C:\WINDOWS\system32\euijjauj.ini
C:\WINDOWS\system32\eurcakkk.dll
C:\WINDOWS\system32\eybwsqyu.ini
C:\WINDOWS\system32\faduoytw.dll
C:\WINDOWS\system32\fcxijhfm.ini
C:\WINDOWS\system32\fcyyyyw.dll
C:\WINDOWS\system32\fdbnsclt.ini
C:\WINDOWS\system32\fewrkioe.dll
C:\WINDOWS\system32\fggmvoje.dll
C:\WINDOWS\system32\fijibfjx.ini
C:\WINDOWS\system32\fkibprpj.ini
C:\WINDOWS\system32\fmuvaqia.dll
C:\WINDOWS\system32\fonwbnkm.dll
C:\WINDOWS\system32\forqjoyr.ini
C:\WINDOWS\system32\fsfaawis.ini
C:\WINDOWS\system32\futpdvfs.ini
C:\WINDOWS\system32\fwhtltqv.dll
C:\WINDOWS\system32\fwnecapt.ini
C:\WINDOWS\system32\fxaktfae.ini
C:\WINDOWS\system32\fywwbjye.dll
C:\WINDOWS\system32\gdxjuhyi.dll
C:\WINDOWS\system32\gebca.dll
C:\WINDOWS\system32\gebcy.dll
C:\WINDOWS\system32\gfgiftnj.dll
C:\WINDOWS\system32\gfyhersf.dll
C:\WINDOWS\system32\ghnruger.ini
C:\WINDOWS\system32\ghrauuvl.dll
C:\WINDOWS\system32\ghxccpuc.dll
C:\WINDOWS\system32\gjixtrli.dll
C:\WINDOWS\system32\gjvkbsns.dll
C:\WINDOWS\system32\gldncmji.ini
C:\WINDOWS\system32\gtelmhrd.dll
C:\WINDOWS\system32\guccbepd.dll
C:\WINDOWS\system32\gyjjluwc.dll
C:\WINDOWS\system32\hecjlcxn.dll
C:\WINDOWS\system32\hejeqmpu.dll
C:\WINDOWS\system32\hlnxhchu.dll
C:\WINDOWS\system32\hnkelqlh.dll
C:\WINDOWS\system32\hnupglno.dll
C:\WINDOWS\system32\hptwjcxv.ini
C:\WINDOWS\system32\hpuxyfiw.dll
C:\WINDOWS\system32\hpxpxhxu.dll
C:\WINDOWS\system32\hqkulbot.ini
C:\WINDOWS\system32\hriailwr.dll
C:\WINDOWS\system32\hvgwkpvd.ini
C:\WINDOWS\system32\hwdfmnom.dll
C:\WINDOWS\system32\hwltjkdv.ini
C:\WINDOWS\system32\idbuxxpa.dll
C:\WINDOWS\system32\idoiurop.ini
C:\WINDOWS\system32\ieyogmdx.dll
C:\WINDOWS\system32\igpueciy.ini
C:\WINDOWS\system32\ihrwqdwb.ini
C:\WINDOWS\system32\ihwxqjrb.dll
C:\WINDOWS\system32\iidylrij.ini
C:\WINDOWS\system32\ijdlsutw.dll
C:\WINDOWS\system32\ijkmp.bak1
C:\WINDOWS\system32\ijkmp.ini
C:\WINDOWS\system32\ikxiwpnv.dll
C:\WINDOWS\system32\ilrtxijg.ini
C:\WINDOWS\system32\imeocdwx.dll
C:\WINDOWS\system32\ipindcbl.ini
C:\WINDOWS\system32\ipljibgn.dll
C:\WINDOWS\system32\iptnkcvj.dll
C:\WINDOWS\system32\iqkjbhpc.ini
C:\WINDOWS\system32\iqlpcsgl.dll
C:\WINDOWS\system32\iqsifejb.dll
C:\WINDOWS\system32\irylnflv.ini
C:\WINDOWS\system32\ithxcmnw.dll
C:\WINDOWS\system32\iumfkord.ini
C:\WINDOWS\system32\ivnvejvm.ini
C:\WINDOWS\system32\ivtxuued.dll
C:\WINDOWS\system32\iwqqespu.ini
C:\WINDOWS\system32\iyeecweo.dll
C:\WINDOWS\system32\iyhqoqyp.dll
C:\WINDOWS\system32\iyhujxdg.ini
C:\WINDOWS\system32\jdsjiwib.ini
C:\WINDOWS\system32\jdwxndqe.ini
C:\WINDOWS\system32\jekjvlde.dll
C:\WINDOWS\system32\jirlydii.dll
C:\WINDOWS\system32\jkhgbvqc.ini
C:\WINDOWS\system32\jlfdgpir.dll
C:\WINDOWS\system32\jlgcfhfm.dll
C:\WINDOWS\system32\jlnillrs.ini
C:\WINDOWS\system32\jlppwymm.ini
C:\WINDOWS\system32\jmjqfvyx.ini
C:\WINDOWS\system32\jmlbxjbv.dll
C:\WINDOWS\system32\jmrqbfqp.ini
C:\WINDOWS\system32\jnxcpbcu.dll
C:\WINDOWS\system32\jqmcirau.ini
C:\WINDOWS\system32\jqqhnfxa.ini
C:\WINDOWS\system32\jqvbxevd.ini
C:\WINDOWS\system32\jsaomtad.ini
C:\WINDOWS\system32\jtlkdgob.dll
C:\WINDOWS\system32\jtvkmlon.dll
C:\WINDOWS\system32\juajjiue.dll
C:\WINDOWS\system32\jxawfvvg.dll
C:\WINDOWS\system32\jxtqgxdv.dll
C:\WINDOWS\system32\kahyycci.dll
C:\WINDOWS\system32\kdhwr.exe
C:\WINDOWS\system32\kdyviugl.dll
C:\WINDOWS\system32\kffqcius.ini
C:\WINDOWS\system32\kfyoyfis.ini
C:\WINDOWS\system32\khcgtwqk.ini
C:\WINDOWS\system32\kicuyqpx.dll
C:\WINDOWS\system32\kifbsluf.dll
C:\WINDOWS\system32\kjodaale.dll
C:\WINDOWS\system32\kjqdmlem.ini
C:\WINDOWS\system32\kkkacrue.ini
C:\WINDOWS\system32\kohkpidi.dll
C:\WINDOWS\system32\kopgmfeo.dll
C:\WINDOWS\system32\kqwtgchk.dll
C:\WINDOWS\system32\krbywpum.dll
C:\WINDOWS\system32\krchvmkt.dll
C:\WINDOWS\system32\ksegluoj.dll
C:\WINDOWS\system32\ksensrmm.ini
C:\WINDOWS\system32\kunuapik.dll
C:\WINDOWS\system32\kvaomjds.ini
C:\WINDOWS\system32\kvasjxan.ini
C:\WINDOWS\system32\kwfhavtb.ini
C:\WINDOWS\system32\ladhdavv.dll
C:\WINDOWS\system32\lbcdnipi.dll
C:\WINDOWS\system32\lgjwtbnl.ini
C:\WINDOWS\system32\lhopttin.dll
C:\WINDOWS\system32\livokipi.dll
C:\WINDOWS\system32\lkeeacyq.dll
C:\WINDOWS\system32\lkefimfv.dll
C:\WINDOWS\system32\lmhbbwwn.dll
C:\WINDOWS\system32\lppjokaj.ini
C:\WINDOWS\system32\lshtbjpn.ini
C:\WINDOWS\system32\lspchouw.dll
C:\WINDOWS\system32\lvcccrmf.dll
C:\WINDOWS\system32\lvuuarhg.ini
C:\WINDOWS\system32\lxcyqkom.dll
C:\WINDOWS\system32\lxqrbdtx.ini
C:\WINDOWS\system32\mcofkiha.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mdmwcmcx.ini
C:\WINDOWS\system32\mdnlctpk.dll
C:\WINDOWS\system32\mdtpykef.dll
C:\WINDOWS\system32\mfhfcglj.ini
C:\WINDOWS\system32\mfhjixcf.dll
C:\WINDOWS\system32\mgqtfiei.dll
C:\WINDOWS\system32\mhdfqwlb.dll
C:\WINDOWS\system32\mjgnnlkh.ini
C:\WINDOWS\system32\mknbwnof.ini
C:\WINDOWS\system32\monmfdwh.ini
C:\WINDOWS\system32\mosuqvvm.dll
C:\WINDOWS\system32\mpvpqnla.dll
C:\WINDOWS\system32\mpxzkrai.dll
C:\WINDOWS\system32\mqrppjag.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mtbscmew.dll
C:\WINDOWS\system32\mualsfox.ini
C:\WINDOWS\system32\mvjevnvi.dll
C:\WINDOWS\system32\mwonhbla.dll
C:\WINDOWS\system32\myqqnmuf.dll
C:\WINDOWS\system32\naxjsavk.dll
C:\WINDOWS\system32\nbpmyndx.ini
C:\WINDOWS\system32\nevkusma.dll
C:\WINDOWS\system32\nffdgstc.ini
C:\WINDOWS\system32\nfibrfpx.dll
C:\WINDOWS\system32\ngbijlpi.ini
C:\WINDOWS\system32\nipuyise.ini
C:\WINDOWS\system32\nlnfnodt.ini
C:\WINDOWS\system32\nmfubvlc.dll
C:\WINDOWS\system32\nolmkvtj.ini
C:\WINDOWS\system32\nopksjyt.dll
C:\WINDOWS\system32\npffsqyd.dll
C:\WINDOWS\system32\nxqdoimb.ini
C:\WINDOWS\system32\o03PrEz
C:\WINDOWS\system32\o03PrEz\o03PrEz1080.exe
C:\WINDOWS\system32\oablejvo.ini
C:\WINDOWS\system32\obfmisdu.dll
C:\WINDOWS\system32\ocvwewak.dll
C:\WINDOWS\system32\oewceeyi.ini
C:\WINDOWS\system32\ogflbhye.dll
C:\WINDOWS\system32\ojoefyvt.dll
C:\WINDOWS\system32\olpvvsts.dll
C:\WINDOWS\system32\oltbqdyp.dll
C:\WINDOWS\system32\oodqmils.dll
C:\WINDOWS\system32\oqedcuuq.dll
C:\WINDOWS\system32\oqkxmqlx.dll
C:\WINDOWS\system32\osrsutsp.ini
C:\WINDOWS\system32\otsqjgsy.ini
C:\WINDOWS\system32\ouuonapd.ini
C:\WINDOWS\system32\ovdcxpuj.dll
C:\WINDOWS\system32\ovfviuye.dll
C:\WINDOWS\system32\owidtjdy.dll
C:\WINDOWS\system32\oyogugqp.dll
C:\WINDOWS\system32\pbwkavad.dll
C:\WINDOWS\system32\pbxvddct.ini
C:\WINDOWS\system32\peigkexx.dll
C:\WINDOWS\system32\peyjboir.dll
C:\WINDOWS\system32\pguuwvqq.ini
C:\WINDOWS\system32\phlvlffa.dll
C:\WINDOWS\system32\pidbxqrk.ini
C:\WINDOWS\system32\pldfxdmr.dll
C:\WINDOWS\system32\plycspic.dll
C:\WINDOWS\system32\pmgkkety.ini
C:\WINDOWS\system32\pmkjg.dll
C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmnscrkm.dll
C:\WINDOWS\system32\pnfefmwm.dll
C:\WINDOWS\system32\pngdpeii.dll
C:\WINDOWS\system32\pnkkyqjh.ini
C:\WINDOWS\system32\pnngdrbu.ini
C:\WINDOWS\system32\poiyhmtl.ini
C:\WINDOWS\system32\poruiodi.dll
C:\WINDOWS\system32\pouniakm.dll
C:\WINDOWS\system32\pqfbqrmj.dll
C:\WINDOWS\system32\pqgugoyo.ini
C:\WINDOWS\system32\prkcqbnr.dll
C:\WINDOWS\system32\ps.exe
C:\WINDOWS\system32\pstusrso.dll
C:\WINDOWS\system32\psxtcfmd.ini
C:\WINDOWS\system32\pudiapxa.dll
C:\WINDOWS\system32\pvhvrlyl.dll
C:\WINDOWS\system32\pvvghcoe.ini
C:\WINDOWS\system32\pyqoqhyi.ini
C:\WINDOWS\system32\qckodcvi.dll
C:\WINDOWS\system32\qdklptod.dll
C:\WINDOWS\system32\qdsyauug.dll
C:\WINDOWS\system32\qfkcuvjt.dll
C:\WINDOWS\system32\qhcekdhy.dll
C:\WINDOWS\system32\qiwftwqf.ini
C:\WINDOWS\system32\qngauyte.dll
C:\WINDOWS\system32\qnolvqmb.dll
C:\WINDOWS\system32\qobicijd.dll
C:\WINDOWS\system32\qpwjajxw.dll
C:\WINDOWS\system32\qqvwuugp.dll
C:\WINDOWS\system32\qtgiuvem.ini
C:\WINDOWS\system32\quqeyyjy.dll
C:\WINDOWS\system32\qvufxerb.ini
C:\WINDOWS\system32\qwokwdpo.dll
C:\WINDOWS\system32\qxuwemds.ini
C:\WINDOWS\system32\racle~1
C:\WINDOWS\system32\rartcydj.dll
C:\WINDOWS\system32\rdqcxvju.ini
C:\WINDOWS\system32\riobjyep.ini
C:\WINDOWS\system32\ripgdflj.ini
C:\WINDOWS\system32\ritwjijf.ini
C:\WINDOWS\system32\rjpcpstx.ini
C:\WINDOWS\system32\rkqedtdl.ini
C:\WINDOWS\system32\rlelihyu.dll
C:\WINDOWS\system32\rmdxfdlp.ini
C:\WINDOWS\system32\rmftgtpt.dll
C:\WINDOWS\system32\rmjkqxyt.dll
C:\WINDOWS\system32\rmwdvefc.dll
C:\WINDOWS\system32\rntxgrls.dll
C:\WINDOWS\system32\rpctfpfv.ini
C:\WINDOWS\system32\rpmbqwhc.ini
C:\WINDOWS\system32\rqnivxvt.dll
C:\WINDOWS\system32\rsiwjsfr.ini
C:\WINDOWS\system32\rsnuloub.dll
C:\WINDOWS\system32\rtxhnaue.dll
C:\WINDOWS\system32\ruybbluf.dll
C:\WINDOWS\system32\rwliairh.ini
C:\WINDOWS\system32\rxqxdkmw.dll
C:\WINDOWS\system32\ryojqrof.dll
C:\WINDOWS\system32\saiptvwd.dll
C:\WINDOWS\system32\sasijvif.dll
C:\WINDOWS\system32\sdjmoavk.dll
C:\WINDOWS\system32\sdmewuxq.dll
C:\WINDOWS\system32\sfvdptuf.dll
C:\WINDOWS\system32\sgjtwcky.dll
C:\WINDOWS\system32\shrierxu.ini
C:\WINDOWS\system32\shsftxqx.dll
C:\WINDOWS\system32\sjgujrrh.dll
C:\WINDOWS\system32\slimqdoo.ini
C:\WINDOWS\system32\slrgxtnr.ini
C:\WINDOWS\system32\sqtvtxio.dll
C:\WINDOWS\system32\srllinlj.dll
C:\WINDOWS\system32\ssqpo.dll
C:\WINDOWS\system32\stidiveq.dll
C:\WINDOWS\system32\stsvvplo.ini
C:\WINDOWS\system32\stwuponv.dll
C:\WINDOWS\system32\subankwx.dll
C:\WINDOWS\system32\suhwalit.ini
C:\WINDOWS\system32\suxtkhnl.dll
C:\WINDOWS\system32\svxajvia.dll
C:\WINDOWS\system32\sxbgvpec.dll
C:\WINDOWS\system32\taehlean.ini
C:\WINDOWS\system32\tandwnsy.dll
C:\WINDOWS\system32\tbvejojp.dll
C:\WINDOWS\system32\texrcahj.dll
C:\WINDOWS\system32\tkmvhcrk.ini
C:\WINDOWS\system32\tlcsnbdf.dll
C:\WINDOWS\system32\tlrnckxv.dll
C:\WINDOWS\system32\tmskwbbj.dll
C:\WINDOWS\system32\toblukqh.dll
C:\WINDOWS\system32\tonyddfa.dll
C:\WINDOWS\system32\tosbaxbv.dll
C:\WINDOWS\system32\tosmmvpo.dll
C:\WINDOWS\system32\tpacenwf.dll
C:\WINDOWS\system32\tptgtfmr.ini
C:\WINDOWS\system32\ttrrypgg.dll
C:\WINDOWS\system32\tvmdspwu.dll
C:\WINDOWS\system32\tvvwa.bak1
C:\WINDOWS\system32\tvvwa.bak2
C:\WINDOWS\system32\tvvwa.ini
C:\WINDOWS\system32\tvvwa.ini2
C:\WINDOWS\system32\tvvwa.tmp
C:\WINDOWS\system32\tvxvinqr.ini
C:\WINDOWS\system32\tvyfeojo.ini
C:\WINDOWS\system32\tyjskpon.ini
C:\WINDOWS\system32\tyxqkjmr.ini
C:\WINDOWS\system32\uaricmqj.dll
C:\WINDOWS\system32\uarilixw.dll
C:\WINDOWS\system32\ubrdgnnp.dll
C:\WINDOWS\system32\ucbpcxnj.ini
C:\WINDOWS\system32\uciusvnr.dll
C:\WINDOWS\system32\ueeeslyt.dll
C:\WINDOWS\system32\ufwmxvex.ini
C:\WINDOWS\system32\ugkdlftf.dll
C:\WINDOWS\system32\ugnfivav.ini
C:\WINDOWS\system32\uguiwrqj.dll
C:\WINDOWS\system32\uhydcmub.dll
C:\WINDOWS\system32\uipcveug.dll
C:\WINDOWS\system32\ujomhndd.ini
C:\WINDOWS\system32\ukslowxt.dll
C:\WINDOWS\system32\ulkfxaia.dll
C:\WINDOWS\system32\unounbhw.dll
C:\WINDOWS\system32\uodxvacv.dll
C:\WINDOWS\system32\upseqqwi.dll
C:\WINDOWS\system32\usdupfpi.dll
C:\WINDOWS\system32\utowoutq.dll
C:\WINDOWS\system32\ututv.bak1
C:\WINDOWS\system32\ututv.ini
C:\WINDOWS\system32\uuhscluv.ini
C:\WINDOWS\system32\uvnlldpb.dll
C:\WINDOWS\system32\uvproipp.dll
C:\WINDOWS\system32\uvvgiueu.dll
C:\WINDOWS\system32\uxebgkfw.ini
C:\WINDOWS\system32\uxeepeas.dll
C:\WINDOWS\system32\uxreirhs.dll
C:\WINDOWS\system32\uyqswbye.dll
C:\WINDOWS\system32\vaukbtoe.ini
C:\WINDOWS\system32\vavifngu.dll
C:\WINDOWS\system32\vbxabsot.ini
C:\WINDOWS\system32\vcbtybgp.dll
C:\WINDOWS\system32\vcnexaxx.dll
C:\WINDOWS\system32\vdkjtlwh.dll
C:\WINDOWS\system32\vdwxkguc.dll
C:\WINDOWS\system32\vdxgqtxj.ini
C:\WINDOWS\system32\vfpftcpr.dll
C:\WINDOWS\system32\vhmcgixj.dll
C:\WINDOWS\system32\vhoynhnd.ini
C:\WINDOWS\system32\vituxvve.ini
C:\WINDOWS\system32\vkpcqmdd.dll
C:\WINDOWS\system32\vkubdivm.dll
C:\WINDOWS\system32\vlfnlyri.dll
C:\WINDOWS\system32\vmhvasrm.ini
C:\WINDOWS\system32\vmskpekw.ini
C:\WINDOWS\system32\vnopuwts.ini
C:\WINDOWS\system32\vonlrgjc.ini
C:\WINDOWS\system32\vqtlthwf.ini
C:\WINDOWS\system32\vtttmkyl.ini
C:\WINDOWS\system32\vtutu.dll
C:\WINDOWS\system32\vtycijqh.dll
C:\WINDOWS\system32\vulcshuu.dll
C:\WINDOWS\system32\vutnudpt.dll
C:\WINDOWS\system32\vvadhdal.ini
C:\WINDOWS\system32\vvbkkdgc.dll
C:\WINDOWS\system32\vvwjgpsw.ini
C:\WINDOWS\system32\vxcjwtph.dll
C:\WINDOWS\system32\vyadd.bak1
C:\WINDOWS\system32\vyadd.ini
C:\WINDOWS\system32\vycdd.bak1
C:\WINDOWS\system32\vycdd.ini
C:\WINDOWS\system32\vynmmiyk.dll
C:\WINDOWS\system32\wbetycva.dll
C:\WINDOWS\system32\wbxvwhga.ini
C:\WINDOWS\system32\wetesxjg.ini
C:\WINDOWS\system32\wfkgbexu.dll
C:\WINDOWS\system32\wfxpmxod.ini
C:\WINDOWS\system32\wgbxyhfr.dll
C:\WINDOWS\system32\whyxlxiu.dll
C:\WINDOWS\system32\wifyxuph.ini
C:\WINDOWS\system32\winnb58.dll
C:\WINDOWS\system32\wkepksmv.dll
C:\WINDOWS\system32\wkqkasfe.dll
C:\WINDOWS\system32\wltsgano.ini
C:\WINDOWS\system32\wmfijuje.dll
C:\WINDOWS\system32\wmhlidhc.ini
C:\WINDOWS\system32\wmlccxcr.ini
C:\WINDOWS\system32\wmwifout.dll
C:\WINDOWS\system32\wpvlyvdt.dll
C:\WINDOWS\system32\wtgpkxwk.ini
C:\WINDOWS\system32\wtusldji.ini
C:\WINDOWS\system32\wtyoudaf.ini
C:\WINDOWS\system32\wvebuxty.ini
C:\WINDOWS\system32\wvwssbcl.ini
C:\WINDOWS\system32\wwaqghcb.dll
C:\WINDOWS\system32\wxgtkfnt.ini
C:\WINDOWS\system32\wxknpcsi.dll
C:\WINDOWS\system32\xcrqcfwc.ini
C:\WINDOWS\system32\xdefdukc.dll
C:\WINDOWS\system32\xdgctkvj.dll
C:\WINDOWS\system32\xdnympbn.dll
C:\WINDOWS\system32\xfvypfeu.dll
C:\WINDOWS\system32\xjfbijif.dll
C:\WINDOWS\system32\xkamafxl.dll
C:\WINDOWS\system32\xkkrsjsa.dll
C:\WINDOWS\system32\xlguduvx.dll
C:\WINDOWS\system32\xlqmxkqo.ini
C:\WINDOWS\system32\xofslaum.dll
C:\WINDOWS\system32\xowwgpve.dll
C:\WINDOWS\system32\xpftfmfd.dll
C:\WINDOWS\system32\xqqbntyh.dll
C:\WINDOWS\system32\xqxtfshs.ini
C:\WINDOWS\system32\xrdrhujq.dll
C:\WINDOWS\system32\xtdbrqxl.dll
C:\WINDOWS\system32\xtsjterj.ini
C:\WINDOWS\system32\xtspcpjr.dll
C:\WINDOWS\system32\xvuduglx.ini
C:\WINDOWS\system32\xxaxencv.ini
C:\WINDOWS\system32\xxnncrbn.dll
C:\WINDOWS\system32\xyvfqjmj.dll
C:\WINDOWS\system32\yapkhqds.ini
C:\WINDOWS\system32\yarfaqtu.dll
C:\WINDOWS\system32\ybsthwaa.ini
C:\WINDOWS\system32\ycbeg.ini
C:\WINDOWS\system32\ycbeg.ini2
C:\WINDOWS\system32\ycnwxkfe.ini
C:\WINDOWS\system32\ydjtdiwo.ini
C:\WINDOWS\system32\ydlvhvvl.ini
C:\WINDOWS\system32\yjwoylpw.ini
C:\WINDOWS\system32\ykcwtjgs.ini
C:\WINDOWS\system32\yrrpbqwe.dll
C:\WINDOWS\system32\ysgjqsto.dll
C:\WINDOWS\system32\ytekkgmp.dll
C:\WINDOWS\system32\yvsfcpto.dll
C:\WINDOWS\system32\yxepkanb.dll
C:\WINDOWS\system32\yxnhsodq.dll
C:\WINDOWS\system32\yxpicinh.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CORE
-------\Legacy_NETWORK_MONITOR
-------\Service_core
-------\Service_Network Monitor
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.
2008-06-19 12:28 . 2008-06-19 12:28 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-19 02:17 . 2008-06-20 00:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-06-18 02:09 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
2008-06-18 02:08 . 2008-06-18 02:09 <DIR> d-------- C:\Program Files\Syncrosoft
2008-06-18 02:08 . 2005-02-01 04:34 700,416 --a------ C:\WINDOWS\system32\SYNSOACC.dll
2008-06-18 02:08 . 2004-05-11 00:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
2008-06-18 02:08 . 2003-08-01 05:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
2008-06-18 02:08 . 2003-05-27 00:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
2008-06-18 02:08 . 2003-05-27 00:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
2008-06-18 02:08 . 2002-11-25 17:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
2008-06-18 02:08 . 2001-04-09 14:03 17,784 --a------ C:\WINDOWS\system32\drivers\NSynas32.sys
2008-06-18 02:08 . 2002-11-25 14:46 16,896 --a------ C:\WINDOWS\system32\drivers\synasUSB.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-19 09:14 --------- d-----w C:\Program Files\QuickTime
2008-06-19 09:13 --------- d-----w C:\Program Files\music_now
2008-06-19 09:10 --------- d-----w C:\Program Files\iTunes
2008-06-19 09:06 --------- d-----w C:\Program Files\HP DigitalMedia Archive
2008-06-19 08:55 --------- d-----w C:\Program Files\America Online 9.0
2008-06-19 06:23 --------- d-----w C:\Program Files\DISC
2008-06-19 06:23 --------- d-----w C:\Program Files\BellSouthWCC
2008-06-18 06:10 --------- d-----w C:\Program Files\VstPlugins
2008-06-18 04:02 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\LimeWire
2008-06-17 22:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-07-09 19:56 167 ----a-w C:\Documents and Settings\HP_Administrator\6297.bat
2007-07-09 19:53 167 ----a-w C:\Documents and Settings\HP_Administrator\6455.bat
2007-07-09 14:24 167 ----a-w C:\Documents and Settings\HP_Administrator\4331.bat
2007-07-08 00:42 167 ----a-w C:\Documents and Settings\HP_Administrator\5767.bat
2007-07-08 00:32 167 ----a-w C:\Documents and Settings\HP_Administrator\8172.bat
2007-07-07 21:25 167 ----a-w C:\Documents and Settings\HP_Administrator\2742.bat
2007-07-06 00:33 167 ----a-w C:\Documents and Settings\HP_Administrator\4312.bat
2007-06-18 00:46 167 ----a-w C:\Documents and Settings\HP_Administrator\5382.bat
2007-06-17 19:06 167 ----a-w C:\Documents and Settings\HP_Administrator\9774.bat
2007-06-17 18:29 167 ----a-w C:\Documents and Settings\HP_Administrator\3440.bat
2007-06-17 18:02 167 ----a-w C:\Documents and Settings\HP_Administrator\1000.bat
2007-06-16 14:52 167 ----a-w C:\Documents and Settings\HP_Administrator\9223.bat
2007-06-16 04:02 167 ----a-w C:\Documents and Settings\HP_Administrator\5619.bat
2007-06-15 16:08 167 ----a-w C:\Documents and Settings\HP_Administrator\7207.bat
2007-06-15 06:48 167 ----a-w C:\Documents and Settings\HP_Administrator\9112.bat
2007-06-15 05:58 167 ----a-w C:\Documents and Settings\HP_Administrator\9963.bat
2007-06-15 04:19 167 ----a-w C:\Documents and Settings\HP_Administrator\9566.bat
2007-06-15 01:41 167 ----a-w C:\Documents and Settings\HP_Administrator\6408.bat
2007-06-14 18:51 167 ----a-w C:\Documents and Settings\HP_Administrator\2314.bat
2007-06-13 17:43 167 ----a-w C:\Documents and Settings\HP_Administrator\3116.bat
2007-06-11 20:04 167 ----a-w C:\Documents and Settings\HP_Administrator\5853.bat
2007-06-11 19:12 167 ----a-w C:\Documents and Settings\HP_Administrator\2670.bat
2007-06-10 19:58 167 ----a-w C:\Documents and Settings\HP_Administrator\9174.bat
2007-06-10 07:44 167 ----a-w C:\Documents and Settings\HP_Administrator\3197.bat
2007-06-10 03:59 167 ----a-w C:\Documents and Settings\HP_Administrator\8785.bat
2007-02-26 17:53 67,048 ----a-w C:\Program Files\INSTALL.LOG
.
<pre>
----a-w 50,776 2008-06-19 01:09:15 C:\Program Files\America Online 9.0\AOL .EXE
----a-w 1,896,448 2008-06-18 00:56:54 C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager .exe
----a-w 884,736 2008-01-31 21:52:09 C:\Program Files\BellSouth\HelpCenter\ssGet .exe
----a-w 543,232 2008-06-18 00:56:49 C:\Program Files\BellSouthWCC\McciTrayApp .exe
----a-w 50,736 2008-06-18 00:57:04 C:\Program Files\Common Files\AOL\1164764026\EE\aolsoftware .exe
----a-w 71,216 2008-06-18 00:56:38 C:\Program Files\Common Files\AOL\ACS\AOLDial .exe
----a-w 81,920 2008-06-18 00:57:10 C:\Program Files\Common Files\InstallShield\UpdateService\issch .exe
----a-w 221,184 2008-06-18 00:59:39 C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM .exe
----a-w 180,269 2008-06-19 01:00:12 C:\Program Files\Common Files\Real\Update_OB\realsched .exe
----a-w 1,077,248 2008-06-18 00:56:29 C:\Program Files\DISC\DISCover .exe
----a-w 61,440 2008-06-18 00:56:31 C:\Program Files\DISC\DiscUpdMgr .exe
----a-w 68,856 2008-02-17 02:55:24 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
----a-w 49,152 2008-06-18 00:56:27 C:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08 .exe
----a-w 49,152 2008-06-18 00:56:37 C:\Program Files\HP\HP Software Update\HPwuSchd2 .exe
----a-w 90,112 2008-06-18 00:56:33 C:\Program Files\HP DigitalMedia Archive\DMAScheduler .exe
----a-w 267,048 2008-06-18 00:57:05 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 1,694,208 2008-01-27 06:02:31 C:\Program Files\Messenger\msmsgs .exe
----a-w 1,277,952 2008-06-18 00:56:54 C:\Program Files\Support.com\BellSouth\hcenter .exe
----a-w 3,461,120 2008-06-17 22:17:31 C:\Program Files\Veoh Networks\Veoh\VeohClient .exe
----a-w 64,512 2008-06-17 22:06:05 C:\WINDOWS\ehome\ehtray .exe
----a-w 237,568 2008-06-18 00:56:35 C:\WINDOWS\SMINST\RECGUARD .EXE
----a-w 15,360 2008-01-24 20:49:10 C:\WINDOWS\system32\ctfmon .exe
----a-w 419,328 2008-06-18 22:22:17 C:\WINDOWS\system32\service .exe
----a-w 419,328 2008-06-18 06:08:42 C:\WINDOWS\system32\service .exe
----a-w 419,328 2008-01-24 21:26:47 C:\WINDOWS\system32\service .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6B93B362-B100-4DAF-B5BF-EDE30DB5BCF3}]
C:\WINDOWS\system32\awvvt.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7260504-9D09-4E36-BD74-8ED3FFF888E2}]
C:\DOCUME~1\Guest\LOCALS~1\Temp\jkkll.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]
2008-06-20 00:12 145984 --------- C:\WINDOWS\system32\mpxzkrai.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c1184104-f2c4-46de-b62c-8ffc7610a25d}]
C:\WINDOWS\system32\uvmkdkob.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{11A69AE4-FBED-4832-A2BF-45AF82825583}"= "C:\WINDOWS\system32\mpxzkrai.dll" [2008-06-20 00:12 145984]
[HKEY_CLASSES_ROOT\clsid\{11a69ae4-fbed-4832-a2bf-45af82825583}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 00:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [ ]
"AOL Fast Start"="C:\Program Files\America Online 9.0\AOL.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 23:56 64512]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 07:54 16010240 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 02:19 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-24 22:15 7311360]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [ ]
"DISCover"="C:\Program Files\DISC\DISCover.exe" [ ]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [ ]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"BellSouthAlertManager.exe"="C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe" [ ]
"tgcmd"="C:\Program Files\Support.com\BellSouth\hcenter.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]
C:\Documents and Settings\Guest\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2008-01-10 14:08:24 147456]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 21:40:44 282624]
Updates From HP.lnk - C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe [2006-05-25 18:02:07 36903]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvvt]
C:\WINDOWS\system32\awvvt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjihgh]
ljjihgh.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mpxzkrai]
mpxzkrai.dll 2008-06-20 00:12 145984 C:\WINDOWS\system32\mpxzkrai.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\DISC\\DiscStreamHub.exe"=
"C:\\Program Files\\DISC\\myFTP.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\WINDOWS\system32\akxlabtg.exe"= C:\WINDOWS\system32\akx
"C:\\Program Files\\HP Rhapsody\\rhapsody.exe"=
"C:\WINDOWS\system32\qofiplxv.exe"= C:\WINDOWS\system32\qof
"C:\WINDOWS\system32\kmhmlbln.exe"= C:\WINDOWS\system32\kmh
"C:\WINDOWS\system32\sttodput.exe"= C:\WINDOWS\system32\stt
"C:\WINDOWS\system32\gswsqpoo.exe"= C:\WINDOWS\system32\gsw
"C:\WINDOWS\system32\csiaeejv.exe"= C:\WINDOWS\system32\csi
"C:\WINDOWS\system32\tyhfepva.exe"= C:\WINDOWS\system32\tyh
"C:\WINDOWS\system32\wabbsdej.exe"= C:\WINDOWS\system32\wab
"C:\WINDOWS\system32\ycyrwjkn.exe"= C:\WINDOWS\system32\ycy
"C:\WINDOWS\system32\icwlklvp.exe"= C:\WINDOWS\system32\icw
"C:\WINDOWS\system32\osbhadml.exe"= C:\WINDOWS\system32\osb
"C:\WINDOWS\system32\htvjxdqh.exe"= C:\WINDOWS\system32\htv
"C:\WINDOWS\system32\pyiwsoma.exe"= C:\WINDOWS\system32\pyi
"C:\WINDOWS\system32\ixymdljx.exe"= C:\WINDOWS\system32\ixy
"C:\WINDOWS\system32\wvacbikw.exe"= C:\WINDOWS\system32\wva
"C:\WINDOWS\system32\ljfgdscq.exe"= C:\WINDOWS\system32\ljf
"C:\WINDOWS\system32\qaeuspms.exe"= C:\WINDOWS\system32\qae
"C:\WINDOWS\system32\ubgowaby.exe"= C:\WINDOWS\system32\ubg
"C:\WINDOWS\system32\mqpsdceu.exe"= C:\WINDOWS\system32\mqp
"C:\WINDOWS\system32\wdueiqky.exe"= C:\WINDOWS\system32\wdu
"C:\WINDOWS\system32\cdjtrhmd.exe"= C:\WINDOWS\system32\cdj
"C:\WINDOWS\system32\cfpmikhh.exe"= C:\WINDOWS\system32\cfp
"C:\WINDOWS\system32\aysmskui.exe"= C:\WINDOWS\system32\ays
"C:\WINDOWS\system32\hrwffhmc.exe"= C:\WINDOWS\system32\hrw
"C:\WINDOWS\system32\pxaensqp.exe"= C:\WINDOWS\system32\pxa
"C:\WINDOWS\system32\ycjdydad.exe"= C:\WINDOWS\system32\ycj
"C:\WINDOWS\system32\kayibnpr.exe"= C:\WINDOWS\system32\kay
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\WINDOWS\system32\vffmagei.exe"= C:\WINDOWS\system32\vff
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\WINDOWS\system32\smfnwrol.exe"= C:\WINDOWS\system32\smf
"C:\WINDOWS\system32\sruardit.exe"= C:\WINDOWS\system32\sru
"C:\WINDOWS\system32\wgtbvmcq.exe"= C:\WINDOWS\system32\wgt
"C:\WINDOWS\system32\cudkcaws.exe"= C:\WINDOWS\system32\cud
"C:\WINDOWS\system32\ydhcxmcy.exe"= C:\WINDOWS\system32\ydh
"C:\WINDOWS\system32\xourrsgl.exe"= C:\WINDOWS\system32\xou
R0 OCDE;ZTekWare Original CD Emulator Service;C:\WINDOWS\system32\Drivers\OCDE.sys [2004-08-09 22:34]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
S3 ASPI;Advanced SCSI Programming Interface Driver;C:\WINDOWS\System32\DRIVERS\ASPI32.sys [2002-07-17 09:05]
S3 GetDataMip;GetDataMip;C:\Program Files\GetData\Mount Image Pro v2\mip32.sys [2007-10-30 15:21]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-03-10 18:54:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-20 00:46:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\mpxzkrai.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Completion time: 2008-06-20 0:50:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-20 04:50:25
Pre-Run: 192,397,377,536 bytes free
Post-Run: 199,073,562,624 bytes free
1215 --- E O F --- 2007-12-22 08:01:40
there's the rest