Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Desktop Hijack,,Can you Help Me?[RESOLVED]


  • This topic is locked This topic is locked

#1
FrankSweetMusic

FrankSweetMusic

    Member

  • Member
  • PipPip
  • 15 posts
Hiiiiiii

I have had my desktop background taken over with a black webpage warning me that I have been infected with spyware. This has also disabled adaware, spybot,,and wont let me download mcafee from my aol account,,, also, this black warning screen pops up when i am on internet explorer, and my internet homepage has been taken over by w-find.com. When on a website, it will also take me to that site if I click on the word "home" and other keywords.

Here is my hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 7:07:14 PM, on 5/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cmdtel.exe
C:\WINDOWS\system32\ahtun.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\lxamsp32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\system32\aaardsvr.exe
C:\WINDOWS\system32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.EXE
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe
C:\WINDOWS\system32\xco500.exe
C:\windows\jkhtstk.exe
C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
C:\Program Files\LexmarkX63\ACMonitor_X63.exe
C:\Program Files\America Online 9.0f\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110254~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110254~1\EE\AOLServiceHost.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\America Online 9.0f\shellmon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Aaron's\LOCALS~1\Temp\Temporary Directory 5 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ipassist.biz/index.php?id=11258
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topfivese.../sidesearch.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {D6CA5D91-5EA2-4654-9B75-499267012611} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D0A283367DD5} - c:\Program Files\Fln\fln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: (no name) - {D053DA56-78BE-44AA-8E83-A47036CF2AFF} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O3 - Toolbar: (no name) - {952EC978-4920-4F18-8237-91D69B54C580} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102544756\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [CaseyVideo[1]] c:\windows\CaseyVideo[1].scr
O4 - HKCU\..\Run: [AOLCC] "C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [xqjpvhb] c:\windows\bwttlws.exe
O4 - HKCU\..\Run: [uggmsyu] c:\windows\bwttlws.exe
O4 - HKCU\..\Run: [xevfkdb] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [pboolev] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [itoaojr] c:\windows\xaknmbj.exe
O4 - HKCU\..\Run: [bjsheou] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [ebxhcok] c:\windows\cxocxdj.exe
O4 - HKCU\..\Run: [wbeajwd] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [oxmcues] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lnjbqhj] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [hpovkhn] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [e0oERXM4Q] xco500.exe
O4 - HKCU\..\Run: [nptkvtm] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vksdpqs] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vfwlpnp] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [ortngtu] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lovsita] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [mpltsvq] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [sufovge] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [anmqdny] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [tjwajbh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hvoqbdj] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [mchdgwl] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [aouiyrn] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [gpjybng] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qtaypdy] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [pqyhiuh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cpnshmr] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [rfscrlo] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hifiary] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [agaaiax] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qlrupis] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [jftapla] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cyaemdr] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [qsaahyt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [tuhpnef] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [mvmlspt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [awdefnj] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [acluehv] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [xllvxwk] c:\windows\ahnxnba.exe
O4 - HKCU\..\Run: [ixbaoot] c:\windows\ahnxnba.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O4 - HKCU\..\Run: [aobirvp] c:\windows\gahpnle.exe
O4 - HKCU\..\Run: [ywfkdjb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ndqpntr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tesmmyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ocqgpuh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mcgohkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qpwdqno] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fndgblr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rnriyye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [djsogub] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [awbwcoq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kbknxor] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [duvuobb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tekjdpm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pttjuhg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hhmtweq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvfyuli] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mlmqpaf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mwxthuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [shpijni] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lxmofdi] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xpmiexd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vqmmprr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rofxtkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nrrfpow] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [klvwijm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fhbmwaw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iyiekve] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ovbtjrc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ccnusyn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pqrrggq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [inpuyft] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ijlvltw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [evwbhfg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vfomdhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [brtjobk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mhdhsmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [chfnpfb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pyqfigc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [owhmxbv] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [npqldqb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdkmvsj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sngmllg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bthipyf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jifwujd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pevwfbm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvyrsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xayddqt] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bjnljvr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [acwywyd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tedlqye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wfnlhvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lmpbxjr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fsppmte] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lgsarnk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwqvefj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xfgwoga] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rpnuyyg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kvvqwvd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [knhclhs] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [arubgrj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gegcbns] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdngsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cgkupik] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gwxsdvu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hpfwfny] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sfkppvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [syorbjn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mgcwsqn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xvheajk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [eijwtdj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiqegap] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dsooeto] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [finofmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jshdqhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jkoqbmy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [httjgqj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gewfbhu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [loroawy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hbxcunq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wgfvrho] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oyusijf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nvlfcer] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fjskoky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ajbbjhq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ctycndb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ulkfxuc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vbavgsf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [voutmtr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kaashuk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ywfgkcf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iypltkj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fncfqhx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bkefhop] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmwamqf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmvolru] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jbhgeuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oawmofn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bbmsjky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gbdgway] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pcdyhok] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rysmthn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qaxlurw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [uhqomyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [anmbgcn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rqulewb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiondyk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tyfgggp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ygefmda] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ilrjatg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [njvflxw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwtakmj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gdhqylq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [huxnpbu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oudubie] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [budahkx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [erhmebl] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ebuupkp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [friigag] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dltgmoh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ullgmvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rlbfbth] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [yemvmsy] c:\windows\cefbvyn.exe
O4 - HKCU\..\Run: [msgrrrb] c:\windows\cefbvyn.exe
O4 - HKCU\..\Run: [qywkvvg] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cwdktit] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cdoddct] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [bporhaq] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [srvdffh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [lrrjspb] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [arvgbea] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [ojvcpdh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tancuiu] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [inubkik] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tcyglhc] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [thmfxiv] c:\windows\qynxost.exe
O4 - HKCU\..\Run: [qpgeaih] c:\windows\dsbuejg.exe
O4 - HKCU\..\Run: [laaumlo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dtjiwmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [flerdma] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yqekbuk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aqbfvyi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmddqap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gtijpbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sdacdxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [scokvww] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [syjqfvy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [srjhwkj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bnkvkpn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayqpjy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vcdlhhy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lpiphbi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vkfjnmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [esevwpc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynqpbey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [akqksvr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cqcvjwk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fygbfsq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwhnmxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckuccdf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xkajyqj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iwgyaqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eibajnw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rgcyhni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dayhxxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yvwhygl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wvlapfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gwgolxu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wytpnlk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nobecys] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eaywksm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tncahmn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kxqrwcj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vysswcv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txywkyl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gmirxld] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [slxieco] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybmkpjq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lfepves] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oeemofp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fdtluwo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rxijlft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ivokvqb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vdxhede] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmulrym] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oqfcrnj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aiwvnxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rsykapt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuvqgxv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eivpupq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rhmbhle] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dlcctuw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hfpsslh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ewlewct] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltvjuru] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [clmupwf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tlkfkbd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sbflpah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kvlokbn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltdvnrf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kbqssfa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [migdnne] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtfkfto] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [deurksb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyvslfv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txcidcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxnafwb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mankihy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cwbryaf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtjyifi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fnoiret] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jjidoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qsqqhkh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jeshflp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mvhqcbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isynbry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxyqmsh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udffrkn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayvlmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ueofhqd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uiderxk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyfuhog] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [axvapee] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idicrgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txmlikh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilwtoik] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [efxvdan] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sjfyuak] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uxoehcw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arfwiup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gfqyuop] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [farwjrr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tuqrefy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jxhhoyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fxloppo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rjhnojc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jaillja] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lugcwjt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttqpbhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wxjtgft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ialppls] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txwtrhh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuxldvd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgwaald] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ljokllw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jajmeli] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pmfgwvu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vywqmjv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckulcou] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dvxtrdx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [snfhgwx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vqjnoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bilijch] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ydmqwah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mdfnjoq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qwwjlbm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [weqyvfb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wjjjvfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [coqbuny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yyhgxxm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eodedfp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jacpiae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkxjtip] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kciwopg] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nwvwycy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jfveydb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [shaachl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udlhtni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybrtmvc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oulbkhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bwdvspi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jqicfuo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xneoicw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgshnlw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bxnrpfs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [suswudp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgdpxgp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hrnbons] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xbbleql] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ggdwarw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dmkfqgs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pobimmw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ysxwgbj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ffjfxgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nymbxrq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [daxfwhp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kgivlfy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [afihouo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eogsnqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ciollpk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arhrffe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fgrlava] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xlqcqro] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nhbsxbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ascxdsa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynofoba] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwjuhrs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qvshoxe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isflase] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ymgvahi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ignpfwi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sexgygd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wpwyejw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tsururl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [myjxfsi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rnrcook] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pttrnfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [abwqcij] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gkyfkap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vjiyrcq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tyslvvf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lefqdje] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iuvjhkt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lbhlulu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dllixap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gumbiar] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ghtgaxt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [swsonsb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ardcsmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fqadmfh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dsicklo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [acepdkl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkfmsbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wfikavp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [crrwmtx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dshgkgl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [loawujf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttvexpb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilgvhry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [honhbfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tekntxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mirxjup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltkxgrw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pdwtuok] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oirdhcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bqjumln] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nacekdt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bmkspng] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idyegwm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xygauey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gbpemyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pkbjvmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kocjtam] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idndjyt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hafkewp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [takrlux] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aoehptq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jlsvvny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [imwxfdv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iadtesl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [otkleae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gqmevut] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ihynsiu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vlxjsmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ebpanem] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fdcuyoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [yaegfkb] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [akyasfq] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [lowovoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [jqfmihs] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vbfbnrg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ygffroc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [drlspam] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [guhnrtn] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sehayha] c:\windows\lfghasb.exe
O4 - Global Startup: AcBtnMgr_X63.exe.lnk = C:\Program Files\LexmarkX63\AcBtnMgr_X63.exe
O4 - Global Startup: ACMonitor_X63.exe.lnk = C:\Program Files\LexmarkX63\ACMonitor_X63.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\websearch\System\Temp\topr1150_script0.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Microsoft AntiSpyware helper - {642C3672-7AB2-4938-A43C-A73004A7CC80} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {642C3672-7AB2-4938-A43C-A73004A7CC80} - (no file) (HKCU)
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weat...Transporter.cab?
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.av.a...83/mcinsctl.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topcon...vex/website.ocx
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) - http://www.180search...com/180saax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.av.a...,20/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AutoComplete Service (Autocomplete) - Unknown owner - C:\PROGRA~1\SYSTEM~1\autocomp.exe (file missing)
O23 - Service: Loading Outpost Connections (KDE) - Unknown owner - C:\WINDOWS\system32\cmdtel.exe
O23 - Service: Debug oupost relations (LAGOS) - Unknown owner - C:\WINDOWS\system32\ahtun.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Thank you in advance for your help


Frank
  • 0

Advertisements


#2
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hi there! I apologize for the delay in someone replying to your thread!

Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
Once the updates are installed do the following:
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean files, click OK
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
After you have done this, please reply to this thread with a copy of the Ewido log, as well as a fresh HijackThis log taken after you have run the Ewido, and we will proceed from there! :tazz:
  • 0

#3
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
ok,,,here is my new hijack this log and the ewido logs,,,

once again,,thanx for your support in advance :tazz:

---------------------------------------------------------
ewido security suite - Connection report
---------------------------------------------------------

+ Created on: 9:01:54 PM, 5/11/2005
+ Report-Checksum: B0142A76

TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1025 0.0.0.0:0 LISTENING
TCP 0.0.0.0:7956 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11500 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11526 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11526 127.0.0.1:1064 TIME_WAIT
TCP 127.0.0.1:11526 127.0.0.1:1065 TIME_WAIT
TCP 127.0.0.1:11526 127.0.0.1:1066 TIME_WAIT
TCP 127.0.0.1:11526 127.0.0.1:1067 TIME_WAIT
TCP 127.0.0.1:11526 127.0.0.1:1068 TIME_WAIT
TCP 127.0.0.1:11527 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11528 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11529 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11530 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11531 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11532 0.0.0.0:0 LISTENING
TCP 127.0.0.1:11533 0.0.0.0:0 LISTENING
UDP 0.0.0.0:445
UDP 0.0.0.0:1045
UDP 67.86.251.228:123
UDP 67.86.251.228:1900
UDP 127.0.0.1:123
UDP 127.0.0.1:1044
UDP 127.0.0.1:1900

---------------------------------------------------------
ewido security suite - Process report
---------------------------------------------------------

+ Created on: 9:01:29 PM, 5/11/2005
+ Report-Checksum: 70647D91

0: System Process
4: System Process
392: C:\Program Files\Common Files\Dell\EUSW\Support.exe
408: \SystemRoot\System32\smss.exe
468: \??\C:\WINDOWS\system32\csrss.exe
492: \??\C:\WINDOWS\system32\winlogon.exe
528: C:\WINDOWS\Explorer.EXE
704: C:\WINDOWS\system32\services.exe
716: C:\WINDOWS\system32\lsass.exe
720: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
752: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
772: C:\Program Files\QuickTime\qttask.exe
828: C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
868: C:\WINDOWS\system32\svchost.exe
876: C:\WINDOWS\system32\lxamsp32.exe
924: C:\WINDOWS\system32\svchost.exe
972: C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
980: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
988: C:\WINDOWS\system32\key0bdhe.exe
1004: C:\WINDOWS\system32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.EXE
1020: C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe
1024: C:\WINDOWS\System32\svchost.exe
1072: C:\WINDOWS\System32\svchost.exe
1228: C:\WINDOWS\System32\svchost.exe
1380: C:\WINDOWS\system32\LEXBCES.EXE
1416: C:\WINDOWS\system32\spoolsv.exe
1424: C:\WINDOWS\system32\LEXPPS.EXE
1568: C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
1580: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
1596: C:\WINDOWS\system32\cisvc.exe
1648: C:\Program Files\ewido\security suite\ewidoctrl.exe
1656: C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
1680: C:\Program Files\ewido\security suite\ewidoguard.exe
1812: C:\WINDOWS\system32\wdfmgr.exe
1968: C:\WINDOWS\wanmpsvc.exe
2112: C:\windows\wbcxpov.exe
2144: C:\windows\wbcxpov.exe
2152: C:\windows\wbcxpov.exe
2160: C:\windows\wbcxpov.exe
2168: C:\windows\wbcxpov.exe
2812: C:\Program Files\America Online 9.0f\waol.exe
2912: C:\Program Files\ewido\security suite\SecuritySuite.exe
3436: C:\Program Files\America Online 9.0f\shellmon.exe
3792: C:\PROGRA~1\COMMON~1\AOL\110254~1\EE\AOLServiceHost.exe
3988: C:\WINDOWS\System32\wbem\wmiprvse.exe
4028: C:\PROGRA~1\COMMON~1\AOL\110254~1\EE\AOLHOS~1.EXE
---------------------------------------------------------
ewido security suite - Startup report
---------------------------------------------------------

+ Created on: 8:58:27 PM, 5/11/2005
+ Report-Checksum: C519F898

Reg\HKCU\Run ebuupkp c:\windows\wbcxpov.exe
Reg\HKCU\Run hnuxsbt c:\windows\lfghasb.exe
Reg\HKCU\Run myavvkj c:\windows\lfghasb.exe
Reg\HKCU\Run njhmfvk c:\windows\yxvkibq.exe
Reg\HKCU\Run crrwmtx c:\windows\uwlxhdu.exe
Reg\HKCU\Run pttjuhg c:\windows\wbcxpov.exe
Reg\HKCU\Run pcdyhok c:\windows\wbcxpov.exe
Reg\HKCU\Run ggrdast c:\windows\tpryaoy.exe
Reg\HKCU\Run ebpanem c:\windows\lfghasb.exe
Reg\HKCU\Run mmdhtsx c:\windows\dwdnirj.exe
Reg\HKCU\Run eitkxgk c:\windows\tpryaoy.exe
Reg\HKCU\Run fxmospp c:\windows\fguchug.exe
Reg\HKCU\Run glntfes c:\windows\yxvkibq.exe
Reg\HKCU\Run arnmjur c:\windows\tpryaoy.exe
Reg\HKCU\Run rkokkbi c:\windows\tpryaoy.exe
Reg\HKCU\Run bodurim c:\windows\tpryaoy.exe
Reg\HKCU\Run mnjmoon c:\windows\lfghasb.exe
Reg\HKCU\Run jvhphrn c:\windows\tpryaoy.exe
Reg\HKCU\Run kchkcrw c:\windows\tpryaoy.exe
Reg\HKCU\Run rypkbsn c:\windows\tpryaoy.exe
Reg\HKCU\Run ulkfxuc c:\windows\wbcxpov.exe
Reg\HKCU\Run aulqtca c:\windows\tpryaoy.exe
Reg\HKCU\Run gdhqylq c:\windows\wbcxpov.exe
Reg\HKCU\Run ckulcou c:\windows\uwlxhdu.exe
Reg\HKCU\Run gwrgqmv c:\windows\tpryaoy.exe
Reg\HKCU\Run rubbenl c:\windows\tpryaoy.exe
Reg\HKCU\Run lovsita c:\windows\lneerul.exe
Reg\HKCU\Run gwxsdvu c:\windows\wbcxpov.exe
Reg\HKCU\Run erhmebl c:\windows\wbcxpov.exe
Reg\HKCU\Run bkefhop c:\windows\wbcxpov.exe
Reg\HKCU\Run pqdbsab c:\windows\tpryaoy.exe
Reg\HKLM\Run DwlClient C:\Program Files\Common Files\Dell\EUSW\Support.exe
Reg\HKLM\Run QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
Reg\HKLM\Run TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Reg\HKLM\Run AOLDialer C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
Reg\HKLM\Run lxamsp32.exe lxamsp32.exe
Reg\HKLM\Run PrinTray C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
Reg\HKLM\Run msnappau "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
Reg\HKLM\Run mmtask "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
Reg\HKCU\Run CaseyVideo[1] c:\windows\CaseyVideo[1].scr
Reg\HKCU\Run AOLCC "C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe" /startup
Reg\HKCU\Run xqjpvhb c:\windows\bwttlws.exe
Reg\HKCU\Run uggmsyu c:\windows\bwttlws.exe
Reg\HKCU\Run xevfkdb c:\windows\ohbljes.exe
Reg\HKCU\Run pboolev c:\windows\ohbljes.exe
Reg\HKCU\Run itoaojr c:\windows\xaknmbj.exe
Reg\HKCU\Run bjsheou c:\windows\orcyntw.exe
Reg\HKCU\Run ebxhcok c:\windows\cxocxdj.exe
Reg\HKCU\Run wbeajwd c:\windows\orcyntw.exe
Reg\HKCU\Run oxmcues c:\windows\lneerul.exe
Reg\HKCU\Run lnjbqhj c:\windows\lneerul.exe
Reg\HKCU\Run hpovkhn c:\windows\lneerul.exe
Reg\HKCU\Run e0oERXM4Q wiaasf.exe
Reg\HKCU\Run nptkvtm c:\windows\lneerul.exe
Reg\HKCU\Run vksdpqs c:\windows\lneerul.exe
Reg\HKCU\Run vfwlpnp c:\windows\lneerul.exe
Reg\HKCU\Run ortngtu c:\windows\lneerul.exe
Reg\HKCU\Run mpltsvq c:\windows\lneerul.exe
Reg\HKCU\Run sufovge c:\windows\jkhtstk.exe
Reg\HKCU\Run anmqdny c:\windows\jkhtstk.exe
Reg\HKCU\Run tjwajbh c:\windows\jkhtstk.exe
Reg\HKCU\Run hvoqbdj c:\windows\jkhtstk.exe
Reg\HKCU\Run mchdgwl c:\windows\jkhtstk.exe
Reg\HKCU\Run aouiyrn c:\windows\jkhtstk.exe
Reg\HKCU\Run gpjybng c:\windows\jkhtstk.exe
Reg\HKCU\Run nssuoxk c:\windows\tbrnudj.exe
Reg\HKCU\Run pqyhiuh c:\windows\jkhtstk.exe
Reg\HKCU\Run cpnshmr c:\windows\jkhtstk.exe
Reg\HKCU\Run rfscrlo c:\windows\jkhtstk.exe
Reg\HKCU\Run hifiary c:\windows\jkhtstk.exe
Reg\HKCU\Run agaaiax c:\windows\jkhtstk.exe
Reg\HKCU\Run qlrupis c:\windows\jkhtstk.exe
Reg\HKCU\Run jftapla c:\windows\jkhtstk.exe
Reg\HKCU\Run cyaemdr c:\windows\yftucxc.exe
Reg\HKCU\Run qsaahyt c:\windows\yftucxc.exe
Reg\HKCU\Run tuhpnef c:\windows\yftucxc.exe
Reg\HKCU\Run mvmlspt c:\windows\yftucxc.exe
Reg\HKCU\Run awdefnj c:\windows\yftucxc.exe
Reg\HKCU\Run acluehv c:\windows\yftucxc.exe
Reg\HKCU\Run xllvxwk c:\windows\ahnxnba.exe
Reg\HKCU\Run ixbaoot c:\windows\ahnxnba.exe
Reg\HKCU\Run AOL Fast Start "C:\Program Files\America Online 9.0f\AOL.EXE" -b
Reg\HKCU\Run aobirvp c:\windows\gahpnle.exe
Reg\HKCU\Run ywfkdjb c:\windows\wbcxpov.exe
Reg\HKCU\Run ndqpntr c:\windows\wbcxpov.exe
Reg\HKCU\Run tesmmyb c:\windows\wbcxpov.exe
Reg\HKCU\Run ocqgpuh c:\windows\wbcxpov.exe
Reg\HKCU\Run mcgohkq c:\windows\wbcxpov.exe
Reg\HKCU\Run qpwdqno c:\windows\wbcxpov.exe
Reg\HKCU\Run fndgblr c:\windows\wbcxpov.exe
Reg\HKCU\Run rnriyye c:\windows\wbcxpov.exe
Reg\HKCU\Run djsogub c:\windows\wbcxpov.exe
Reg\HKCU\Run awbwcoq c:\windows\wbcxpov.exe
Reg\HKCU\Run kbknxor c:\windows\wbcxpov.exe
Reg\HKCU\Run duvuobb c:\windows\wbcxpov.exe
Reg\HKCU\Run tekjdpm c:\windows\wbcxpov.exe
Reg\HKCU\Run qkyvmxa c:\windows\gierelw.exe
Reg\HKCU\Run gvfyuli c:\windows\wbcxpov.exe
Reg\HKCU\Run mlmqpaf c:\windows\wbcxpov.exe
Reg\HKCU\Run mwxthuo c:\windows\wbcxpov.exe
Reg\HKCU\Run shpijni c:\windows\wbcxpov.exe
Reg\HKCU\Run lxmofdi c:\windows\wbcxpov.exe
Reg\HKCU\Run xpmiexd c:\windows\wbcxpov.exe
Reg\HKCU\Run vqmmprr c:\windows\wbcxpov.exe
Reg\HKCU\Run rofxtkq c:\windows\wbcxpov.exe
Reg\HKCU\Run nrrfpow c:\windows\wbcxpov.exe
Reg\HKCU\Run klvwijm c:\windows\wbcxpov.exe
Reg\HKCU\Run fhbmwaw c:\windows\wbcxpov.exe
Reg\HKCU\Run iyiekve c:\windows\wbcxpov.exe
Reg\HKCU\Run ovbtjrc c:\windows\wbcxpov.exe
Reg\HKCU\Run ccnusyn c:\windows\wbcxpov.exe
Reg\HKCU\Run pqrrggq c:\windows\wbcxpov.exe
Reg\HKCU\Run inpuyft c:\windows\wbcxpov.exe
Reg\HKCU\Run ijlvltw c:\windows\wbcxpov.exe
Reg\HKCU\Run evwbhfg c:\windows\wbcxpov.exe
Reg\HKCU\Run vfomdhe c:\windows\wbcxpov.exe
Reg\HKCU\Run brtjobk c:\windows\wbcxpov.exe
Reg\HKCU\Run mhdhsmx c:\windows\wbcxpov.exe
Reg\HKCU\Run chfnpfb c:\windows\wbcxpov.exe
Reg\HKCU\Run pyqfigc c:\windows\wbcxpov.exe
Reg\HKCU\Run jbmuqxu c:\windows\gtfkktw.exe
Reg\HKCU\Run npqldqb c:\windows\wbcxpov.exe
Reg\HKCU\Run sdkmvsj c:\windows\wbcxpov.exe
Reg\HKCU\Run sngmllg c:\windows\wbcxpov.exe
Reg\HKCU\Run bthipyf c:\windows\wbcxpov.exe
Reg\HKCU\Run jifwujd c:\windows\wbcxpov.exe
Reg\HKCU\Run pevwfbm c:\windows\wbcxpov.exe
Reg\HKCU\Run gvyrsmf c:\windows\wbcxpov.exe
Reg\HKCU\Run xayddqt c:\windows\wbcxpov.exe
Reg\HKCU\Run acwywyd c:\windows\wbcxpov.exe
Reg\HKCU\Run tedlqye c:\windows\wbcxpov.exe
Reg\HKCU\Run wfnlhvp c:\windows\wbcxpov.exe
Reg\HKCU\Run lmpbxjr c:\windows\wbcxpov.exe
Reg\HKCU\Run frbhtev c:\windows\lfghasb.exe
Reg\HKCU\Run lgsarnk c:\windows\wbcxpov.exe
Reg\HKCU\Run iwqvefj c:\windows\wbcxpov.exe
Reg\HKCU\Run xfgwoga c:\windows\wbcxpov.exe
Reg\HKCU\Run rpnuyyg c:\windows\wbcxpov.exe
Reg\HKCU\Run kvvqwvd c:\windows\wbcxpov.exe
Reg\HKCU\Run knhclhs c:\windows\wbcxpov.exe
Reg\HKCU\Run arubgrj c:\windows\wbcxpov.exe
Reg\HKCU\Run gegcbns c:\windows\wbcxpov.exe
Reg\HKCU\Run sdngsmf c:\windows\wbcxpov.exe
Reg\HKCU\Run cgkupik c:\windows\wbcxpov.exe
Reg\HKCU\Run hpfwfny c:\windows\wbcxpov.exe
Reg\HKCU\Run sfkppvp c:\windows\wbcxpov.exe
Reg\HKCU\Run syorbjn c:\windows\wbcxpov.exe
Reg\HKCU\Run mgcwsqn c:\windows\wbcxpov.exe
Reg\HKCU\Run xvheajk c:\windows\wbcxpov.exe
Reg\HKCU\Run eijwtdj c:\windows\wbcxpov.exe
Reg\HKCU\Run tiqegap c:\windows\wbcxpov.exe
Reg\HKCU\Run dsooeto c:\windows\wbcxpov.exe
Reg\HKCU\Run finofmx c:\windows\wbcxpov.exe
Reg\HKCU\Run jshdqhe c:\windows\wbcxpov.exe
Reg\HKCU\Run jkoqbmy c:\windows\wbcxpov.exe
Reg\HKCU\Run gewfbhu c:\windows\wbcxpov.exe
Reg\HKCU\Run loroawy c:\windows\wbcxpov.exe
Reg\HKCU\Run hbxcunq c:\windows\wbcxpov.exe
Reg\HKCU\Run wgfvrho c:\windows\wbcxpov.exe
Reg\HKCU\Run nvlfcer c:\windows\wbcxpov.exe
Reg\HKCU\Run fjskoky c:\windows\wbcxpov.exe
Reg\HKCU\Run ajbbjhq c:\windows\wbcxpov.exe
Reg\HKCU\Run ctycndb c:\windows\wbcxpov.exe
Reg\HKCU\Run vbavgsf c:\windows\wbcxpov.exe
Reg\HKCU\Run voutmtr c:\windows\wbcxpov.exe
Reg\HKCU\Run kaashuk c:\windows\wbcxpov.exe
Reg\HKCU\Run ywfgkcf c:\windows\wbcxpov.exe
Reg\HKCU\Run iypltkj c:\windows\wbcxpov.exe
Reg\HKCU\Run fncfqhx c:\windows\wbcxpov.exe
Reg\HKCU\Run cmvolru c:\windows\wbcxpov.exe
Reg\HKCU\Run jbhgeuo c:\windows\wbcxpov.exe
Reg\HKCU\Run oawmofn c:\windows\wbcxpov.exe
Reg\HKCU\Run bbmsjky c:\windows\wbcxpov.exe
Reg\HKCU\Run gbdgway c:\windows\wbcxpov.exe
Reg\HKCU\Run qaxlurw c:\windows\wbcxpov.exe
Reg\HKCU\Run uhqomyb c:\windows\wbcxpov.exe
Reg\HKCU\Run anmbgcn c:\windows\wbcxpov.exe
Reg\HKCU\Run rqulewb c:\windows\wbcxpov.exe
Reg\HKCU\Run tiondyk c:\windows\wbcxpov.exe
Reg\HKCU\Run tyfgggp c:\windows\wbcxpov.exe
Reg\HKCU\Run ygefmda c:\windows\wbcxpov.exe
Reg\HKCU\Run ilrjatg c:\windows\wbcxpov.exe
Reg\HKCU\Run njvflxw c:\windows\wbcxpov.exe
Reg\HKCU\Run huxnpbu c:\windows\wbcxpov.exe
Reg\HKCU\Run oudubie c:\windows\wbcxpov.exe
Reg\HKCU\Run budahkx c:\windows\wbcxpov.exe
Reg\HKCU\Run friigag c:\windows\wbcxpov.exe
Reg\HKCU\Run dltgmoh c:\windows\wbcxpov.exe
Reg\HKCU\Run ullgmvp c:\windows\wbcxpov.exe
Reg\HKCU\Run rlbfbth c:\windows\wbcxpov.exe
Reg\HKCU\Run yemvmsy c:\windows\cefbvyn.exe
Reg\HKCU\Run msgrrrb c:\windows\cefbvyn.exe
Reg\HKCU\Run qywkvvg c:\windows\soekfcm.exe
Reg\HKCU\Run bporhaq c:\windows\soekfcm.exe
Reg\HKCU\Run srvdffh c:\windows\soekfcm.exe
Reg\HKCU\Run lrrjspb c:\windows\soekfcm.exe
Reg\HKCU\Run arvgbea c:\windows\soekfcm.exe
Reg\HKCU\Run ojvcpdh c:\windows\soekfcm.exe
Reg\HKCU\Run tancuiu c:\windows\soekfcm.exe
Reg\HKCU\Run inubkik c:\windows\soekfcm.exe
Reg\HKCU\Run tcyglhc c:\windows\soekfcm.exe
Reg\HKCU\Run thmfxiv c:\windows\qynxost.exe
Reg\HKCU\Run qpgeaih c:\windows\dsbuejg.exe
Reg\HKCU\Run laaumlo c:\windows\uwlxhdu.exe
Reg\HKCU\Run dtjiwmj c:\windows\uwlxhdu.exe
Reg\HKCU\Run flerdma c:\windows\uwlxhdu.exe
Reg\HKCU\Run yqekbuk c:\windows\uwlxhdu.exe
Reg\HKCU\Run aqbfvyi c:\windows\uwlxhdu.exe
Reg\HKCU\Run mmddqap c:\windows\uwlxhdu.exe
Reg\HKCU\Run gtijpbc c:\windows\uwlxhdu.exe
Reg\HKCU\Run scokvww c:\windows\uwlxhdu.exe
Reg\HKCU\Run syjqfvy c:\windows\uwlxhdu.exe
Reg\HKCU\Run srjhwkj c:\windows\uwlxhdu.exe
Reg\HKCU\Run bnkvkpn c:\windows\uwlxhdu.exe
Reg\HKCU\Run qayqpjy c:\windows\uwlxhdu.exe
Reg\HKCU\Run vcdlhhy c:\windows\uwlxhdu.exe
Reg\HKCU\Run lpiphbi c:\windows\uwlxhdu.exe
Reg\HKCU\Run vkfjnmq c:\windows\uwlxhdu.exe
Reg\HKCU\Run esevwpc c:\windows\uwlxhdu.exe
Reg\HKCU\Run ynqpbey c:\windows\uwlxhdu.exe
Reg\HKCU\Run akqksvr c:\windows\uwlxhdu.exe
Reg\HKCU\Run cqcvjwk c:\windows\uwlxhdu.exe
Reg\HKCU\Run fygbfsq c:\windows\uwlxhdu.exe
Reg\HKCU\Run fwhnmxd c:\windows\uwlxhdu.exe
Reg\HKCU\Run ckuccdf c:\windows\uwlxhdu.exe
Reg\HKCU\Run xkajyqj c:\windows\uwlxhdu.exe
Reg\HKCU\Run iwgyaqf c:\windows\uwlxhdu.exe
Reg\HKCU\Run eibajnw c:\windows\uwlxhdu.exe
Reg\HKCU\Run rgcyhni c:\windows\uwlxhdu.exe
Reg\HKCU\Run dayhxxd c:\windows\uwlxhdu.exe
Reg\HKCU\Run yvwhygl c:\windows\uwlxhdu.exe
Reg\HKCU\Run wvlapfx c:\windows\uwlxhdu.exe
Reg\HKCU\Run gwgolxu c:\windows\uwlxhdu.exe
Reg\HKCU\Run wytpnlk c:\windows\uwlxhdu.exe
Reg\HKCU\Run nobecys c:\windows\uwlxhdu.exe
Reg\HKCU\Run eaywksm c:\windows\uwlxhdu.exe
Reg\HKCU\Run tncahmn c:\windows\uwlxhdu.exe
Reg\HKCU\Run kxqrwcj c:\windows\uwlxhdu.exe
Reg\HKCU\Run vysswcv c:\windows\uwlxhdu.exe
Reg\HKCU\Run txywkyl c:\windows\uwlxhdu.exe
Reg\HKCU\Run gmirxld c:\windows\uwlxhdu.exe
Reg\HKCU\Run slxieco c:\windows\uwlxhdu.exe
Reg\HKCU\Run ybmkpjq c:\windows\uwlxhdu.exe
Reg\HKCU\Run lfepves c:\windows\uwlxhdu.exe
Reg\HKCU\Run oeemofp c:\windows\uwlxhdu.exe
Reg\HKCU\Run fdtluwo c:\windows\uwlxhdu.exe
Reg\HKCU\Run rxijlft c:\windows\uwlxhdu.exe
Reg\HKCU\Run ivokvqb c:\windows\uwlxhdu.exe
Reg\HKCU\Run vdxhede c:\windows\uwlxhdu.exe
Reg\HKCU\Run mmulrym c:\windows\uwlxhdu.exe
Reg\HKCU\Run oqfcrnj c:\windows\uwlxhdu.exe
Reg\HKCU\Run aiwvnxr c:\windows\uwlxhdu.exe
Reg\HKCU\Run rsykapt c:\windows\uwlxhdu.exe
Reg\HKCU\Run vuvqgxv c:\windows\uwlxhdu.exe
Reg\HKCU\Run eivpupq c:\windows\uwlxhdu.exe
Reg\HKCU\Run rhmbhle c:\windows\uwlxhdu.exe
Reg\HKCU\Run dlcctuw c:\windows\uwlxhdu.exe
Reg\HKCU\Run hfpsslh c:\windows\uwlxhdu.exe
Reg\HKCU\Run ewlewct c:\windows\uwlxhdu.exe
Reg\HKCU\Run ltvjuru c:\windows\uwlxhdu.exe
Reg\HKCU\Run clmupwf c:\windows\uwlxhdu.exe
Reg\HKCU\Run sbflpah c:\windows\uwlxhdu.exe
Reg\HKCU\Run kvlokbn c:\windows\uwlxhdu.exe
Reg\HKCU\Run kbqssfa c:\windows\uwlxhdu.exe
Reg\HKCU\Run migdnne c:\windows\uwlxhdu.exe
Reg\HKCU\Run xtfkfto c:\windows\uwlxhdu.exe
Reg\HKCU\Run deurksb c:\windows\uwlxhdu.exe
Reg\HKCU\Run nyvslfv c:\windows\uwlxhdu.exe
Reg\HKCU\Run sxnafwb c:\windows\uwlxhdu.exe
Reg\HKCU\Run mankihy c:\windows\uwlxhdu.exe
Reg\HKCU\Run cwbryaf c:\windows\uwlxhdu.exe
Reg\HKCU\Run xtjyifi c:\windows\uwlxhdu.exe
Reg\HKCU\Run fnoiret c:\windows\uwlxhdu.exe
Reg\HKCU\Run jjidoei c:\windows\uwlxhdu.exe
Reg\HKCU\Run qsqqhkh c:\windows\uwlxhdu.exe
Reg\HKCU\Run jeshflp c:\windows\uwlxhdu.exe
Reg\HKCU\Run mvhqcbv c:\windows\uwlxhdu.exe
Reg\HKCU\Run isynbry c:\windows\uwlxhdu.exe
Reg\HKCU\Run sxyqmsh c:\windows\uwlxhdu.exe
Reg\HKCU\Run udffrkn c:\windows\uwlxhdu.exe
Reg\HKCU\Run qayvlmj c:\windows\uwlxhdu.exe
Reg\HKCU\Run ueofhqd c:\windows\uwlxhdu.exe
Reg\HKCU\Run uiderxk c:\windows\uwlxhdu.exe
Reg\HKCU\Run nyfuhog c:\windows\uwlxhdu.exe
Reg\HKCU\Run axvapee c:\windows\uwlxhdu.exe
Reg\HKCU\Run idicrgy c:\windows\uwlxhdu.exe
Reg\HKCU\Run txmlikh c:\windows\uwlxhdu.exe
Reg\HKCU\Run ilwtoik c:\windows\uwlxhdu.exe
Reg\HKCU\Run efxvdan c:\windows\uwlxhdu.exe
Reg\HKCU\Run sjfyuak c:\windows\uwlxhdu.exe
Reg\HKCU\Run uxoehcw c:\windows\uwlxhdu.exe
Reg\HKCU\Run arfwiup c:\windows\uwlxhdu.exe
Reg\HKCU\Run farwjrr c:\windows\uwlxhdu.exe
Reg\HKCU\Run tuqrefy c:\windows\uwlxhdu.exe
Reg\HKCU\Run jxhhoyd c:\windows\uwlxhdu.exe
Reg\HKCU\Run fxloppo c:\windows\uwlxhdu.exe
Reg\HKCU\Run rjhnojc c:\windows\uwlxhdu.exe
Reg\HKCU\Run jaillja c:\windows\uwlxhdu.exe
Reg\HKCU\Run lugcwjt c:\windows\uwlxhdu.exe
Reg\HKCU\Run ttqpbhv c:\windows\uwlxhdu.exe
Reg\HKCU\Run wxjtgft c:\windows\uwlxhdu.exe
Reg\HKCU\Run ialppls c:\windows\uwlxhdu.exe
Reg\HKCU\Run txwtrhh c:\windows\uwlxhdu.exe
Reg\HKCU\Run vuxldvd c:\windows\uwlxhdu.exe
Reg\HKCU\Run qgwaald c:\windows\uwlxhdu.exe
Reg\HKCU\Run ljokllw c:\windows\uwlxhdu.exe
Reg\HKCU\Run jajmeli c:\windows\uwlxhdu.exe
Reg\HKCU\Run pmfgwvu c:\windows\uwlxhdu.exe
Reg\HKCU\Run vywqmjv c:\windows\uwlxhdu.exe
Reg\HKCU\Run dvxtrdx c:\windows\uwlxhdu.exe
Reg\HKCU\Run snfhgwx c:\windows\uwlxhdu.exe
Reg\HKCU\Run vqjnoei c:\windows\uwlxhdu.exe
Reg\HKCU\Run bilijch c:\windows\uwlxhdu.exe
Reg\HKCU\Run ydmqwah c:\windows\uwlxhdu.exe
Reg\HKCU\Run mdfnjoq c:\windows\uwlxhdu.exe
Reg\HKCU\Run qwwjlbm c:\windows\uwlxhdu.exe
Reg\HKCU\Run weqyvfb c:\
  • 0

#4
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Open Ewido, and click the "Scanner" button. Highlight the C: drive with one left mouse click, then click on "Start". Let it run, it will take awhile. Each time it finds something, you will be prompted to let it clean/remove. Once the scan is done, there will be a button located on the bottom of the screen named Save report
Click Save report
Save the report to your desktop

Post a reply here with THAT Ewido log, as well as the new HJT log taken after Ewido has run!
  • 0

#5
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
hiiiiiiiiiiiii

when the scan finishes,,the programs just disappears or closes down,,if just goes POOF,,LOL..there is no button on the bottom when the scan ends or if there was,,it closes so fast i cant touch it,,,,,the save report button is on the side panel when i reopen the program,,,anything else i can do?? I also said yes to alot of clean options,,let me know

Frank
  • 0

#6
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Let's just see a new HJT log, ok? If I think there's still problems with any viruses or anything, I have a couple of other scans I could have you do if we need to! :tazz:
  • 0

#7
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
OK,,I had to run this in safe mode,,now this virus has disabled my access to my c drive,,and mostly all programs except aol....internet explorer doesnt work either

Logfile of HijackThis v1.99.1
Scan saved at 10:40:08 PM, on 5/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\Aaron's\LOCALS~1\Temp\Temporary Directory 7 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topfivese.../sidesearch.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: (no name) - {D6CA5D91-5EA2-4654-9B75-499267012611} - (no file)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D0A283367DD5} - c:\Program Files\Fln\fln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: (no name) - {D053DA56-78BE-44AA-8E83-A47036CF2AFF} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O3 - Toolbar: (no name) - {952EC978-4920-4F18-8237-91D69B54C580} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Agent WebControl] C:\WINDOWS\system32\key0bdhe.exe
O4 - HKLM\..\Run: [FlnCPY] "C:\Program Files\Common Files\Java\flncpy.exe"
O4 - HKLM\..\Run: [v37O37g] wmesd10n.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\system32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.EXE
O4 - HKCU\..\Run: [CaseyVideo[1]] c:\windows\CaseyVideo[1].scr
O4 - HKCU\..\Run: [AOLCC] "C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [xevfkdb] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [pboolev] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [itoaojr] c:\windows\xaknmbj.exe
O4 - HKCU\..\Run: [bjsheou] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [wbeajwd] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [oxmcues] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lnjbqhj] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [hpovkhn] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [e0oERXM4Q] wiaasf.exe
O4 - HKCU\..\Run: [nptkvtm] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vksdpqs] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vfwlpnp] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [ortngtu] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lovsita] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [mpltsvq] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [sufovge] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [anmqdny] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [tjwajbh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hvoqbdj] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [mchdgwl] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [aouiyrn] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [gpjybng] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qtaypdy] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [pqyhiuh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cpnshmr] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [rfscrlo] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hifiary] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [agaaiax] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qlrupis] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [jftapla] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cyaemdr] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [qsaahyt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [tuhpnef] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [mvmlspt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [awdefnj] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [acluehv] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O4 - HKCU\..\Run: [aobirvp] c:\windows\gahpnle.exe
O4 - HKCU\..\Run: [ywfkdjb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ndqpntr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tesmmyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ocqgpuh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mcgohkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qpwdqno] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fndgblr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rnriyye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [djsogub] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [awbwcoq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kbknxor] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [duvuobb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tekjdpm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pttjuhg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hhmtweq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvfyuli] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mlmqpaf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mwxthuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [shpijni] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lxmofdi] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xpmiexd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vqmmprr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rofxtkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nrrfpow] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [klvwijm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fhbmwaw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iyiekve] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ovbtjrc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ccnusyn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pqrrggq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [inpuyft] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ijlvltw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [evwbhfg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vfomdhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [brtjobk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mhdhsmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [chfnpfb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pyqfigc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [owhmxbv] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [npqldqb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdkmvsj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sngmllg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bthipyf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jifwujd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pevwfbm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvyrsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xayddqt] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bjnljvr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [acwywyd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tedlqye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wfnlhvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lmpbxjr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fsppmte] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lgsarnk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwqvefj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xfgwoga] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rpnuyyg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kvvqwvd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [knhclhs] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [arubgrj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gegcbns] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdngsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cgkupik] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gwxsdvu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hpfwfny] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sfkppvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [syorbjn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mgcwsqn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xvheajk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [eijwtdj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiqegap] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dsooeto] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [finofmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jshdqhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jkoqbmy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [httjgqj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gewfbhu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [loroawy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hbxcunq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wgfvrho] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oyusijf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nvlfcer] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fjskoky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ajbbjhq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ctycndb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ulkfxuc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vbavgsf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [voutmtr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kaashuk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ywfgkcf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iypltkj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fncfqhx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bkefhop] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmwamqf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmvolru] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jbhgeuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oawmofn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bbmsjky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gbdgway] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pcdyhok] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rysmthn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qaxlurw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [uhqomyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [anmbgcn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rqulewb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiondyk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tyfgggp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ygefmda] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ilrjatg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [njvflxw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwtakmj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gdhqylq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [huxnpbu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oudubie] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [budahkx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [erhmebl] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ebuupkp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [friigag] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dltgmoh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ullgmvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rlbfbth] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qywkvvg] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cwdktit] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cdoddct] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [bporhaq] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [srvdffh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [lrrjspb] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [arvgbea] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [ojvcpdh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tancuiu] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [inubkik] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tcyglhc] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [thmfxiv] c:\windows\qynxost.exe
O4 - HKCU\..\Run: [qpgeaih] c:\windows\dsbuejg.exe
O4 - HKCU\..\Run: [laaumlo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dtjiwmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [flerdma] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yqekbuk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aqbfvyi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmddqap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gtijpbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sdacdxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [scokvww] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [syjqfvy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [srjhwkj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bnkvkpn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayqpjy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vcdlhhy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lpiphbi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vkfjnmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [esevwpc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynqpbey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [akqksvr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cqcvjwk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fygbfsq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwhnmxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckuccdf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xkajyqj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iwgyaqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eibajnw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rgcyhni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dayhxxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yvwhygl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wvlapfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gwgolxu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wytpnlk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nobecys] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eaywksm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tncahmn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kxqrwcj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vysswcv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txywkyl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gmirxld] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [slxieco] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybmkpjq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lfepves] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oeemofp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fdtluwo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rxijlft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ivokvqb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vdxhede] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmulrym] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oqfcrnj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aiwvnxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rsykapt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuvqgxv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eivpupq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rhmbhle] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dlcctuw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hfpsslh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ewlewct] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltvjuru] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [clmupwf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tlkfkbd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sbflpah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kvlokbn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltdvnrf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kbqssfa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [migdnne] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtfkfto] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [deurksb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyvslfv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txcidcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxnafwb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mankihy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cwbryaf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtjyifi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fnoiret] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jjidoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qsqqhkh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jeshflp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mvhqcbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isynbry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxyqmsh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udffrkn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayvlmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ueofhqd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uiderxk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyfuhog] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [axvapee] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idicrgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txmlikh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilwtoik] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [efxvdan] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sjfyuak] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uxoehcw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arfwiup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gfqyuop] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [farwjrr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tuqrefy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jxhhoyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fxloppo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rjhnojc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jaillja] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lugcwjt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttqpbhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wxjtgft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ialppls] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txwtrhh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuxldvd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgwaald] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ljokllw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jajmeli] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pmfgwvu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vywqmjv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckulcou] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dvxtrdx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [snfhgwx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vqjnoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bilijch] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ydmqwah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mdfnjoq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qwwjlbm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [weqyvfb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wjjjvfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [coqbuny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yyhgxxm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eodedfp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jacpiae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkxjtip] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kciwopg] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nwvwycy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jfveydb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [shaachl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udlhtni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybrtmvc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oulbkhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bwdvspi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jqicfuo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xneoicw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgshnlw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bxnrpfs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [suswudp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgdpxgp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hrnbons] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xbbleql] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ggdwarw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dmkfqgs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pobimmw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ysxwgbj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ffjfxgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nymbxrq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [daxfwhp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kgivlfy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [afihouo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eogsnqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ciollpk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arhrffe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fgrlava] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xlqcqro] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nhbsxbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ascxdsa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynofoba] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwjuhrs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qvshoxe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isflase] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ymgvahi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ignpfwi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sexgygd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wpwyejw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tsururl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [myjxfsi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rnrcook] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pttrnfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [abwqcij] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gkyfkap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vjiyrcq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tyslvvf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lefqdje] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iuvjhkt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lbhlulu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dllixap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gumbiar] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ghtgaxt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [swsonsb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ardcsmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fqadmfh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dsicklo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [acepdkl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkfmsbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wfikavp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [crrwmtx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dshgkgl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [loawujf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttvexpb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilgvhry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [honhbfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tekntxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mirxjup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltkxgrw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pdwtuok] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oirdhcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bqjumln] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nacekdt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bmkspng] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idyegwm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xygauey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gbpemyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pkbjvmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kocjtam] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idndjyt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hafkewp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [takrlux] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aoehptq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jlsvvny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [imwxfdv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iadtesl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [otkleae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gqmevut] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ihynsiu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vlxjsmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ebpanem] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fdcuyoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [yaegfkb] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [akyasfq] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [lowovoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [jqfmihs] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vbfbnrg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ygffroc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [drlspam] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [guhnrtn] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sehayha] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [qkudtfu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hjwmeey] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hlrmimd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [onovacl] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nnsqoxv] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [frbhtev] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [pbfxcvg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vobctvd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [mnjmoon] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [xixoxmd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [myavvkj] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [yihoikc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [itivmgk] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nmspxid] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [wqlsaer] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [popggwr] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fhlyrnh] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sguaftl] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [rsdwvnc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [iwtyxvo] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [awvarpf] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fokouwy] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [kisjxrd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vccvfmp] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ulnople] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [btuvudv] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [jcaoruu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nfhioww] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [kbtmlcg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [imeyvgg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hnuxsbt] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vslptdm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [oermtrm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ivoekpm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sdwqjxx] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vualflp] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [rwhvxvu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [dvrojkx] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [npqgcxj] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [xkawvxd] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [wbekina] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [xsyvwmf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [glntfes] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [phcuxdb] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [aisrplo] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [qwckkty] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [diurnre] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [gjdnork] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [yiwrcqb] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [licppot] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [njhmfvk] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [csaxjvp] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [orppyxs] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [fpkoqfh] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [bibpinr] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [headxrf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [hlqipjr] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [rcdqaxx] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [prstfuf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [yfjpsuf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [liejiff] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [nmjspbk] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [jabbyor] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [bmnlawo] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [lvxjoav] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evqkdcp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ewbnyop] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [psdppvp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sxqghxh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ymfcukh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [wufwxst] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ijbduus] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kchkcrw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jmrukns] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fywjhlt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drqtcwo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ndenkxm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [klqpkws] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rqlsaka] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fsduppv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [axqxuqg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pciyvmg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ysuasmy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [wqicgor] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ygbabxg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bgeysxc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [akybwtb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pqglwii] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yucqhah] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [psvbfjk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fiuvalc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gwrgqmv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ddqpigl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [girhqgo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [plrbrsd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hmepbmu] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hoobuxx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [arluwnt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fwilcte] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xkjbcqa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fdexilq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ihwhojs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xcdhuss] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kjaupba] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vlckqvx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eitkxgk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ymgtioo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [buhhjla] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [luvjwfe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [htefmsq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xocmbal] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lwxofil] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sapsufp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hdjpvpw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yxaxlot] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vimtjss] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eivctjy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [apnubqv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dyyslif] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ekjlmdt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ciawdrc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mujrtre] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ibiikcn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evhgapx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vbgbjwt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gvtijjg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qgmhkdc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rubbenl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cscjhbf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pdqjjir] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qmnsnfr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xveqjri] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xvdwdvy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [onkngyg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fixtsmg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ltsydcx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bbrmvgl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ibvyyjj] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evhblmk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [novsoxq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yyndfoq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hyqsykt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cwyalcg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [glmthqq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hknkbiy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hqfglnl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [spunfia] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rseltrn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qajyoir] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rohslqc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drtcyjt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [etocooy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gjhyemt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [terofiv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [scrpboa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jvhphrn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rypkbsn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [svyuela] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [tewkyhp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pglpbmf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mypsdcj] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [axbrhis] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [enabrud] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xaldldg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xhdejlk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [inywfms] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [avloplw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jasxwnq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nleeupe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bmqbhuv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nbhxahi] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bwgxrld] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ersuxgg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ejigdhx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lawmdew] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nwishen] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dqkjtrd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rkokkbi] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [arnmjur] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [swhxnpq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kkfpccq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [skrtghs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gwfjjkc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lhgrpfa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ypyhocy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qopfjft] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [giehjwn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [haocnwg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sbhpaby] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jrlvhxs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eotohqe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xhundyf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xwfpmte] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lvhimjf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [oucdyqm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jwfijbg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fmrqqkf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hmtjpix] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nbmvgeb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bqlyjbg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vjourru] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [khverjg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vvpckvf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aulqtca] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [adbhtmd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mektgqw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ggrdast] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drvrvmd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ujlbccs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rddqmct] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nynnjyr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kswbpos] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mrxxavd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [thxyqyn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [txcqnwr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ykwnesw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [todimhm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hsufxfg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pqdbsab] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [iffmshq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xjwpwci] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [unmkyce] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ftyxftg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [olqeyom] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ycxlnuh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bodurim] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rhcotqq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qlibdoa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [uplhpap] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cqabvvt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [diysrcf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jdjkdft] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [niavqfc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ogewxxw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xdoebhb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [shlrvbv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ojbnipm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xpekoyo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ubfbygk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aiobkgo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vfqvcgn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [koqmmle] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [diehoua] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dgvobrh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aybqfyj] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ybaoamf] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [caajfqp] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qvbhsrk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gncqekd] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wcjpnsk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [fgnfigk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dxgeyju] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jtljlvq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [mmdhtsx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gegoehk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qodshlx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [boofefe] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [syebfex] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [orhlwgj] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [vjfiryc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [tpxeiiu] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [rxqrosc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [cmnumqh] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [obogbvv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jhnntsi] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [shoquvy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ixjcbkx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ygpedvs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [vsvfomq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [rnpmore] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wbknvlv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [yttqviw] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [tqfcbjq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [grugdep] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [kkaootr] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [egakllt] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ketrapu] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [uacbsul] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wdfnmif] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dfsytvv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [abaibxx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wgdjtrr] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [stdsrcs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qagyguh] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ulmtnlw] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [hiypxmv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [cgwggvy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [uqtohas] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [isnqxpd] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [glrjhfs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [xthaiep] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gysbiqt] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ntxsben] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [pxebsiy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ivgnmjc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jhtaeev] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dlpoyaa] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [bdrhxpx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ngtgwog] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [mfmsgmn] c:\windows\ftqfogm.exe
O4 - HKCU\..\Run: [nkjeafm] c:\windows\gnlmnxm.exe
O4 - HKCU\..\Run: [yrmkscp] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [phljxtg] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [kisdvjp] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [hrqndjx] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [dlaaaye] c:\windows\fdbrcvt.exe
O4 - HKCU\..\Run: [anoulsr] c:\windows\fdbrcvt.exe
O4 - HKCU\..\Run: [xfdceov] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bmxmxcc] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [psnhpvl] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [pklwjbf] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [lcqcbpn] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [htsfrff] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [etportx] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [gyjtewv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [vmdjjbx] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [osvnxqr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [afdukdv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [sjekqbw] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [qgxjxxr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [vmvrlat] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [kvsbpjr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bxruxjp] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [nccsijl] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [xweuxvk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [jypecgk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [crditiw] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [lxgxnda] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [qmguhef] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [aolyfdn] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bobgxjg] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [gvlcckd] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [nujvdlk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [ammkexa] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bomomcv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [cohkvfm] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bpqefvs] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [dsjssog] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [kwopmii] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [xkscepq] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [mhsnpjs] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [olqsyfn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jihiycj] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vpwnnhg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [xvfkeqo] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ymwbqmf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vxbprkf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [oildavn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [klipmgj] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ejedmjf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [yaoarmp] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [rmebytg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [yfcbxds] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ghxivoi] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [osprtyr] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [utrdpat] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [nnnqmwc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [etvcvyq] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [pemrdgn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ioatkij] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [pixnfdu] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jjyqdxo] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [wvkgbwe] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [dhmqptg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vqwqetp] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [rwxempf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [xynllfb] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [baityxv] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vdqwysk] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vvbmpqk] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [hcfgsmc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [uqklnmc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [tggckeu] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [eyrgtla] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [qhckkru] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ppraeqh] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [bxouice] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jrgrlrd] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [fxmospp] c:\windows\fguchug.exe
  • 0

#8
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
*Edited will post back in a bit

Edited by ~Kat~, 12 May 2005 - 09:28 PM.

  • 0

#9
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello again! First of all, I need you to create a permanent folder for HijackThis, either in your C:\ drive or your My Documents folder. Then, cut and paste your HJT program into it! Running it from the Temp directory won't allow HJT to save the backups!


Download and Save Spywadfix to your computer from this link: http://www.thespykil...s/spywadfix.exe and double click on the spywadfix.exe

It will automatically extract to c:\spywad where it needs to be to run and will automatically open the remove spywad.vbs script for you ready to paste in the line mentioned below

If it doesn't open then go to c:\spywad and double click on the remove spywad.vbs Do not run any other file from there please unless asked to

If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.

It will open an Input box. Paste this line into the box

C:\windows\jkhtstk.exe

The script will kill that process, backup and then delete any matching files in System32 and your Windows Directory. It will create a log of all files deleted. This log file will be named Spywad.txt and be located inside the C:\Spywad Folder. The backups will also be located in two subfolders there. One named Systems and the other named Window.

The script will search the Windows Directory and delete desktop.html and popup.html if they exist. It will add entries to the log if these files are found and deleted.

It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.

It will restart Explorer. Once it has, it should automatically open HijackThis. If it does not, please go to HJT and open it. I want you to place a check only next to all of the random 04 entries. They have no actual names, just appear random, such as this:
O4 - HKCU\..\Run: [vlxjsmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ebpanem] c:\windows\lfghasb.exe

At this time, do not fix anything else. We'll tackle the other stuff once we get this cleared out, ok? Make sure ALL other programs and windows are closed, other than HJT, and click the "Fix Selected" button with all those 04's checked.

Then, reboot, and reply here with a new HJT log, and a copy of the Spywad.txt log!
  • 0

#10
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
hiii kat,,,,

i put that file in there on the input box,,,but it says it doesnt exist,,i followed your instructions on the hijackthis file,,,but I had to run it in safe mode,,this is what I have:

Logfile of HijackThis v1.99.1
Scan saved at 6:47:27 PM, on 5/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.topfivese.../sidesearch.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R3 - URLSearchHook: (no name) - {D6CA5D91-5EA2-4654-9B75-499267012611} - (no file)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: FlashEnhancer Extnder - {A749B4BC-7621-4a80-9220-D0A283367DD5} - c:\Program Files\Fln\fln.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: (no name) - {D053DA56-78BE-44AA-8E83-A47036CF2AFF} - (no file)
O3 - Toolbar: (no name) - {BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} - (no file)
O3 - Toolbar: (no name) - {952EC978-4920-4F18-8237-91D69B54C580} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [lxamsp32.exe] lxamsp32.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Agent WebControl] C:\WINDOWS\system32\key0bdhe.exe
O4 - HKLM\..\Run: [FlnCPY] "C:\Program Files\Common Files\Java\flncpy.exe"
O4 - HKLM\..\Run: [v37O37g] wmesd10n.exe
O4 - HKLM\..\Run: [Service Host] C:\WINDOWS\system32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.EXE
O4 - HKCU\..\Run: [CaseyVideo[1]] c:\windows\CaseyVideo[1].scr
O4 - HKCU\..\Run: [AOLCC] "C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [xevfkdb] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [pboolev] c:\windows\ohbljes.exe
O4 - HKCU\..\Run: [itoaojr] c:\windows\xaknmbj.exe
O4 - HKCU\..\Run: [bjsheou] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [wbeajwd] c:\windows\orcyntw.exe
O4 - HKCU\..\Run: [oxmcues] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lnjbqhj] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [hpovkhn] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [e0oERXM4Q] wiaasf.exe
O4 - HKCU\..\Run: [nptkvtm] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vksdpqs] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [vfwlpnp] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [ortngtu] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [lovsita] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [mpltsvq] c:\windows\lneerul.exe
O4 - HKCU\..\Run: [sufovge] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [anmqdny] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [tjwajbh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hvoqbdj] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [mchdgwl] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [aouiyrn] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [gpjybng] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qtaypdy] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [pqyhiuh] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cpnshmr] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [rfscrlo] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [hifiary] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [agaaiax] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [qlrupis] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [jftapla] c:\windows\jkhtstk.exe
O4 - HKCU\..\Run: [cyaemdr] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [qsaahyt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [tuhpnef] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [mvmlspt] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [awdefnj] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [acluehv] c:\windows\yftucxc.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0f\AOL.EXE" -b
O4 - HKCU\..\Run: [aobirvp] c:\windows\gahpnle.exe
O4 - HKCU\..\Run: [ywfkdjb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ndqpntr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tesmmyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ocqgpuh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mcgohkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qpwdqno] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fndgblr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rnriyye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [djsogub] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [awbwcoq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kbknxor] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [duvuobb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tekjdpm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pttjuhg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hhmtweq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvfyuli] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mlmqpaf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mwxthuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [shpijni] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lxmofdi] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xpmiexd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vqmmprr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rofxtkq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nrrfpow] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [klvwijm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fhbmwaw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iyiekve] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ovbtjrc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ccnusyn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pqrrggq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [inpuyft] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ijlvltw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [evwbhfg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vfomdhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [brtjobk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mhdhsmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [chfnpfb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pyqfigc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [owhmxbv] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [npqldqb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdkmvsj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sngmllg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bthipyf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jifwujd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pevwfbm] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gvyrsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xayddqt] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bjnljvr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [acwywyd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tedlqye] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wfnlhvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lmpbxjr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fsppmte] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [lgsarnk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwqvefj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xfgwoga] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rpnuyyg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kvvqwvd] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [knhclhs] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [arubgrj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gegcbns] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sdngsmf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cgkupik] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gwxsdvu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hpfwfny] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [sfkppvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [syorbjn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [mgcwsqn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [xvheajk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [eijwtdj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiqegap] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dsooeto] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [finofmx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jshdqhe] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jkoqbmy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [httjgqj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gewfbhu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [loroawy] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [hbxcunq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [wgfvrho] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oyusijf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [nvlfcer] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fjskoky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ajbbjhq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ctycndb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ulkfxuc] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [vbavgsf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [voutmtr] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [kaashuk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ywfgkcf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iypltkj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [fncfqhx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bkefhop] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmwamqf] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [cmvolru] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [jbhgeuo] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oawmofn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [bbmsjky] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gbdgway] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [pcdyhok] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rysmthn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qaxlurw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [uhqomyb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [anmbgcn] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rqulewb] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tiondyk] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [tyfgggp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ygefmda] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ilrjatg] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [njvflxw] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [iwtakmj] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [gdhqylq] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [huxnpbu] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [oudubie] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [budahkx] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [erhmebl] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ebuupkp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [friigag] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [dltgmoh] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [ullgmvp] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [rlbfbth] c:\windows\wbcxpov.exe
O4 - HKCU\..\Run: [qywkvvg] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cwdktit] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [cdoddct] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [bporhaq] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [srvdffh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [lrrjspb] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [arvgbea] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [ojvcpdh] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tancuiu] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [inubkik] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [tcyglhc] c:\windows\soekfcm.exe
O4 - HKCU\..\Run: [thmfxiv] c:\windows\qynxost.exe
O4 - HKCU\..\Run: [qpgeaih] c:\windows\dsbuejg.exe
O4 - HKCU\..\Run: [laaumlo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dtjiwmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [flerdma] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yqekbuk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aqbfvyi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmddqap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gtijpbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sdacdxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [scokvww] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [syjqfvy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [srjhwkj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bnkvkpn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayqpjy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vcdlhhy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lpiphbi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vkfjnmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [esevwpc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynqpbey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [akqksvr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cqcvjwk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fygbfsq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwhnmxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckuccdf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xkajyqj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iwgyaqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eibajnw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rgcyhni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dayhxxd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yvwhygl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wvlapfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gwgolxu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wytpnlk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nobecys] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eaywksm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tncahmn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kxqrwcj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vysswcv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txywkyl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gmirxld] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [slxieco] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybmkpjq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lfepves] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oeemofp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fdtluwo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rxijlft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ivokvqb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vdxhede] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mmulrym] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oqfcrnj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aiwvnxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rsykapt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuvqgxv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eivpupq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rhmbhle] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dlcctuw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hfpsslh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ewlewct] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltvjuru] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [clmupwf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tlkfkbd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sbflpah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kvlokbn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltdvnrf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kbqssfa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [migdnne] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtfkfto] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [deurksb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyvslfv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txcidcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxnafwb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mankihy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [cwbryaf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xtjyifi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fnoiret] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jjidoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qsqqhkh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jeshflp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mvhqcbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isynbry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sxyqmsh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udffrkn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qayvlmj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ueofhqd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uiderxk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nyfuhog] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [axvapee] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idicrgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txmlikh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilwtoik] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [efxvdan] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sjfyuak] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [uxoehcw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arfwiup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gfqyuop] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [farwjrr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tuqrefy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jxhhoyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fxloppo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rjhnojc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jaillja] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lugcwjt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttqpbhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wxjtgft] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ialppls] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [txwtrhh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vuxldvd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgwaald] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ljokllw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jajmeli] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pmfgwvu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vywqmjv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ckulcou] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dvxtrdx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [snfhgwx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vqjnoei] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bilijch] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ydmqwah] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mdfnjoq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qwwjlbm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [weqyvfb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wjjjvfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [coqbuny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [yyhgxxm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eodedfp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jacpiae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkxjtip] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kciwopg] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nwvwycy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jfveydb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [shaachl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [udlhtni] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ybrtmvc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oulbkhv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bwdvspi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jqicfuo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xneoicw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgshnlw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bxnrpfs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [suswudp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qgdpxgp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hrnbons] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xbbleql] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ggdwarw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dmkfqgs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pobimmw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ysxwgbj] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ffjfxgy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nymbxrq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [daxfwhp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kgivlfy] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [afihouo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [eogsnqf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ciollpk] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [arhrffe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fgrlava] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xlqcqro] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nhbsxbv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ascxdsa] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ynofoba] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fwjuhrs] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [qvshoxe] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [isflase] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ymgvahi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ignpfwi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [sexgygd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wpwyejw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tsururl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [myjxfsi] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rnrcook] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pttrnfn] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [abwqcij] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gkyfkap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vjiyrcq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tyslvvf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lefqdje] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iuvjhkt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [lbhlulu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dllixap] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gumbiar] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ghtgaxt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [swsonsb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ardcsmq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [fqadmfh] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dsicklo] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [acepdkl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [rkfmsbc] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [wfikavp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [crrwmtx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [dshgkgl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [loawujf] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ttvexpb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ilgvhry] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [honhbfx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [tekntxr] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [mirxjup] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ltkxgrw] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pdwtuok] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [oirdhcb] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bqjumln] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [nacekdt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [bmkspng] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idyegwm] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [xygauey] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gbpemyd] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [pkbjvmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [kocjtam] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [idndjyt] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [hafkewp] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [takrlux] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [aoehptq] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [jlsvvny] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [imwxfdv] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [iadtesl] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [otkleae] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [gqmevut] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ihynsiu] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [vlxjsmx] c:\windows\uwlxhdu.exe
O4 - HKCU\..\Run: [ebpanem] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fdcuyoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [yaegfkb] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [akyasfq] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [lowovoa] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [jqfmihs] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vbfbnrg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ygffroc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [drlspam] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [guhnrtn] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sehayha] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [qkudtfu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hjwmeey] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hlrmimd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [onovacl] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nnsqoxv] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [frbhtev] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [pbfxcvg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vobctvd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [mnjmoon] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [xixoxmd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [myavvkj] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [yihoikc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [itivmgk] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nmspxid] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [wqlsaer] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [popggwr] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fhlyrnh] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sguaftl] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [rsdwvnc] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [iwtyxvo] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [awvarpf] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [fokouwy] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [kisjxrd] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vccvfmp] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ulnople] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [btuvudv] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [jcaoruu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [nfhioww] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [kbtmlcg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [imeyvgg] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [hnuxsbt] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vslptdm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [oermtrm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [ivoekpm] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [sdwqjxx] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [vualflp] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [rwhvxvu] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [dvrojkx] c:\windows\lfghasb.exe
O4 - HKCU\..\Run: [npqgcxj] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [xkawvxd] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [wbekina] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [xsyvwmf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [glntfes] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [phcuxdb] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [aisrplo] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [qwckkty] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [diurnre] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [gjdnork] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [yiwrcqb] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [licppot] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [njhmfvk] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [csaxjvp] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [orppyxs] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [fpkoqfh] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [bibpinr] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [headxrf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [hlqipjr] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [rcdqaxx] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [prstfuf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [yfjpsuf] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [liejiff] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [nmjspbk] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [jabbyor] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [bmnlawo] c:\windows\yxvkibq.exe
O4 - HKCU\..\Run: [lvxjoav] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evqkdcp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ewbnyop] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [psdppvp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sxqghxh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ymfcukh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [wufwxst] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ijbduus] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kchkcrw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jmrukns] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fywjhlt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drqtcwo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ndenkxm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [klqpkws] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rqlsaka] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fsduppv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [axqxuqg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pciyvmg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ysuasmy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [wqicgor] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ygbabxg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bgeysxc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [akybwtb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pqglwii] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yucqhah] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [psvbfjk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fiuvalc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gwrgqmv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ddqpigl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [girhqgo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [plrbrsd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hmepbmu] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hoobuxx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [arluwnt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fwilcte] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xkjbcqa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fdexilq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ihwhojs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xcdhuss] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kjaupba] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vlckqvx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eitkxgk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ymgtioo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [buhhjla] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [luvjwfe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [htefmsq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xocmbal] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lwxofil] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sapsufp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hdjpvpw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yxaxlot] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vimtjss] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eivctjy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [apnubqv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dyyslif] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ekjlmdt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ciawdrc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mujrtre] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ibiikcn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evhgapx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vbgbjwt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gvtijjg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qgmhkdc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rubbenl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cscjhbf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pdqjjir] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qmnsnfr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xveqjri] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xvdwdvy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [onkngyg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fixtsmg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ltsydcx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bbrmvgl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ibvyyjj] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [evhblmk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [novsoxq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [yyndfoq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hyqsykt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cwyalcg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [glmthqq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hknkbiy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hqfglnl] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [spunfia] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rseltrn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qajyoir] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rohslqc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drtcyjt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [etocooy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gjhyemt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [terofiv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [scrpboa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jvhphrn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rypkbsn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [svyuela] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [tewkyhp] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pglpbmf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mypsdcj] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [axbrhis] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [enabrud] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xaldldg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xhdejlk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [inywfms] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [avloplw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jasxwnq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nleeupe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bmqbhuv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nbhxahi] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bwgxrld] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ersuxgg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ejigdhx] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lawmdew] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nwishen] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dqkjtrd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rkokkbi] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [arnmjur] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [swhxnpq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kkfpccq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [skrtghs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [gwfjjkc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lhgrpfa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ypyhocy] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qopfjft] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [giehjwn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [haocnwg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [sbhpaby] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jrlvhxs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [eotohqe] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xhundyf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xwfpmte] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [lvhimjf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [oucdyqm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jwfijbg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [fmrqqkf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hmtjpix] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nbmvgeb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bqlyjbg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vjourru] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [khverjg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vvpckvf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aulqtca] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [adbhtmd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mektgqw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ggrdast] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [drvrvmd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ujlbccs] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rddqmct] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [nynnjyr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [kswbpos] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [mrxxavd] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [thxyqyn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [txcqnwr] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ykwnesw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [todimhm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [hsufxfg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [pqdbsab] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [iffmshq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xjwpwci] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [unmkyce] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ftyxftg] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [olqeyom] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ycxlnuh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [bodurim] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [rhcotqq] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [qlibdoa] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [uplhpap] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [cqabvvt] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [diysrcf] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [jdjkdft] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [niavqfc] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ogewxxw] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xdoebhb] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [shlrvbv] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ojbnipm] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [xpekoyo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [ubfbygk] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aiobkgo] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [vfqvcgn] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [koqmmle] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [diehoua] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [dgvobrh] c:\windows\tpryaoy.exe
O4 - HKCU\..\Run: [aybqfyj] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ybaoamf] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [caajfqp] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qvbhsrk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gncqekd] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wcjpnsk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [fgnfigk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dxgeyju] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jtljlvq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [mmdhtsx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gegoehk] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qodshlx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [boofefe] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [syebfex] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [orhlwgj] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [vjfiryc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [tpxeiiu] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [rxqrosc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [cmnumqh] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [obogbvv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jhnntsi] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [shoquvy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ixjcbkx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ygpedvs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [vsvfomq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [rnpmore] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wbknvlv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [yttqviw] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [tqfcbjq] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [grugdep] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [kkaootr] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [egakllt] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ketrapu] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [uacbsul] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wdfnmif] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dfsytvv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [abaibxx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [wgdjtrr] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [stdsrcs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [qagyguh] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ulmtnlw] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [hiypxmv] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [cgwggvy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [uqtohas] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [isnqxpd] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [glrjhfs] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [xthaiep] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [gysbiqt] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ntxsben] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [pxebsiy] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ivgnmjc] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [jhtaeev] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [dlpoyaa] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [bdrhxpx] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [ngtgwog] c:\windows\dwdnirj.exe
O4 - HKCU\..\Run: [mfmsgmn] c:\windows\ftqfogm.exe
O4 - HKCU\..\Run: [nkjeafm] c:\windows\gnlmnxm.exe
O4 - HKCU\..\Run: [yrmkscp] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [phljxtg] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [kisdvjp] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [hrqndjx] c:\windows\njnrbrk.exe
O4 - HKCU\..\Run: [dlaaaye] c:\windows\fdbrcvt.exe
O4 - HKCU\..\Run: [anoulsr] c:\windows\fdbrcvt.exe
O4 - HKCU\..\Run: [xfdceov] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bmxmxcc] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [psnhpvl] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [pklwjbf] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [lcqcbpn] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [htsfrff] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [etportx] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [gyjtewv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [vmdjjbx] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [osvnxqr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [afdukdv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [sjekqbw] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [qgxjxxr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [vmvrlat] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [kvsbpjr] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bxruxjp] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [nccsijl] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [xweuxvk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [jypecgk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [crditiw] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [lxgxnda] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [qmguhef] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [aolyfdn] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bobgxjg] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [gvlcckd] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [nujvdlk] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [ammkexa] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bomomcv] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [cohkvfm] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [bpqefvs] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [dsjssog] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [kwopmii] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [xkscepq] c:\windows\ppwtdax.exe
O4 - HKCU\..\Run: [mhsnpjs] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [olqsyfn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jihiycj] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vpwnnhg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [xvfkeqo] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ymwbqmf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vxbprkf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [oildavn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [klipmgj] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ejedmjf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [yaoarmp] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [rmebytg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [yfcbxds] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ghxivoi] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [osprtyr] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [utrdpat] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [nnnqmwc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [etvcvyq] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [pemrdgn] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ioatkij] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [pixnfdu] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jjyqdxo] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [wvkgbwe] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [dhmqptg] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vqwqetp] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [rwxempf] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [xynllfb] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [baityxv] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vdqwysk] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [vvbmpqk] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [hcfgsmc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [uqklnmc] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [tggckeu] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [eyrgtla] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [qhckkru] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ppraeqh] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [bxouice] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [jrgrlrd] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [fxmospp] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ubkckos] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [cxsidoq] c:\windows\fguchug.exe
O4 - HKCU\..\Run: [ejnqaoc] c:\wi
  • 0

Advertisements


#11
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hi again!! I am sorry I haven't gotten back to you sooner. You, my friend, have a nearly brand new infection! The good news is, we can and will get you fixed up, but it's going to take a few steps, and some patience on both of our parts! I'm game if you are!! :tazz:

First of all, I am writing up the fix for you, but I need something from you first, ok?

I need you to download MWav

This scan might take around 3+ hours to finish when set to scan everything. I need you to run MWav, put a check next to below items before scanning:

*Memory
*Startup Folders
*Drive - All Local Drives
*Folder - then click "browse" to change the directory to C: (default is C:\Windows)
*Registry
*System Folders
*Services
*Include Sub-Directory
*Scan All Files

Please make sure ALL of these are checked, then press the scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

Highlight the portion of the scan that lists infected items and hold CTRL + C to Copy then paste it here. The whole log will be extremely BIG so there is no way to copy the whole thing. I just need the infected items list.

Reply here with that Infected Items list. Don't worry about another HJT log right now, we'll get to that in a bit, ok? I need that Infected Items list so I can finish up writing the fix!!

I'll be here for a couple more hours tonight. Tomorrow I won't be on until at least 5pm Central time. My daughter has her first Prom tomorrow, and I'll be helping her get ready all afternoon! ;)
  • 0

#12
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
hiii kat,,good luck with your daughters prom,,i truely do appreciate this very much,,i promise i will donate when this is all done :tazz:

and I am game,,

I did what u asked,,it took close to 5hrs,,,but here is what u asked for:

hiii kat,,good luck with your daughters prom,,i truely do appreciate this very much,,i promise i will donate when this is all done ;)

and I am game,,

I did what u asked,,it took close to 5hrs,,,but here is what u asked for:

File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335866.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335867.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335868.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335869.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335870.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335872.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335873.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335878.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335879.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335881.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335883.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335884.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335886.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335887.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335888.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335889.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335890.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335891.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335892.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335893.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335894.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335895.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335896.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335897.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335898.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335899.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335900.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335901.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335908.dll infected by "Trojan-Proxy.Win32.Small.bk" Virus. Action Taken: No Action Taken.
File C:\updaterInstall_108.exe infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\cydelng.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ddmyhpf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dfivnxf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doloeli.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doriasf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dpilkuh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dxxbwai.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dypnnru.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\eblijfv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ecqcfmt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\emsrewb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\fwynevv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gojbqmq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gpejehi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hfxwsbm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\htuofxt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hvoojxk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iefdvdf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iqbsrlb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ittnaxg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jcxmkmw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jdgntcs.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jehvhub.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jgbbcme.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jmgcwed.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jnlvskb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jwoojxd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kmdmkjv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kwbomnn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ladflwp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mqqmfoj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mrudgpp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mulromm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\naciksf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nbsuodr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nkjvxbe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nrhkabj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ntrxroe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nvvfgyh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\oappeey.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ofjnapv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\omcjfjd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ossgbsr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pbadvrt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pfjegju.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pivialu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qjqsivo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qxwsdpr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ridoenm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmkeokr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmrjkml.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rpbkuem.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rqbnyuk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\shfhpfi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\syalcgn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SysRen.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\anlpaaaa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho infected by "Trojan.Win32.Qhost.f" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\jcssaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\spoolsrv32.exe infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\srpcsrv32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\taskmg.exe infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\txfdb32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\vqwaaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tdlbhdb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\bpc_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\ft28s.exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tfxqepk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tmkacka.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\txltira.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucaaiug.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\uirpjqu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ujayrsy.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\umjluoh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\UnstSA2.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vftymuq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vmhkpos.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vwsamtr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wast2.exe infected by "not-a-virus:AdWare.AdWast.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wgysicn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\winview.exe infected by "Trojan-PSW.Win32.VB.cc" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wqukktg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wsem301.dll infected by "Trojan-Downloader.Win32.Dyfuca.dd" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wuxyctn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wwusxlo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xbakkqf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlghloh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlqjfih.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xuegjwb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yjfjufw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ylghlpa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ymvvnvi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yrissly.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yumahwc.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yxdpowv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\CJXP63LE.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\180SAInstaller.exe infected by "not-a-virus:AdWare.180Solutions.g" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\73.exe\73.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\948 KB.exe infected by "not-a-virus:AdWare.ToolBar.GigatechSuperBar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\alchem.cab infected by "Trojan-Downloader.Win32.Alchemic" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\app6CE.tmp infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\cpr_in.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\ferretbar.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.c" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\gdDAD.exe infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\GLF7.EXE infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\perfectnavUninstall.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\polmx.cab infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\searchlocate.exe infected by "not-a-virus:AdWare.Sidesearch.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\sysren.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI2E34.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI3D25.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI4E1D.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI52F.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI626B.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI6468.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI67B4.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~MySetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpkw_setupSTUS\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\updateni_setup90\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\SETUPX63PART2.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\180searchassistant\sac.exe infected by "not-a-virus:AdWare.180Solutions.e" Virus. Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0a\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0b\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0c\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0d\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0e\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\backup\restore\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Bpt\bptre_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\RemoveX63.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\X63Twain.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc1\pn\remove.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335835.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335836.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335837.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335838.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335839.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335840.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335841.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335842.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335843.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335844.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335845.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335846.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335852.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335853.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335854.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335861.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335864.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335866.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335867.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335868.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335869.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335870.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335872.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335873.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335878.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335879.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335881.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335883.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335884.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335886.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335887.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335888.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335889.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335890.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335891.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335892.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335893.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335894.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335895.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335896.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335897.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335898.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335899.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335900.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335901.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP644\A0335908.dll infected by "Trojan-Proxy.Win32.Small.bk" Virus. Action Taken: No Action Taken.
File C:\updaterInstall_108.exe infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\cydelng.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ddmyhpf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dfivnxf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doloeli.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doriasf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dpilkuh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dxxbwai.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dypnnru.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\eblijfv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ecqcfmt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\emsrewb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\fwynevv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gojbqmq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gpejehi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hfxwsbm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\htuofxt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hvoojxk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iefdvdf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iqbsrlb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ittnaxg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jcxmkmw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jdgntcs.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jehvhub.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jgbbcme.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jmgcwed.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jnlvskb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jwoojxd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kmdmkjv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kwbomnn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ladflwp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mqqmfoj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mrudgpp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mulromm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\naciksf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nbsuodr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nkjvxbe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nrhkabj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ntrxroe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nvvfgyh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\oappeey.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ofjnapv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\omcjfjd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ossgbsr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pbadvrt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pfjegju.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pivialu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qjqsivo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qxwsdpr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ridoenm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmkeokr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmrjkml.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rpbkuem.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rqbnyuk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\shfhpfi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\syalcgn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SysRen.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\anlpaaaa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho infected by "Trojan.Win32.Qhost.f" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\jcssaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\spoolsrv32.exe infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\srpcsrv32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\taskmg.exe infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\txfdb32.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\vqwaaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tdlbhdb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\Altnet\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\bpc_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\Temp\ft28s.exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tfxqepk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tmkacka.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\txltira.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucaaiug.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\uirpjqu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ujayrsy.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\umjluoh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\UnstSA2.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vftymuq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Take
  • 0

#13
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Ok, before we dive in to the *big* fix, we are going to do a couple of other things first. I didn't expect your MWav log to be quite so large! :tazz:

1. Clear out your Temp folders, cache, etc.


2. I need you to disable and re-enable System restore to clean out several more of those trojans

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.


3. Download a free trial of Trojan Hunter here. Make sure you check for updates after install, and then let that sucker clean out everything it can find!!

After you have done this, (please don't shoot me!!) I need you to run the MWav scan again, and post me anything that it still shows as infected. The above steps will clean a LOT of it out for us, and will make the next steps easier.....for BOTH of us! ;)

Got my kiddo off to Prom, and yah...she looks amazing....and yah, I cried! I'll be around all night! ;)
  • 0

#14
FrankSweetMusic

FrankSweetMusic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 15 posts
HI KAT,,, :tazz:

I DID WHAT U SAID,,HERE IS THE NEW LOG,,,

IM GLAD EVERYTHING WENT WELL AT THE PROM,,,,, THEY GROW UP SO QUICK DONT THEY???

THANK U IN ADVANCE FOR YOUR HELP

FRANK




File C:\WINDOWS\system32\spood532.dll infected by "Backdoor.Win32.PPdoor.j" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\key0bdhe.exe infected by "Backdoor.Win32.PPdoor.m" Virus. Action Taken: No Action Taken.
File System Found infected by "CWS.GonnaSearch Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Grokster Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Grokster Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Grokster Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Grokster Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "DyFuCA Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "DyFuCA Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Adintelligence.AproposToolbar Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Wind Updates Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "CoolWebSearch Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "WindUpdate Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "180Solutions Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Quicken Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "180Solutions Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "saap Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "180Solutions Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Kazoom Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "mysearch Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "webrebates Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "kazaa Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "GrokSter Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "Claria Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "altnet Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "AdDestroyer Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "cws.therealsearch Spyware/Adware" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\cydelng.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ddmyhpf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dfivnxf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doloeli.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doriasf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dpilkuh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dxxbwai.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dypnnru.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\eblijfv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ecqcfmt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\emsrewb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\fwynevv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gojbqmq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gpejehi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hfxwsbm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\htuofxt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hvoojxk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iefdvdf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iqbsrlb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ittnaxg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jcxmkmw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jdgntcs.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jehvhub.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jgbbcme.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jmgcwed.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jnlvskb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jwoojxd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kmdmkjv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kwbomnn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ladflwp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mqqmfoj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mrudgpp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mulromm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\naciksf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nbsuodr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nkjvxbe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nrhkabj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ntrxroe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nvvfgyh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\oappeey.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ofjnapv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\omcjfjd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ossgbsr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pbadvrt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pfjegju.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pivialu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qjqsivo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qxwsdpr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ridoenm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmkeokr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmrjkml.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rpbkuem.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rqbnyuk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\shfhpfi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\syalcgn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SysRen.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tdlbhdb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tfxqepk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tmkacka.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\txltira.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucaaiug.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\uirpjqu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ujayrsy.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\umjluoh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\UnstSA2.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vftymuq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vmhkpos.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vwsamtr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wast2.exe infected by "not-a-virus:AdWare.AdWast.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wgysicn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\winview.exe infected by "Trojan-PSW.Win32.VB.cc" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wqukktg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wsem301.dll infected by "Trojan-Downloader.Win32.Dyfuca.dd" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wuxyctn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wwusxlo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xbakkqf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlghloh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlqjfih.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xuegjwb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yjfjufw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ylghlpa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ymvvnvi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yrissly.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yumahwc.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yxdpowv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\anlpaaaa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\jcssaaaa.exe.tcf infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\spoolsrv32.exe.tcf infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\srpcsrv32.dll.tcf infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\taskmg.exe.tcf infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\txfdb32.dll.tcf infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\vqwaaaaa.exe.tcf infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\180SAInstaller.exe infected by "not-a-virus:AdWare.180Solutions.g" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\73.exe\73.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\948 KB.exe infected by "not-a-virus:AdWare.ToolBar.GigatechSuperBar" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\alchem.cab infected by "Trojan-Downloader.Win32.Alchemic" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\app6CE.tmp infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\cpr_in.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\ferretbar.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.c" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\gdDAD.exe.tcf infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\GLF7.EXE infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\perfectnavUninstall.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\polmx.cab infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\searchlocate.exe infected by "not-a-virus:AdWare.Sidesearch.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\sysren.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI2E34.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI3D25.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI4E1D.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI52F.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI626B.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI6468.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\THI67B4.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\~MySetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\DOCUME~1\Aaron's\LOCALS~1\Temp\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\CJXP63LE.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\180SAInstaller.exe infected by "not-a-virus:AdWare.180Solutions.g" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\73.exe\73.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\948 KB.exe infected by "not-a-virus:AdWare.ToolBar.GigatechSuperBar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\alchem.cab infected by "Trojan-Downloader.Win32.Alchemic" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\app6CE.tmp infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\cpr_in.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\ferretbar.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.c" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\gdDAD.exe.tcf infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\GLF7.EXE infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\perfectnavUninstall.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\polmx.cab infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\searchlocate.exe infected by "not-a-virus:AdWare.Sidesearch.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\sysren.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI2E34.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI3D25.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI4E1D.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI52F.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI626B.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI6468.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI67B4.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~MySetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpkw_setupSTUS\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\updateni_setup90\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\SETUPX63PART2.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\180searchassistant\sac.exe infected by "not-a-virus:AdWare.180Solutions.e" Virus. Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0a\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0b\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0c\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0d\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0e\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\backup\restore\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Bpt\bptre_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\RemoveX63.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\X63Twain.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc1\pn\remove.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc87.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc92.exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000026.exe infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000027.exe infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000028.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000029.exe infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000030.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000031.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\updaterInstall_108.exe infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\cydelng.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ddmyhpf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dfivnxf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doloeli.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doriasf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dpilkuh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dxxbwai.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dypnnru.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\eblijfv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ecqcfmt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\emsrewb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\fwynevv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gojbqmq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gpejehi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hfxwsbm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\htuofxt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hvoojxk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iefdvdf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iqbsrlb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ittnaxg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jcxmkmw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jdgntcs.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jehvhub.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jgbbcme.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jmgcwed.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jnlvskb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jwoojxd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kmdmkjv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kwbomnn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ladflwp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mqqmfoj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mrudgpp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mulromm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\naciksf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nbsuodr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nkjvxbe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nrhkabj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ntrxroe.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\nvvfgyh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\oappeey.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ofjnapv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\omcjfjd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ossgbsr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pbadvrt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pfjegju.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\pivialu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qjqsivo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\qxwsdpr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ridoenm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmkeokr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rmrjkml.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rpbkuem.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\rqbnyuk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\shfhpfi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\syalcgn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SysRen.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\anlpaaaa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho infected by "Trojan.Win32.Qhost.f" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\jcssaaaa.exe.tcf infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{0B5DDD35-7172-42B5-BA3D-86DC53838420}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{1F657AF6-CD2A-4057-AE15-52AFAD156E25}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{39799F86-7554-4D98-B9B5-28160A097C2D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{63B68C53-918D-4EDC-AB92-7881431C4B59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{7AD5BC53-273E-4645-A6C3-A79B85188E59}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{8805A616-D82F-4A3F-8AAF-20C2E5C408CF}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{BE48F693-EC31-4F7B-A740-86D9B680B127}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{C35CE135-2706-4DD1-90FC-AA7C353F8C23}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SECURITY.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST.EXE infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\Services\{CA80102A-1A0A-48C2-9179-0E005795476D}\SVCHOST32.DLL infected by "Trojan.Win32.WebSearch.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\spoolsrv32.exe.tcf infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\srpcsrv32.dll.tcf infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\SWRT01.dll infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\taskmg.exe.tcf infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\txfdb32.dll.tcf infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\vqwaaaaa.exe.tcf infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM32\wldr.dll infected by "Trojan-Downloader.Win32.Agent.le" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tdlbhdb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tfxqepk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\tmkacka.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\txltira.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucaaiug.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\uirpjqu.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ujayrsy.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\umjluoh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\UnstSA2.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vftymuq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vmhkpos.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\vwsamtr.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wast2.exe infected by "not-a-virus:AdWare.AdWast.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wgysicn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\winview.exe infected by "Trojan-PSW.Win32.VB.cc" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wqukktg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wsem301.dll infected by "Trojan-Downloader.Win32.Dyfuca.dd" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wuxyctn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\wwusxlo.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xbakkqf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlghloh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xlqjfih.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\xuegjwb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yjfjufw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ylghlpa.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ymvvnvi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yrissly.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yumahwc.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\yxdpowv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\CJXP63LE.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\180SAInstaller.exe infected by "not-a-virus:AdWare.180Solutions.g" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\73.exe\73.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\948 KB.exe infected by "not-a-virus:AdWare.ToolBar.GigatechSuperBar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\alchem.cab infected by "Trojan-Downloader.Win32.Alchemic" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\app6CE.tmp infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.l" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\cpr_in.exe infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\ferretbar.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.c" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\gdDAD.exe.tcf infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\GLF7.EXE infected by "Trojan-Downloader.Win32.Adroar" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\perfectnavUninstall.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\polmx.cab infected by "Trojan-Downloader.Win32.Agent.ae" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\searchlocate.exe infected by "not-a-virus:AdWare.Sidesearch.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\sysren.exe infected by "not-a-virus:AdWare.SysRen.a" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI2E34.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI3D25.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI4E1D.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI52F.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI626B.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI6468.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.f" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\THI67B4.tmp\twaintec.cab infected by "not-a-virus:AdWare.BiSpy.m" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~MySetup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\Aaron's\Local Settings\Temp\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\lpkw_setupSTUS\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\AOL Downloads\updateni_setup90\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\LxkX63\Scan\SETUPX63PART2.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\180searchassistant\sac.exe infected by "not-a-virus:AdWare.180Solutions.e" Virus. Action Taken: No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0a\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0b\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0c\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0d\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0e\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\backup\restore\comp02.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\America Online 9.0f\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Bpt\bptre_inst.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\RemoveX63.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\LexmarkX63\X63Twain.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc1\pn\remove.exe infected by "Trojan-Downloader.Win32.Keenval.f" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\dmfiles.cab infected by "not-a-virus:AdWare.Altnet.g" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\mysearch.cab infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\pmexe.cab infected by "not-a-virus:AdWare.Altnet.h" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc81\pmfiles.cab infected by "not-a-virus:AdWare.BrilliantDigital.1007" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc87.exe infected by "not-a-virus:AdWare.Broadcap.a" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-2960945794-2813382376-67046659-1007\Dc92.exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000026.exe infected by "Trojan-Dropper.Win32.Agent.ka" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000027.exe infected by "not-a-virus:AdWare.FindSpy.e" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000028.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000029.exe infected by "Trojan.Win32.Hpt.j" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000030.dll infected by "Trojan-Downloader.Win32.Adload.g" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000031.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\updaterInstall_108.exe infected by "Trojan-Downloader.Win32.Keenval" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\cydelng.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ddmyhpf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dfivnxf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doloeli.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\doriasf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dpilkuh.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dxxbwai.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\dypnnru.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\eblijfv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ecqcfmt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\emsrewb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\fwynevv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gojbqmq.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\gpejehi.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hfxwsbm.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\htuofxt.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\hvoojxk.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iefdvdf.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\iqbsrlb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ittnaxg.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jcxmkmw.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jdgntcs.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jehvhub.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jgbbcme.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jmgcwed.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jnlvskb.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\jwoojxd.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kmdmkjv.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\kwbomnn.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ladflwp.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mqqmfoj.exe infected by "Trojan.Win32.StartPage.he" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\mrudgpp.exe infected by "Trojan.Win32.StartPa
  • 0

#15
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
ok. well, wow. :tazz: I have most of the fix written up, but I need to wait for one of the Malware geniuses named noahdfear to jump back online. I want him to look part of it over, to see if my thinking is correct. Like I said, this is something not real common yet, and I want to make DARN sure we wipe it out for you!! I hope he'll be back around yet tonight, if not...then I will get to you as soon as I catch him tomorrow!

One question about something I noticed in your newest MWav log. Are you using kazaa or any other P2P program? If so please UNINSTALL it/them. Kazaa and its' friends are notorious for causing users to become infected....and to KEEP reinfecting you. If you have them and uninstall them....I promise when we are finished cleaning you up, I will tell you some P2P programs that will not cause you to become infected!!

Hang in there, we WILL get this!! ;)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP