - HKCU\..\Run: [Adxk] D:\WINNT\system32\w?nspool.exe
O4 - HKCU\..\Run: [klmmrts] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ntcuthh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [synhwhf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xtmmyti] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [deltndl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [svqquiq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gwsavtd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [unbevfl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xijeedh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [oxkokcf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [aqspvco] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [tuypcud] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gjmpjsw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ubogeuw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [gqtgmkb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [qxqbjan] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kearnog] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [pjlcvqb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [uyirwfj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [lnbkikj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [fkrujhn] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [dehrsam] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [cepevfb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [btyaaec] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [roqjddh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [wmtpvvb] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ugyrswr] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [dakqwfm] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [mfhurcx] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [pcjgvjf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [orfbfjd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [itmpsbq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [hfvukuo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [irlhaeh] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [iknfafk] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [sshtgye] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ogbvycc] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [boiapeq] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [rbnqdjm] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [balpwwo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [uwcevmn] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ebawqas] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [tyvrxay] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [lyqrtvk] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [xkaqsey] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ylutqwo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [cqnxmuf] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [frvsfxd] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [adktlsl] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [plswgfo] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kymwcrw] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [mbhyjxu] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [kbfqiyj] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [fisxppv] d:\winnt\aojinvx.exe
O4 - HKCU\..\Run: [ytowjmd] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [rpqsrqo] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [nfswdxc] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [utkgfwn] d:\winnt\yaeddje.exe
O4 - HKCU\..\Run: [ieytnvk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hoendrc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [snhvawe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gurwyrq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iudehmt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wsnnbhc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hohhudx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wsliskg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [edwrfmh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rwtdusf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [knfgcei] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [egjhoca] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mddnnti] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xfvpdsb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nbtfduk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [twjppnj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aBo2RWMml] wua_mtf.exe
O4 - HKCU\..\Run: [ceppqya] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hlsjphw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [peaebgn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xwsvjlb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ingaavb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lqefvnu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kthmkes] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ramqaee] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wkstqwn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [viuoptq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qdxghaa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pjahytk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [oihiqpi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aeqtljw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wlwlljx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [buljybe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xjcvins] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ugmmlcj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dlalfhw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jmsggpe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pqqnikk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [icndpuo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [oeidcxg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nonyfbd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nspvjpm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [audibey] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [towqjva] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jubaeie] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wgckbgh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vltobla] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xjspkuv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omnatuc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ahwedoc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jdbsbge] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tckxthj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lbtthvg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xlmfbmh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jlvtepm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lqljchp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yddfqap] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wyxhuba] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [obyounb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bumexbc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [smshnug] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nfkrcys] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xueqvom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xtnxiwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uwcjrwy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [csuytgq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uubbvjx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [frnidgv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jkvawck] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bxvvpwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fjcixfb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [moldgjm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yjglyph] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cjjyoox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jiampwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ytiaoru] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dpivehh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lkyfwqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nghdfgv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xyypxqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wvaluvt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [frygftc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jrkjhig] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [garsowd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [guxflfi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwrhgyl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ipvjvvi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tvphrpr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fshfeby] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [siaokqh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mqxghox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ijbqstq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yxcacdp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mujcgqd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vvloexb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwksiiv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [masnnyt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bourqhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [owhqbmp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [arhpgur] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [italcjl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gxqnvpp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ycnclrs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dutpdqk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wqccmdt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wnffkrc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kqrbqkg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yqiyxwt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tkdbcrh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [odysquy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [usoejxn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jxufgmy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vacfmei] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pwepkyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ibxvrom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tnvulha] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xkyouuy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qkirafb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [juebwrf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [akksrlg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tjyboiw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dyqvsem] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xondsnm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bnxjomg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [foowvqb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [muaoipf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [giiowlf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iapwsyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sijiuyc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jncvbca] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tmxwcqj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xgxogjh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mbpcjxs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gjddcqc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jynlvsc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qcofwec] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fdrjjuv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ivixumr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [chtrnnh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xaulyvy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xemgupi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bcnfevf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sdbynok] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ioxnhvb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [phhyuov] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hoccjun] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kfyuyhp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [goeotxo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lnsklhh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [osgfais] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wvcapre] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atvlsic] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eynldhi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yqrqhfy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jkyadhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bdujmvr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rnxogni] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yxjktaa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttvaogw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [unjtylx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lgcmeup] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ukvnjko] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [etyohjo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nhjuaot] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lycqlmv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ccrnngl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kxywcdt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qykutot] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dvccmfd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yfityts] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mbyhtgx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fxapjgx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kgvfiix] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wehblae] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pblxxkx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [clfbfkn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [thjnxep] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sroyedh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dmcgydo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xfgtaqn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [axkqsll] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gvjtbtl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mvbuqso] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wpclvyy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gpngjoj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omiswsi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ocrwsbw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hlmawob] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yhdbyep] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lhuegiu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [juilduf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [affvwpd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [smhxlsh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jhoyefw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vfpveht] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rctfsil] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xljcjcs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iexurwi] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ihxajvt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ueemjty] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dylhbbh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ptypgoj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bxibivp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mrkuebg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jcsyyjr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gpgwvxq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aertebv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fktlkeg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atjyigh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mlrrxaq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [emdlxwm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [huvibkw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [atmkhla] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qayphck] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cewftxy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cspxfme] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cqvqdyl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hrycnwl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qrhdadm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cucrjsp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rklmxhc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [veupshb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gijrrsn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cywammw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yypxqdk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ioyvhtb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [flicnjt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ldotuqa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [brjthvk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nbsiikn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qmvrcdh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dtxqoxl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wcgfljl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [iyhojfe] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kddkgvw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rvtsokx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dmcxhno] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [svnrxkw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rpylwhg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [onbpmih] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ktnpskr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [njuwfum] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mafwgqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cxamvmw] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [biobyqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dtmfcgc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tknfcpf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eidlgda] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ysobisg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wugaodj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uqrgqge] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [axxhvqx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wviiitl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hegtjup] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [unsvpbo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lbjfbna] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [uvaxfsj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fuywvmo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [umvwkwp] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fckwybh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bfmbtii] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [qifrmsc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [bfhbblt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xaxxkkh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ivelijv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mlnbefv] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mfyywbq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yfbfcud] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hmyodvu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ynponnf] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tqreffk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [edpsjiy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [eqjdclx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ydmoqeu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hcqgote] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fmasuha] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dfpgyom] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [gutidjd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wjgcwmj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [aunqrke] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nrybieq] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hpbxlcm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [pocargn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttrtjxu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ssogotk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cbdxqdj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [stngove] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vvyvcfl] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [donqrmy] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tvugefa] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lndcdgn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [obfdcal] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [mrguofc] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [xwttjfj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [omfocox] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rjudfxs] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [shfsopb] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rdfqwji] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lxnswka] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ttlmmwg] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sjstmqu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [apdxqqh] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [nuojibt] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [jujgfxx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [vwrhqli] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [esowhyx] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cdcouuo] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [yplrkry] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [kgttndr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [sdrvfun] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [dfpitju] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [utcpncn] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [orqppxu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [rdorbsk] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [thwniif] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [lkdkhij] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [tlcfjrd] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [wwtrfqr] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ytaklpm] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [fcelimj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cuqbxod] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [cuxewuj] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [hylufee] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ideijnu] d:\winnt\ymyaygq.exe
O4 - HKCU\..\Run: [ocwbhev] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [jfjfnjh] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [ylhbrjl] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [ieyvwim] d:\winnt\axqjxuf.exe
O4 - HKCU\..\Run: [xtgqstr] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [mpxiabl] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [efekcvj] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [gufixbi] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [jpdopyv] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [mmwsjvf] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [qdfahba] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [jpfgsnd] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [pdvpenj] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [lfpdsdv] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [wkwbhpx] d:\winnt\mjfegak.exe
O4 - HKCU\..\Run: [lngshhc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [yeyqpvi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [buhgbuw] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vkqrnme] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [okgavil] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ilnaayn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wjpkqur] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gvovlxb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mjmrbml] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bakcevp] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wstuchm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sbyvlud] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ugakchn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ocumsxv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mkagbko] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vhwgnst] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pjkitug] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hdiqbnv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nagywxh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [psjoapb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mfgrqib] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [cylqtka] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [swtmshq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [olwqvsu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fcmvoci] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ypgerwv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rbnrnba] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jbwchud] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ichuabd] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ftbnbmg] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [aulawaj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fsmamff] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [npfmovq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [smbwbvc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [urimyvq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [favldyh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [umogwlq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sssgqyh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pkxgoio] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kypfjjh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ktgknnn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tmqyuwe] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nplnwxr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ubrshbe] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [uxtuwfj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bfxsxgy] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qiyfgkt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xkhqjni] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ysqolht] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [adncpcu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sqyhinl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nxnvpoq] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hmcrjii] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kvfwsiy] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nhdhqmh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tqyjoug] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ghavjbb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jppqcbi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xlluida] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [oswneim] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bfjhylt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [disfssk] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ukafiej] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kkkvkhf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wmrsxgv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [truhiwk] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bsfirsr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [eskfppf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hjfghhl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rmeeijs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [uqnclun] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vsiexuj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [wxylgbu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qtvltbt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fsilpox] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ujnedup] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kekjucw] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [afercmc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hgbglep] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [csyquwo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gegukwt] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rpvoplv] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [hvxaift] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kedytql] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rbtmefn] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pggmvtj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [efpfqqa] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [apbeuvb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [oifggaf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kmbtuel] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ptlaygu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ksgdswh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [xbrmifs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [sigpwbo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [dpypatx] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tmfosnb] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [aidoape] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gblenno] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [serlcoo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [enuhfkc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bkbevrh] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qyhtbjs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nhafusl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [vosgrho] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [qnwbepo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [neogxbx] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [caykjxo] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [ybgvaeu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [bxnhvki] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tkhxcxl] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [txsqlqu] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [jtjlgac] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [kxgiuwj] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [yyelvjs] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [pypbjgm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [fnfikaf] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [khtkmxr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [tqpptyr] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [gvnqufm] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [exwsucc] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [nxajsst] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [rtsmmbi] d:\winnt\piprgrl.exe
O4 - HKCU\..\Run: [mbsgggl] d:\winnt\piprgrl.exe
  • 0

#4
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's part two of the log file. Oh, btw, the wallpaper problem is fixed all thanx to YOU!

O4 - HKCU\..\Run: [sdkchpw] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [wvhekai] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [jvarhpf] d:\winnt\qppbljm.exe
O4 - HKCU\..\Run: [kapmvcv] d:\winnt\enhtapa.exe
O4 - HKCU\..\Run: [cbacktm] d:\winnt\enhtapa.exe
O4 - HKCU\..\Run: [derunqp] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ygcovxv] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [nwfgvow] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gyrsqfb] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [jytpvjs] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [keqgoik] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [iyvkbtc] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [skwjaum] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [acbaepw] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [algusdq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yjcdock] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [qqehqkl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [kggtlsi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [mdpbkrb] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [otlcuqd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [oetfgyh] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [pspdlmu] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [vunuwqn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gkpwwtn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [hfxhmkd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yjmohdr] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [jpjgjuq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [grfgyvq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [sykfdhi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [uxoospk] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ydyjnrl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [taxskoi] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [foyriqq] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gbodxjx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [agewgbl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [yrhlgka] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ofweqnp] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [vajbugl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ytwonxx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ftwohtf] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [srrftmu] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [rgaauqr] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [koxofvc] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ypfovsg] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [paqolnn] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [dfwqrhx] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [ravmxmf] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [gvegbxt] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [buughmd] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [xxwgdbl] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [dvfieoy] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [wcavler] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [wilidju] d:\winnt\tiyhbud.exe
O4 - HKCU\..\Run: [amchekx] d:\winnt\cpvvptm.exe
O4 - HKCU\..\Run: [jcwivmk] d:\winnt\shcybvt.exe
O4 - HKCU\..\Run: [obcumrt] d:\winnt\shcybvt.exe
O4 - HKCU\..\Run: [teuegdn] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [dlmrahc] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [rswaoed] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [urwgewj] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [hmkwbsk] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [mywqpki] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [lxislbj] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [xwdcsqo] d:\winnt\mlfccal.exe
O4 - HKCU\..\Run: [adumqen] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [iufymnm] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qqvhqgy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ypgcfyy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [lfunpbu] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [uqocmpf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nreflis] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gppvtxa] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [uxypftn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ihkccsn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nqulgms] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [blflssk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fmtjtwp] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [oarskdf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fhklqqv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [nswoaqc] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gpubhcf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [spllcpv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [pnbprds] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [toojsjh] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ismlvvy] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [appyrej] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [mgtiqth] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [eykwxux] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [shrbgyb] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [vqslifv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [evnlyvs] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [berexox] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [fmkomww] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [veaufqv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [unsqcxf] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [aschbdv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [elaosyd] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [xjyleyj] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [npopkju] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [xqxkcbe] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [hfruqkj] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [mvtgpyn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qkjchrn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [iujbjtu] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [wsujrcn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qwxswdl] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [bbhribk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [hwuwglc] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [tptrndn] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [ntuwphd] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [netmftl] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [gjgufna] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [oofghlv] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [qtmycpk] d:\winnt\awqqhpd.exe
O4 - HKCU\..\Run: [tsqrtdm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gvydaco] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wdmkusf] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [eahmftf] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [btaxcku] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [pyqdnko] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [dipvdsg] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [pntyaan] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [rcyqvso] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [khtuvif] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [bthkrls] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [qawhubg] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [cdvsgko] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [hsfmpwm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [hnfsbpc] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gxixjrn] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [nimoxnm] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wybtwvo] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [lscdukr] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [acpxdnk] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wabuljp] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [wihqgbc] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [xravifs] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [phbgfew] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [baktlki] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [nkliict] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [ukbfcxl] d:\winnt\xthuvry.exe
O4 - HKCU\..\Run: [gqfqwst] d:\winnt\bqccqyj.exe
O4 - HKCU\..\Run: [fmeoxvb] d:\winnt\bqccqyj.exe
O4 - HKCU\..\Run: [uicsqef] d:\winnt\cssrlqo.exe
O4 - HKCU\..\Run: [wmglvgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cgxpyjq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vmawilt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tehoqxo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qesgwfi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aedgevs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vsccpqg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bmcwkfe] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vbcvyih] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [arodimb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [thxuhnc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xcfwacw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [huhdgmg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sjxorkt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gushjjs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lllhltv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tgggijw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jvuuhpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ncqrirj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [udlllfo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxlbckh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mvclyan] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dwhkfpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aguxxru] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [piqjugg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ygeydvk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ckhquif] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yfuhwos] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cvbspyv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qlqgfru] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ekmvbwq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qluxtii] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mtvoyje] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sshhbyk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wxgfipt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tjwbvxj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pnwdfqs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bhisgcq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [eebmfce] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [syvncgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oaubiqq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gcbuvif] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [apsnfpb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tffdgrn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [domyyls] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pwsxlwh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ayndoie] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rnhgnnv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oppmifl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [titsntw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jktxkyr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ojlncrr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rwubmpl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxmaefm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dswbayu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ybvphfs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qaanvrc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lgmoarb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vnnivfv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lbmubir] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cxargqt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sjlkpfn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lnhdjmx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kenenue] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uojwbte] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [luavxre] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oaiqpip] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cevagfc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ulxiuiv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xfxpkir] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uftrqkw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dryjgoy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dlcdxmi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jncfeam] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [awbhyvu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [feonxnh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [poxtyok] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wrvdlvg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yswqjja] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dwqpwdg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qrjbcyu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bathpuo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hdcpvwu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hcsgfjs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ipqtwlw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nvuliio] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vtjynvl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dcweavt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vwcxiid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ggmrwvb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fludtxx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ijjfnlc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ialikxq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uvoygwo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [suyixiu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yagybgf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tiecotx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fieuyqh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ohijetl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hxuurfm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pjhhbcc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uoxxsxs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lbwglau] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nhptyid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dxmkbjk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [plpxxdf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hwgwlpb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [evtoflq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vkloluc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bxchagf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ojttywy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ktkvvik] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mcorscg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wvmcoyo] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pyiyjtn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gtpcgta] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wravjxq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [liuwcuh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ogdutsm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lerctvg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qqcygud] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [htpycdh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [iybabvs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [egnbeyd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qtuvvxv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xemceuf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bpenrwp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qhoailm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [muueeyn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hhewwdn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wrmvimv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jfsehlp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mcusocg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bfpvmmt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xakvgin] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pocklxp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ofakgvi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mmusfot] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [plwiskm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wlmxmrl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fwcqwjr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [raosvgd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mhmxwla] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jorpycd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xqjmoin] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bbwyqrf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yxjsvhb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [acpvypg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nbjedhd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xjgsmjg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uprldfe] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [efgfkss] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nfphrvb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rnsifow] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pdoclsp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wxjeagg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aftpqxy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jwwgqgy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uotftxx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xnfbomj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jadgwgg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ccoboss] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rgltqgn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mutvkvq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gpjpfse] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gfkahvf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jtnnbea] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [csyfham] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qisuiyp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tmcrdox] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [atwwecf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wjunlot] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ibdnxro] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uopbuhe] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qenoxxj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [exxxdni] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xmgsgro] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rbgamqb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [egjplgq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hbonkvg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sthsrdu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [deipqcn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [isxxefa] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rnrmcfx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [krjtdme] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wouxcke] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [sgtswlg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pxloisd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [plhhemy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [strddtp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mkxbnip] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pnfferl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cbgvxrp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jfgofid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nkwdxam] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [awjbrme] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [adigdqc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ixccxep] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [efqlbpj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cbcifkh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vobqhtc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oqbcgkr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uhgbkrn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vewpbvy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bfeanne] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [onsaayq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [harncjl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fvtbldh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [twxcojm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cnaptwv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ijtsqva] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fumitse] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dfqatcp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pfkkcdg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bnwsswt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tomhgix] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [inloecw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [odefwfs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ovkqpgp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pbqpshr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [yxnvwmw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [twcrked] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xhbxqkt] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qjuvypp] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lmlpurk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cogxexc] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [crxdfax] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qsecarv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [afdarsm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kysdnut] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xmmfrwb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wfnegho] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ukqfkty] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bgrlhvi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nrlqhna] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uvgnlkn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [mxyewsi] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kctswih] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uawxqdy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dlbjepk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [amjgpvs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wmwjpnr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [tbglcly] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [bwruork] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pbnmlin] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [cgdgkaw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ijwjvqm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gbkcnha] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qjcatey] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nsjvxsm] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [isnreow] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nhdvawf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ujxksaf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [omndmmv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fmscbnr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jionucw] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [rykmevs] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [keyufyj] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jbufuul] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hxeqlct] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [unmrmdb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ufmjkju] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [oyblqnq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dbqjsai] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [orlygpn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uadofsg] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xuyryek] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xmqadkh] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [acqfkpy] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [aptnamx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [xpmydvx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [teypxvl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [jdtktvx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [vbvdgbv] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dhrhspq] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [hxsqnln] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [lejcxyx] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nfioqle] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [pqmsxdl] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [laiqurr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [wcutbnk] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [addttyn] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kxgaham] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fxecgva] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [drejqim] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [kdrxrcf] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [qqvxuma] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [fyfdyfr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [enwraav] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [uiygdxu] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [nmdcgdr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [dilolnd] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [gelgmfr] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [drxkcsb] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [ehlgyid] d:\winnt\rqocxfp.exe
O4 - HKCU\..\Run: [concblh] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [hnuxfss] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [hlqoond] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [uatpacj] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [vuqaqdx] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [kyhjlrv] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [ukcgwan] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [tdllmrh] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [qfngwgp] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [aqjncjh] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [quuaovm] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [vekpfns] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [bqowfcj] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [ifamhlo] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [uowmqqn] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [vvkeurp] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [qjbhpco] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [qdvddyo] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [faddijh] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [ygdqqlo] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [ptfvesa] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [moalhri] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [ooqxatj] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [wukkmcv] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [jgmvfqt] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [elnwsup] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [hkjjfvj] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [blmhbjd] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [yeubkya] d:\winnt\slfxtwn.exe
O4 - HKCU\..\Run: [phkurxa] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [snwplwq] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [dtbcvbw] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [xkcnfgw] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [nawwmke] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [oxxbmsa] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [pttbvso] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [huhmjvv] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [kiispjy] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [ovrejvk] d:\winnt\momuxbi.exe
O4 - HKCU\..\Run: [acqsdvp] d:\winnt\momuxbi.exe
O4 - HKCU\..\Run: [fpmdxgc] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [rvnpewc] d:\winnt\hfcueck.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] D:\WINNT\System32\spoolsrv32.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O9 - Extra button: Microsoft AntiSpyware helper - {8814A75D-98B5-44DF-BAAB-5A13BCBE5B15} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8814A75D-98B5-44DF-BAAB-5A13BCBE5B15} - (no file) (HKCU)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} (VacPro.internazionale_ver10) - http://www.advnt01.c...onale_ver10.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#5
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
OK, you have a lot here. Take your time on this.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Download ETRemover and unzip it. Don't run it yet.

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknigh...spy/Cleanup.exe ) and install it. Don't run it yet.

Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work.
Run ETRemover.exe now.

Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click 'Kill process' for each one if they are still listed (they shouldn't be - but double check):

d:\winnt\ewxdfwb.exe

Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:

180 Search Assistant
Security iGuard


Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
O2 - BHO: (no name) - {ED103D9F-3070-4580-AB1E-E5C179C1AE41} - (no file)
O4 - HKLM\..\Run: [DI2] "d:\DOCUME~1\PÅVEN\LOKALA~1\Temp\27.exe\27.exe"
O4 - HKLM\..\Run: [etbrun] d:\winnt\system32\elitekts32.exe
O4 - HKLM\..\Run: [Security iGuard] d:\Program\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [TUh9PM] d:\WINNT\pojtdaoy.exe
O4 - HKLM\..\Run: [dsd] d:\WINNT\dsd.exe
O4 - HKLM\..\Run: [rs7S36g] gejnv.exe
O4 - HKLM\..\Run: [saap] d:\program files\180search assistant\saap.exe
O4 - HKLM\..\RunOnce: [Srv32 spool service] d:\WINNT\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [ycaumky] d:\winnt\ewxdfwb.exe

OK this is where the long list begins. I'm going to tell you a shortcut way to do this (it will still be very tedious, but much better than checking each of individually by clicking with the mouse). Starting from here on down (see below - I will tell you when to stop doing this), just hit the space bar key and then down arrow key. Keep doing this and it will check the entry and move down. So keep going until I tell you to stop (see below)

O4 - HKCU\..\Run: [WindowsFY] d:\wp.exe
O4 - HKCU\..\Run: [Opmo] d:\WINNT\system32\iias.exe
O4 - HKCU\..\Run: [Adxk] d:\WINNT\system32\w?nspool.exe

...skipping all the in betweens here for obvious reasons (too big), but just keep checking until you get to the bottom part (right before the 09 Extra Button entries - then start checking them off manually with the mouse since this will slow down a little now)...

O4 - HKCU\..\Run: [kiispjy] d:\winnt\krxabtb.exe
O4 - HKCU\..\Run: [ovrejvk] d:\winnt\momuxbi.exe
O4 - HKCU\..\Run: [acqsdvp] d:\winnt\momuxbi.exe
O4 - HKCU\..\Run: [fpmdxgc] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [rvnpewc] d:\winnt\hfcueck.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] d:\WINNT\System32\spoolsrv32.exe
O9 - Extra button: Microsoft AntiSpyware helper - {8814A75D-98B5-44DF-BAAB-5A13BCBE5B15} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {8814A75D-98B5-44DF-BAAB-5A13BCBE5B15} - (no file) (HKCU)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {AD0B8220-7DA4-4C0A-8532-B25A9F631D3D} (VacPro.internazionale_ver10) - http://www.advnt01.c...onale_ver10.CAB


Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

d:\winnt\aojinvx.exe
d:\winnt\yaeddje.exe
d:\winnt\ymyaygq.exe
wua_mtf.exe
d:\winnt\axqjxuf.exe
d:\winnt\mjfegak.exe
d:\winnt\piprgrl.exe
d:\winnt\qppbljm.exe
d:\winnt\enhtapa.exe
d:\winnt\tiyhbud.exe
d:\winnt\cpvvptm.exe
d:\winnt\shcybvt.exe
d:\winnt\shcybvt.exe
d:\winnt\mlfccal.exe
d:\winnt\awqqhpd.exe
d:\winnt\xthuvry.exe
d:\winnt\bqccqyj.exe
d:\winnt\cssrlqo.exe
d:\winnt\rqocxfp.exe
d:\winnt\slfxtwn.exe
d:\winnt\krxabtb.exed
c:\winnt\system32\elitekts32.exe
d:\Program\Security iGuard\
d:\WINNT\pojtdaoy.exe
d:\WINNT\dsd.exe
gejnv.exe
d:\program files\180search assistant\
d:\WINNT\System32\spoolsrv32.exe
d:\winnt\ewxdfwb.exe
d:\wp.exe
d:\wp.bmp
d:\WINNT\system32\iias.exe
d:\winnt\krxabtb.exe
d:\winnt\momuxbi.exe
d:\winnt\hfcueck.exe

Do a search for w?nspool.exe and right click on any of the files found. Go to Properties->Version tab and see if it's from Microsoft. Do this for each file found. If it's not from Microsoft (or doesn't even have a version tab) and it was created recently, then delete it.

Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.

Please empty any Quarantine folder in your antivirus program and purge all recovery items in the Spybot program (if you use it) before running this tool.

Download the Mwav virus checker at http://www.mwti.net/antivirus/mwav.asp (Use Link 3)

1. Save it to a folder.
2. Reboot into Safe Mode.
3. Double click the Mwav.exe file. This is a stand alone tool and NOT just a virus checker......so it won't install anything.
4. Select all local drives, scan all files, and press SCAN. When it is completed, anything found will be displayed in the lower pane.
5. In the Virus Log Information Pane......
Left click and highlight all the information in the Lower pane --- Use &CTRL C &on your keyboard to copy everything found in the lower pane and save it to a notepad file
*Note* If prompted that a virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning. We are not going to use this to remove anything...but to ID the bad files.

Once you copy that to a Notepad file...highlight the text and copy it here.
  • 0

#6
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
OK - here's the new log file, substantially smaller than before. What puzzles me is that my default browser page is still w-find.com. Again, thanks for helping me out.

Logfile of HijackThis v1.99.1
Scan saved at 17:33:13, on 2005-04-30
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\Program\Norton AntiVirus\navapsvc.exe
D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\Program\Delade filer\Symantec Shared\ccApp.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
D:\WINNT\system32\internat.exe
D:\winnt\pfofnoi.exe
D:\WINNT\system32\NOTEPAD.EXE
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "D:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ribwcca] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [paxvlnp] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [tkcnywv] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [bwinnld] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [krkengn] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [gqtfcsl] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [pehdaoj] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [rrbysji] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [qfwylxu] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [oydptio] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [qonqand] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [vpysqkl] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [cbwoclo] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [hkxaipv] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [woqndmt] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [rblauci] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [ctaknrg] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [xbkmqmr] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [oltemxu] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [bikijub] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [aranhuo] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [lhrpuef] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [yqbpxmw] d:\winnt\lsjsuqb.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#7
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Yes, we need to remove all the files here since they may be recreating that problem.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work. Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click 'Kill process' for each one if they are still listed (they shouldn't be - but double check):

d:\winnt\pfofnoi.exe

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
O4 - HKCU\..\Run: [ribwcca] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [paxvlnp] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [tkcnywv] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [bwinnld] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [krkengn] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [gqtfcsl] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [pehdaoj] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [rrbysji] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [qfwylxu] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [oydptio] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [qonqand] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [vpysqkl] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [cbwoclo] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [hkxaipv] d:\winnt\hfcueck.exe
O4 - HKCU\..\Run: [woqndmt] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [rblauci] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [ctaknrg] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [xbkmqmr] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [oltemxu] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [bikijub] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [aranhuo] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [lhrpuef] d:\winnt\pfofnoi.exe
O4 - HKCU\..\Run: [yqbpxmw] d:\winnt\lsjsuqb.exe


Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

d:\winnt\hfcueck.exe
d:\winnt\lsjsuqb.exe
d:\winnt\pfofnoi.exe


Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.
  • 0

#8
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Things are looking up. My web browser displayed "about:blank" on startup and I was able to reset the default homepage. I ran a virus scan with the mwa.exe (or whatever its name was) before I fixed the w-find.com related files and the other files you told me to fix. I don't know if there's any point in posting the virus scan log file since it may be obsolete, but I'll do it anyway.

Logfile of HijackThis v1.99.1
Scan saved at 00:29:36, on 2005-05-01
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\Program\Norton AntiVirus\navapsvc.exe
D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\Program\Delade filer\Symantec Shared\ccApp.exe
D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\WINNT\system32\internat.exe
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [ccApp] "D:\Program\Delade filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [rkxfqxp] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [shqxdxn] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [hngbmla] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [yttagud] d:\winnt\yagynhv.exe
O4 - HKCU\..\Run: [sojfpgx] d:\winnt\yagynhv.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - D:\Program\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - D:\Program\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\Program\DELADE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program\Delade filer\Symantec Shared\CCPD-LC\symlcsvc.exe

...and here's the virus scan log:

File d:\winnt\pfofnoi.exe infected by "Trojan.Win32.StartPage.xt" Virus. Action Taken: No Action Taken.
File d:\winnt\lsjsuqb.exe infected by "Trojan.Win32.StartPage.xt" Virus. Action Taken: No Action Taken.
File System Found infected by "AdDestroyer Spyware/Adware" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\NLNP13.dll infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\NLNP!3.exe infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\BO2802040113.dll infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\shimbase.dll infected by "Backdoor.Win32.PPdoor.j" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\gejcaaaa.exe infected by "Trojan.Win32.StartPage.xt" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\ovjfqwqn.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\srpcsrv32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\txfdb32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\hochkaod3.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\TEMP\bpc_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Program\Windows Media Player\wmplayer.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\Program\CxtPls\WinGenerics.dll infected by "not-a-virus:AdWare.Apropos.f" Virus. Action Taken: No Action Taken.
File C:\ft22s.exe infected by "not-a-virus:AdWare.Broadcap.b" Virus. Action Taken: No Action Taken.
File C:\Sierra\Counter-Strike\hltv.exe tagged as not-a-virus:RiskWare.Proxy.Hltv. No Action Taken.
File C:\Sierra\Half-Life\hltv.exe tagged as not-a-virus:RiskWare.Proxy.Hltv. No Action Taken.
File D:\WINNT\system32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\NLNP13.dll infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\NLNP!3.exe infected by "not-a-virus:AdWare.IGetNet" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\BO2802040113.dll infected by "not-a-virus:AdWare.VirtualBouncer.d" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\shimbase.dll infected by "Backdoor.Win32.PPdoor.j" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\gejcaaaa.exe infected by "Trojan.Win32.StartPage.xt" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\ovjfqwqn.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\srpcsrv32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\txfdb32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File D:\WINNT\system32\hochkaod3.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken.
File D:\Documents and Settings\Påven\Skrivbord\backups\backup-20050430-161851-136.dll infected by "not-a-virus:AdWare.WinAD.ak" Virus. Action Taken: No Action Taken.
(End of Log File)
  • 0

#9
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
No. There definitely is something bad showing up in the mwav log. I think you have another infection there also, but we should be close to nailing this one now.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Download KillBox http://www.greyknigh...spy/KillBox.exe. Don't run it yet.

The Temp folders should be cleaned out periodically as installation programs and hijack programs leave a lot of junk there. Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknigh...spy/Cleanup.exe ) and install it. Don't run it yet.

Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work. Make sure to close any open browsers. Uninstall the following via the Add/Remove Panel (Start->(Settings)->Control Panel->Add/Remove Programs) if they exist:

AdDestroyer

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O4 - HKCU\..\Run: [rkxfqxp] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [shqxdxn] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [hngbmla] d:\winnt\lsjsuqb.exe
O4 - HKCU\..\Run: [yttagud] d:\winnt\yagynhv.exe
O4 - HKCU\..\Run: [sojfpgx] d:\winnt\yagynhv.exe


Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. For each of the following files below, check the box that says 'Unregister .dll Before Deleting' if it's not grayed out. Copy and paste each of the following into KillBox (hitting the X button for each file - choose NO when it asks if you want to reboot):

d:\winnt\pfofnoi.exe
d:\winnt\lsjsuqb.exe
D:\WINNT\system32\hochkaod3.exe
C:\Program\Windows Media Player\wmplayer.exe
C:\Program\CxtPls\
C:\ft22s.exe
D:\WINNT\system32\SWRT01.dll
D:\WINNT\system32\NLNP13.dll
D:\WINNT\system32\NLNP!3.exe
D:\WINNT\system32\BO2802040113.dll
D:\WINNT\system32\shimbase.dll
D:\WINNT\system32\gejcaaaa.exe
D:\WINNT\system32\ovjfqwqn.exe
D:\WINNT\system32\srpcsrv32.dll
D:\WINNT\system32\wldr.dll
D:\WINNT\system32\txfdb32.dll
D:\WINNT\system32\hochkaod3.exe
d:\winnt\lsjsuqb.exe
d:\winnt\yagynhv.exe
D:\Documents and Settings\Påven\Skrivbord\backups\backup-20050430-161851-136.dll


Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.

Download L2MFix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts. Then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing Enter. This will scan your computer and it may appear nothing is happening. After a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 or any other files in the l2mfix folder until you are asked to do so!
  • 0

#10
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's the log. More to come...

Logfile of HijackThis v1.99.1
Scan saved at 21:12:56, on 2005-05-03
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\Program\Delade filer\Symantec Shared\Security Center\UsrPrmpt.exe
D:\WINNT\system32\internat.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\WINNT\system32\NOTEPAD.EXE
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ysgbrlf] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [rwqtfbc] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [vqmryhv] d:\winnt\jhcdnwc.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
  • 0

Advertisements


#11
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's the l2mfix log. There's a familiar and very annoying toolbar in IE again.

L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName"="D:\\WINNT\\System32\\NavLogon.dll"
"Logoff"="NavLogoffEvent"
"StartShell"="NavStartShellEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
"DLLName"="wzcdlg.dll"
"Logon"="WZCEventLogon"
"Logoff"="WZCEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000000

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"iebar"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Egenskapsf”rteckning f”r multimediafiler"
"{176d6597-26d3-11d1-b350-080036a75b03}"="Hantering av ICM-skanner"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-s„kerhetssida"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Egenskapssida f”r OLE-dokumentfiler"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell-till„gg f”r delning"
"{41E300E0-78B6-11ce-849B-444553540000}"="Kontrollpanelstill„gg f”r PlusPack"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Kontrollpanelstill„gg f”r bildsk„rmskort"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Kontrollpanelstill„gg f”r bildsk„rm"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Kontrollpanelstill„gg f”r bildsk„rmspanorering"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS-s„kerhetssida"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Diskkopiering - till„gg"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell-till„gg f”r Microsoft Windows Network-objekt"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Hantering av ICM-bildsk„rm"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Hantering av ICM-skrivare"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell-till„gg f”r filkomprimering"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Shell-till„gg f”r webbutskrift"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Snabbmeny f”r kryptering"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Portf”lj"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-ikontill„gg"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profil"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Skrivars„kerhetssida"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell-till„gg f”r delning"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO-till„gg"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Till„gg f”r kryptografisk signering"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="N„tverks- och fj„rranslutningar"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Schemalagda aktiviteter"
"{1A9BA3A0-143A-11CF-8350-444553540000}"="Shell Favorite Folder"
"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"="Den h„r datorn"
"{86747AC0-42A0-1069-A2E6-08002B30309D}"="Mappen Portf”lj"
"{0AFACED1-E828-11D1-9187-B532F1E9575D}"="Mappgenv„g"
"{12518493-00B2-11d2-9FA5-9E3420524153}"="Monterad volym"
"{21B22460-3AEA-1069-A2DC-08002B30309D}"="File Property Page Extension"
"{B091E540-83E3-11CF-A713-0020AFD79762}"="File Types Page"
"{FBF23B41-E3F0-101B-8488-00AA003E56F8}"="MIME File Types Hook"
"{C2FBB630-2971-11d1-A18C-00C04FD75D13}"="Microsoft CopyTo Service"
"{C2FBB631-2971-11d1-A18C-00C04FD75D13}"="Microsoft MoveTo Service"
"{13709620-C279-11CE-A49E-444553540000}"="Shell Automation Service"
"{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}"="Shell Automation Folder View"
"{4622AD11-FF23-11d0-8D34-00A0C90F2719}"="Start-meny"
"{7BA4C740-9E81-11CF-99D3-00AA004AE837}"="Microsoft SendTo Service"
"{D969A300-E7FF-11d0-A93B-00A0C90F2719}"="Microsoft New Object Service"
"{09799AFB-AD67-11d1-ABCD-00C04FC30936}"="Open With Context Menu Handler"
"{3FC0B520-68A9-11D0-8D77-00C04FD70822}"="Display Control Panel HTML Extensions"
"{75048700-EF1F-11D0-9888-006097DEACF9}"="ActiveDesktop"
"{6D5313C0-8C62-11D1-B2CD-006097DF8C11}"="Folder Options Property Page Extension"
"{57651662-CE3E-11D0-8D77-00C04FC99D61}"="CmdFileIcon"
"{4657278A-411B-11d2-839A-00C04FD918D0}"="Hj„lpprogram f”r dra och sl„pp"
"{A470F8CF-A1E8-4f65-8335-227475AA5C46}"="L„gger till ett krypteringsalternativ i snabbmenyer i Utforskaren"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{568804CA-CBD7-11d0-9816-00C04FD91972}"="Menu Shell Folder"
"{5b4dae26-b807-11d0-9815-00c04fd91972}"="Menyband"
"{8278F931-2A3E-11d2-838F-00C04FD918D0}"="Tracking Shell Menu"
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}"="Menu Site"
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}"="Menu Desk Bar"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}"="IShellFolderBand"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}"="&L„nkar"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adress"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7487cd30-f71a-11d0-9ea7-00805f714772}"="Thumbnail Image"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Globala mappinst„llningar"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft-tj„nst f”r tidigare adresser (URL)"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="Tidigare"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Tillf„lliga Internet-filer"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="V„lkomstsk„rm f”r Internet Explorer 4.0 Suite"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="Mappen ActiveX Cache"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Mappen Subscriptions"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}"="Miniatyrer"
"{EAB841A0-9550-11CF-8C16-00805F1408F3}"="Extraherare f”r HTML-miniatyr"
"{1AEB1360-5AFC-11D0-B806-00C04FD706EC}"="Miniatyrhanterare f”r Office-grafikfilter"
"{9DBD2C50-62AD-11D0-B806-00C04FD706EC}"="Information om miniatyrer (DOC-filer)"
"{500202A0-731E-11D0-B829-00C04FD706EC}"="LNK file thumbnail interface delegator"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Programhanteraren"
"{0B124F8C-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{fe1290f0-cfbd-11cf-a330-00aa00c16e65}"="Directory Namespace"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{450D8FBA-AD25-11D0-98A8-0800361B1103}"="MyDocs Folder"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offlinefiler-menyn"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Alternativ f”r mappen Offlinefiler"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offlinefiler"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Parsning f”r adressf„lt"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Tillf„lliga Internet-filer"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="Efter &personer..."
"{59850401-6664-101B-B21C-00AA004BA90B}"="Microsoft Office Binder Unbind"
"{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
"{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
"{F802F260-519B-11D1-BB5D-0060974C6013}"="ICQ Shell Extension"
"{BDA77241-42F6-11d0-85E2-00AA001FE28C}"="LDVP Shell Extensions"
"{448f4a40-2602-11d1-b4c0-080000051171}"="MP3-Info Extension"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Skrivbordsutforskaren"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{52B87208-9CCF-42C9-B88E-069281105805}"="Trojan Remover Shell Extension"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanalfil"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanalgenv„g"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"MP3-Info extension"="{448f4a40-2602-11d1-b4c0-080000051171}"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"

**********************************************************************************
HKEY ROOT CLASSIDS:
**********************************************************************************
Files Found are not all bad files:

D:\WINNT\SYSTEM32\
symredir.dll Tue 2005-04-05 11.17.04 A.... 132 824 129,71 K
0ekpg8~1.dll Tue 2005-05-03 21.17.02 A.... 6 144 6,00 K
symneti.dll Tue 2005-04-05 11.17.04 A.... 517 848 505,71 K
vnetbsh.dll Tue 2005-05-03 21.19.16 A.... 28 681 28,01 K
nodfheld.dll Sat 2005-04-16 18.57.14 A.... 2 630 2,57 K
nldsrmbj.dll Tue 2005-05-03 21.11.12 A.... 15 429 15,07 K
thun.dll Sat 2005-04-16 18.57.46 A.... 32 0,03 K
flsmngr.dll Sat 2005-04-16 18.57.48 A.... 126 976 124,00 K
browseui.dll Fri 2005-02-18 17.38.30 A.... 1 017 856 994,00 K
iepeers.dll Fri 2005-02-18 17.38.32 A.... 236 032 230,50 K
mshtml.dll Thu 2005-02-24 14.05.00 A.... 2 811 904 2,68 M
msrating.dll Thu 2005-02-24 14.05.00 A.... 132 096 129,00 K
shdocvw.dll Fri 2005-02-18 17.38.34 A.... 1 337 344 1,27 M
wininet.dll Fri 2005-02-18 17.38.34 A.... 593 920 580,00 K
shell32.dll Fri 2005-03-04 8.57.30 A.... 2 365 712 2,25 M
winsrv.dll Sat 2005-03-12 9.55.40 A.... 245 008 239,27 K
user32.dll Sat 2005-03-12 9.55.40 A.... 380 688 371,77 K
authz.dll Fri 2005-02-04 7.34.04 A.... 55 568 54,27 K
sp3res.dll Mon 2005-02-07 7.32.28 A.... 271 872 265,50 K
spmsg.dll Mon 2005-03-21 15.00.10 ..... 14 560 14,22 K
msi.dll Mon 2005-03-21 15.00.20 A.... 2 890 240 2,75 M
msihnd.dll Mon 2005-03-21 15.00.22 A.... 271 360 265,00 K
msimsg.dll Mon 2005-03-21 15.00.22 A.... 884 736 864,00 K
msisip.dll Mon 2005-03-21 15.00.22 A.... 15 360 15,00 K

24 items found: 24 files, 0 directories.
Total of file sizes: 14 354 820 bytes 13,69 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volymen i enhet D har etiketten LOKAL DISK
Volymens serienummer „r 102F-1B01

Inneh†ll i katalogen D:\WINNT\System32

2005-05-02 18:22 421ÿ888 w?wexec.exe
2002-01-13 19:54 <KAT> dllcache
1 fil(er) 421ÿ888 byte
1 katalog(er) 2ÿ210ÿ316ÿ288 byte ledigt
  • 0

#12
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Update all your antispyware and antivirus programs - Ad-aware, Spybot, Norton. Then run a scan - do them one by one. Make sure to delete all the bad files/entries those programs find.

Now do this:

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing Enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2MFix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

  • 0

#13
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Here's the HiJack log file. The l2mfix doesn't seem to be working properly - I've followed the instructions, but after the reboot no txt-file shows up. Not even after a good 25 minutes of waiting. Other than that, Norton AV 2005 only works in safe mode (I've completed a scan w/ the latest updates for NAV2005, Spybot S&D and Ad-Aware SE as per your instructions and removed all bad files/entries, emptied quaratine folders and recovery folders in Spybot S&D). Not even the online Trend Micro Virus Scan works! I'm giving serious thought to formatting both drives and starting fresh...grrr...

Logfile of HijackThis v1.99.1
Scan saved at 17:57:42, on 2005-05-04
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\WINNT\system32\internat.exe
D:\Documents and Settings\Påven\Application Data\iias.exe
D:\WINNT\system32\w?wexec.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\Program\Internet Explorer\iexplore.exe
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [checkrun] D:\winnt\system32\eliteyel32.exe
O4 - HKLM\..\Run: [HELPER] D:\WINNT\system32\sweden.exe -N
O4 - HKLM\..\Run: [second] D:\Documents and Settings\P†ven\Skrivbord\l2mfix\second.bat
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ysgbrlf] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [rwqtfbc] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [vqmryhv] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [Opmo] D:\Documents and Settings\Påven\Application Data\iias.exe
O4 - HKCU\..\Run: [Qaxm] D:\WINNT\system32\w?wexec.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
  • 0

#14
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
It's your choice. If you want to format now, then we will close this topic. If you want to continue, then:

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Reboot into Safe Mode by hitting the F8 key until menu shows up. In some systems, this may be the F5 key, so try that if F8 doesn't work.
Run ETRemover again. Do not restart yet.

Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click 'Kill process' for each one if they are still listed (they shouldn't be - but double check):

D:\Documents and Settings\Påven\Application Data\iias.exe
D:\WINNT\system32\w?wexec.exe


Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O4 - HKLM\..\Run: [checkrun] D:\winnt\system32\eliteyel32.exe
O4 - HKLM\..\Run: [HELPER] D:\WINNT\system32\sweden.exe -N
O4 - HKLM\..\Run: [second] D:\Documents and Settings\P†ven\Skrivbord\l2mfix\second.bat
O4 - HKCU\..\Run: [ysgbrlf] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [rwqtfbc] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [vqmryhv] d:\winnt\jhcdnwc.exe
O4 - HKCU\..\Run: [Opmo] D:\Documents and Settings\Påven\Application Data\iias.exe
O4 - HKCU\..\Run: [Qaxm] D:\WINNT\system32\w?wexec.exe
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab


Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

D:\Documents and Settings\Påven\Application Data\iias.exe
D:\winnt\system32\eliteyel32.exe
D:\WINNT\system32\sweden.exe
d:\winnt\jhcdnwc.exe


Do a search for w?wexec.exe and right click on any of the files found. Go to Properties->Version tab and see if it's from Microsoft. Do this for each file found. If it's not from Microsoft (or doesn't even have a version tab) and it was created recently, then delete it.

Reboot into Normal Mode run a new HijackThis scan. Save the log file and post it here.
  • 0

#15
Poppapope

Poppapope

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
I'll give it a go again, I really shouldn't complain since I've found this site/forum.

:tazz:

Logfile of HijackThis v1.99.1
Scan saved at 17:16:50, on 2005-05-05
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
D:\WINNT\System32\svchost.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\system32\MSTask.exe
D:\WINNT\System32\WBEM\WinMgmt.exe
D:\WINNT\System32\mspmspsv.exe
D:\WINNT\Explorer.EXE
D:\Program\Delade filer\Real\Update_OB\realsched.exe
D:\WINNT\system32\internat.exe
D:\Program\Logitech\MouseWare\system\em_exec.exe
D:\Documents and Settings\Påven\Skrivbord\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.google.com"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (D:\Documents and Settings\Påven\Application Data\Mozilla\Profiles\default\2i5woe8c.slt\prefs.js)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program\google\googletoolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program\google\googletoolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\Program\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "D:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINNT\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: Microsoft Office.lnk = D:\Program\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search - res://D:\Program\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://D:\Program\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Program\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINNT\System32\Shdocvw.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O17 - HKLM\System\CS3\Services\Tcpip\..\{7242F3A3-B760-4599-A9C9-4B9104027C0E}: NameServer = 192.168.0.254,192.168.0.254
O20 - Winlogon Notify: NavLogon - D:\WINNT\System32\NavLogon.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - D:\WINNT\System32\nvsvc32.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP