Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Smitfraud.c trojan Please Help! [CLOSED]


  • This topic is locked This topic is locked

#31
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
still getting grey screen when opening up my documents...here is the new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 4:42:14 PM, on 5/23/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\PROGRAM FILES\OPTIMUM ONLINE\NETSURF.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\HP OFFICEJET V SERIES\BIN\HPOANT07.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOEVM07.EXE
C:\WINDOWS\SYSTEM\HPOIPM07.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [HPLogiFinder] \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
  • 0

Advertisements


#32
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Hmm can you somehow get me a screenshot of what is looks like?
  • 0

#33
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
i can't send a screenshot because when it happens i have to restart...it basically goes grey and flickers...it happens when i go into my documents first after rebooting...and seems to not happen if i go into IE first and then go into my documents...i'm also getting a mfc42.dll error when opening up another program...
  • 0

#34
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Open Hijackthis click open the misc tools section > check mark List also minor sections (full) and List enpty sections (complete) then click generate Startup list log post that log here in a reply.
  • 0

#35
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
the about:blank problem is back along with the pop ups...here is my updated HJT log and below it is the startup log....

Logfile of HijackThis v1.99.1
Scan saved at 11:52:01 PM, on 5/23/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\PROGRAM FILES\OPTIMUM ONLINE\NETSURF.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\HP OFFICEJET V SERIES\BIN\HPOANT07.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOEVM07.EXE
C:\WINDOWS\SYSTEM\HPOIPM07.EXE
C:\PROGRAM FILES\BACKWEB\BACKWEB\PROGRAM\BWDELAY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\TEMP\TD_0007.DIR\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\TEMP\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {30EC2272-4A9B-463B-B4C7-A27D579A889C} - C:\WINDOWS\SYSTEM\NDKJCAB.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [HPLogiFinder] \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [sp] rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O18 - Filter: text/html - {0D2B2436-7684-4B90-8F43-DBB123A76FEE} - C:\WINDOWS\SYSTEM\NDKJCAB.DLL
O18 - Filter: text/plain - {0D2B2436-7684-4B90-8F43-DBB123A76FEE} - C:\WINDOWS\SYSTEM\NDKJCAB.DLL















StartupList report, 5/23/2005, 11:45:45 PM
StartupList version: 1.52.2
Started from : C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE
Detected: Windows ME (Win9x 4.90.3000)
Detected: Internet Explorer v5.50 (5.50.4134.0600)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\PROGRAM FILES\OPTIMUM ONLINE\NETSURF.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\HP OFFICEJET V SERIES\BIN\HPOANT07.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOEVM07.EXE
C:\WINDOWS\SYSTEM\HPOIPM07.EXE
C:\PROGRAM FILES\BACKWEB\BACKWEB\PROGRAM\BWDELAY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\TEMP\TD_0005.DIR\HIJACKTHIS.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\WINDOWS\All Users\Start Menu\Programs\StartUp]
ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
PCHealth = C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
Keyboard Manager = C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
hpsysdrv = c:\windows\system\hpsysdrv.exe
Delay = C:\WINDOWS\delayrun.exe
MotiveMonitor = C:\Program Files\Motive\motmon.exe
HPLogiFinder = \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
Optimum Online = C:\Program Files\Optimum Online\Netsurf.exe -tray
Symantec Core LC = C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
NAV CfgWiz = C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
sp = rundll32 C:\WINDOWS\TEMP\SE.DLL,DllInstall

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
SSDPSRV = C:\WINDOWS\SYSTEM\ssdpsrv.exe
*StateMgr = C:\WINDOWS\System\Restore\StateMgr.exe
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
TrueVector = C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ccSetMgr = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Taskbar Display Controls = RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
MSMSGS = C:\PROGRA~1\MESSEN~1\msmsgs.exe /background

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
*No values found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\SYSTEM\MSHTA.EXE "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = C:\WINDOWS\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[SetupcPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection SetupcPerUser 64 C:\WINDOWS\INF\setupc.inf

[AppletsPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection AppletsPerUser 64 C:\WINDOWS\INF\applets.inf

[PerUser_CVT_Inis]
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CVT_Inis 64 C:\WINDOWS\INF\applets1.inf

[FontsPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection FontsPerUser 64 C:\WINDOWS\INF\fonts.inf

[PerUser_HNW_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_HNW_Inis 64 C:\WINDOWS\INF\ICS.inf

[PerUser_ICW_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_ICW_Inis 0 C:\WINDOWS\INF\icw97.inf

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[{89820200-ECBD-11cf-8B85-00AA005B4395}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[PerUser_moviemaker] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_moviemaker 64 C:\WINDOWS\INF\moviemk.inf

[>PerUser_MSN_Clean] *
StubPath = C:\WINDOWS\msnmgsr1.exe

[{CA0A4247-44BE-11d1-A005-00805F8ABE06}] *
StubPath = RunDLL setupx.dll,InstallHinfSection PowerCfg.user 0 powercfg.inf

[PerUser_Msinfo] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Msinfo 64 C:\WINDOWS\INF\msinfo.inf

[PerUser_Msinfo2] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Msinfo2 64 C:\WINDOWS\INF\msinfo.inf

[MotownMmsysPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MotownMmsysPerUser 64 C:\WINDOWS\INF\motown.inf

[MotownAvivideoPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MotownAvivideoPerUser 64 C:\WINDOWS\INF\motown.inf

[PerUser_Base] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Base 64 C:\WINDOWS\INF\msmail.inf

[SamplerPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection SamplerPerUser 64 C:\WINDOWS\INF\sampler.inf

[ShellPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection ShellPerUser 64 C:\WINDOWS\INF\shell.inf

[Shell2PerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection Shell2PerUser 64 C:\WINDOWS\INF\shell2.inf

[PerUser_winbase_Links] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_winbase_Links 64 C:\WINDOWS\INF\subase.inf

[PerUser_winapps_Links] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_winapps_Links 64 C:\WINDOWS\INF\subase.inf

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[TapiPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection TapiPerUser 64 C:\WINDOWS\INF\tapi.inf

[PerUser_MSWordPad_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_MSWordPad_Inis 64 C:\WINDOWS\INF\wordpad.inf

[PerUserOldLinks] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUserOldLinks 64 C:\WINDOWS\INF\appletpp.inf

[MmoptRegisterPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MmoptRegisterPerUser 64 C:\WINDOWS\INF\mmopt.inf

[PerUser_CDPlayer_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CDPlayer_Inis 64 C:\WINDOWS\INF\mmopt.inf

[OlsPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsPerUser 64 C:\WINDOWS\INF\ols.inf

[OlsMsnPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsMsnPerUser 64 C:\WINDOWS\INF\ols.inf

[PerUser_PCHealth] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_PCHealth 64 C:\WINDOWS\INF\pchealth.inf

[{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplayer2.inf,PerUserStub

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

[PerUser_Paint_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Paint_Inis 64 C:\WINDOWS\INF\applets.inf

[PerUser_Calc_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Calc_Inis 64 C:\WINDOWS\INF\applets.inf

[PerUser_dxxspace_Links] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_dxxspace_Links 64 C:\WINDOWS\INF\applets1.inf

[PerUser_Enable_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Enable_Inis 64 C:\WINDOWS\INF\enable.inf

[PerUser_Wingames_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Wingames_Inis 64 C:\WINDOWS\INF\games.inf

[PerUser_ZoneGame_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_ZoneGame_Inis 64 C:\WINDOWS\INF\games.inf

[PerUser_PBGame_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_PBGame_Inis 64 C:\WINDOWS\INF\games.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser

[MotownRecPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MotownRecPerUser 64 C:\WINDOWS\INF\motown.inf

[PerUser_Vol] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Vol 64 C:\WINDOWS\INF\motown.inf

[MotownMPlayPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MotownMPlayPerUser 64 C:\WINDOWS\INF\motown.inf

[PerUser_RNA_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_RNA_Inis 64 C:\WINDOWS\INF\rna.inf

[PerUser_Sysmon_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Sysmon_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_Sysmeter_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Sysmeter_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_netwatch_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_netwatch_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_CharMap_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CharMap_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_Onlinelnks_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Onlinelnks_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_Dialer_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Dialer_Inis 64 C:\WINDOWS\INF\appletpp.inf

[PerUser_ClipBrd_Inis] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_ClipBrd_Inis 64 C:\WINDOWS\INF\clip.inf

[MmoptMusicaPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MmoptMusicaPerUser 64 C:\WINDOWS\INF\mmopt.inf

[MmoptJunglePerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MmoptJunglePerUser 64 C:\WINDOWS\INF\mmopt.inf

[MmoptRobotzPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MmoptRobotzPerUser 64 C:\WINDOWS\INF\mmopt.inf

[MmoptUtopiaPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection MmoptUtopiaPerUser 64 C:\WINDOWS\INF\mmopt.inf

[{44BBA842-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.W95

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[OlsAolPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsAolPerUser 64 C:\WINDOWS\INF\ols.inf

[OlsAttPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsAttPerUser 64 C:\WINDOWS\INF\ols.inf

[OlsProdigyPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsProdigyPerUser 64 C:\WINDOWS\INF\ols.inf

[OlsEarthlinkPerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection OlsEarthlinkPerUser 64 C:\WINDOWS\INF\ols.inf

[Shell3PerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection Shell3PerUser 64 C:\WINDOWS\INF\shell3.inf

[Theme_MoreWindows_PerUser] *
StubPath = rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection Themes_MoreWindows_PerUser 0 C:\WINDOWS\INF\themes.inf

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = C:\WINDOWS\SYSTEM\ie4uinit.exe

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

[{44BBA851-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wpie5x86.inf,PerUserStub

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=
run=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\SYSTEM\BLANKS~1.SCR
drivers=mmsystem.dll power.drv

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.INI listing:

*File not found*

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 23/5/2005, 14:13:46)

[Rename]
NUL=c:\windows\start menu\sex.lnk
NUL=c:\program files\websiteviewer\127062.exe
NUL=c:\program files\websiteviewer\127062.dd
NUL=c:\program files\websiteviewer\127062.ico
NUL=c:\program files\websiteviewer\127062.dlr
NUL=c:\windows\cookies\brett hunt@cgi-bin[1].txt
NUL=c:\windows\cookies\brett hunt@casalemedia[2].txt
NUL=c:\windows\cookies\brett hunt@bfast[1].txt
NUL=c:\windows\cookies\brett hunt@2o7[2].txt
NUL=c:\windows\cookies\brett hunt@advertising[1].txt
NUL=c:\windows\cookies\brett [email protected][1].txt
NUL=c:\windows\cookies\brett hunt@doubleclick[1].txt

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

SET windir=C:\WINDOWS
SET winbootdir=C:\WINDOWS
SET COMSPEC=C:\WINDOWS\COMMAND.COM
SET PATH=C:\WINDOWS;C:\WINDOWS\COMMAND
SET PROMPT=$p$g
SET TEMP=C:\WINDOWS\TEMP
SET TMP=C:\WINDOWS\TEMP

--------------------------------------------------

C:\CONFIG.SYS listing:

*File is empty*

--------------------------------------------------

C:\WINDOWS\WINSTART.BAT listing:

*File not found*

--------------------------------------------------

C:\WINDOWS\DOSSTART.BAT listing:

echo off
REM Notes:
REM DOSSTART.BAT is run whenenver you choose "Restart the computer
REM in MS-DOS mode" from the Shutdown menu in Windows. It allows
REM you to load programs that you might not want loaded in Windows,
REM (because they have functional equivalents) but that you do
REM want loaded under MS-DOS. The two primary candidates for
REM this are MSCDEX and a real mode driver for the mouse you ship
REM with your system. Commands that you want present in both Windows
REM and MS-DOS should be placed in the Autoexec.bat in the
REM \Image directory of your reference server. Please note that for
REM MSCDEX you will need to load the corresponding real-mode CD
REM driver in Config.sys. This driver won't be used by Windows 98
REM but will be available prior to and after Windows 98 exits.
REM
REM This file is also helpful if you want to F8 boot into MS-DOS 7.0
REM before Windows loads and access the CD-ROM. All you have to do
REM is press F8 and then run DOSSTART to load MSCDEX and your real
REM mode mouse driver (no need to remember the command line parameters
REM for these two files.
REM
REM - You MUST explicitly specify the CD ROM Drive Letter for MSCDEX.
REM - The string following the /D: statement must explicitly match
REM the string in CONFIG.SYS following your CD-ROM device driver.
REM MSCDEX.EXE /D:OEMCD001 /l:d
REM MOUSE.EXE
mscdex.exe /d:IDECD000 /L:M

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - C:\WINDOWS\SYSTEM\NDKJCAB.DLL - {30EC2272-4A9B-463B-B4C7-A27D579A889C}

--------------------------------------------------

Enumerating Task Scheduler jobs:

PCHealth Scheduler for Data Collection.job
Symantec NetDetect.job
Norton AntiVirus - Scan my computer.job

--------------------------------------------------

Enumerating Download Program Files:

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINDOWS\SYSTEM\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupd...7883.2314699074

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macr...director/sw.cab

[{3334504D-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.micros...386/mpeg4ax.cab

[{33564D57-9980-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.micros...386/wmv9dmo.cab

[{32564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.micros...i386/wmv8ax.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.micr...922/wmv9VCM.CAB

[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai...all/xscan53.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\SYSTEM\rnr20.dll
Protocol #1: C:\WINDOWS\SYSTEM\mswsosp.dll
Protocol #2: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #3: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #4: C:\WINDOWS\SYSTEM\msafd.dll
Protocol #5: C:\WINDOWS\SYSTEM\rsvpsp.dll
Protocol #6: C:\WINDOWS\SYSTEM\rsvpsp.dll

--------------------------------------------------

Enumerating Win9x VxD services:

VNETSUP: vnetsup.vxd
VPOWERD: *VPOWERD
NDIS: ndis.vxd
JAVASUP: JAVASUP.VXD
CONFIGMG: *CONFIGMG
NTKern: *NTKERN
VWIN32: *VWIN32
VFBACKUP: *VFBACKUP
VCOMM: *VCOMM
COMBUFF: *COMBUFF
IFSMGR: *IFSMGR
IOS: *IOS
MTRR: *MTRR
SPOOLER: *SPOOLER
UDF: *UDF
VFAT: *VFAT
VCACHE: *VCACHE
VCOND: *VCOND
VCDFSD: *VCDFSD
VXDLDR: *VXDLDR
VDEF: *VDEF
VPICD: *VPICD
VTD: *VTD
REBOOT: *REBOOT
VDMAD: *VDMAD
VSD: *VSD
V86MMGR: *V86MMGR
PAGESWAP: *PAGESWAP
DOSMGR: *DOSMGR
VMPOLL: *VMPOLL
SHELL: *SHELL
PARITY: *PARITY
BIOSXLAT: *BIOSXLAT
VMCPD: *VMCPD
VTDAPI: *VTDAPI
PERF: *PERF
VNETBIOS: vnetbios.vxd
VREDIR: vredir.vxd
DFS: dfs.vxd
NDISWAN: ndiswan.vxd
VSDATA95: vsdata95.vxd
SYMTDI: SYMTDI.VXD

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
UPnPMonitor: C:\WINDOWS\SYSTEM\UPNPUI.DLL
AUHook: C:\WINDOWS\SYSTEM\AUHOOK.DLL

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

End of report, 28,100 bytes
Report generated in 0.334 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
  • 0

#36
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

This will likely be a few step process in removing the malware that has infected your system. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.

You have a nasty CoolWebSearch infection. First we will need to download a few tools that will help us in the removal of your problem.

Download about:buster by RubbeRDuckY Here.
Download CWShredder Here.
Download SpSeHjfix Here.
Download and install CleanUp! Here

Save all of these files somewhere you will remember like to the Desktop.

Unzip SpSeHjfix to its own folder (ie c:\SpSeHjfix)

Run the CleanUp! installer. You dont need to do anything with it right now.

Update About:Buster
  • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
  • Navigate to the AboutBuster directory and double-click on AboutBuster.exe.
  • Click "OK" at the prompt with instructions.
  • Click "Update" and then "Check For Update" to begin the update process.
  • If any updates exist please download them by clicking "Download Update" then click the X to close that window.
  • Now close About:Buster
Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close CWShredder
Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please run about:buster by RubbeRDuckY:
  • Click Start and then OK to allow AboutBuster to scan for Alternate Data Streams.
  • Click Yes to allow it to shutdown explorer.exe.
  • It will begin to check your computer for malicious files. If it asks if you would like to do a second pass, allow it to do so.
  • When it has finished, click Save Log. Make sure you save it as I may need a copy of it later.
  • Reboot your computer into safe mode again
Run about:buster again following the same instructions as above, this time without the restart at the end

Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about.

Now run SpSeHjfix. A log will be saved in the same folder that you put the exe into. Please post the results of that log in your next reply.

Now run CleanUp!. Click CleanUp and allow it to delete all the temporary files.Reboot your computer into normal windows.

Please run an on-line virus scan at Kaspersky OnLine Scan or if that doesnt work, you can use TrendMicro or BitDefender. (Please post the results of the scan(s) in your next reply)

After all that, please post back with how things went as well as the logs requested and a new HiJackThis log.

Good Luck
  • 0

#37
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
here is the kaspersky log...it's pretty lengthy...should i delete all infected files???

File Name Virus Name Send Delete

c:\WINDOWS\SYSTEM32\telnet.exe Virus.Win32.Bube.l send delete

c:\WINDOWS\Al...opconverting1.zip Passwor...tected-EXE send delete

c:\WINDOWS\SY...hive\EXPLORER.EXE Virus.Win32.Bube.l send delete

c:\WINDOWS\SY...hive\EXPLORER.EX0 Virus.Win32.Bube.l send delete

c:\WINDOWS\SYSTEM\pmhc.dll Trojan....artPage.qr send delete

c:\WINDOWS\SYSTEM\mseggo.gif Trojan-...32.Delf.dx send delete

c:\WINDOWS\SYSTEM\wldr.dll Trojan-...2.Agent.le send delete

c:\WINDOWS\SYSTEM\poker.exe Trojan-...2.Agent.nj send delete

c:\WINDOWS\Do...FLICT.1\black.ocx Trojan-...2.Agent.ex send delete

c:\WINDOWS\Do...m Files\BLACK.OCX Trojan-...2.Agent.ex send delete

c:\WINDOWS\sasetup.dll Trojan.....Dialer.bi send delete

c:\WINDOWS\explorer.new Virus.Win32.Bube.l send delete

c:\WINDOWS\EXPLORER.EXE Virus.Win32.Bube.l send delete

c:\WINDOWS\displdy.txt Trojan-...32.Agent.j send delete

c:\WINDOWS\SAinstaller.exe Trojan.....Dialer.bi send delete

c:\WINDOWS\er34r3.dat Trojan....LowZones.y send delete

c:\WINDOWS\cxtpls_loader.exe Trojan-....Apropo.ab send delete

c:\WINDOWS\isrvs\sysupd.dll Trojan-...32.Ieser.a send delete

c:\WINDOWS\isrvs\delprot.sys Trojan.....Delprot.a send delete

c:\WINDOWS\isrvs\edmond.exe Trojan.....Delprot.a send delete

c:\WINDOWS\sasent.dll Trojan.....Dialer.bi send delete

c:\WINDOWS\tct101.dll Trojan-....Dyfuca.eg send delete

c:\WINDOWS\drexinit.dll Trojan....2.Agent.co send delete

c:\WINDOWS\installer_SIAC.exe Trojan-...2.Adload.a send delete

c:\_RESTORE\TEMP\A0477867.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0477810.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0478073.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0478099.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0478100.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0478111.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0479080.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0479096.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0479097.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0479100.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0479111.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0479112.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0479115.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0479117.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0479119.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0479121.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0479128.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0480090.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0480096.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0480097.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0480100.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0480101.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0480102.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0480112.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0480120.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0480122.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0480127.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\KGODFAA.0 Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0481075.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0481109.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0481110.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0481111.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0481114.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0481115.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0481116.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0481118.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0481119.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0481120.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0481121.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0481127.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0482071.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0482107.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0482108.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0482111.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0482112.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0482113.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0482115.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0482118.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\KGODFAA.1 Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0482127.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0482148.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0482149.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0482152.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0482153.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0482154.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0482156.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0482159.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0483129.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0483151.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0483152.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0483155.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0483156.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0483157.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0483159.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\KGODFAA.2 Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0484129.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0484164.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0484165.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0484168.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0484170.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0484171.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0484172.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0485134.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0485151.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0485152.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0485155.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0485157.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0485158.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0485162.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0485166.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0485170.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0485185.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0485199.CPY Trojan-....Small.asf send delete

c:\_RESTORE\TEMP\A0486125.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0486143.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0486146.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0486147.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0486148.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0486150.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0486155.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0486159.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0486163.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0486167.CPY Trojan-....Apropo.ab send delete

c:\_RESTORE\TEMP\A0486170.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0486174.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0486175.CPY Trojan-...2.Adload.a send delete

c:\_RESTORE\TEMP\A0486181.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0486183.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0486190.CPY Trojan-....Small.asf send delete

c:\_RESTORE\TEMP\A0486194.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0486198.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0486197.CPY Trojan-...Dyfuca.gen send delete

c:\_RESTORE\TEMP\A0486199.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0486200.CPY Trojan-....Dyfuca.eg send delete

c:\_RESTORE\TEMP\A0486232.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0487155.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0487158.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0487161.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0487162.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0487164.CPY Trojan-...2.Small.rd send delete

c:\_RESTORE\TEMP\A0487165.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0487166.CPY Trojan....2.Agent.ct send delete

c:\_RESTORE\TEMP\A0487168.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0487171.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0487178.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0487225.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0487241.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0487264.CPY Trojan-...Dyfuca.gen send delete

c:\_RESTORE\TEMP\A0487326.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0488144.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0488152.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0488155.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0488158.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0488159.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0488164.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0488168.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0489134.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0489147.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0489148.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0489151.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0489280.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0489292.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0489304.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0489316.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0489328.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0489344.CPY Trojan-...Dyfuca.gen send delete

c:\_RESTORE\TEMP\A0489355.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0489356.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0489581.CPY Trojan-....IstBar.gi send delete

c:\_RESTORE\TEMP\A0489654.CPY Trojan-....IstBar.jd send delete

c:\_RESTORE\TEMP\A0490135.CPY Trojan....owZones.bf send delete

c:\_RESTORE\TEMP\A0490138.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0490156.CPY Trojan-....IstBar.it send delete

c:\_RESTORE\TEMP\A0490162.CPY Trojan-...2.Small.ga send delete

c:\_RESTORE\TEMP\A0490164.CPY Trojan-....IstBar.it send delete

c:\_RESTORE\TEMP\A0490165.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0490170.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0490171.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0490173.CPY Trojan-...2.Small.rd send delete

c:\_RESTORE\TEMP\A0490174.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0490177.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0490201.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0490215.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0490222.CPY Trojan....2.Agent.co send delete

c:\_RESTORE\TEMP\A0491135.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0491153.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0491156.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0491157.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0491159.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0491160.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0491163.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0491165.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0492135.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0492152.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0492154.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0492156.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0492159.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0492161.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0492162.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0492167.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0492172.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0492176.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0493135.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0493153.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0493156.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0493159.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0493162.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0493163.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0493166.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0493168.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0493180.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0493182.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0493198.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0493203.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0493212.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0493213.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0493225.CPY Trojan....2.Agent.co send delete

c:\_RESTORE\TEMP\A0493250.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0493254.CPY Trojan-....Apropo.ab send delete

c:\_RESTORE\TEMP\A0493257.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0493261.CPY Trojan-....Dyfuca.eg send delete

c:\_RESTORE\TEMP\A0493311.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0493325.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0493328.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0493337.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0493338.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0493341.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0493348.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0494313.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0494331.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0494332.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0494335.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0494338.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0494341.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0494342.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0494344.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0495313.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0495329.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0495331.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0495334.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0495336.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0495337.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0495338.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0495344.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0495350.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0496314.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0496332.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0496335.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0496337.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0496342.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0496343.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0496345.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0496347.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0496368.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0496375.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0497313.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0497331.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0497334.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0497335.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0497342.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0497343.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0497345.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0497346.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0497349.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0497361.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0497363.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0497364.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0497365.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0497383.CPY Trojan....2.Agent.co send delete

c:\_RESTORE\TEMP\A0498319.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0498328.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0498331.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0498333.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0498338.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0498339.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0498341.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0498346.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0498351.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0498372.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0498373.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0498374.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0498375.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0498392.CPY Trojan....2.Agent.co send delete

c:\_RESTORE\TEMP\A0498596.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0498597.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0498601.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0498602.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0498638.CPY Trojan-...2.Apropo.g send delete

c:\_RESTORE\TEMP\A0498641.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0498642.CPY Trojan-....Dyfuca.dx send delete

c:\_RESTORE\TEMP\A0498653.CPY Trojan-...Dyfuca.gen send delete

c:\_RESTORE\TEMP\A0498752.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0498763.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0498774.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0499313.CPY Trojan-...IstBar.gen send delete

c:\_RESTORE\TEMP\A0499330.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499338.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0499341.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0499343.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0499344.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0499347.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0499350.CPY Trojan-...2.Agent.le send delete

c:\_RESTORE\TEMP\A0499354.CPY Trojan....2.Small.bb send delete

c:\_RESTORE\TEMP\A0499367.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0499368.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0499369.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0499387.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0499429.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499437.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0499440.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0499456.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499457.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499458.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499459.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499460.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499461.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499471.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499472.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499473.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499474.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499476.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499477.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499478.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499479.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499480.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499481.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499482.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499483.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499484.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499485.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499487.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499488.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499499.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499536.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0499547.CPY Trojan-...32.Agent.j send delete

c:\_RESTORE\TEMP\A0499564.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0499586.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0499592.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0499593.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0499596.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0499597.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0499598.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0499599.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0499606.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0499610.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0499614.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0499615.CPY Trojan....2.Agent.co send delete

c:\_RESTORE\TEMP\A0500585.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500593.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0500596.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0500597.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0500598.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0500599.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0500606.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0500620.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0500621.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0500622.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0500623.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0500647.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0500657.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0500667.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500668.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500670.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500672.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500673.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0500674.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0501578.CPY Trojan-...IstBar.gen send delete

c:\_RESTORE\TEMP\A0501597.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0501600.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0501601.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0501622.CPY Virus.Win32.Bube.l send delete

c:\_RESTORE\TEMP\A0501624.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0501625.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0502586.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0503577.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0503585.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0503586.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0503587.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0503589.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0503592.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0503593.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0503594.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0503597.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0504585.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0504591.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0504592.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0504595.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0504598.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0504599.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0505591.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0505592.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0505593.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0505594.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0505596.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0505760.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0506770.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0506771.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0506772.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0506773.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0506775.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0506883.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0506889.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0506895.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0507755.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0508760.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0508775.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0508776.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0508777.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0509765.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0509771.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0509772.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0509775.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0510763.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0510774.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0510775.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0510781.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0511771.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0511772.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0511773.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0511776.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0511777.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0511779.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0511788.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0511805.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0511807.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0511808.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0511809.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0511828.CPY Trojan.....Dialer.bi send delete

c:\_RESTORE\TEMP\A0511852.CPY Trojan.....Dialer.bi send delete

c:\_RESTORE\TEMP\A0511863.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0511870.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0511871.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0511874.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0511875.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0511876.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0511879.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0511896.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0511897.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0511898.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0511899.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0511924.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0511991.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0511994.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0512857.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0512865.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0512869.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0512871.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0512872.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0512875.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0512889.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0512892.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0512893.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0512897.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0512961.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0512997.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0513000.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0513003.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0513025.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0513046.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0513047.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0513050.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0513062.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0513063.CPY Trojan-...32.Ieser.a send delete

c:\_RESTORE\TEMP\A0513065.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0513067.CPY Trojan.....Delprot.a send delete

c:\_RESTORE\TEMP\A0513095.CPY Trojan.....Dialer.bi send delete

c:\_RESTORE\TEMP\A0513184.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0513185.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0513186.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0513189.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0514232.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0514262.CPY Trojan....2.Agent.ct send delete

c:\_RESTORE\TEMP\A0514267.CPY Trojan-....Dyfuca.dk send delete

c:\_RESTORE\TEMP\A0514269.CPY Trojan-....IstBar.ij send delete

c:\_RESTORE\TEMP\A0514287.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0514300.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0514301.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0514303.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0515289.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0515296.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0515297.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0515300.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0515304.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0515305.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0516380.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0516386.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0516387.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0516388.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0516390.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0516427.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0517461.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0517462.CPY Trojan-...2.Small.bo send delete

c:\_RESTORE\TEMP\A0517485.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0517502.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0517503.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0518491.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0518496.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0518497.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0518498.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0518500.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0518505.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0518506.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0518507.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0518513.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0519487.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0519495.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0519496.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0519499.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0519503.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0519505.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0519506.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0519507.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0520486.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0520496.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0520497.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0520500.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0520502.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0522473.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0522474.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0522475.CPY Trojan-...2.Adload.a send delete

c:\_RESTORE\TEMP\A0522482.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0522504.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0522508.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0522509.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0522510.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0522512.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0522622.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0523507.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0523551.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0523567.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0523568.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0523569.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0524537.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0524559.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0524560.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0524563.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0524567.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0524569.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0524570.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0525551.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0525582.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0525583.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0525586.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0525588.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0525589.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0530542.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0539554.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539564.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0539565.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0539566.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0539568.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0539603.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539636.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539637.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539638.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539639.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539640.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539641.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539642.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539643.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539659.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539660.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539661.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539662.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539663.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539664.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539665.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539669.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539681.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539703.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539704.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539711.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539719.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539731.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539741.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539751.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539756.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539759.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539760.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539761.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539762.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539763.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539764.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539765.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539766.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539767.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539792.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0539840.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0540604.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0540619.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0540620.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0540630.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0541598.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0541616.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0541634.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0541635.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0541638.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0541640.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0541648.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0541651.CPY Trojan-...2.Agent.dq send delete

c:\_RESTORE\TEMP\A0541678.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0541693.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0542699.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0542710.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0542711.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0542713.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0543683.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0543699.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0543700.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0543703.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0543707.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0543719.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0543744.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0543745.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0543750.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0543753.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0543761.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0543770.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0544732.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0544739.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0544740.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0544743.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0544748.CPY Trojan....artPage.qr send delete

c:\_RESTORE\TEMP\A0544750.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0544751.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0544753.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0544756.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0544763.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0545721.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0545739.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0545740.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0545743.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0545744.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0545749.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0545750.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0546719.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0546738.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0546746.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0546747.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0546748.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0546752.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0546760.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0547739.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0547755.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0547756.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0547758.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0548740.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0548748.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0548749.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0548752.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0548755.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0548756.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0548757.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0548758.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0548762.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0549725.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0549740.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549749.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0549750.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0549753.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0549817.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549826.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549827.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549828.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549855.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0549879.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0549951.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549953.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549954.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549955.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549956.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549957.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0549958.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0550017.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0550029.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0550041.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0550053.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0550065.CPY Trojan....artPage.ix send delete

c:\_RESTORE\TEMP\A0550291.CPY Trojan-...IstBar.gen send delete

c:\_RESTORE\TEMP\A0550308.CPY Trojan-...2.Lookme.g send delete

c:\_RESTORE\TEMP\A0550382.CPY Trojan-...SurfSide.a send delete

c:\_RESTORE\TEMP\A0550480.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0550483.CPY Trojan-...2.Agent.nj send delete

c:\_RESTORE\TEMP\A0550508.CPY Trojan.Win32.Pakes send delete

c:\_RESTORE\TEMP\A0550621.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0550659.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0550675.CPY Trojan....artPage.yf send delete

c:\_RESTORE\TEMP\A0550676.CPY Trojan....LowZones.y send delete

c:\_RESTORE\TEMP\A0550677.CPY Trojan-...2.Agent.ex send delete

c:\_RESTORE\TEMP\A0550679.CPY Trojan....32.Crypt.b send delete

c:\_RESTORE\TEMP\A0550686.CPY Trojan-....Apropo.ab send delete

c:\_RESTORE\TEMP\A0551661.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551670.CPY Trojan-....Small.aut send delete

c:\_RESTORE\TEMP\A0551673.CPY Trojan-...32.Delf.lf send delete

c:\_RESTORE\TEMP\A0551676.CPY Trojan-....Small.aqt send delete

c:\_RESTORE\TEMP\A0551678.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0551684.CPY Trojan-...32.Sobit.e send delete

c:\_RESTORE\TEMP\A0551692.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551693.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551694.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551695.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551696.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551697.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551698.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551699.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551700.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551701.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551755.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551756.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551757.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551758.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551759.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551760.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551761.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551762.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551763.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551764.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551765.CPY Trojan-...32.Delf.dg send delete

c:\_RESTORE\TEMP\A0551766.CPY Trojan-
  • 0

#38
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
To get rid of them files you need to disable system restore go here for infomation on how to do this http://service1.syma...=&osv=&osv_lvl=

After that please post a new Hijackthis log here in a reply.
  • 0

#39
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
when i disable the system restore i have to restart and i'll lose the scan...will i have to re run the scan....if so, is there a quicker scan, this one took about 16 hours to scan....


can i delete all infected files now and then restart and then just scan the restore folder....or just scan it all again....

Edited by wolfpacker, 25 May 2005 - 12:11 PM.

  • 0

#40
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
No you shouldent have to rescan after disabling system restore.
  • 0

Advertisements


#41
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
it's telling me to restart after i disable system restore...so what's going to happen to my kaspersky scan when i restart
  • 0

#42
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
It will stop runnning then you will have to start it again it should take long though as your last log from it was big but them files wont be there this time becuase of your system restore being disabled.
  • 0

#43
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
i'm getting errors when deleting selected files from kaspersky.
  • 0

#44
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
What does it say when its trying to delete them and are you scanning with it in safemode if not it might be best to.
  • 0

#45
wolfpacker

wolfpacker

    Member

  • Topic Starter
  • Member
  • PipPip
  • 30 posts
it was saying that there was an error when trying to delete and that it will delete on restart...so i restarted and here is my new HJT log. i'm still getting a different homepage when i go online....do i need to enable system restore also...


Logfile of HijackThis v1.99.1
Scan saved at 1:09:53 PM, on 5/26/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\PROGRAM FILES\MOTIVE\MOTMON.EXE
C:\WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
C:\PROGRAM FILES\OPTIMUM ONLINE\NETSURF.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\HP OFFICEJET V SERIES\BIN\HPOANT07.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\AIO\SHARED\BIN\HPOEVM07.EXE
C:\WINDOWS\SYSTEM\HPOIPM07.EXE
C:\WINDOWS\TEMP\TD_0001.DIR\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [MotiveMonitor] C:\Program Files\Motive\motmon.exe
O4 - HKLM\..\Run: [HPLogiFinder] \WINDOWS\OPTIONS\CABS\LOGITECH\HP_FINDER.EXE
O4 - HKLM\..\Run: [Optimum Online] C:\Program Files\Optimum Online\Netsurf.exe -tray
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\PROGRAM FILES\PARTYPOKER\IEEXTENSION.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.../kavwebscan.cab

Edited by wolfpacker, 26 May 2005 - 11:13 AM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP