Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Pum virus issue + some other stuff [Solved]


  • This topic is locked This topic is locked

#1
Wolffie

Wolffie

    Member

  • Member
  • PipPip
  • 56 posts
ok so my pc is really messed up

1.first problem was it couldn`t boot from HDD , only from cd-rom wich is kinda weird cause its not the windows xp cd, but the motherboard cd that featured a bunch of programs
i did try and set the "boot from HDD first,2nd and 3rd" and it still said booting from cd-rom
i ignored that and just decided to just keep that cd in there as long as windows could start

after the first boot screen with memory check and where you could enter bios, the next one shows:
"master disk HDD capability.......disabled"
big table thing
then after it starts booting from cd-rom.

2.when i try running safe mode for doing some steps of removing this virus i found in malwarebytes, after it loads a bunch of files needed for safe mode,it restarts, and only if i run "last known good configuration" the system can start
thou i can`t tell if this was always like this or not cause its the first time i try it

3.my parents use it so i can`t tell exactley what they did, but suddently the task manager wouldn`t open,regeddit wouldn`t open, and after i ran the malware scan it found a bunch of stuff, but it couldn`t get rid of 5-6 Pum viruses + 1 trojan

4.also i get an error on start-up
"microsoft visual C++ runtime error
(commodo internet security path)
R6002
floating point not support loaded"


so to sum up all the stuff that i could notice
-malwarebytes site won`t work("firefox can`t find the server"), also when i run the upgrade database, it just gets stuck at 0%
-tsk manager disabled
-regedit disabled
-safemode disabled?
-tried running windows repair from tweaking.com it wouldn`t let me start it "not have the authority to run this setup" or something even thou i was logged as administrator
-google chrome only showed one big blank page(same color as default desktop color)
-when i tried reinstalling google chrome it just loaded for a second then stopped, with no error message this time



MALWAREBYTES LOG


Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.01.14.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 6.0.2900.5512
Logan :: HOME-FA201A11EA [administrator]

5/7/2013 1:14:55 PM
mbam-log-2013-05-07 (13-14-55).txt

Scan type: Full scan (C:\|D:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 283018
Time elapsed: 1 hour(s), 20 minute(s), 18 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Taskman (Trojan.Agent) -> Data: c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe -> Delete on reboot.

Registry Data Items Detected: 5
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Taskman (Worm.Autorun.B) -> Bad: (c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe) Good: () -> Delete on reboot.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools (PUM.Hijack.Regedit) -> Bad: (1) Good: (0) -> Delete on reboot.
HKLM\SOFTWARE\Microsoft\Security Center|AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Delete on reboot.
HKLM\SOFTWARE\Microsoft\Security Center|FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Delete on reboot.
HKLM\SOFTWARE\Microsoft\Security Center|UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Delete on reboot.

Folders Detected: 1
C:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013 (Worm.AutoRun.Gen) -> Quarantined and deleted successfully.

Files Detected: 7
C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions\trash\5affxtbr-bs@MyWebFace_5a.com\content\MyWebFace.exe (PUP.FunWebProducts) -> No action taken.
C:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe (Worm.Autorun.B) -> Quarantined and deleted successfully.
D:\Program files\Hijackthis\HijackThis.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Program files\Internet Explorer\iexplore.exe (Trojan.FakeMS) -> Quarantined and deleted successfully.
D:\Program files\Winampppp\winampa.exe (Trojan.Zbot) -> Quarantined and deleted successfully.
D:\VIAUSB2V256-L\_ISDel.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Worm.AutoRun.Gen) -> Quarantined and deleted successfully.

(end)




OTL:

OTL logfile created on: 5/7/2013 4:00:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Logan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.97 Gb Available Physical Memory | 65.02% Memory free
2.11 Gb Paging File | 1.70 Gb Available in Paging File | 80.75% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.65 Gb Total Space | 1.34 Gb Free Space | 9.18% Space Free | Partition Type: NTFS
Drive D: | 97.13 Gb Total Space | 12.94 Gb Free Space | 13.33% Space Free | Partition Type: NTFS
Drive E: | 585.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 454.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HOME-FA201A11EA | User Name: Logan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/07 16:00:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Logan\My Documents\Downloads\OTL.exe
PRC - [2013/04/12 23:58:29 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/12/09 20:22:26 | 000,152,576 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2010/04/19 14:47:26 | 000,719,688 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/11/15 13:20:20 | 000,151,552 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE


========== Modules (No Company Name) ==========

MOD - [2013/04/12 23:58:16 | 003,133,336 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/01/28 13:09:50 | 014,586,888 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll
MOD - [2008/04/14 03:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (MSDTC)
SRV - File not found [Unknown (-1) | Stopped] -- -- (diovmvo)
SRV - [2013/03/08 20:30:01 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/28 13:09:51 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/12/07 03:02:47 | 000,504,648 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/04/19 14:42:36 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Unknown (-1) | Unknown (-1) | Unknown] -- -- (diovmvo)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\llrjkn.sys -- (abp470n5)
DRV - [2013/01/08 21:47:56 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/12/14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/11 22:13:48 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2012/03/11 22:13:46 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdguard.sys -- (cmdGuard)
DRV - [2012/03/11 22:13:46 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdhlp.sys -- (cmdHlp)
DRV - [2010/02/25 12:18:08 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2008/04/13 21:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum)
DRV - [2004/11/17 14:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2004/08/04 01:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139)
DRV - [2004/08/04 01:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/16 09:19:52 | 000,070,400 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys -- (RTL8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 23:58:40 | 000,000,000 | ---D | M]

[2012/03/07 21:53:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions\trash
[2013/04/12 23:57:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 23:58:38 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/12 23:57:55 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/12 23:57:55 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.ro/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: c\u0103utare Google = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2001/08/23 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.96.7.88 95.77.94.88
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{561FCA04-03EC-4ECD-A742-B656D6FA86EF}: DhcpNameServer = 78.96.7.88 95.77.94.88
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/01/23 21:58:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/10/04 10:57:04 | 000,000,043 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [2001/06/20 16:23:22 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{0b33f200-58f7-11e2-b569-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{0b33f200-58f7-11e2-b569-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0b33f200-58f7-11e2-b569-00e04c811a7b}\Shell\AutoRun\command - "" = F:\setup.exe -- [2000/10/05 17:00:06 | 000,054,272 | R--- | M] (InstallShield Software Corporation)
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\open\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutOplAy\cOmmANd - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutoRun\command - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\exPloRE\COMMANd - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\OpEn\CommAnd - "" = G:\udgtms.pif
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutOplay\cOmMaND - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutoRun\command - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\Explore\COmMANd - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\open\ComMAnD - "" = G:\rygj.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/07 15:48:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Logan\Desktop\RK_Quarantine
[2013/05/07 15:28:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2013/05/07 13:08:43 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2013/04/12 23:57:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/07 16:04:10 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/05/07 15:29:35 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/05/07 15:29:35 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/05/07 15:25:09 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/05/07 15:24:54 | 1610,141,696 | -HS- | M] () -- C:\hiberfil.sys
[2013/04/23 15:02:22 | 000,034,799 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:59 | 000,360,457 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/04/19 22:00:40 | 000,009,216 | ---- | M] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/23 15:02:20 | 000,034,799 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:54 | 000,360,457 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/01/28 13:01:16 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2013/01/07 21:54:26 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2012/12/23 04:05:38 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/08/02 10:17:08 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/15 17:04:07 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/02/15 17:02:48 | 000,189,792 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/15 15:49:25 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/02/15 15:25:50 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2012/02/15 15:25:46 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2012/02/15 15:25:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2012/02/15 15:17:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/02/15 15:10:38 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 03:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 03:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >



OTL EXTRAS


OTL Extras logfile created on: 5/7/2013 4:00:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Logan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.97 Gb Available Physical Memory | 65.02% Memory free
2.11 Gb Paging File | 1.70 Gb Available in Paging File | 80.75% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.65 Gb Total Space | 1.34 Gb Free Space | 9.18% Space Free | Partition Type: NTFS
Drive D: | 97.13 Gb Total Space | 12.94 Gb Free Space | 13.33% Space Free | Partition Type: NTFS
Drive E: | 585.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 454.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HOME-FA201A11EA | User Name: Logan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"UacDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"FirewallOverride" = 1
"UpdatesDisableNotify" = 1
"UacDisableNotify" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"4559:TCP" = 4559:TCP:*:Enabled:grcxjap
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent -- (BitTorrent, Inc.)
"G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe:*:Enabled:ipsec
"C:\WINDOWS\Explorer.EXE" = C:\WINDOWS\Explorer.EXE:*:Enabled:ipsec -- (Microsoft Corporation)
"c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe" = c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe:*:Enabled:ipsec
"C:\Program Files\Winamp\winampa.exe" = C:\Program Files\Winamp\winampa.exe:*:Enabled:ipsec -- (Nullsoft, Inc.)
"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" = C:\Program Files\COMODO\COMODO Internet Security\cfp.exe:*:Enabled:ipsec -- (COMODO)
"C:\WINDOWS\SOUNDMAN.EXE" = C:\WINDOWS\SOUNDMAN.EXE:*:Enabled:ipsec -- (Realtek Semiconductor Corp.)
"C:\WINDOWS\system32\netsh.exe" = C:\WINDOWS\system32\netsh.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe:*:Enabled:ipsec
"C:\WINDOWS\system32\userinit.exe" = C:\WINDOWS\system32\userinit.exe:*:Enabled:ipsec -- (Microsoft Corporation)
"C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" = C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:ipsec
"C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" = C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe:*:Enabled:ipsec -- (InstallShield Software Corporation)
"C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe" = C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe:*:Enabled:ipsec -- (Adobe Systems Incorporated)
"C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe" = C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe:*:Enabled:ipsec
"C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe" = C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe:*:Enabled:ipsec -- (TuneUp Software)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{BBF10B37-4ED3-11D5-A818-00500435FC18}" = Gothic
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}" = COMODO Internet Security
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Comodo Dragon" = Comodo Dragon
"COMODO GeekBuddy" = COMODO GeekBuddy
"DAEMON Tools Lite" = DAEMON Tools Lite
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR 4.01 (32-bit)
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 5/7/2013 7:40:33 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 5/7/2013 7:46:20 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 5/7/2013 8:03:25 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/7/2013 8:03:25 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 5/7/2013 8:05:45 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/7/2013 8:30:52 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/7/2013 8:30:52 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.

Error - 5/7/2013 8:37:56 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/7/2013 8:41:37 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

Error - 5/7/2013 8:48:25 AM | Computer Name = HOME-FA201A11EA | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: The server name or address could not be resolved

[ System Events ]
Error - 5/7/2013 7:51:19 AM | Computer Name = HOME-FA201A11EA | Source = Service Control Manager | ID = 7023
Description = The Config Image service terminated with the following error: %%1114

Error - 5/7/2013 8:08:26 AM | Computer Name = HOME-FA201A11EA | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{561FCA04-03EC-4ECD-A742-B656D6FA86EF}. The
backup browser is stopping.

Error - 5/7/2013 8:10:10 AM | Computer Name = HOME-FA201A11EA | Source = Service Control Manager | ID = 7000
Description = The abp470n5 service failed to start due to the following error: %%2

Error - 5/7/2013 8:10:10 AM | Computer Name = HOME-FA201A11EA | Source = Service Control Manager | ID = 7000
Description = The abp470n5 service failed to start due to the following error: %%2

Error - 5/7/2013 8:14:21 AM | Computer Name = HOME-FA201A11EA | Source = Service Control Manager | ID = 7023
Description = The Config Image service terminated with the following error: %%1114

Error - 5/7/2013 8:16:05 AM | Computer Name = HOME-FA201A11EA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 5/7/2013 8:16:05 AM | Computer Name = HOME-FA201A11EA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 5/7/2013 8:25:30 AM | Computer Name = HOME-FA201A11EA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 5/7/2013 8:25:33 AM | Computer Name = HOME-FA201A11EA | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 5/7/2013 8:26:35 AM | Computer Name = HOME-FA201A11EA | Source = Service Control Manager | ID = 7023
Description = The Config Image service terminated with the following error: %%1114


< End of report >
  • 0

Advertisements


#2
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts
Hello, Wolffie and welcome to GeeksToGo!

You can call me Phel and today I will try to help you with your trouble.

Please, read these instructions carefully, because they contain some very useful information.

Please, let me know, if you don't understand something. It is really important to understand any instruction. Also, please read all instructions carefully before performing them. Feel free to ask questions, if you aren't sure.

Please, be patient. You should stay here until your computer will become really clean. Malware Removal isn't very fast procedure, it usually has multiple steps, but result should be glad.;)

Please, wait for a while now, currently I'm analyzing your logs. Please note, that my answers could come with a slight delay, because they are checked by my teacher.
  • 0

#3
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
hey, phel! take your time
its no hurry at all, that pc isn`t used very much
but its about time i should get it fixed
  • 0

#4
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts
Hello,

Fix is here!

Please, follow these steps:

Download Dr.Web CureIt .
  • Doubleclick the drweb-cureit.exe file to open it.
  • A window will open offerring a choice of EPM or Standard Mode
  • Chose EPM
  • A license and updates window will appear. If necessary update, otherwise go to the wrench at the top right and check the box Automatically apply actions to threats.
  • Check the box "I agree to participate..." and click Continue
  • You will not be able to use your computer until the scan is finished. It generally takes only a short time say... around 15/20 mins.
  • Dr Web will scan your computer. When finished close Dr Web.
  • A report is saved to C:\users\....\Doctor Web named cureit.log. Copy and paste the contents back here.

  • 0

#5
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
hey,sorry for the late reply

the link actually didnt work on this pc i got the :cannot find server" error again
but i managed to download it and sent it trough email
starting scan now, will post the log soon

actually i get "error 1722" and says "scan couldnt start" :S


here is the log thou..might help

=============================================================================
Dr.Web Scanner SE for Windows v8.1.0.04290
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/05/10 20:13:37
Module location : c:\documents and settings\logan\local settings\temp\8181B448-E996C270-29D17E50-76D81670\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
=============================================================================
Dr.Web Scanner SE for Windows v8.1.0.04290
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/05/10 20:16:24
Module location : c:\documents and settings\logan\local settings\temp\FA45AA3A-C6BB2D3C-DD9427C6-74093A6C\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Error load engine. Error code: 0x2
Using c:\documents and settings\logan\local settings\temp\FA45AA3A-C6BB2D3C-DD9427C6-74093A6C\ges1krvp.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)
=============================================================================
Dr.Web Scanner SE for Windows v8.1.0.04290
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/05/10 20:31:50
Module location : c:\documents and settings\logan\local settings\temp\A28E26CD-7EC0931F-EE087644-E6471C36\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
=============================================================================
Dr.Web Scanner SE for Windows v8.1.0.04290
© Doctor Web, Ltd., 1992-2013
Scan session started 2013/05/10 20:32:52
Module location : c:\documents and settings\logan\local settings\temp\262C128B-B5D22057-569D186B-D647A660\
=============================================================================
OPTION [Automatic Apply Actions] NO
OPTION [Turn Off Computer After Scan] NO
OPTION [Use Sound Alerts] NO
OPTION [Block Network] NO
OPTION [Protect Process] NO
OPTION [Protect Raw Disk] NO
Using language: "English"
Error load engine. Error code: 0x2
Using c:\documents and settings\logan\local settings\temp\262C128B-B5D22057-569D186B-D647A660\ges1krvp.key as Dr.Web ® Key file
This Dr.Web ® Key is for 1 computer (A User)

Edited by Wolffie, 10 May 2013 - 11:40 AM.

  • 0

#6
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts
Hello,

Please, follow these steps:

  • Download and unpack the file SalityKiller.exe in the root of disk C:\.
  • Press Win+R key sequence.
  • In the new window copy and paste the following:
  • C:\SalityKiller.exe -l C:\sklog.txt
  • Click OK button.
  • A reboot might be required after disinfection.
  • Download the file Sality_RegKeys.zip.
  • Unpack the file Sality_RegKeys.zip (using WinZip).
  • Run the file Disable_autorun.reg from the archive Sality_RegKeys.zip.
  • Click Yes to confirm adding the information to the registry.
  • Post contents of C:\sklog.txt file in your next message.

  • 0

#7
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
holy crap? :lol:


17:32:38:330 3004 scanning threads ...
17:32:39:799 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:39:799 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:39:861 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:39:861 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:39:908 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:39:955 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:018 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:064 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:064 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:111 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:143 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:189 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:236 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:236 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:283 3004 Infected thread was killed in process SOUNDMAN.EXE with PID 1900
17:32:40:299 3004 Infected thread was killed in process winampa.exe with PID 1908
17:32:40:299 3004 Infected thread was killed in process winampa.exe with PID 1908
17:32:40:439 3004 Infected thread was killed in process YahooMessenger.exe with PID 2012
17:32:40:471 3004 Infected thread was killed in process YahooMessenger.exe with PID 2012
17:32:44:814 3004
17:32:44:814 3004 scanning processes ...
17:32:44:846 3004 C:\WINDOWS\SOUNDMAN.EXE infected Virus.Win32.Sality.aa ...17:32:45:158 3004 terminated
17:32:45:189 3004 C:\WINDOWS\SOUNDMAN.EXE infected Virus.Win32.Sality.aa ...17:32:45:189 3004 cured
17:32:45:189 3004 C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe infected Virus.Win32.Sality.aa ...17:32:45:518 3004 terminated
17:32:45:549 3004 C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe infected Virus.Win32.Sality.aa ...17:32:45:549 3004 cured
17:32:45:580 3004
17:32:45:580 3004 fixing registry ...
17:32:45:580 3004 SalityRegCure: Restoring general registry keys
17:32:45:580 1148
Monitoring thread started
17:32:45:846 3004 SalityRegCure: Fixing system.ini
17:32:46:033 3004
17:32:46:033 3004 scanning drives ...
17:32:46:033 3004 scanning C:\ ...
17:32:46:674 3004 C:\Documents and Settings\All Users\Application Data\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AA1000000001}\setup.exe infected Virus.Win32.Sality.aa ...17:32:46:674 3004 cured
17:32:52:986 3004 C:\Documents and Settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe infected Virus.Win32.Sality.aa ...17:32:52:986 3004 cured
17:33:09:268 3004 C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions\trash\5affxtbr-bs@MyWebFace_5a.com\content\MyWebFace.exe infected Virus.Win32.Sality.aa ...17:33:09:268 3004 cured
17:36:22:674 3004 C:\Documents and Settings\Logan\Local Settings\Temp\2Vb1Rpr8.exe.part infected Virus.Win32.Sality.aa ...17:36:22:674 3004 cured
17:36:24:846 3004 C:\Documents and Settings\Logan\Local Settings\Temp\cis132f31\cmdinstall.exe infected Virus.Win32.Sality.aa ...17:36:24:846 3004 cured
17:36:27:189 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\CDSTART.EXE infected Virus.Win32.Sality.aa ...17:36:27:189 3004 cured
17:36:27:455 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\CommonFi\SYMSHARE\SMNLnch.exe infected Virus.Win32.Sality.aa ...17:36:27:455 3004 cured
17:36:27:736 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\APP\ccIMScn.exe infected Virus.Win32.Sality.aa ...17:36:27:736 3004 cured
17:36:28:643 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\APP\NAVStub.exe infected Virus.Win32.Sality.aa ...17:36:28:643 3004 cured
17:36:29:221 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\APP\OPScan.exe infected Virus.Win32.Sality.aa ...17:36:29:221 3004 cured
17:36:29:346 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\APP\qconsole.exe infected Virus.Win32.Sality.aa ...17:36:29:346 3004 cured
17:36:30:236 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\BootWarn.exe infected Virus.Win32.Sality.aa ...17:36:30:236 3004 cured
17:36:30:283 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\External\NORTON\CfgWiz.exe infected Virus.Win32.Sality.aa ...17:36:30:299 3004 cured
17:36:30:518 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\NAV\Omigrate.exe infected Virus.Win32.Sality.aa ...17:36:30:518 3004 cured
17:36:31:924 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\asCore\COMMON\SYMSHARE\AntiSpam\EudoHelp.exe infected Virus.Win32.Sality.aa ...17:36:31:924 3004 cured
17:36:32:643 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\Firewall\APP\HNetWiz.exe infected Virus.Win32.Sality.aa ...17:36:32:643 3004 cured
17:36:32:955 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\ISCommon\APP\AlertAst.exe infected Virus.Win32.Sality.aa ...17:36:32:955 3004 cured
17:36:33:127 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\ISCommon\APP\ALEScan.exe infected Virus.Win32.Sality.aa ...17:36:33:127 3004 cured
17:36:33:158 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\ISCommon\APP\ALEUpdat.exe infected Virus.Win32.Sality.aa ...17:36:33:174 3004 cured
17:36:33:221 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\ISCommon\APP\ccEmFlSv.exe infected Virus.Win32.Sality.aa ...17:36:33:221 3004 cured
17:36:33:486 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\ISCommon\APP\iamstats.exe infected Virus.Win32.Sality.aa ...17:36:33:486 3004 cured
17:36:34:455 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\PControl\APP\PCWiz.exe infected Virus.Win32.Sality.aa ...17:36:34:455 3004 cured
17:36:34:611 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\PControl\APP\UrlLstCk.exe infected Virus.Win32.Sality.aa ...17:36:34:611 3004 cured
17:36:34:768 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\PControl\APP\Urlupdat.exe infected Virus.Win32.Sality.aa ...17:36:34:768 3004 cured
17:36:35:752 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\Setup\SYMSHARE\AntiSpam\EudoHelp.exe infected Virus.Win32.Sality.aa ...17:36:35:752 3004 cured
17:36:35:877 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\SymLT\CfgWiz.exe infected Virus.Win32.Sality.aa ...17:36:35:877 3004 cured
17:36:36:002 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Setup\SymLT\SYMSHARE\SMNLnch.exe infected Virus.Win32.Sality.aa ...17:36:36:002 3004 cured
17:36:36:455 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\ccCommon\ccCommon\ccLgView.exe infected Virus.Win32.Sality.aa ...17:36:36:455 3004 cured
17:36:36:549 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\ccCommon\ccCommon\ccPwdSvc.exe infected Virus.Win32.Sality.aa ...17:36:36:549 3004 cured
17:36:37:799 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\FRE\FREMSI.exe infected Virus.Win32.Sality.aa ...17:36:37:799 3004 cured
17:36:38:408 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\FRE\FREUpdt.exe infected Virus.Win32.Sality.aa ...17:36:38:408 3004 cured
17:36:39:736 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LiveReg\Advisor.exe infected Virus.Win32.Sality.aa ...17:36:39:736 3004 cured
17:36:39:814 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LiveReg\IraLrShl.exe infected Virus.Win32.Sality.aa ...17:36:39:814 3004 cured
17:36:40:221 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LiveReg\symcsub.exe infected Virus.Win32.Sality.aa ...17:36:40:221 3004 cured
17:36:40:314 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LiveReg\VcClnUp.exe infected Virus.Win32.Sality.aa ...17:36:40:314 3004 cured
17:36:40:377 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LiveReg\VcSetup.exe infected Virus.Win32.Sality.aa ...17:36:40:377 3004 cured
17:36:40:705 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\LUpdate\LUSetup.exe infected Virus.Win32.Sality.aa ...17:36:40:705 3004 cured
17:36:40:846 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\MSI\InstMSIa.exe infected Virus.Win32.Sality.aa ...17:36:40:846 3004 cured
17:36:40:908 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\MSI\InstMSIw.exe infected Virus.Win32.Sality.aa ...17:36:40:908 3004 cured
17:36:40:939 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\NISTools\ISRlRstr.exe infected Virus.Win32.Sality.aa ...17:36:40:939 3004 cured
17:36:42:002 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SEVINST\sevinst.exe infected Virus.Win32.Sality.aa ...17:36:42:002 3004 cured
17:36:42:236 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SPBBC\Common\SYMSHARE\SPBBC\UpdMgr.exe infected Virus.Win32.Sality.aa ...17:36:42:236 3004 cured
17:36:42:424 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymLnch\SymLnch.exe infected Virus.Win32.Sality.aa ...17:36:42:424 3004 cured
17:36:42:611 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymNet\SymNet\SYMSHARE\IDS\IdsInst.exe infected Virus.Win32.Sality.aa ...17:36:42:611 3004 cured
17:36:42:768 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymNet\SymNet\SYMSHARE\SNDInst.exe infected Virus.Win32.Sality.aa ...17:36:42:768 3004 cured
17:36:42:830 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymNet\SymNet\SYMSHARE\SNDSrvc.exe infected Virus.Win32.Sality.aa ...17:36:42:830 3004 cured
17:36:43:252 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymSC\SYMWMIAV\SymSC\UsrPrmpt.exe infected Virus.Win32.Sality.aa ...17:36:43:252 3004 cured
17:36:43:377 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\Support\SymSC\SYMWMIIS\SymSC\UsrPrmpt.exe infected Virus.Win32.Sality.aa ...17:36:43:377 3004 cured
17:36:43:643 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\SymSetup.EXE infected Virus.Win32.Sality.aa ...17:36:43:643 3004 cured
17:36:43:799 3004 C:\Documents and Settings\Logan\Local Settings\Temp\Norton Internet Security 2005\VirusDef\DefInst.exe infected Virus.Win32.Sality.aa ...17:36:43:799 3004 cured
17:39:14:283 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 18.0 (1).exe infected Virus.Win32.Sality.aa ...17:39:14:283 3004 cured
17:39:15:861 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 18.0 (2).exe infected Virus.Win32.Sality.aa ...17:39:15:861 3004 cured
17:39:16:799 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 18.0.1.exe infected Virus.Win32.Sality.aa ...17:39:16:799 3004 cured
17:39:17:658 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 18.0.exe infected Virus.Win32.Sality.aa ...17:39:17:658 3004 cured
17:39:20:252 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 9.0.1 (1).exe infected Virus.Win32.Sality.aa ...17:39:20:252 3004 cured
17:39:21:924 3004 C:\Documents and Settings\Logan\My Documents\Downloads\Firefox Setup 9.0.1.exe infected Virus.Win32.Sality.aa ...17:39:21:924 3004 cured
17:39:22:377 3004 C:\Documents and Settings\Logan\My Documents\Downloads\iLividSetup.exe infected Virus.Win32.Sality.aa ...17:39:22:377 3004 cured
17:39:22:893 3004 C:\Documents and Settings\Logan\My Documents\Downloads\msgr11us.exe infected Virus.Win32.Sality.aa ...17:39:22:893 3004 cured
17:39:24:627 3004 C:\Documents and Settings\Logan\My Documents\Downloads\The_KMPlayer_2.9.4.1434_EN.exe infected Virus.Win32.Sality.aa ...17:39:24:627 3004 cured
17:39:26:752 3004 C:\Documents and Settings\Logan\My Documents\Downloads\winamp5623_full_emusic-7plus_all.exe infected Virus.Win32.Sality.aa ...17:39:26:752 3004 cured
17:39:27:096 3004 C:\Documents and Settings\Logan\My Documents\Downloads\wrar401.exe infected Virus.Win32.Sality.aa ...17:39:27:096 3004 cured
17:39:27:158 3004 C:\Documents and Settings\Logan\My Documents\Morrowind.exe infected Virus.Win32.Sality.aa ...17:39:27:158 3004 cured
17:40:05:033 3004 C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe infected Virus.Win32.Sality.aa ...17:40:05:033 3004 cured
17:40:07:439 3004 C:\Program Files\AvRack\rtlrack.exe infected Virus.Win32.Sality.aa ...17:40:07:439 3004 cured
17:40:08:877 3004 C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe infected Virus.Win32.Sality.aa ...17:40:08:877 3004 cured
17:40:09:346 3004 C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE infected Virus.Win32.Sality.aa ...17:40:09:346 3004 cured
17:40:09:768 3004 C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE infected Virus.Win32.Sality.aa ...17:40:09:768 3004 cured
17:40:10:721 3004 C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPVIEW.EXE infected Virus.Win32.Sality.aa ...17:40:10:721 3004 cured
17:40:11:268 3004 C:\Program Files\Common Files\Microsoft Shared\MSInfo\OINFOP11.EXE infected Virus.Win32.Sality.aa ...17:40:11:268 3004 cured
17:40:11:955 3004 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE infected Virus.Win32.Sality.aa ...17:40:11:955 3004 cured
17:40:12:955 3004 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE infected Virus.Win32.Sality.aa ...17:40:12:955 3004 cured
17:40:18:580 3004 C:\Program Files\Common Files\Microsoft Shared\Web Components\11\DFUICOM.EXE infected Virus.Win32.Sality.aa ...17:40:18:580 3004 cured
17:40:23:361 3004 C:\Program Files\Comodo\COMODO GeekBuddy\uninstall.exe infected Virus.Win32.Sality.aa ...17:40:23:361 3004 cured
17:40:23:455 3004 C:\Program Files\Comodo\COMODO Internet Security\cavscan.exe infected Virus.Win32.Sality.aa ...17:40:23:455 3004 cured
17:40:23:518 3004 C:\Program Files\Comodo\COMODO Internet Security\cfp.exe infected Virus.Win32.Sality.aa ...17:40:23:518 3004 cured
17:40:23:564 3004 C:\Program Files\Comodo\COMODO Internet Security\cfpconfg.exe infected Virus.Win32.Sality.aa ...17:40:23:564 3004 cured
17:40:23:643 3004 C:\Program Files\Comodo\COMODO Internet Security\cfpupdat.exe infected Virus.Win32.Sality.aa ...17:40:23:643 3004 cured
17:40:23:971 3004 C:\Program Files\Comodo\COMODO Internet Security\cmdinstall.exe infected Virus.Win32.Sality.aa ...17:40:23:971 3004 cured
17:40:24:064 3004 C:\Program Files\Comodo\COMODO Internet Security\crashrep.exe infected Virus.Win32.Sality.aa ...17:40:24:064 3004 cured
17:40:24:955 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cavscan.exe infected Virus.Win32.Sality.aa ...17:40:24:955 3004 cured
17:40:25:033 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cfp.exe infected Virus.Win32.Sality.aa ...17:40:25:033 3004 cured
17:40:25:205 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cfpconfg.exe infected Virus.Win32.Sality.aa ...17:40:25:205 3004 cured
17:40:25:346 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cfpupdat.exe infected Virus.Win32.Sality.aa ...17:40:25:346 3004 cured
17:40:25:518 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cmdagent.exe infected Virus.Win32.Sality.aa ...17:40:25:533 3004 cured
17:40:25:799 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\cmdinstall.exe infected Virus.Win32.Sality.aa ...17:40:25:799 3004 cured
17:40:25:971 3004 C:\Program Files\Comodo\COMODO Internet Security\repair\crashrep.exe infected Virus.Win32.Sality.aa ...17:40:25:971 3004 cured
17:40:35:814 3004 C:\Program Files\Comodo\Dragon\uninstall.exe infected Virus.Win32.Sality.aa ...17:40:35:814 3004 cured
17:40:36:252 3004 C:\Program Files\DAEMON Tools Lite\DTHelper.exe infected Virus.Win32.Sality.aa ...17:40:36:268 3004 cured
17:40:36:455 3004 C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe infected Virus.Win32.Sality.aa ...17:40:36:455 3004 cured
17:40:38:705 3004 C:\Program Files\DAEMON Tools Lite\uninst.exe infected Virus.Win32.Sality.aa ...17:40:38:705 3004 cured
17:40:38:893 3004 C:\Program Files\InstallShield Installation Information\{7C21EEE0-E6FD-11D4-BD19-00D0B702AEC0}\Setup.exe infected Virus.Win32.Sality.aa ...17:40:38:893 3004 cured
17:40:39:033 3004 C:\Program Files\InstallShield Installation Information\{94FB906A-CF42-4128-A509-D353026A607E}\Setup.exe infected Virus.Win32.Sality.aa ...17:40:39:033 3004 cured
17:40:39:174 3004 C:\Program Files\InstallShield Installation Information\{BBF10B37-4ED3-11D5-A818-00500435FC18}\Setup.exe infected Virus.Win32.Sality.aa ...17:40:39:174 3004 cured
17:40:39:549 3004 C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\Setup.exe infected Virus.Win32.Sality.aa ...17:40:39:549 3004 cured
17:40:41:893 3004 C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe infected Virus.Win32.Sality.aa ...17:40:41:893 3004 cured
17:40:56:455 3004 C:\Program Files\Microsoft Office\OFFICE11\1033\MSOHELP.EXE infected Virus.Win32.Sality.aa ...17:40:56:455 3004 cured
17:41:02:283 3004 C:\Program Files\Microsoft Office\OFFICE11\1033\UNPACK.EXE infected Virus.Win32.Sality.aa ...17:41:02:283 3004 cured
17:41:04:908 3004 C:\Program Files\Microsoft Office\OFFICE11\DSSM.EXE infected Virus.Win32.Sality.aa ...17:41:04:908 3004 cured
17:41:05:377 3004 C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE infected Virus.Win32.Sality.aa ...17:41:05:377 3004 cured
17:41:06:018 3004 C:\Program Files\Microsoft Office\OFFICE11\GRAPH.EXE infected Virus.Win32.Sality.aa ...17:41:06:018 3004 cured
17:41:06:533 3004 C:\Program Files\Microsoft Office\OFFICE11\MSACCESS.EXE infected Virus.Win32.Sality.aa ...17:41:06:533 3004 cured
17:41:06:814 3004 C:\Program Files\Microsoft Office\OFFICE11\MSOHTMED.EXE infected Virus.Win32.Sality.aa ...17:41:06:814 3004 cured
17:41:07:330 3004 C:\Program Files\Microsoft Office\OFFICE11\MSPUB.EXE infected Virus.Win32.Sality.aa ...17:41:07:330 3004 cured
17:41:07:908 3004 C:\Program Files\Microsoft Office\OFFICE11\MSTORDB.EXE infected Virus.Win32.Sality.aa ...17:41:07:908 3004 cured
17:41:08:346 3004 C:\Program Files\Microsoft Office\OFFICE11\MSTORE.EXE infected Virus.Win32.Sality.aa ...17:41:08:346 3004 cured
17:41:09:471 3004 C:\Program Files\Microsoft Office\OFFICE11\PROFLWIZ.EXE infected Virus.Win32.Sality.aa ...17:41:09:471 3004 cured
17:41:13:846 3004 C:\Program Files\Mozilla Firefox\maintenanceservice_installer.exe infected Virus.Win32.Sality.aa ...17:41:13:846 3004 cured
17:41:15:424 3004 C:\Program Files\Mozilla Firefox\uninstall\helper.exe infected Virus.Win32.Sality.aa ...17:41:15:424 3004 cured
17:41:15:705 3004 C:\Program Files\Mozilla Firefox\webapp-uninstaller.exe infected Virus.Win32.Sality.aa ...17:41:15:721 3004 cured
17:41:16:033 3004 C:\Program Files\Mozilla Maintenance Service\Uninstall.exe infected Virus.Win32.Sality.aa ...17:41:16:033 3004 cured
17:41:16:127 3004 C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe infected Virus.Win32.Sality.aa ...17:41:16:127 3004 cured
17:41:16:314 3004 C:\Program Files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe infected Virus.Win32.Sality.aa ...17:41:16:314 3004 cured
17:41:16:439 3004 C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe infected Virus.Win32.Sality.aa ...17:41:16:439 3004 cured
17:41:51:893 3004 C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe infected Virus.Win32.Sality.aa ...17:41:51:893 3004 cured
17:41:53:439 3004 C:\Program Files\uTorrent\uTorrent.exe infected Virus.Win32.Sality.aa ...17:41:53:439 3004 cured
17:42:06:377 3004 C:\Program Files\Winamp\UninstWA.exe infected Virus.Win32.Sality.aa ...17:42:06:377 3004 cured
17:42:06:611 3004 C:\Program Files\Winamp\winampa.exe infected Virus.Win32.Sality.aa ...17:42:06:611 3004 cured
17:42:07:033 3004 C:\Program Files\Winamp Detect\UninstWaDetect.exe infected Virus.Win32.Sality.aa ...17:42:07:033 3004 cured
17:42:07:283 3004 C:\Program Files\Windows Media Player\dlimport.exe infected Virus.Win32.Sality.aa ...17:42:07:283 3004 cured
17:42:07:752 3004 C:\Program Files\Windows Media Player\wmsetsdk.exe infected Virus.Win32.Sality.aa ...17:42:07:752 3004 cured
17:42:09:205 3004 C:\Program Files\Yahoo!\Common\unyt.exe infected Virus.Win32.Sality.aa ...17:42:09:205 3004 cured
17:42:09:283 3004 C:\Program Files\Yahoo!\Common\unyt_wrap.exe infected Virus.Win32.Sality.aa ...17:42:09:283 3004 cured
17:42:20:314 3004 C:\Program Files\Yahoo!\Messenger\UNWISE.EXE infected Virus.Win32.Sality.aa ...17:42:20:314 3004 cured
17:42:20:627 3004 C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe infected Virus.Win32.Sality.aa ...17:42:20:627 3004 cured
17:42:20:814 3004 C:\Program Files\Yahoo!\SoftwareUpdate\Uninst_AutoUpdater.exe infected Virus.Win32.Sality.aa ...17:42:20:830 3004 cured
17:47:59:486 3004 scanning D:\ ...
17:48:12:564 3004 D:\Black And White - Keygen.exe infected Virus.Win32.Sality.aa ...17:48:12:564 3004 cured
17:48:35:080 3004 D:\d\HyperIM\HyperIM.exe infected Virus.Win32.Sality.aa ...17:48:35:080 3004 cured
17:48:35:939 3004 D:\d\HyperIM\uninstall.exe infected Virus.Win32.Sality.aa ...17:48:35:939 3004 cured
17:48:37:564 3004 D:\ddasdedsk\Adobe\Audition 3.0 Trial\Adobe Audition 3.0\Audition 3.0 Setup.exe infected Virus.Win32.Sality.aa ...17:48:37:564 3004 cured
17:48:37:830 3004 D:\ddasdedsk\Adobe\Audition 3.0 Trial\Adobe Audition 3.0\instmsiw.exe infected Virus.Win32.Sality.aa ...17:48:37:830 3004 cured
17:48:48:049 3004 D:\ddasdedsk\ga\Garena\uninst.exe infected Virus.Win32.Sality.aa ...17:48:48:049 3004 cured
17:48:48:299 3004 D:\ddasdedsk\ga\Garena\update.exe infected Virus.Win32.Sality.aa ...17:48:48:299 3004 cured
17:48:48:502 3004 D:\ddasdedsk\ga\Garena\update2.exe infected Virus.Win32.Sality.aa ...17:48:48:502 3004 cured
17:48:52:564 3004 D:\ddasdedsk\UnityWebPlayer.exe infected Virus.Win32.Sality.aa ...17:48:52:564 3004 cured
17:49:11:283 3004 D:\Desktop\ChromeSetup.exe infected Virus.Win32.Sality.aa ...17:49:11:283 3004 cured
17:49:11:643 3004 D:\Desktop\CJB5200EN.exe infected Virus.Win32.Sality.aa ...17:49:11:643 3004 cured
17:49:12:174 3004 D:\Desktop\SaveVal.exe infected Virus.Win32.Sality.aa ...17:49:12:174 3004 cured
17:49:14:111 3004 D:\Dj\VirtualDJ\crashguard3.exe infected Virus.Win32.Sality.aa ...17:49:14:111 3004 cured
17:49:20:268 3004 D:\Dj\VirtualDJ\ripdvd.exe infected Virus.Win32.Sality.aa ...17:49:20:268 3004 cured
17:49:20:424 3004 D:\Dj\VirtualDJ\ripvinyl.exe infected Virus.Win32.Sality.aa ...17:49:20:424 3004 cured
17:49:26:018 3004 D:\Dj\VirtualDJ\UNWISE.EXE infected Virus.Win32.Sality.aa ...17:49:26:018 3004 cured
17:49:27:471 3004 D:\Dj\VirtualDJ\virtualdj.exe infected Virus.Win32.Sality.aa ...17:49:27:471 3004 cured
17:49:28:658 3004 D:\Dj\VirtualDJj\virtualdj.exe infected Virus.Win32.Sality.aa ...17:49:28:658 3004 cured
17:49:50:408 3004 D:\docs\deskt\realarcade_r1home_stub.exe infected Virus.Win32.Sality.aa ...17:49:50:408 3004 cured
17:49:50:502 3004 D:\docs\deskt\SaveVal.exe infected Virus.Win32.Sality.aa ...17:49:50:502 3004 cured
17:49:51:393 3004 D:\docs\desktop\SaveVal.exe infected Virus.Win32.Sality.aa ...17:49:51:393 3004 cured
17:49:58:268 3004 D:\docs\dsktp\MsgPlusLive-423.exe infected Virus.Win32.Sality.aa ...17:49:58:268 3004 cured
17:49:58:705 3004 D:\docs\dsktp\SaveVal.exe infected Virus.Win32.Sality.aa ...17:49:58:705 3004 cured
17:49:59:127 3004 D:\docs\dsktp\TM_CALIB_103.exe infected Virus.Win32.Sality.aa ...17:49:59:127 3004 cured
17:51:10:783 3004 D:\fn\FunNames.exe infected Virus.Win32.Sality.aa ...17:51:10:783 3004 cured
17:51:11:268 3004 D:\Games\av\avp2.exe infected Virus.Win32.Sality.aa ...17:51:11:268 3004 cured
17:51:12:174 3004 D:\Games\av\avp2_en_096.exe infected Virus.Win32.Sality.aa ...17:51:12:174 3004 cured
17:51:12:986 3004 D:\Games\Avp2\Autorun.exe infected Virus.Win32.Sality.aa ...17:51:12:986 3004 cured
17:51:13:314 3004 D:\Games\Avp2\AVP2.exe infected Virus.Win32.Sality.aa ...17:51:13:314 3004 cured
17:51:13:705 3004 D:\Games\Avp2\AVP2Serv.exe infected Virus.Win32.Sality.aa ...17:51:13:705 3004 cured
17:51:13:971 3004 D:\Games\Avp2\lithtech.exe infected Virus.Win32.Sality.aa ...17:51:13:971 3004 cured
17:51:16:783 3004 D:\Games\Avp2\SierraUp.exe infected Virus.Win32.Sality.aa ...17:51:16:783 3004 cured
17:51:17:299 3004 D:\Games\Avp2PrimalHunt\AVP2Serv.exe infected Virus.Win32.Sality.aa ...17:51:17:299 3004 cured
17:51:17:502 3004 D:\Games\Avp2PrimalHunt\AVP2XServ.exe infected Virus.Win32.Sality.aa ...17:51:17:502 3004 cured
17:51:17:924 3004 D:\Games\Avp2PrimalHunt\lithtech.exe infected Virus.Win32.Sality.aa ...17:51:17:924 3004 cured
17:51:18:158 3004 D:\Games\Avp2PrimalHunt\PrimalHunt.exe infected Virus.Win32.Sality.aa ...17:51:18:158 3004 cured
17:51:18:533 3004 D:\Games\Avp2PrimalHunt\SierraUp.exe infected Virus.Win32.Sality.aa ...17:51:18:533 3004 cured
17:51:20:330 3004 D:\Games\Avp2PrimalHunt\Tools\avp2tools.exe infected Virus.Win32.Sality.aa ...17:51:20:330 3004 cured
17:51:20:939 3004 D:\Games\Avp2PrimalHunt\Tools\avp2tools_update.exe infected Virus.Win32.Sality.aa ...17:51:20:939 3004 cured
17:51:21:564 3004 D:\Games\Avp2PrimalHunt\Tools\avp2tools_update2.exe infected Virus.Win32.Sality.aa ...17:51:21:564 3004 cured
17:51:29:033 3004 D:\Games\Avp2PrimalHunt\Trailers\NOLF2_576.exe infected Virus.Win32.Sality.aa ...17:51:29:033 3004 cured
17:51:29:814 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_093.exe infected Virus.Win32.Sality.aa ...17:51:29:814 3004 cured
17:51:31:064 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_094.exe infected Virus.Win32.Sality.aa ...17:51:31:064 3004 cured
17:51:33:924 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_095.exe infected Virus.Win32.Sality.aa ...17:51:33:924 3004 cured
17:51:35:658 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_096.exe infected Virus.Win32.Sality.aa ...17:51:35:658 3004 cured
17:51:39:002 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_mp1.exe infected Virus.Win32.Sality.aa ...17:51:39:002 3004 cured
17:51:41:080 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_en_sp1.exe infected Virus.Win32.Sality.aa ...17:51:41:080 3004 cured
17:51:41:549 3004 D:\Games\Avp2PrimalHunt\Updates\avp2_us_092.exe infected Virus.Win32.Sality.aa ...17:51:41:549 3004 cured
17:51:42:127 3004 D:\Games\Chicken Invaders 2\ChickenInvaders2.exe infected Virus.Win32.Sality.aa ...17:51:42:127 3004 cured
17:51:43:018 3004 D:\Games\Chicken Invaders 3 Xmas\CI3Xmas.exe infected Virus.Win32.Sality.aa ...17:51:43:018 3004 cured
17:52:07:908 3004 D:\Games\Morrowind\CSUninstall\Setup.exe infected Virus.Win32.Sality.aa ...17:52:07:908 3004 cured
17:53:49:736 3004 D:\Games\Morrowind\Morrowind.exe infected Virus.Win32.Sality.aa ...17:53:49:736 3004 cured
17:53:49:971 3004 D:\Games\Morrowind\MWUninstall\Setup.exe infected Virus.Win32.Sality.aa ...17:53:49:971 3004 cured
17:54:04:424 3004 D:\Games\Need for Speed Carbon\eauninstall.exe infected Virus.Win32.Sality.aa ...17:54:04:424 3004 cured
17:54:12:471 3004 D:\Games\Need for Speed Carbon\nfs_inst.exe infected Virus.Win32.Sality.aa ...17:54:12:471 3004 cured
17:54:12:502 3004 D:\Games\Need for Speed Carbon\nfs_uninst.exe infected Virus.Win32.Sality.aa ...17:54:12:502 3004 cured
17:54:16:564 3004 D:\Games\Need for Speed Carbon\setup.exe infected Virus.Win32.Sality.aa ...17:54:16:564 3004 cured
17:54:33:846 3004 D:\Games\Need for Speed Carbon\Support\EasyInfo.exe infected Virus.Win32.Sality.aa ...17:54:33:846 3004 cured
17:54:34:002 3004 D:\Games\Need for Speed Carbon\Support\EReg.exe infected Virus.Win32.Sality.aa ...17:54:34:002 3004 cured
17:54:34:033 3004 D:\Games\Need for Speed Carbon\Support\Need for Speed Carbon_code.exe infected Virus.Win32.Sality.aa ...17:54:34:033 3004 cured
17:54:34:096 3004 D:\Games\Need for Speed Carbon\Support\Need for Speed Carbon_uninst.exe infected Virus.Win32.Sality.aa ...17:54:34:096 3004 cured
17:54:56:252 3004 D:\Games\Quake III Arenaedgsdfg\Check for Quake III Arena Updates.exe infected Virus.Win32.Sality.aa ...17:54:56:252 3004 cured
17:55:00:283 3004 D:\Games\Quake III Arenaedgsdfg\quake3.exe infected Virus.Win32.Sality.aa ...17:55:00:283 3004 cured
17:55:05:736 3004 D:\Games\Quake III!!\quake3.exe infected Virus.Win32.Sality.aa ...17:55:05:830 3004 cured
17:55:16:174 3004 D:\Games\QUAKE2\quake2.exe infected Virus.Win32.Sality.aa ...17:55:16:174 3004 cured
17:55:45:721 3004 D:\Games\Quake31\Check for Quake III Arena Updates.exe infected Virus.Win32.Sality.aa ...17:55:45:721 3004 cured
17:55:45:939 3004 D:\Games\Quake31\cnq3.exe infected Virus.Win32.Sality.aa ...17:55:45:939 3004 cured
17:56:00:127 3004 D:\Games\Quake31\defrag\misc\tools\DemosViewer.exe infected Virus.Win32.Sality.aa ...17:56:00:127 3004 cured
17:56:08:768 3004 D:\Games\Quake31\osp\OSP Config Generator.exe infected Virus.Win32.Sality.aa ...17:56:08:768 3004 cured
17:56:11:908 3004 D:\Games\Quake31\osp\voodoo\voodoostats41-c.exe infected Virus.Win32.Sality.aa ...17:56:11:908 3004 cured
17:56:12:111 3004 D:\Games\Quake31\osp\voodoo\voodoostats42-c.exe infected Virus.Win32.Sality.aa ...17:56:12:111 3004 cured
17:56:12:314 3004 D:\Games\Quake31\osp\voodoo\vs-preparse.exe infected Virus.Win32.Sality.aa ...17:56:12:314 3004 cured
17:56:13:377 3004 D:\Games\Quake31\pb\PnkBstrB.exe infected Virus.Win32.Sality.aa ...17:56:13:377 3004 cured
17:56:13:455 3004 D:\Games\Quake31\pbsetup.exe infected Virus.Win32.Sality.aa ...17:56:13:455 3004 cured
17:56:13:674 3004 D:\Games\Quake31\quake3.exe infected Virus.Win32.Sality.aa ...17:56:13:674 3004 cured
17:56:42:236 3004 D:\Games\SILENT HILL 4\sh4check.exe infected Virus.Win32.Sality.aa ...17:56:42:236 3004 cured
17:56:42:393 3004 D:\Games\SILENT HILL 4\SH4Config.exe infected Virus.Win32.Sality.aa ...17:56:42:393 3004 cured
17:56:42:596 3004 D:\Games\SILENT HILL 4\SILENT HILL 4.exe infected Virus.Win32.Sality.aa ...17:56:42:596 3004 cured
17:56:46:424 3004 D:\Games\teeworlds-0.5.1-win32\teeworlds.exe infected Virus.Win32.Sality.aa ...17:56:46:424 3004 cured
17:56:46:455 3004 D:\Games\teeworlds-0.5.1-win32\teeworlds_srv.exe infected Virus.Win32.Sality.aa ...17:56:46:455 3004 cured
17:56:50:533 3004 D:\gta\Chess3D.v2.6.Incl.Keygen-HERiTAGE\Setup.exe infected Virus.Win32.Sality.aa ...17:56:50:533 3004 cured
17:56:52:518 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-JRiver.exe infected Virus.Win32.Sality.aa ...17:56:52:518 3004 cured
17:56:52:596 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-Musicmatch.exe infected Virus.Win32.Sality.aa ...17:56:52:596 3004 cured
17:56:52:814 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-Real.exe infected Virus.Win32.Sality.aa ...17:56:52:830 3004 cured
17:56:52:908 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-Winamp.exe infected Virus.Win32.Sality.aa ...17:56:52:908 3004 cured
17:56:53:018 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-WMP.exe infected Virus.Win32.Sality.aa ...17:56:53:018 3004 cured
17:56:53:564 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX 8.352 Power Pack\dfxInstall-Yahoo.exe infected Virus.Win32.Sality.aa ...17:56:53:564 3004 cured
17:56:53:830 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\dfxInstall-JRiver_recovered\dfxInstall-JRiver.exe infected Virus.Win32.Sality.aa ...17:56:53:830 3004 cured
17:56:53:939 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\dfxInstall-Musicmatch\dfxInstall-Musicmatch.exe infected Virus.Win32.Sality.aa ...17:56:53:939 3004 cured
17:56:54:252 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\dfxInstall-Real\dfxInstall-Real.exe infected Virus.Win32.Sality.aa ...17:56:54:252 3004 cured
17:56:54:393 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\dfxInstall-Winamp\dfxInstall-Winamp.exe infected Virus.Win32.Sality.aa ...17:56:54:393 3004 cured
17:56:54:658 3004 D:\gta\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\DFX Audio Enhancer 8.350 and 8.352 + Key [App][Ingles][www.zonatorrent.com]\dfxInstall-WMP\dfxInstall-WMP.exe infected Virus.Win32.Sality.aa ...17:56:54:658 3004 cured
17:57:18:424 3004 D:\gta\Downloads\Magic ISO Maker v5.3+keygen\keygen.exe infected Virus.Win32.Sality.aa ...17:57:18:424 3004 cured
17:57:18:471 3004 D:\gta\Downloads\Magic ISO Maker v5.3+keygen\MagicISO 5.3.exe infected Virus.Win32.Sality.aa ...17:57:18:471 3004 cured
17:57:20:705 3004 D:\gta\Driver.Magician.v3.32.WinAll.Cracked-CRD\Crack\Crack\Driver Magician.exe infected Virus.Win32.Sality.aa ...17:57:20:705 3004 cured
17:58:02:705 3004 D:\gta\Fraps 2.9.4 Build 7037\fraps_2.9.4.exe infected Virus.Win32.Sality.aa ...17:58:02:830 3004 cured
17:58:09:002 3004 D:\gta\I-Doser ALL Doses including the new 2008 QuickHits\I-Doser\IDoser.exe infected Virus.Win32.Sality.aa ...17:58:09:002 3004 cured
17:58:09:674 3004 D:\gta\I-Doser ALL Doses including the new 2008 QuickHits\I-Doser\Uninstal.exe infected Virus.Win32.Sality.aa ...17:58:09:674 3004 cured
17:58:11:158 3004 D:\gta\Lavasoft.Ad-Aware.2007.Professional.Edition.v7.0.1.3-DVT\setup\setup\aaw2007.exe infected Virus.Win32.Sality.aa ...17:58:11:158 3004 cured
17:58:11:736 3004 D:\gta\Magic ISO Maker 5.55555\Magic ISO Maker 5.5\Setup_MagicISO.exe infected Virus.Win32.Sality.aa ...17:58:11:736 3004 cured
17:58:43:393 3004 D:\gta\Morrowind Elder Scrolls 3 + Expansions & [Plugins+Tweaks]\NO-CD\Morrowind.exe infected Virus.Win32.Sality.aa ...17:58:43:393 3004 cured
17:58:43:908 3004 D:\gta\Movie.DVD.Maker.v1.6.4.WinALL.Incl.Keygen-ViRiLiTY\keygen.exe infected Virus.Win32.Sality.aa ...17:58:43:908 3004 cured
17:58:43:971 3004 D:\gta\NFSCARBON\Crack\NFSC.exe infected Virus.Win32.Sality.aa ...17:58:43:971 3004 cured
17:58:46:971 3004 D:\gta\Quake.PACK-iNT\Quake2.Ground.Zero-RAZOR\Q2MPZERO\quake2.exe infected Virus.Win32.Sality.aa ...17:58:46:971 3004 cured
17:58:47:736 3004 D:\gta\Quake.PACK-iNT\Quake2.Ground.Zero-RAZOR\q2zero01\Q2MPZERO\quake2.exe infected Virus.Win32.Sality.aa ...17:58:47:736 3004 cured
17:58:49:814 3004 D:\gta\Quake.PACK-iNT\Quake2.Ground.Zero-RAZOR\quake2.exe infected Virus.Win32.Sality.aa ...17:58:49:814 3004 cured
17:58:50:768 3004 D:\gta\Super.Mp3.Download.v3.2.6.6-MFD\SuperMp3Download-3.2.6.6.Setup\SuperMp3Download-3.2.6.6.Setup.exe infected Virus.Win32.Sality.aa ...17:58:50:768 3004 cured
17:58:51:330 3004 D:\gta\TuneUp.Utilities.2008-REA\TU2008TrialEN.exe infected Virus.Win32.Sality.aa ...17:58:51:330 3004 cured
17:58:58:299 3004 D:\gta\WinRAR v3.90 Final + Crack (CLEAN) [h33t] - CaZoR\WinRAR 3.90 Final\Setup\wrar390.exe infected Virus.Win32.Sality.aa ...17:58:58:299 3004 cured
17:59:22:127 3004 D:\Mouse Pack by Korndog2003\mousepack\usbmrs11\usbmrs11.exe infected Virus.Win32.Sality.aa ...17:59:22:127 3004 cured
17:59:22:252 3004 D:\Mouse Pack by Korndog2003\mousepack.exe infected Virus.Win32.Sality.aa ...17:59:22:252 3004 cured
17:59:27:252 3004 D:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\DW20.EXE infected Virus.Win32.Sality.aa ...17:59:27:252 3004 cured
17:59:27:408 3004 D:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\DWTRIG20.EXE infected Virus.Win32.Sality.aa ...17:59:27:408 3004 cured
17:59:27:643 3004 D:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\OFFCLN.EXE infected Virus.Win32.Sality.aa ...17:59:27:643 3004 cured
17:59:27:814 3004 D:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\SETUP\OSE.EXE infected Virus.Win32.Sality.aa ...17:59:27:814 3004 cured
18:00:07:408 3004 D:\My Downloads\10-2_legacy_xp32-64_wdm.exe infected Virus.Win32.Sality.aa ...18:00:07:408 3004 cured
18:00:18:768 3004 D:\My Downloads\cf.exe infected Virus.Win32.Sality.aa ...18:00:18:768 3004 cured
18:00:19:705 3004 D:\My Downloads\ChromeSetup.exe infected Virus.Win32.Sality.aa ...18:00:19:705 3004 cured
18:00:28:174 3004 D:\My Downloads\dotnetfx35setup.exe infected Virus.Win32.Sality.aa ...18:00:28:174 3004 cured
18:00:29:314 3004 D:\My Downloads\DTMV4\DTMV4\Data\WinMPQ.exe infected Virus.Win32.Sality.aa ...18:00:29:314 3004 cured
18:00:29:502 3004 D:\My Downloads\DTMV4\DTMV4\DTMV4.exe infected Virus.Win32.Sality.aa ...18:00:29:502 3004 cured
18:00:35:939 3004 D:\My Downloads\HyperIM_2.14_Setup\HyperIM 2.14 Setup.exe infected Virus.Win32.Sality.aa ...18:00:35:939 3004 cured
18:00:40:424 3004 D:\My Downloads\mirc635.exe infected Virus.Win32.Sality.aa ...18:00:40:424 3004 cured
18:00:40:799 3004 D:\My Downloads\msgr10us.exe infected Virus.Win32.Sality.aa ...18:00:40:799 3004 cured
18:00:41:189 3004 D:\My Downloads\New Foldejuyfr (3)\Firefox Setup 3.6.10.exe infected Virus.Win32.Sality.aa ...18:00:41:189 3004 cured
18:00:41:221 3004 D:\My Downloads\New Foldejuyfr (3)\msgr10us.exe infected Virus.Win32.Sality.aa ...18:00:41:221 3004 cured
18:00:42:283 3004 D:\My Downloads\New Foldejuyfr (3)\Warkeys-1.17.1.0b.exe infected Virus.Win32.Sality.aa ...18:00:42:283 3004 cured
18:00:42:346 3004 D:\My Downloads\New Foldejuyfr (3)\winamp5581_full_emusic-7plus_en-us.exe infected Virus.Win32.Sality.aa ...18:00:42:346 3004 cured
18:00:42:424 3004 D:\My Downloads\New Foldejuyfr (3)\wrar393.exe infected Virus.Win32.Sality.aa ...18:00:42:424 3004 cured
18:00:45:252 3004 D:\My Downloads\PartyPokerSetup(2).exe infected Virus.Win32.Sality.aa ...18:00:45:252 3004 cured
18:00:45:393 3004 D:\My Downloads\PartyPokerSetup.exe infected Virus.Win32.Sality.aa ...18:00:45:393 3004 cured
18:00:50:002 3004 D:\My Downloads\SoftonicDownloader63021.exe infected Virus.Win32.Sality.aa ...18:00:50:002 3004 cured
18:00:50:080 3004 D:\My Downloads\SoftonicDownloader_for_directx.exe infected Virus.Win32.Sality.aa ...18:00:50:080 3004 cured
18:00:51:049 3004 D:\My Downloads\SUPERAntiSpyware.exe infected Virus.Win32.Sality.aa ...18:00:51:049 3004 cured
18:00:53:471 3004 D:\My Downloads\utorrent.exe infected Virus.Win32.Sality.aa ...18:00:53:471 3004 cured
18:00:53:830 3004 D:\My Downloads\vcredist_x86.exe infected Virus.Win32.Sality.aa ...18:00:53:830 3004 cured
18:00:54:189 3004 D:\My Downloads\Warkeys-1.14.1.0b.exe infected Virus.Win32.Sality.aa ...18:00:54:189 3004 cured
18:00:55:799 3004 D:\My Downloads\Warkeys-1.15.1.0b.exe infected Virus.Win32.Sality.aa ...18:00:55:799 3004 cured
18:00:55:877 3004 D:\My Downloads\Warkeys-1.18.1.0b.exe infected Virus.Win32.Sality.aa ...18:00:55:877 3004 cured
18:00:57:002 3004 D:\My Downloads\winamp5571_full_emusic-7plus_en-us.exe infected Virus.Win32.Sality.aa ...18:00:57:002 3004 cured
18:00:57:033 3004 D:\My Downloads\WinsockXPFix\WinsockXPFix.exe infected Virus.Win32.Sality.aa ...18:00:57:033 3004 cured
18:01:17:424 3004 D:\Program files\ATI Technologies\ATI Control Panel\atiadaxx.exe infected Virus.Win32.Sality.aa ...18:01:17:424 3004 cured
18:01:17:580 3004 D:\Program files\ATI Technologies\ATI Control Panel\Atiiprxx.exe infected Virus.Win32.Sality.aa ...18:01:17:580 3004 cured
18:01:17:658 3004 D:\Program files\ATI Technologies\ATI Control Panel\atiphexx.exe infected Virus.Win32.Sality.aa ...18:01:17:658 3004 cured
18:01:17:736 3004 D:\Program files\ATI Technologies\ATI Control Panel\atiprbxx.exe infected Virus.Win32.Sality.aa ...18:01:17:736 3004 cured
18:01:17:783 3004 D:\Program files\ATI Technologies\ATI Control Panel\atiptaxx.exe infected Virus.Win32.Sality.aa ...18:01:17:783 3004 cured
18:01:19:471 3004 D:\Program files\ATI Technologies\UninstallAll\AtiCimUn.exe infected Virus.Win32.Sality.aa ...18:01:19:471 3004 cured
18:01:19:674 3004 D:\Program files\BitComet\codec\CodecCheck.exe infected Virus.Win32.Sality.aa ...18:01:19:674 3004 cured
18:01:19:752 3004 D:\Program files\BitComet\CrashReport.exe infected Virus.Win32.Sality.aa ...18:01:19:752 3004 cured
18:01:23:799 3004 D:\Program files\BitComet\uninst.exe infected Virus.Win32.Sality.aa ...18:01:23:799 3004 cured
18:01:24:283 3004 D:\Program files\BootSkin\BootSkin.exe infected Virus.Win32.Sality.aa ...18:01:24:283 3004 cured
18:01:25:080 3004 D:\Program files\BootSkin\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:01:25:080 3004 cured
18:01:26:002 3004 D:\Program files\CCleaner\ccleaner.exe infected Virus.Win32.Sality.aa ...18:01:26:002 3004 cured
18:01:26:424 3004 D:\Program files\CCleaner\uninst.exe infected Virus.Win32.Sality.aa ...18:01:26:424 3004 cured
18:01:26:533 3004 D:\Program files\chestiemarphaptjocuripelanfarasatitrebuieascalan\Git.exe infected Virus.Win32.Sality.aa ...18:01:26:533 3004 cured
18:01:26:814 3004 D:\Program files\CleanUp!\Cleanup.exe infected Virus.Win32.Sality.aa ...18:01:26:814 3004 cured
18:01:27:064 3004 D:\Program files\clonespy\CloneSpy.exe infected Virus.Win32.Sality.aa ...18:01:27:064 3004 cured
18:01:28:439 3004 D:\Program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe infected Virus.Win32.Sality.aa ...18:01:28:439 3004 cured
18:01:28:658 3004 D:\Program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver2.exe infected Virus.Win32.Sality.aa ...18:01:28:658 3004 cured
18:01:28:799 3004 D:\Program files\Common Files\InstallShield\Driver\9\Intel 32\IDriver.exe infected Virus.Win32.Sality.aa ...18:01:28:799 3004 cured
18:01:29:002 3004 D:\Program files\Common Files\InstallShield\Driver\9\Intel 32\IDriver2.exe infected Virus.Win32.Sality.aa ...18:01:29:002 3004 cured
18:01:29:377 3004 D:\Program files\Common Files\InstallShield\engine\6\Intel 32\IKernel.exe infected Virus.Win32.Sality.aa ...18:01:29:377 3004 cured
18:01:30:893 3004 D:\Program files\Common Files\Microsoft Shared\MSInfo\msinfo32.exe infected Virus.Win32.Sality.aa ...18:01:30:893 3004 cured
18:01:31:111 3004 D:\Program files\Common Files\Microsoft Shared\MSInfo\OFFPRV10.EXE infected Virus.Win32.Sality.aa ...18:01:31:111 3004 cured
18:01:31:236 3004 D:\Program files\Common Files\Microsoft Shared\MSSearch\Bin\SrchAdmStp.exe infected Virus.Win32.Sality.aa ...18:01:31:236 3004 cured
18:01:31:408 3004 D:\Program files\Common Files\Microsoft Shared\Office10\DW.EXE infected Virus.Win32.Sality.aa ...18:01:31:408 3004 cured
18:01:32:393 3004 D:\Program files\Common Files\Microsoft Shared\Speech\sapisvr.exe infected Virus.Win32.Sality.aa ...18:01:32:393 3004 cured
18:01:35:283 3004 D:\Program files\Common Files\Microsoft Shared\web server extensions\50\bin\CFGWIZ.EXE infected Virus.Win32.Sality.aa ...18:01:35:283 3004 cured
18:01:35:564 3004 D:\Program files\Common Files\Microsoft Shared\web server extensions\50\bin\OWSADM.EXE infected Virus.Win32.Sality.aa ...18:01:35:564 3004 cured
18:01:35:611 3004 D:\Program files\Common Files\Microsoft Shared\web server extensions\50\bin\OWSRMADM.EXE infected Virus.Win32.Sality.aa ...18:01:35:611 3004 cured
18:01:35:799 3004 D:\Program files\Common Files\Microsoft Shared\web server extensions\50\bin\TCPTEST.EXE infected Virus.Win32.Sality.aa ...18:01:35:799 3004 cured
18:01:36:033 3004 D:\Program files\Common Files\Microsoft Shared\web server extensions\50\isapi\FPCOUNT.EXE infected Virus.Win32.Sality.aa ...18:01:36:033 3004 cured
18:02:14:064 3004 D:\Program files\Common Files\Symantec Shared\LiveReg\VCSETUP.EXE infected Virus.Win32.Sality.aa ...18:02:14:064 3004 cured
18:02:17:580 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\cfpupdat.exe infected Virus.Win32.Sality.aa ...18:02:17:580 3004 cured
18:02:17:861 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\cmdagent.exe infected Virus.Win32.Sality.aa ...18:02:17:861 3004 cured
18:02:18:189 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\crashrep.exe infected Virus.Win32.Sality.aa ...18:02:18:189 3004 cured
18:02:18:924 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\repair\cfpupdat.exe infected Virus.Win32.Sality.aa ...18:02:18:924 3004 cured
18:02:19:018 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\repair\cmdagent.exe infected Virus.Win32.Sality.aa ...18:02:19:018 3004 cured
18:02:19:158 3004 D:\Program files\Comodo firewall\Comodo\COMODO Internet Security\repair\crashrep.exe infected Virus.Win32.Sality.aa ...18:02:19:158 3004 cured
18:02:30:783 3004 D:\Program files\CompuPicPro\scsiaccess.exe infected Virus.Win32.Sality.aa ...18:02:30:783 3004 cured
18:02:32:299 3004 D:\Program files\Cookie Remover Platinum 2004\Cookie Remover Platinum 2004.exe infected Virus.Win32.Sality.aa ...18:02:32:299 3004 cured
18:02:32:611 3004 D:\Program files\Cosmic Scenes\CosmicScenes.exe infected Virus.Win32.Sality.aa ...18:02:32:611 3004 cured
18:02:32:971 3004 D:\Program files\Cosmic Scenes\smartlinker.exe infected Virus.Win32.Sality.aa ...18:02:32:971 3004 cured
18:02:33:393 3004 D:\Program files\CursorXP\AniUtil.exe infected Virus.Win32.Sality.aa ...18:02:33:393 3004 cured
18:02:33:486 3004 D:\Program files\CursorXP\CursorXP.exe infected Virus.Win32.Sality.aa ...18:02:33:486 3004 cured
18:02:33:736 3004 D:\Program files\CursorXP\CurXPCpl.exe infected Virus.Win32.Sality.aa ...18:02:33:736 3004 cured
18:02:33:799 3004 D:\Program files\CursorXP\CurXPUtil.exe infected Virus.Win32.Sality.aa ...18:02:33:799 3004 cured
18:02:34:580 3004 D:\Program files\CyberLink\Common\UpdateIPR.exe infected Virus.Win32.Sality.aa ...18:02:34:580 3004 cured
18:02:35:736 3004 D:\Program files\CyberLink\MediaShow\MediaShow.exe infected Virus.Win32.Sality.aa ...18:02:35:736 3004 cured
18:02:36:018 3004 D:\Program files\CyberLink\MediaShow\msinit.exe infected Virus.Win32.Sality.aa ...18:02:36:018 3004 cured
18:02:36:268 3004 D:\Program files\CyberLink\MediaShow\Pack\Player.exe infected Virus.Win32.Sality.aa ...18:02:36:268 3004 cured
18:02:37:143 3004 D:\Program files\CyberLink\PowerDVD\cldma.exe infected Virus.Win32.Sality.aa ...18:02:37:143 3004 cured
18:02:37:268 3004 D:\Program files\CyberLink\PowerDVD\cltest.exe infected Virus.Win32.Sality.aa ...18:02:37:268 3004 cured
18:02:37:377 3004 D:\Program files\CyberLink\PowerDVD\dvdrgn.exe infected Virus.Win32.Sality.aa ...18:02:37:377 3004 cured
18:02:37:721 3004 D:\Program files\CyberLink\PowerDVD\PowerDVD.exe infected Virus.Win32.Sality.aa ...18:02:37:721 3004 cured
18:02:38:518 3004 D:\Program files\Desktop Architect\da.exe infected Virus.Win32.Sality.aa ...18:02:38:518 3004 cured
18:02:38:846 3004 D:\Program files\Desktop Architect\datray.exe infected Virus.Win32.Sality.aa ...18:02:38:846 3004 cured
18:02:40:080 3004 D:\Program files\DesktopX\AniUtil.exe infected Virus.Win32.Sality.aa ...18:02:40:080 3004 cured
18:02:40:643 3004 D:\Program files\DesktopX\DesktopX Builder.exe infected Virus.Win32.Sality.aa ...18:02:40:643 3004 cured
18:02:41:580 3004 D:\Program files\DesktopX\DesktopX.exe infected Virus.Win32.Sality.aa ...18:02:41:580 3004 cured
18:02:42:408 3004 D:\Program files\DesktopX\DXWidget.exe infected Virus.Win32.Sality.aa ...18:02:42:408 3004 cured
18:02:44:705 3004 D:\Program files\DesktopX\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:02:44:705 3004 cured
18:02:45:252 3004 D:\Program files\DesktopX\WidgetManager.exe infected Virus.Win32.Sality.aa ...18:02:45:252 3004 cured
18:02:47:189 3004 D:\Program files\Digital Talking Parrot\Parrot.exe infected Virus.Win32.Sality.aa ...18:02:47:189 3004 cured
18:02:47:533 3004 D:\Program files\Digital Talking Parrot\Uninstall.exe infected Virus.Win32.Sality.aa ...18:02:47:533 3004 cured
18:02:48:361 3004 D:\Program files\DirectX9.0c\DXSETUP.exe infected Virus.Win32.Sality.aa ...18:02:48:361 3004 cured
18:02:48:752 3004 D:\Program files\Diver\AutoUpdate.exe infected Virus.Win32.Sality.aa ...18:02:48:752 3004 cured
18:02:50:611 3004 D:\Program files\Diver\protect.exe infected Virus.Win32.Sality.aa ...18:02:50:611 3004 cured
18:02:51:330 3004 D:\Program files\DivX\ConverterUninstall.exe infected Virus.Win32.Sality.aa ...18:02:51:330 3004 cured
18:02:51:439 3004 D:\Program files\DivX\DivX\config.exe infected Virus.Win32.Sality.aa ...18:02:51:439 3004 cured
18:02:51:658 3004 D:\Program files\DivX\DivX\DivX EKG.exe infected Virus.Win32.Sality.aa ...18:02:51:658 3004 cured
18:02:52:033 3004 D:\Program files\DivX\DivX Codec\config.exe infected Virus.Win32.Sality.aa ...18:02:52:033 3004 cured
18:02:52:127 3004 D:\Program files\DivX\DivX Codec\DivX EKG.exe infected Virus.Win32.Sality.aa ...18:02:52:127 3004 cured
18:02:52:752 3004 D:\Program files\DivX\DivX Converter\Converter.exe infected Virus.Win32.Sality.aa ...18:02:52:752 3004 cured
18:02:53:799 3004 D:\Program files\DivX\DivX Player\DivX Player.exe infected Virus.Win32.Sality.aa ...18:02:53:799 3004 cured
18:02:55:408 3004 D:\Program files\DivX\DivXBundleUninstall.exe infected Virus.Win32.Sality.aa ...18:02:55:408 3004 cured
18:02:55:814 3004 D:\Program files\DivX\DivXCodecUninstall.exe infected Virus.Win32.Sality.aa ...18:02:55:814 3004 cured
18:02:55:955 3004 D:\Program files\DivX\DivXContentUploaderUninstall.exe infected Virus.Win32.Sality.aa ...18:02:55:955 3004 cured
18:02:56:111 3004 D:\Program files\DivX\DivXPlayerUninstall.exe infected Virus.Win32.Sality.aa ...18:02:56:111 3004 cured
18:02:56:486 3004 D:\Program files\DivX\DivXWebPlayerUninstall.exe infected Virus.Win32.Sality.aa ...18:02:56:486 3004 cured
18:03:18:111 3004 D:\Program files\FlashGet\flashget.exe infected Virus.Win32.Sality.aa ...18:03:18:111 3004 cured
18:03:19:846 3004 D:\Program files\FlashGet\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:03:19:846 3004 cured
18:03:23:252 3004 D:\Program files\GameSpy Arcade\ArcadeInstallFull203-google.exe infected Virus.Win32.Sality.aa ...18:03:23:252 3004 cured
18:03:24:314 3004 D:\Program files\GameSpy Arcade\GSAPak.exe infected Virus.Win32.Sality.aa ...18:03:24:314 3004 cured
18:03:24:721 3004 D:\Program files\GameSpy Arcade\RptCrash.exe infected Virus.Win32.Sality.aa ...18:03:24:721 3004 cured
18:03:30:158 3004 D:\Program files\GameSpy Arcade\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:03:30:158 3004 cured
18:03:30:877 3004 D:\Program files\GameSpy Arcade2()\Aphex.exe infected Virus.Win32.Sality.aa ...18:03:30:877 3004 cured
18:03:33:471 3004 D:\Program files\GameSpy Arcade2()\GSAPak.exe infected Virus.Win32.Sality.aa ...18:03:33:471 3004 cured
18:03:36:861 3004 D:\Program files\GameSpy Arcade2()\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:03:36:861 3004 cured
18:03:39:111 3004 D:\Program files\GetDiz\Uninstall\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:03:39:111 3004 cured
18:03:39:330 3004 D:\Program files\Gigabyte\Gigabyte Windows Utility Manager\bios\gwf32.exe infected Virus.Win32.Sality.aa ...18:03:39:330 3004 cured
18:03:39:627 3004 D:\Program files\Gigabyte\Gigabyte Windows Utility Manager\bios\Gwflash.exe infected Virus.Win32.Sality.aa ...18:03:39:627 3004 cured
18:03:40:549 3004 D:\Program files\Google\Google Earth\GoogleEarth.exe infected Virus.Win32.Sality.aa ...18:03:40:549 3004 cured
18:03:40:799 3004 D:\Program files\Google\Google Earth\gpsbabel.exe infected Virus.Win32.Sality.aa ...18:03:40:799 3004 cured
18:03:42:002 3004 D:\Program files\Hamachi\hamachi.exe infected Virus.Win32.Sality.aa ...18:03:42:002 3004 cured
18:03:42:236 3004 D:\Program files\Hamachi\nicmgr.exe infected Virus.Win32.Sality.aa ...18:03:42:236 3004 cured
18:03:42:361 3004 D:\Program files\Hamachi\uninstall.exe infected Virus.Win32.Sality.aa ...18:03:42:361 3004 cured
18:03:43:471 3004 D:\Program files\HLSW\hlsw.exe infected Virus.Win32.Sality.aa ...18:03:43:471 3004 cured
18:03:46:314 3004 D:\Program files\Internet Explorer\Connection Wizard\icwconn1.exe infected Virus.Win32.Sality.aa ...18:03:46:314 3004 cured
18:03:46:393 3004 D:\Program files\Internet Explorer\Connection Wizard\icwconn2.exe infected Virus.Win32.Sality.aa ...18:03:46:393 3004 cured
18:03:46:705 3004 D:\Program files\Internet Explorer\Connection Wizard\icwrmind.exe infected Virus.Win32.Sality.aa ...18:03:46:705 3004 cured
18:03:46:783 3004 D:\Program files\Internet Explorer\Connection Wizard\icwtutor.exe infected Virus.Win32.Sality.aa ...18:03:46:783 3004 cured
18:03:46:908 3004 D:\Program files\Internet Explorer\Connection Wizard\inetwiz.exe infected Virus.Win32.Sality.aa ...18:03:46:908 3004 cured
18:03:47:283 3004 D:\Program files\Internet Explorer\iedw.exe infected Virus.Win32.Sality.aa ...18:03:47:283 3004 cured
18:03:48:064 3004 D:\Program files\MagicISO\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:03:48:064 3004 cured
18:03:48:283 3004 D:\Program files\Messenger\msmsgs.exe infected Virus.Win32.Sality.aa ...18:03:48:283 3004 cured
18:03:48:658 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\acercade.exe infected Virus.Win32.Sality.aa ...18:03:48:658 3004 cured
18:03:49:221 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\cleanup.exe infected Virus.Win32.Sality.aa ...18:03:49:221 3004 cured
18:03:49:424 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\defrag.exe infected Virus.Win32.Sality.aa ...18:03:49:424 3004 cured
18:03:49:705 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\defragl.exe infected Virus.Win32.Sality.aa ...18:03:49:705 3004 cured
18:03:49:955 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\freeram.exe infected Virus.Win32.Sality.aa ...18:03:49:955 3004 cured
18:03:50:236 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\interfaz.exe infected Virus.Win32.Sality.aa ...18:03:50:236 3004 cured
18:03:50:627 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\maintena.exe infected Virus.Win32.Sality.aa ...18:03:50:627 3004 cured
18:03:50:986 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\mumain.exe infected Virus.Win32.Sality.aa ...18:03:50:986 3004 cured
18:03:51:268 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\regclean.exe infected Virus.Win32.Sality.aa ...18:03:51:268 3004 cured
18:03:51:361 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\RegDLL.exe infected Virus.Win32.Sality.aa ...18:03:51:361 3004 cured
18:03:51:486 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\registro.exe infected Virus.Win32.Sality.aa ...18:03:51:486 3004 cured
18:03:51:596 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\renamer.exe infected Virus.Win32.Sality.aa ...18:03:51:596 3004 cured
18:03:51:924 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\safereg.exe infected Virus.Win32.Sality.aa ...18:03:51:924 3004 cured
18:03:52:018 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\scandisk.exe infected Virus.Win32.Sality.aa ...18:03:52:018 3004 cured
18:03:52:330 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\scandskl.exe infected Virus.Win32.Sality.aa ...18:03:52:330 3004 cured
18:03:52:424 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\shelter.exe infected Virus.Win32.Sality.aa ...18:03:52:424 3004 cured
18:03:52:736 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\shutdown.exe infected Virus.Win32.Sality.aa ...18:03:52:736 3004 cured
18:03:52:846 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\split.exe infected Virus.Win32.Sality.aa ...18:03:52:846 3004 cured
18:03:53:252 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\srestore.exe infected Virus.Win32.Sality.aa ...18:03:53:252 3004 cured
18:03:53:596 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\startup.exe infected Virus.Win32.Sality.aa ...18:03:53:596 3004 cured
18:03:53:908 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\systinfo.exe infected Virus.Win32.Sality.aa ...18:03:53:908 3004 cured
18:03:54:314 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\undeltl.exe infected Virus.Win32.Sality.aa ...18:03:54:314 3004 cured
18:03:54:736 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\uninstl.exe infected Virus.Win32.Sality.aa ...18:03:54:736 3004 cured
18:03:55:439 3004 D:\Program files\MindSoft\MindSoft Utilities XP 9\wipe.exe infected Virus.Win32.Sality.aa ...18:03:55:439 3004 cured
18:03:55:814 3004 D:\Program files\Movie Maker\moviemk.exe infected Virus.Win32.Sality.aa ...18:03:55:814 3004 not cured
18:03:59:096 3004 D:\Program files\Mozila firefox\firefox.exe infected Virus.Win32.Sality.aa ...18:03:59:096 3004 cured
18:03:59:877 3004 D:\Program files\Mozila firefox\plugins\GetFlash.exe infected Virus.Win32.Sality.aa ...18:03:59:877 3004 cured
18:04:01:783 3004 D:\Program files\Mozila firefox\uninstall\uninstall.exe infected Virus.Win32.Sality.aa ...18:04:01:783 3004 cured
18:04:02:127 3004 D:\Program files\Mozila firefox\updater.exe infected Virus.Win32.Sality.aa ...18:04:02:127 3004 cured
18:04:02:346 3004 D:\Program files\Mozila firefox\xpicleanup.exe infected Virus.Win32.Sality.aa ...18:04:02:346 3004 cured
18:04:03:674 3004 D:\Program files\MSN\MSNCoreFiles\copymar.exe infected Virus.Win32.Sality.aa ...18:04:03:674 3004 cured
18:04:03:814 3004 D:\Program files\MSN\MSNCoreFiles\dw.exe infected Virus.Win32.Sality.aa ...18:04:03:814 3004 cured
18:04:04:299 3004 D:\Program files\MSN\MSNCoreFiles\msn6.exe infected Virus.Win32.Sality.aa ...18:04:04:299 3004 cured
18:04:04:658 3004 D:\Program files\MSN\MSNCoreFiles\Setup\msnunin.exe infected Virus.Win32.Sality.aa ...18:04:04:658 3004 cured
18:04:05:049 3004 D:\Program files\MSN\MSNCoreFiles\update.exe infected Virus.Win32.Sality.aa ...18:04:05:049 3004 cured
18:04:05:174 3004 D:\Program files\MSN Messenger\dw.exe infected Virus.Win32.Sality.aa ...18:04:05:174 3004 cured
18:04:05:643 3004 D:\Program files\MSN Messenger\msnmsgr.exe infected Virus.Win32.Sality.aa ...18:04:05:643 3004 cured
18:04:06:127 3004 D:\Program files\MSN Messenger\Several MSN sessions\msmsgs.exe infected Virus.Win32.Sality.aa ...18:04:06:127 3004 cured
18:04:06:846 3004 D:\Program files\My Received Files\handwriting\InkRedist\Setup.Exe infected Virus.Win32.Sality.aa ...18:04:06:846 3004 cured
18:04:07:268 3004 D:\Program files\My Received Files\handwriting\installer.exe infected Virus.Win32.Sality.aa ...18:04:07:268 3004 cured
18:04:07:814 3004 D:\Program files\MYMA Decoder and Viewer\Myma.exe infected Virus.Win32.Sality.aa ...18:04:07:814 3004 cured
18:04:08:486 3004 D:\Program files\NetMeeting\conf.exe infected Virus.Win32.Sality.aa ...18:04:08:486 3004 cured
18:04:08:877 3004 D:\Program files\QuickTime\PictureViewer.exe infected Virus.Win32.Sality.aa ...18:04:08:877 3004 cured
18:04:09:033 3004 D:\Program files\QuickTime\QTInfo.exe infected Virus.Win32.Sality.aa ...18:04:09:033 3004 cured
18:04:09:252 3004 D:\Program files\QuickTime\qttask.exe infected Virus.Win32.Sality.aa ...18:04:09:252 3004 cured
18:04:10:236 3004 D:\Program files\QuickTime\QuickTimePlayer.exe infected Virus.Win32.Sality.aa ...18:04:10:236 3004 cured
18:04:11:221 3004 D:\Program files\QuickTime\QuickTimeUpdater.exe infected Virus.Win32.Sality.aa ...18:04:11:221 3004 cured
18:04:11:533 3004 D:\Program files\sfix\download.exe infected Virus.Win32.Sality.aa ...18:04:11:533 3004 cured
18:04:12:236 3004 D:\Program files\sfix\sfix.exe infected Virus.Win32.Sality.aa ...18:04:12:236 3004 cured
18:04:12:971 3004 D:\Program files\SlySoft\AnyDVD\AnyDVD-uninst.exe infected Virus.Win32.Sality.aa ...18:04:13:049 3004 cured
18:04:13:471 3004 D:\Program files\SlySoft\AnyDVD\AnyDVD.exe infected Virus.Win32.Sality.aa ...18:04:13:471 3004 cured
18:04:14:064 3004 D:\Program files\SlySoft\AnyDVD\RegAnyDVD.exe infected Virus.Win32.Sality.aa ...18:04:14:064 3004 cured
18:04:14:236 3004 D:\Program files\SlySoft\AnyDVD\SetDisplayFrequency.exe infected Virus.Win32.Sality.aa ...18:04:14:236 3004 cured
18:04:14:939 3004 D:\Program files\Sony Setup\Sony Media Manager 2.3\Setup.exe infected Virus.Win32.Sality.aa ...18:04:14:939 3004 cured
18:04:15:268 3004 D:\Program files\SP2 Connection Patcher\SP2ConnPatcher.exe infected Virus.Win32.Sality.aa ...18:04:15:268 3004 cured
18:04:15:580 3004 D:\Program files\SP2 Connection Patcher\uninstall.exe infected Virus.Win32.Sality.aa ...18:04:15:580 3004 cured
18:04:18:205 3004 D:\Program files\SpywareBlaster\sbautoupdate.exe infected Virus.Win32.Sality.aa ...18:04:18:205 3004 cured
18:04:18:361 3004 D:\Program files\SpywareBlaster\spywareblaster.exe infected Virus.Win32.Sality.aa ...18:04:18:361 3004 cured
18:04:32:783 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\Screen.exe infected Virus.Win32.Sality.aa ...18:04:32:783 3004 cured
18:04:33:111 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\skincst.exe infected Virus.Win32.Sality.aa ...18:04:33:111 3004 cured
18:04:33:283 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:04:33:283 3004 cured
18:04:33:518 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\wbconfig.exe infected Virus.Win32.Sality.aa ...18:04:33:518 3004 cured
18:04:33:627 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\WBInstall32.exe infected Virus.Win32.Sality.aa ...18:04:33:627 3004 cured
18:04:33:752 3004 D:\Program files\Stardock\Object Desktop\WindowBlinds\wbload.exe infected Virus.Win32.Sality.aa ...18:04:33:752 3004 cured
18:04:39:502 3004 D:\Program files\Stardock\ObjectDock\ObjectDock.exe infected Virus.Win32.Sality.aa ...18:04:39:502 3004 cured
18:04:40:127 3004 D:\Program files\Stardock\ObjectDock\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:04:40:127 3004 cured
18:04:40:783 3004 D:\Program files\Symantec\LiveUpdate\ALUNOTIFY.EXE infected Virus.Win32.Sality.aa ...18:04:40:783 3004 cured
18:04:40:877 3004 D:\Program files\Symantec\LiveUpdate\AUPDATE.EXE infected Virus.Win32.Sality.aa ...18:04:40:877 3004 cured
18:04:41:268 3004 D:\Program files\Symantec\LiveUpdate\LSETUP.EXE infected Virus.Win32.Sality.aa ...18:04:41:283 3004 cured
18:04:41:424 3004 D:\Program files\Symantec\LiveUpdate\LUALL.EXE infected Virus.Win32.Sality.aa ...18:04:41:424 3004 cured
18:04:41:611 3004 D:\Program files\Symantec\LiveUpdate\LUInit.exe infected Virus.Win32.Sality.aa ...18:04:41:611 3004 cured
18:04:42:002 3004 D:\Program files\Symantec\LiveUpdate\NDETECT.EXE infected Virus.Win32.Sality.aa ...18:04:42:002 3004 cured
18:04:42:518 3004 D:\Program files\Symantec\LiveUpdate\SymantecRootInstaller.exe infected Virus.Win32.Sality.aa ...18:04:42:518 3004 cured
18:04:42:861 3004 D:\Program files\Systweak BoostXP2\aptplaner.exe infected Virus.Win32.Sality.aa ...18:04:42:861 3004 cured
18:04:43:455 3004 D:\Program files\Systweak BoostXP2\bxp2.exe infected Virus.Win32.Sality.aa ...18:04:43:455 3004 cured
18:04:43:799 3004 D:\Program files\Systweak BoostXP2\bxp2aso.exe infected Virus.Win32.Sality.aa ...18:04:43:799 3004 cured
18:04:44:361 3004 D:\Program files\Systweak BoostXP2\zipfix.exe infected Virus.Win32.Sality.aa ...18:04:44:361 3004 cured
18:04:45:596 3004 D:\Program files\tgtsoft\StyleXP\Logon\CurrentLogon.EXE infected Virus.Win32.Sality.aa ...18:04:45:596 3004 cured
18:04:46:627 3004 D:\Program files\tgtsoft\StyleXP\StyleXP-uninstall.exe infected Virus.Win32.Sality.aa ...18:04:46:627 3004 cured
18:04:46:752 3004 D:\Program files\tgtsoft\StyleXP\stylexp.exe infected Virus.Win32.Sality.aa ...18:04:46:752 3004 cured
18:04:46:955 3004 D:\Program files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe infected Virus.Win32.Sality.aa ...18:04:46:955 3004 cured
18:04:47:861 3004 D:\Program files\The Weather Channel FW\Desktop Weather\TheWeatherChannelCustomUninstall.exe infected Virus.Win32.Sality.aa ...18:04:47:861 3004 cured
18:04:47:955 3004 D:\Program files\The Weather Channel FW\Desktop Weather\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:04:47:955 3004 cured
18:04:48:361 3004 D:\Program files\The Weather Channel FW\Framework\TheWeatherChannelqx.exe infected Virus.Win32.Sality.aa ...18:04:48:361 3004 cured
18:04:48:455 3004 D:\Program files\The Weather Channel FW\Framework\TheWeatherChannelSetup.exe infected Virus.Win32.Sality.aa ...18:04:48:455 3004 cured
18:04:48:549 3004 D:\Program files\The Weather Channel FW\Framework\TheWeatherChannelSlnchr.exe infected Virus.Win32.Sality.aa ...18:04:48:549 3004 cured
18:04:48:939 3004 D:\Program files\The Weather Channel FW\Framework\TheWeatherChannelUpdate.exe infected Virus.Win32.Sality.aa ...18:04:48:939 3004 cured
18:04:49:377 3004 D:\Program files\The Weather Channel FW\Framework\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:04:49:377 3004 cured
18:04:52:955 3004 D:\Program files\TOBEST\AudioMaestro\AMCDDAExtractor.exe infected Virus.Win32.Sality.aa ...18:04:52:971 3004 cured
18:04:53:314 3004 D:\Program files\TOBEST\AudioMaestro\AMCDWriter.exe infected Virus.Win32.Sality.aa ...18:04:53:314 3004 cured
18:04:53:721 3004 D:\Program files\TOBEST\AudioMaestro\AMConverter.exe infected Virus.Win32.Sality.aa ...18:04:53:721 3004 cured
18:04:54:143 3004 D:\Program files\TOBEST\AudioMaestro\AMEditor.exe infected Virus.Win32.Sality.aa ...18:04:54:143 3004 cured
18:04:54:361 3004 D:\Program files\TOBEST\AudioMaestro\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:04:54:361 3004 cured
18:04:54:518 3004 D:\Program files\Trust\270KD Silverline Keyboard & Wireless Mouse\Keyboard\Ikeymain.exe infected Virus.Win32.Sality.aa ...18:04:54:518 3004 cured
18:04:54:674 3004 D:\Program files\Trust\270KD Silverline Keyboard & Wireless Mouse\Keyboard\Uninst32.exe infected Virus.Win32.Sality.aa ...18:04:54:674 3004 cured
18:04:55:018 3004 D:\Program files\Trust\270KD Silverline Keyboard & Wireless Mouse\Mouse\Amoumain.exe infected Virus.Win32.Sality.aa ...18:04:55:018 3004 cured
18:04:55:205 3004 D:\Program files\Trust\270KD Silverline Keyboard & Wireless Mouse\Mouse\Uninst32.exe infected Virus.Win32.Sality.aa ...18:04:55:205 3004 cured
18:05:09:424 3004 D:\Program files\TuneUp Utilities 2010\TuneUpDefragService.exe infected Virus.Win32.Sality.aa ...18:05:09:424 3004 cured
18:05:10:596 3004 D:\Program files\uTorrent\Uninstall.exe infected Virus.Win32.Sality.aa ...18:05:10:596 3004 cured
18:05:17:580 3004 D:\Program files\VideoLAN\VLC\uninstall.exe infected Virus.Win32.Sality.aa ...18:05:17:580 3004 cured
18:05:17:846 3004 D:\Program files\VideoLAN\VLC\vlc.exe infected Virus.Win32.Sality.aa ...18:05:17:846 3004 cured
18:05:22:002 3004 D:\Program files\VLC\uninstall.exe infected Virus.Win32.Sality.aa ...18:05:22:002 3004 cured
18:05:22:393 3004 D:\Program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe infected Virus.Win32.Sality.aa ...18:05:22:393 3004 cured
18:05:33:768 3004 D:\Program files\Warkeys\uninst.exe infected Virus.Win32.Sality.aa ...18:05:33:768 3004 cured
18:05:34:783 3004 D:\Program files\Webshots\Launcher.exe infected Virus.Win32.Sality.aa ...18:05:34:783 3004 cured
18:05:35:080 3004 D:\Program files\Webshots\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:05:35:080 3004 cured
18:05:35:221 3004 D:\Program files\Webshots\webshots.scr infected Virus.Win32.Sality.aa ...18:05:35:221 3004 cured
18:05:36:408 3004 D:\Program files\Winamp\uninstall_dfx.exe infected Virus.Win32.Sality.aa ...18:05:36:408 3004 cured
18:05:36:814 3004 D:\Program files\Winamp Detect\UninstWaDetect.exe infected Virus.Win32.Sality.aa ...18:05:36:814 3004 cured
18:05:38:768 3004 D:\Program files\Winampp\Plugins\DFX\Apps\askemail.exe infected Virus.Win32.Sality.aa ...18:05:38:768 3004 cured
18:05:38:908 3004 D:\Program files\Winampp\Plugins\DFX\Apps\record_date.exe infected Virus.Win32.Sality.aa ...18:05:38:908 3004 cured
18:05:39:252 3004 D:\Program files\Winampp\Plugins\DFX\Apps\record_email.exe infected Virus.Win32.Sality.aa ...18:05:39:252 3004 cured
18:05:39:580 3004 D:\Program files\Winampp\Plugins\DFX\Apps\registryCleanUsers.exe infected Virus.Win32.Sality.aa ...18:05:39:580 3004 cured
18:05:39:674 3004 D:\Program files\Winampp\Plugins\DFX\Apps\step1.exe infected Virus.Win32.Sality.aa ...18:05:39:674 3004 cured
18:05:40:002 3004 D:\Program files\Winampp\Plugins\DFX\Apps\touch_file.exe infected Virus.Win32.Sality.aa ...18:05:40:002 3004 cured
18:05:40:158 3004 D:\Program files\Winampp\Plugins\DFX\dfxwsettings.exe infected Virus.Win32.Sality.aa ...18:05:40:158 3004 cured
18:05:51:502 3004 D:\Program files\Winampp\uninstall_dfx.exe infected Virus.Win32.Sality.aa ...18:05:51:502 3004 cured
18:05:51:768 3004 D:\Program files\Winampp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:05:51:768 3004 cured
18:06:11:674 3004 D:\Program files\Winamppp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:06:11:674 3004 cured
18:06:11:783 3004 D:\Program files\Winamppp\winampa.exe infected Virus.Win32.Sality.aa ...18:06:11:783 3004 cured
18:06:36:861 3004 D:\Program files\Winampppp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:06:36:861 3004 cured
18:06:37:064 3004 D:\Program files\WinCustomize\LogonStudio\LogonStudio.exe infected Virus.Win32.Sality.aa ...18:06:37:064 3004 cured
18:06:37:611 3004 D:\Program files\WinCustomize\LogonStudio\UNWISE.EXE infected Virus.Win32.Sality.aa ...18:06:37:611 3004 cured
18:06:38:549 3004 D:\Program files\windesk\SkinChangerMSNV2\uninstall.exe infected Virus.Win32.Sality.aa ...18:06:38:549 3004 cured
18:06:38:674 3004 D:\Program files\Windows Media Player\dlimport.exe infected Virus.Win32.Sality.aa ...18:06:38:674 3004 cured
18:06:38:861 3004 D:\Program files\Windows Media Player\migrate.exe infected Virus.Win32.Sality.aa ...18:06:38:861 3004 cured
18:06:39:174 3004 D:\Program files\Windows Media Player\setup_wm.exe infected Virus.Win32.Sality.aa ...18:06:39:174 3004 cured
18:06:40:018 3004 D:\Program files\Windows Media Player\wmlaunch.exe infected Virus.Win32.Sality.aa ...18:06:40:018 3004 cured
18:06:40:299 3004 D:\Program files\Windows Media Player\wmpenc.exe infected Virus.Win32.Sality.aa ...18:06:40:299 3004 cured
18:06:40:580 3004 D:\Program files\Windows Media Player\wmplayer.exe infected Virus.Win32.Sality.aa ...18:06:40:580 3004 cured
18:06:41:018 3004 D:\Program files\Windows Media Player\wmsetsdk.exe infected Virus.Win32.Sality.aa ...18:06:41:018 3004 cured
18:06:41:158 3004 D:\Program files\Windows NT\Accessories\wordpad.exe infected Virus.Win32.Sality.aa ...18:06:41:158 3004 cured
18:06:41:283 3004 D:\Program files\Windows NT\dialer.exe infected Virus.Win32.Sality.aa ...18:06:41:283 3004 cured
18:06:41:658 3004 D:\Program files\Windows NT\Pinball\pinball.exe infected Virus.Win32.Sality.aa ...18:06:41:658 3004 cured
18:06:43:377 3004 D:\Program files\WinFast\WFTVFM\wfcpuuse.exe infected Virus.Win32.Sality.aa ...18:06:43:393 3004 cured
18:06:43:768 3004 D:\Program files\WinFast\WFTVFM\WFFM.exe infected Virus.Win32.Sality.aa ...18:06:43:768 3004 cured
18:06:44:080 3004 D:\Program files\WinFast\WFTVFM\WFIEPG.exe infected Virus.Win32.Sality.aa ...18:06:44:080 3004 cured
18:06:44:189 3004 D:\Program files\WinFast\WFTVFM\WFLauncher.exe infected Virus.Win32.Sality.aa ...18:06:44:189 3004 cured
18:06:44:346 3004 D:\Program files\WinFast\WFTVFM\WFMultRM.EXE infected Virus.Win32.Sality.aa ...18:06:44:346 3004 cured
18:06:44:768 3004 D:\Program files\WinFast\WFTVFM\WFSCHDL.exe infected Virus.Win32.Sality.aa ...18:06:44:768 3004 cured
18:06:44:861 3004 D:\Program files\WinFast\WFTVFM\WFTTX.exe infected Virus.Win32.Sality.aa ...18:06:44:861 3004 cured
18:06:45:236 3004 D:\Program files\WinFast\WFTVFM\WFTV.exe infected Virus.Win32.Sality.aa ...18:06:45:236 3004 cured
18:06:45:627 3004 D:\Program files\WinFast\WFTVFM\WFVTX.exe infected Virus.Win32.Sality.aa ...18:06:45:627 3004 cured
18:06:45:736 3004 D:\Program files\WinFast\WFTVFM\WFWIZ.exe infected Virus.Win32.Sality.aa ...18:06:45:736 3004 cured
18:06:47:596 3004 D:\Program files\Xfire\51.exe infected Virus.Win32.Sality.aa ...18:06:47:596 3004 cured
18:06:48:064 3004 D:\Program files\Xfire\83.exe infected Virus.Win32.Sality.aa ...18:06:48:064 3004 cured
18:07:10:533 3004 D:\Program files\Xfire\uninst.exe infected Virus.Win32.Sality.aa ...18:07:10:533 3004 cured
18:07:10:908 3004 D:\Program files\Xfire\xfencoder.exe infected Virus.Win32.Sality.aa ...18:07:10:908 3004 cured
18:07:11:018 3004 D:\Program files\Xfire\Xfire.exe infected Virus.Win32.Sality.aa ...18:07:11:018 3004 cured
18:07:11:205 3004 D:\Program files\Xfire\xfire_exception.exe infected Virus.Win32.Sality.aa ...18:07:11:205 3004 cured
18:07:12:502 3004 D:\Program files\XviD\MiniCalc.exe infected Virus.Win32.Sality.aa ...18:07:12:502 3004 cured
18:07:13:221 3004 D:\Program files\XviD\UninstXviD.exe infected Virus.Win32.Sality.aa ...18:07:13:221 3004 cured
18:07:14:158 3004 D:\Programe\ChrSD112\Chrono Shutdown.exe infected Virus.Win32.Sality.aa ...18:07:14:346 3004 cured
18:07:28:236 3004 D:\Programe\Winamp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:07:28:236 3004 cured
18:07:29:049 3004 D:\Programe\Winamp\winamp.exe infected Virus.Win32.Sality.aa ...18:07:29:049 3004 cured
18:07:38:955 3004 D:\Prophet IT\ABC Auto\Surse\bord.exe infected Virus.Win32.Sality.aa ...18:07:38:955 3004 cured
18:07:39:393 3004 D:\Prophet IT\ABC Auto\Surse\mijloace semnalizare.exe infected Virus.Win32.Sality.aa ...18:07:39:393 3004 cured
18:07:54:580 3004 D:\Q3stuff\-12- WM9Codecs.exe infected Virus.Win32.Sality.aa ...18:07:54:596 3004 cured
18:07:55:846 3004 D:\Q3stuff\1.16n- Quake 3 Update.exe infected Virus.Win32.Sality.aa ...18:07:55:846 3004 cured
18:07:57:674 3004 D:\Q3stuff\q3log\Q3Log.exe infected Virus.Win32.Sality.aa ...18:07:57:689 3004 cured
18:08:04:143 3004 D:\Q3stuff\q3pointrelease_132.exe infected Virus.Win32.Sality.aa ...18:08:04:143 3004 cured
18:08:09:018 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd11\misc\tools\DemosViewer.exe infected Virus.Win32.Sality.aa ...18:08:09:018 3004 cured
18:08:09:299 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd11\misc\tools\GhostsConverter.exe infected Virus.Win32.Sality.aa ...18:08:09:299 3004 cured
18:08:10:486 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd25\DELTEMP.EXE infected Virus.Win32.Sality.aa ...18:08:10:486 3004 cured
18:08:10:939 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd25\DOTNETFX.EXE infected Virus.Win32.Sality.aa ...18:08:10:939 3004 cured
18:08:13:314 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd25\NDPSP.EXE infected Virus.Win32.Sality.aa ...18:08:13:314 3004 cured
18:08:13:408 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd25\REBOOTST.EXE infected Virus.Win32.Sality.aa ...18:08:13:408 3004 cured
18:08:13:564 3004 D:\RECYCLER\S-1-5-21-1957994488-1450960922-725345543-1003\Dd25\SETUP.EXE infected Virus.Win32.Sality.aa ...18:08:13:564 3004 cured
18:08:15:471 3004 D:\RECYCLER\S-1-5-21-436374069-630328440-839522115-1005\Dd13.exe infected Virus.Win32.Sality.aa ...18:08:15:471 3004 cured
18:08:20:486 3004 D:\RECYCLER\S-1-5-21-436374069-630328440-839522115-1005\Dd31.2010\kav6.0.1.411en.exe infected Virus.Win32.Sality.aa ...18:08:20:486 3004 cured
18:08:22:080 3004 D:\RECYCLER\S-1-5-21-436374069-630328440-839522115-1005\Dd32.GAME-Lz0\Crack\CI3Xmas.exe infected Virus.Win32.Sality.aa ...18:08:22:080 3004 cured
18:08:24:018 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd1\OpenALwEAX.exe infected Virus.Win32.Sality.aa ...18:08:24:018 3004 cured
18:08:25:721 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd3\!Patches\1.2 - US Patch\x2update1.2us.exe infected Virus.Win32.Sality.aa ...18:08:25:721 3004 cured
18:08:27:424 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd3\!Patches\1.3 - US Patch\Patch1.3US.exe infected Virus.Win32.Sality.aa ...18:08:27:424 3004 cured
18:08:27:596 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd3\!Patches\1.4 - AL - Update\AL_script_update.exe infected Virus.Win32.Sality.aa ...18:08:27:596 3004 cured
18:08:27:971 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd3\!Patches\1.4 - NoCD\X2NoCopyProt14ALL.exe infected Virus.Win32.Sality.aa ...18:08:27:971 3004 cured
18:08:28:658 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd3\!Patches\1.4 - US Patch\x2update14us.exe infected Virus.Win32.Sality.aa ...18:08:28:658 3004 cured
18:08:30:924 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd4.NFO\Tools\sfdrvrem.exe infected Virus.Win32.Sality.aa ...18:08:30:924 3004 cured
18:08:31:580 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd4.NFO\Tools\subinacl.exe infected Virus.Win32.Sality.aa ...18:08:31:580 3004 cured
18:08:31:721 3004 D:\RECYCLER\S-1-5-21-602162358-261903793-1417001333-1005\Dd4.NFO\Tools\virtual-cd-hide.exe infected Virus.Win32.Sality.aa ...18:08:31:721 3004 cured
18:08:40:439 3004 D:\[bleep]\andromeda\setup.exe infected Virus.Win32.Sality.aa ...18:08:40:439 3004 cured
18:08:40:533 3004 D:\[bleep]\andromeda\Support\Amdromeda Web Browser.exe infected Virus.Win32.Sality.aa ...18:08:40:533 3004 cured
18:08:40:908 3004 D:\[bleep]\andromeda\Support\SETUP.EXE infected Virus.Win32.Sality.aa ...18:08:40:924 3004 cured
18:08:41:002 3004 D:\[bleep]\andromeda\Support\SETUP1.EXE infected Virus.Win32.Sality.aa ...18:08:41:002 3004 cured
18:08:41:064 3004 D:\[bleep]\andromeda\Support\ST6UNST.EXE infected Virus.Win32.Sality.aa ...18:08:41:080 3004 cured
18:10:04:736 3004 D:\[bleep]\DC++\magnet.exe infected Virus.Win32.Sality.aa ...18:10:04:736 3004 cured
18:10:05:861 3004 D:\[bleep]\DC++\uninstall.exe infected Virus.Win32.Sality.aa ...18:10:05:861 3004 cured
18:10:10:486 3004 D:\[bleep]\DVDVideoSoft\Free Studio\Free DVD Video Converter\HandBrakeCLI.exe infected Virus.Win32.Sality.aa ...18:10:10:486 3004 cured
18:10:17:674 3004 D:\[bleep]\HLSW\hlsw.exe infected Virus.Win32.Sality.aa ...18:10:17:674 3004 cured
18:10:18:643 3004 D:\[bleep]\HLSW\update.exe infected Virus.Win32.Sality.aa ...18:10:18:643 3004 cured
18:10:20:486 3004 D:\[bleep]\Starcraft\install.exe infected Virus.Win32.Sality.aa ...18:10:20:486 3004 cured
18:10:33:174 3004 D:\[bleep]\winamp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:10:33:174 3004 cured
18:10:34:752 3004 D:\source\bin\q3asm.exe infected Virus.Win32.Sality.aa ...18:10:34:752 3004 cured
18:10:49:346 3004 D:\stuff\Cookie Remover Platinum 2004\Cookie Remover Platinum 2004.exe infected Virus.Win32.Sality.aa ...18:10:49:346 3004 cured
18:11:07:674 3004 D:\stuff\DC++\magnet.exe infected Virus.Win32.Sality.aa ...18:11:07:674 3004 cured
18:11:08:189 3004 D:\stuff\DC++\uninstall.exe infected Virus.Win32.Sality.aa ...18:11:08:189 3004 cured
18:11:09:799 3004 D:\stuff\namemaker\ASCIIStudio.exe infected Virus.Win32.Sality.aa ...18:11:09:799 3004 cured
18:11:10:080 3004 D:\stuff\namemaker\NMS6.exe infected Virus.Win32.Sality.aa ...18:11:10:080 3004 cured
18:11:10:486 3004 D:\stuff\Winamp\eMusic\EMusicClient.exe infected Virus.Win32.Sality.aa ...18:11:10:486 3004 cured
18:11:10:580 3004 D:\stuff\Winamp\eMusic\Uninst-eMusic-promotion.exe infected Virus.Win32.Sality.aa ...18:11:10:580 3004 cured
18:11:13:018 3004 D:\stuff\Winamp\Plugins\DFX\Apps\askemail.exe infected Virus.Win32.Sality.aa ...18:11:13:018 3004 cured
18:11:13:096 3004 D:\stuff\Winamp\Plugins\DFX\Apps\record_date.exe infected Virus.Win32.Sality.aa ...18:11:13:096 3004 cured
18:11:13:346 3004 D:\stuff\Winamp\Plugins\DFX\Apps\record_email.exe infected Virus.Win32.Sality.aa ...18:11:13:346 3004 cured
18:11:13:424 3004 D:\stuff\Winamp\Plugins\DFX\Apps\registryCleanUsers.exe infected Virus.Win32.Sality.aa ...18:11:13:424 3004 cured
18:11:13:518 3004 D:\stuff\Winamp\Plugins\DFX\Apps\step1.exe infected Virus.Win32.Sality.aa ...18:11:13:518 3004 cured
18:11:13:799 3004 D:\stuff\Winamp\Plugins\DFX\Apps\touch_file.exe infected Virus.Win32.Sality.aa ...18:11:13:799 3004 cured
18:11:14:080 3004 D:\stuff\Winamp\Plugins\DFX\dfxwsettings.exe infected Virus.Win32.Sality.aa ...18:11:14:080 3004 cured
18:11:26:205 3004 D:\stuff\Winamp\uninstall_dfx.exe infected Virus.Win32.Sality.aa ...18:11:26:205 3004 cured
18:11:26:283 3004 D:\stuff\Winamp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:11:26:283 3004 cured
18:11:26:596 3004 D:\stuff\Winamp\winampa.exe infected Virus.Win32.Sality.aa ...18:11:26:596 3004 cured
18:11:29:174 3004 D:\stuff\Winampp\Plugins\DFX\Apps\askemail.exe infected Virus.Win32.Sality.aa ...18:11:29:174 3004 cured
18:11:29:439 3004 D:\stuff\Winampp\Plugins\DFX\Apps\record_date.exe infected Virus.Win32.Sality.aa ...18:11:29:439 3004 cured
18:11:29:705 3004 D:\stuff\Winampp\Plugins\DFX\Apps\record_email.exe infected Virus.Win32.Sality.aa ...18:11:29:705 3004 cured
18:11:29:986 3004 D:\stuff\Winampp\Plugins\DFX\Apps\registryCleanUsers.exe infected Virus.Win32.Sality.aa ...18:11:29:986 3004 cured
18:11:30:111 3004 D:\stuff\Winampp\Plugins\DFX\Apps\step1.exe infected Virus.Win32.Sality.aa ...18:11:30:111 3004 cured
18:11:30:221 3004 D:\stuff\Winampp\Plugins\DFX\Apps\touch_file.exe infected Virus.Win32.Sality.aa ...18:11:30:221 3004 cured
18:11:30:314 3004 D:\stuff\Winampp\Plugins\DFX\dfxwsettings.exe infected Virus.Win32.Sality.aa ...18:11:30:314 3004 cured
18:11:39:611 3004 D:\stuff\Winampp\uninstall_dfx.exe infected Virus.Win32.Sality.aa ...18:11:39:611 3004 cured
18:11:39:877 3004 D:\stuff\Winampp\UninstWA.exe infected Virus.Win32.Sality.aa ...18:11:39:877 3004 cured
18:11:40:033 3004 D:\stuff\Winampp\winampa.exe infected Virus.Win32.Sality.aa ...18:11:40:033 3004 cured
18:20:23:971 3004 D:\TORENT\Gothic II The Dark Saga\DarkSaga-1.0.0.4.exe infected Virus.Win32.Sality.aa ...18:20:23:971 3004 cured
18:20:27:830 3004 D:\VIAUSB2V256-L\Setup.exe infected Virus.Win32.Sality.aa ...18:20:27:830 3004 cured
18:20:28:096 3004 D:\VIAUSB2V256-L\win98&me\viacb.exe infected Virus.Win32.Sality.aa ...18:20:28:096 3004 cured
18:20:56:439 3004
18:20:56:439 1148
Monitoring thread stopped
18:20:56:439 3004
completed
18:20:56:439 3004 Infected files: 596
18:20:56:439 3004 Infected processes: 2
18:20:56:439 3004 Infected threads: 19
18:20:56:439 3004 Cured files: 595
18:20:56:439 3004 Will be cured on reboot: 0
18:20:56:439 3004 Executed registry scripts: 1

Edited by Wolffie, 11 May 2013 - 09:26 AM.

  • 0

#8
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

holy crap?



Don't worry, just a file infector. :) You are lucky - such a small amount of infected files. Hope that this tool got rid of this nasty virus. Let's re-run scan once more!

Please, follow these steps:

Step 1. SalityKiller scan.

  • Press Win+R key sequence.
  • In the new window copy and paste the following:
  • C:\SalityKiller.exe -l C:\sklog1.txt
  • Click OK button.
  • A reboot might be required after disinfection.
  • Post contents of C:\sklog1.txt file in your next message.

Step 2. OTL scan.

Run OTL
  • Pick a tick near Scan All Users option, which is located near Quick Scan button.
  • Then click the Run Scan button at the top
  • Let the program run unhindered
  • When the scan completes, it will open notepad window - OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file, one at a time and post them in your topic.

So, please, don't forget to post in your next message:

  • Contents of SalityKiller's log
  • OTL's log

  • 0

#9
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
scaning now
i did a malwarebytes scan earlier and seems that the pum thing is gone and task mnger and the rest of the stuff work
only 1 lonely trojan that had to reboot to delete it, dunno if its gone
but some sites still cannot be opened and i get the same "server cannot be found" error
  • 0

#10
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
SK

22:08:47:234 3796 scanning threads ...
22:08:53:953 3796
22:08:53:953 3796 scanning processes ...
22:08:54:031 3796
22:08:54:031 3796 fixing registry ...
22:08:54:031 2796
Monitoring thread started
22:08:59:281 3796 SalityRegCure: Restoring general registry keys
22:08:59:328 3796 SalityRegCure: Fixing system.ini
22:08:59:562 3796
22:08:59:562 3796 scanning drives ...
22:08:59:578 3796 scanning C:\ ...
22:23:31:453 3796 scanning D:\ ...
22:37:51:875 3796 D:\Program files\Movie Maker\moviemk.exe infected Virus.Win32.Sality.aa ...22:37:51:875 3796 not cured
22:52:47:703 3796
22:52:50:718 2796
Monitoring thread stopped
22:52:50:718 3796
completed
22:52:50:718 3796 Infected files: 1
22:52:50:718 3796 Infected processes: 0
22:52:50:718 3796 Infected threads: 0
22:52:50:718 3796 Cured files: 0
22:52:50:718 3796 Will be cured on reboot: 0
22:52:50:718 3796 Executed registry scripts: 1



OTL


OTL logfile created on: 5/11/2013 11:01:31 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Logan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.93 Gb Available Physical Memory | 61.90% Memory free
2.11 Gb Paging File | 1.69 Gb Available in Paging File | 80.34% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.65 Gb Total Space | 1.33 Gb Free Space | 9.05% Space Free | Partition Type: NTFS
Drive D: | 97.13 Gb Total Space | 12.98 Gb Free Space | 13.36% Space Free | Partition Type: NTFS
Drive E: | 585.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 454.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HOME-FA201A11EA | User Name: Logan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/11 17:42:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2013/05/11 17:32:45 | 007,419,192 | ---- | M] (Yahoo! Inc.) -- C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2013/05/11 17:32:45 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2013/05/07 16:00:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Logan\My Documents\Downloads\OTL.exe
PRC - [2013/04/12 23:58:29 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2010/04/19 14:47:26 | 000,719,688 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE


========== Modules (No Company Name) ==========

MOD - [2013/04/12 23:58:16 | 003,133,336 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/04 03:47:42 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2012/01/04 03:47:42 | 000,078,336 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\pcre.dll
MOD - [2011/05/28 23:04:56 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/11/27 20:11:44 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2008/04/14 03:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 03:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (MSDTC)
SRV - File not found [Unknown (-1) | Stopped] -- -- (diovmvo)
SRV - [2013/05/11 17:41:51 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2013/03/08 20:30:01 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/28 13:09:51 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/04/19 14:42:36 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Unknown (-1) | Unknown (-1) | Unknown] -- -- (diovmvo)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/01/08 21:47:56 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/12/14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/11 22:13:48 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2012/03/11 22:13:46 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdguard.sys -- (cmdGuard)
DRV - [2012/03/11 22:13:46 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdhlp.sys -- (cmdHlp)
DRV - [2010/02/25 12:18:08 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2008/04/13 21:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum)
DRV - [2004/11/17 14:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2004/08/04 01:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139)
DRV - [2004/08/04 01:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/16 09:19:52 | 000,070,400 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys -- (RTL8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 23:58:40 | 000,000,000 | ---D | M]

[2012/03/07 21:53:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions\trash
[2013/04/12 23:57:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 23:58:38 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/12 23:57:55 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/12 23:57:55 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.ro/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: c\u0103utare Google = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2001/08/23 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDriveTypeAutoRun: NoDriveTypeAutoRun = 177
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1454471165-1659004503-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 177
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.96.7.88 95.77.94.88
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{561FCA04-03EC-4ECD-A742-B656D6FA86EF}: DhcpNameServer = 78.96.7.88 95.77.94.88
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2012/01/23 21:58:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/10/04 10:57:04 | 000,000,043 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [2001/06/20 16:23:22 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\open\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell - "" = AutoRun
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutOplAy\cOmmANd - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutoRun\command - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\exPloRE\COMMANd - "" = G:\udgtms.pif
O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\OpEn\CommAnd - "" = G:\udgtms.pif
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutOplay\cOmMaND - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutoRun\command - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\Explore\COmMANd - "" = G:\rygj.exe
O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\open\ComMAnD - "" = G:\rygj.exe
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- [2004/12/22 11:30:34 | 000,425,984 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/11 17:34:12 | 000,000,000 | ---D | C] -- C:\Sality_RegKeys
[2013/05/11 17:31:51 | 000,171,344 | ---- | C] (Kaspersky Lab ZAO) -- C:\SalityKiller.exe
[2013/05/10 20:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Logan\Doctor Web
[2013/05/07 15:48:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Logan\Desktop\RK_Quarantine
[2013/05/07 15:28:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2013/05/07 13:08:43 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2013/04/12 23:57:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/11 23:04:01 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/05/11 21:21:48 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/05/11 21:21:48 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/05/11 21:17:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/05/11 21:17:15 | 1610,141,696 | -HS- | M] () -- C:\hiberfil.sys
[2013/05/11 17:39:27 | 004,280,320 | ---- | M] (Bethesda Softworks) -- C:\Documents and Settings\Logan\My Documents\Morrowind.exe
[2013/05/11 17:32:45 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
[2013/04/23 15:02:22 | 000,034,799 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:59 | 000,360,457 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/04/19 22:00:40 | 000,009,216 | ---- | M] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/23 15:02:20 | 000,034,799 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:54 | 000,360,457 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/01/28 13:01:16 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2013/01/07 21:54:26 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2012/12/23 04:05:38 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/08/02 10:17:08 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/15 17:04:07 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/02/15 17:02:48 | 000,189,792 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/15 15:49:25 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/02/15 15:25:50 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2012/02/15 15:25:46 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2012/02/15 15:25:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2012/02/15 15:17:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/02/15 15:10:38 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 03:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 03:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
  • 0

Advertisements


#11
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts

but some sites still cannot be opened and i get the same "server cannot be found" error


Can you please give examples of such sites?

Do you have this folder on your computer?

C:\windows\servicepackfiles

Please, follow these steps:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    SRV - File not found [Unknown (-1) | Stopped] -- -- (diovmvo)
    DRV - File not found [Unknown (-1) | Unknown (-1) | Unknown] -- -- (diovmvo)
    O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell - "" = AutoRun
    O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{7da56a47-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\AutoRun\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
    O33 - MountPoints2\{7da56a49-fe3b-11e1-b434-00e04c811a7b}\Shell\open\command - "" = G:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe
    O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell - "" = AutoRun
    O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{8f2d715c-6932-11e2-b5a4-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell - "" = AutoRun
    O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{a1e2f18e-8d58-11e1-b340-00e04c811a7b}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
    O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutOplAy\cOmmANd - "" = G:\udgtms.pif
    O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\AutoRun\command - "" = G:\udgtms.pif
    O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\exPloRE\COMMANd - "" = G:\udgtms.pif
    O33 - MountPoints2\{ad99bd18-123d-11e2-b47a-00e04c811a7b}\Shell\OpEn\CommAnd - "" = G:\udgtms.pif
    O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutOplay\cOmMaND - "" = G:\rygj.exe
    O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\AutoRun\command - "" = G:\rygj.exe
    O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\Explore\COmMANd - "" = G:\rygj.exe
    O33 - MountPoints2\{b5944fca-675b-11e1-b30f-00e04c811a7b}\Shell\open\ComMAnD - "" = G:\rygj.exe
    
    :Files
    rename "D:\Program files\Movie Maker\moviemk.exe" "D:\Program files\Movie Maker\moviemk.ex_" /c
    
    :Commands
    [EMPTYTEMP]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#12
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
well malwarebytes.org won`t work for example

i will carry on with the rest tomorrow morning

also could you help me with the booting problem please?
why windows can`t boot from hdd even thou i changed it in the boot screen?
  • 0

#13
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
ok
got the folder
did the fix
heres the log

OTL logfile created on: 5/12/2013 12:08:04 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Logan\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 66.79% Memory free
2.11 Gb Paging File | 1.72 Gb Available in Paging File | 81.58% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.65 Gb Total Space | 2.25 Gb Free Space | 15.35% Space Free | Partition Type: NTFS
Drive D: | 97.13 Gb Total Space | 12.98 Gb Free Space | 13.36% Space Free | Partition Type: NTFS
Drive E: | 585.11 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 454.56 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: HOME-FA201A11EA | User Name: Logan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/11 17:42:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2013/05/11 17:32:45 | 007,419,192 | ---- | M] (Yahoo! Inc.) -- C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2013/05/11 17:32:45 | 000,077,824 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
PRC - [2013/05/07 16:00:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Logan\My Documents\Downloads\OTL.exe
PRC - [2013/04/12 23:58:29 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
PRC - [2010/04/19 14:47:26 | 000,719,688 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
PRC - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
PRC - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE


========== Modules (No Company Name) ==========

MOD - [2013/04/12 23:58:16 | 003,133,336 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/01/04 03:47:42 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2012/01/04 03:47:42 | 000,078,336 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\pcre.dll
MOD - [2009/11/27 20:11:44 | 001,291,776 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2008/04/14 03:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/14 03:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- -- (MSDTC)
SRV - File not found [Unknown (-1) | Stopped] -- -- (diovmvo)
SRV - [2013/05/11 17:41:51 | 000,435,016 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2013/03/08 20:30:01 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/28 13:09:51 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/03/11 22:13:22 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/11/23 13:27:04 | 001,052,472 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe -- (CLPSLS)
SRV - [2010/04/19 14:45:44 | 001,050,440 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/04/19 14:42:36 | 000,030,024 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\WINDOWS\system32\uxtuneup.dll -- (UxTuneUp)
SRV - [2008/11/09 23:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Unknown (-1) | Unknown (-1) | Unknown] -- -- (diovmvo)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/01/08 21:47:56 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2012/12/14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/11 22:13:48 | 000,097,760 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2012/03/11 22:13:46 | 000,494,968 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdguard.sys -- (cmdGuard)
DRV - [2012/03/11 22:13:46 | 000,031,704 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\System32\DRIVERS\cmdhlp.sys -- (cmdHlp)
DRV - [2010/02/25 12:18:08 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2008/04/13 21:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum)
DRV - [2004/11/17 14:05:38 | 002,297,664 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\ALCXWDM.SYS -- (ALCXWDM)
DRV - [2004/08/04 01:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\RTL8139.SYS -- (rtl8139)
DRV - [2004/08/04 01:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag)
DRV - [2004/07/16 09:19:52 | 000,070,400 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys -- (RTL8023xp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..network.proxy.type: 0


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\IB Updater\Firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 23:58:40 | 000,000,000 | ---D | M]

[2012/03/07 21:53:33 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions
[2013/01/20 02:01:41 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Logan\Application Data\Mozilla\Firefox\Profiles\ayb2neaw.default\extensions\trash
[2013/04/12 23:57:35 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 23:58:38 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/04/12 23:57:55 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/04/12 23:57:55 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.google.ro/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\Application\26.0.1410.64\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: c\u0103utare Google = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Gmail = C:\Documents and Settings\Logan\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

O1 HOSTS File: ([2001/08/23 13:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe (COMODO)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe (COMODO)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDriveTypeAutoRun: NoDriveTypeAutoRun = 177
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 177
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 78.96.7.88 95.77.94.88
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{561FCA04-03EC-4ECD-A742-B656D6FA86EF}: DhcpNameServer = 78.96.7.88 95.77.94.88
O20 - AppInit_DLLs: (C:\WINDOWS\system32\guard32.dll) - C:\WINDOWS\system32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: TaskMan - (c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Logan\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2012/01/23 21:58:14 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [1998/10/04 10:57:04 | 000,000,043 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [2001/06/20 16:23:22 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{b7cd615d-57dc-11e1-9e9b-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- [2004/12/22 11:30:34 | 000,425,984 | R--- | M] ()
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/12 11:42:19 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/05/11 17:34:12 | 000,000,000 | ---D | C] -- C:\Sality_RegKeys
[2013/05/11 17:31:51 | 000,171,344 | ---- | C] (Kaspersky Lab ZAO) -- C:\SalityKiller.exe
[2013/05/10 20:13:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Logan\Doctor Web
[2013/05/07 15:48:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Logan\Desktop\RK_Quarantine
[2013/05/07 15:28:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2013/05/07 13:08:43 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2013/04/12 23:57:34 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/12 12:07:31 | 000,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/05/12 12:07:31 | 000,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/05/12 12:04:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/05/12 12:03:08 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/05/12 12:03:07 | 1610,141,696 | -HS- | M] () -- C:\hiberfil.sys
[2013/05/11 17:39:27 | 004,280,320 | ---- | M] (Bethesda Softworks) -- C:\Documents and Settings\Logan\My Documents\Morrowind.exe
[2013/04/23 15:02:22 | 000,034,799 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:59 | 000,360,457 | ---- | M] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/04/19 22:00:40 | 000,009,216 | ---- | M] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/23 15:02:20 | 000,034,799 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\la multi ani!.jpg
[2013/04/23 14:55:54 | 000,360,457 | ---- | C] () -- C:\Documents and Settings\Logan\Desktop\photo.htm
[2013/01/28 13:01:16 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\vusetup.dll
[2013/01/07 21:54:26 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2012/12/23 04:05:38 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/08/02 10:17:08 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\Logan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/15 17:04:07 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/02/15 17:02:48 | 000,189,792 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/15 15:49:25 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/02/15 15:25:50 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2012/02/15 15:25:46 | 000,156,672 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2012/02/15 15:25:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2012/02/15 15:17:20 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/02/15 15:10:38 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat

========== ZeroAccess Check ==========


[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 03:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 15:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 03:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/12 01:42:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CPA_VA
[2013/01/08 21:49:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2012/12/07 03:01:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TuneUp Software
[2012/12/07 02:59:55 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
[2013/01/08 21:50:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Logan\Application Data\DAEMON Tools Lite
[2012/12/07 03:02:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Logan\Application Data\TuneUp Software
[2013/03/31 12:10:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Logan\Application Data\uTorrent

========== Purity Check ==========



< End of report >
  • 0

#14
Phel

Phel

    Trusted Helper

  • Malware Removal
  • 1,386 posts
Have you runned Sality_RegKeys.zip?

also could you help me with the booting problem please?


Ok, can you please list me exactly boot sequence of your hardware on this computer?

Check if you have this file on your computer:

C:\windows\servicepackfiles\i386\moviemk.exe

Please, follow these steps:

Step 1. OTL fix.

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Files
    ipconfig /flushdns /c
    route /f /c
    
    :Commands
    [REBOOT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • After reboot Notepad window containing log should appear. Post it's contents in your next message.

What is with access to the sites now?

Step 2. GMER scan.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

So, please, don't forget to post in your next message:

  • GMER log
  • OTL log

  • 0

#15
Wolffie

Wolffie

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
edit:forgot to answer your questions sorry:
yes got the moviemk.exe there
and i did the saltyregkeys thing only when you asked me to(first step that worked i think it was)

had to open the otl log manually
dunno if it mathers



also since a few steps back(don`t know exactley witch)
youtube is acting up like this:
http://tinypic.com/r/33az3b5/5
and on this site,my avatar won`t show up,but everyone elses does(kinda weird)
and also yahoo mail inbox i click "compose new email" and it loads,and loads forever

========== FILES ==========
< ipconfig /flushdns /c >
No captured output from command...
C:\Documents and Settings\Logan\My Documents\Downloads\cmd.bat deleted successfully.
< route /f /c >
No captured output from command...
C:\Documents and Settings\Logan\My Documents\Downloads\cmd.bat deleted successfully.
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.69.0 log created on 05132013_213435






GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-05-13 23:32:17
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1200JD-00HBB0 rev.08.02D08 111.79GB
Running: gmer.exe; Driver: C:\DOCUME~1\Logan\LOCALS~1\Temp\uwrdqpog.sys


---- System - GMER 2.1 ----

SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwAdjustPrivilegesToken [0xA7BCF824]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwConnectPort [0xA7BCEDD0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateFile [0xA7BCF48A]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateKey [0xA7BD0062]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateSection [0xA7BD1C26]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateSymbolicLinkObject [0xA7BD1FA4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateThread [0xA7BCE7BC]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDeleteKey [0xA7BCFA10]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDeleteValueKey [0xA7BCFC18]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDuplicateObject [0xA7BCE5C2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateKey [0xA7BD0830]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateValueKey [0xA7BD0A86]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwLoadDriver [0xA7BD1658]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwMakeTemporaryObject [0xA7BCF098]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenFile [0xA7BCF666]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenKey [0xA7BD0052]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenProcess [0xA7BCE1F0]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenSection [0xA7BCF332]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenThread [0xA7BCE3F4]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryKey [0xA7BD0C94]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryMultipleValueKey [0xA7BD10E8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryValueKey [0xA7BD0EA6]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwRenameKey [0xA7BD05C8]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetSecurityObject [0xA7BCFE76]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetSystemInformation [0xA7BD1944]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetValueKey [0xA7BD0330]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwShutdownSystem [0xA7BCF002]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSystemDebugControl [0xA7BCF21E]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwTerminateProcess [0xA7BCEBD2]
SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwTerminateThread [0xA7BCE9C0]

---- User code sections - GMER 2.1 ----

.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Winamp\winampa.exe[192] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wdfmgr.exe[208] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 1002ADA0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 1002AD60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 1002AE20 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 1002AE00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtDeleteFile 7C90D23E 5 Bytes JMP 1002ADC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtFreeVirtualMemory 7C90D38E 5 Bytes JMP 1002A430 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtLoadDriver 7C90D46E 5 Bytes JMP 1002AD80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtOpenFile 7C90D59E 5 Bytes JMP 1002AD40 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 1002A3E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtSetInformationProcess 7C90DC9E 5 Bytes JMP 1002AD00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtUnloadDriver 7C90DEBE 5 Bytes JMP 1002AD20 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 1002ADE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 7 Bytes JMP 1002A6F0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!RtlAllocateHeap 7C9100C4 5 Bytes JMP 1002A480 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01566D70 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ntdll.dll!LdrGetProcedureAddress 7C917EA8 5 Bytes JMP 1002ACE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 1002AC20 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 1002A9C0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 1002AC60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 1002AC80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 1002AA20 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 018BD736 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 1002ACC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 1002AA00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!GetModuleHandleA 7C80B741 5 Bytes JMP 1002AA60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 018BD713 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!GetModuleHandleW 7C80E4DD 5 Bytes JMP 1002AA40 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1002AC00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileWithProgressW 7C81F72E 5 Bytes JMP 1002AAC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileW 7C821261 5 Bytes JMP 1002AB40 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!OpenFile 7C821982 5 Bytes JMP 1002AC40 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CopyFileExW 7C827B32 7 Bytes JMP 1002AB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CopyFileA 7C8286EE 5 Bytes JMP 1002ABE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CopyFileW 7C82F87B 5 Bytes JMP 1002ABC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!DeleteFileA 7C831EDD 5 Bytes JMP 1002AAA0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!DeleteFileW 7C831F63 5 Bytes JMP 1002AA80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileExW 7C83568B 5 Bytes JMP 1002AB00 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileA 7C835EBF 5 Bytes JMP 1002AB60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileWithProgressA 7C835EDE 5 Bytes JMP 1002AAE0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!ValidateLocale + B130 7C844958 7 Bytes JMP 01581C62 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!MoveFileExA 7C85E49B 5 Bytes JMP 1002AB20 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CopyFileExA 7C85F39C 1 Byte [E9]
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!CopyFileExA 7C85F39C 5 Bytes JMP 1002ABA0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 1002A9E0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] kernel32.dll!LoadModule 7C86261E 5 Bytes JMP 1002ACA0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 018BD694 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[416] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[480] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\csrss.exe[588] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 10001450 C:\WINDOWS\system32\cmdcsr.dll
.text C:\WINDOWS\system32\csrss.exe[588] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 100017F0 C:\WINDOWS\system32\cmdcsr.dll
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] RPCRT4.dll!RpcServerRegisterIfEx 77E8E05B 5 Bytes JMP 1001F060 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\services.exe[676] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\lsass.exe[688] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe[856] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] RPCRT4.dll!RpcServerRegisterIfEx 77E8E05B 5 Bytes JMP 1001F060 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[868] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] RPCRT4.dll!RpcServerRegisterIfEx 77E8E05B 5 Bytes JMP 1001F060 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[924] rpcss.dll!WhichService 76A84234 8 Bytes JMP ED501001
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[992] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1000] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00533F00 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
.text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1000] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 0054D9A0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 01F49DC2
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] RPCRT4.dll!RpcServerRegisterIfEx 77E8E05B 5 Bytes JMP 1001F060 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1028] NETAPI32.dll!NetpwPathCanonicalize 5B86A3A9 5 Bytes JMP 01F49D62
.text C:\gmer.exe[1116] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\gmer.exe[1116] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\gmer.exe[1116] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtQueryInformationProcess 7C90D7FE 5 Bytes JMP 008A9DC2
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\svchost.exe[1248] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\Explorer.EXE[1488] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\spoolsv.exe[1576] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 0114D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [84, 84]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 0115BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 0115B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01157DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 0114D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 01154F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 01155AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 01153A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 01154390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 01158BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 01158990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 01159CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe[1904] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 01159BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe[1916] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe[2024] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\SOUNDMAN.EXE[2040] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!NtClose 7C90CFEE 2 Bytes JMP 1001D080 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!NtClose + 3 7C90CFF1 2 Bytes [71, 93] {JNO 0xffffff95}
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BB80 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B860 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 10027DF0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ntdll.dll!LdrUnloadDll 7C91738B 5 Bytes JMP 1001D1A0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10024F30 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025AC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ADVAPI32.dll!CreateProcessAsUserW 77DEA8A9 5 Bytes JMP 10023A60 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] ADVAPI32.dll!CreateProcessAsUserA 77E10CE8 5 Bytes JMP 10024390 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028BC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028990 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029CC0 C:\WINDOWS\system32\guard32.dll
.text C:\WINDOWS\system32\NOTEPAD.EXE[2464] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029BC0 C:\WINDOWS\system32\guard32.dll

---- Devices - GMER 2.1 ----

AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys
AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys
AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys
AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys

---- Processes - GMER 2.1 ----

Process (*** hidden *** ) [4] 8A6C4830

---- Services - GMER 2.1 ----

Service C:\WINDOWS\system32\iwqks.dll (*** hidden *** ) [AUTO] diovmvo <-- ROOTKIT !!!

---- Registry - GMER 2.1 ----

Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@DisplayName Config Image
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@Type 32
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@Start 2
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\diovmvo\Parameters@ServiceDll C:\WINDOWS\system32\iwqks.dll
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@DisplayName Config Image
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\diovmvo\Parameters@ServiceDll C:\WINDOWS\system32\iwqks.dll
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@DisplayName Config Image
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@Type 32
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\diovmvo\Parameters@ServiceDll C:\WINDOWS\system32\iwqks.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@DisplayName Config Image
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo\Parameters@ServiceDll C:\WINDOWS\system32\iwqks.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\diovmvo
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@DisplayName Config Image
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@Type 32
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@Start 2
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\diovmvo\Parameters@ServiceDll C:\WINDOWS\system32\iwqks.dll

---- EOF - GMER 2.1 ----





edit: i fixed that booting thing
the problem was the priority was set to "bootable input devices" instead of hardisk(someone else installed xp on this pc)
so the first,2nd and 3rd boot devices didn`t mather what i switched it kept starting from cd
i was scared to change anything i wasn`t sure of in bios

Edited by Wolffie, 13 May 2013 - 03:22 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP