Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Bloodhound.W32.EP [RESOLVED]


  • This topic is locked This topic is locked

#16
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
File c:\windows\diejkli.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File c:\windows\nmqehvn.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File c:\windows\nevpdmq.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
Object "FunWeb Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MyWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "IBIS Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "180Solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bargain buddy Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "FunWeb Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "FunWebProducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "myway Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ncase Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "WhenU Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "altnet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "eZula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MyWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.loadbat Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.loadbat Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\Program Files\Yahoo!\Common\yinsthelper.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\FilePlanetDownloadCtrl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\gsda.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\nCaseInstaller.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\v2.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\nethv32.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\windec32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\AOLHelper.AOLToolbarBridge" refers to invalid object "{EE7CB360-F635-449D-BBB1-0D844F2A269D}". Action Taken: No Action Taken.
Entry "HKCR\AOLHelper.AOLToolbarBridge.1" refers to invalid object "{EE7CB360-F635-449D-BBB1-0D844F2A269D}". Action Taken: No Action Taken.
Entry "HKCR\auxSock2.auxSock" refers to invalid object "{B47BE342-5D4A-11D7-84F4-000AE634B086}". Action Taken: No Action Taken.
Entry "HKCR\BJAXSecurityManager.SecurityManager" refers to invalid object "{CEDDF50D-9FA7-41A8-BCD0-6350D1ED2306}". Action Taken: No Action Taken.
Entry "HKCR\BJAXSecurityManager.SecurityManager.1" refers to invalid object "{CEDDF50D-9FA7-41A8-BCD0-6350D1ED2306}". Action Taken: No Action Taken.
Entry "HKCR\CmdLineExt.CmdLineContextMenu" refers to invalid object "{9869EFB4-18E9-11D3-A837-00104B9E30B5}". Action Taken: No Action Taken.
Entry "HKCR\CmdLineExt.CmdLineContextMenu.1" refers to invalid object "{9869EFB4-18E9-11D3-A837-00104B9E30B5}". Action Taken: No Action Taken.
Entry "HKCR\DKIBand.DKIBandObj" refers to invalid object "{40D41A8B-D79B-43d7-99A7-9EE0F344C385}". Action Taken: No Action Taken.
Entry "HKCR\DKIBand.DKIBandObj.1" refers to invalid object "{40D41A8B-D79B-43d7-99A7-9EE0F344C385}". Action Taken: No Action Taken.
Entry "HKCR\LVbuttons.LaVolpeButton" refers to invalid object "{C63A574F-D681-4F2C-BC55-8C9BB71577E0}". Action Taken: No Action Taken.
Entry "HKCR\MSLFD.Debug" refers to invalid object "{9A47AE6D-B9F1-4197-A794-48B6A8CF9F4F}". Action Taken: No Action Taken.
Entry "HKCR\MSLFD.Debug.10" refers to invalid object "{9A47AE6D-B9F1-4197-A794-48B6A8CF9F4F}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.RootDevice" refers to invalid object "{7063B95A-70DB-4BAC-AF83-2E07A14B5D90}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.RootDevice.1" refers to invalid object "{7063B95A-70DB-4BAC-AF83-2E07A14B5D90}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.X_MSearch" refers to invalid object "{4A633ED4-41C3-466e-8E3C-82C33950B53C}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.X_MSearch.1" refers to invalid object "{4A633ED4-41C3-466e-8E3C-82C33950B53C}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.X_Notify" refers to invalid object "{3D36A6CC-E87B-4ae7-BE09-3BDF338445C1}". Action Taken: No Action Taken.
Entry "HKCR\RGWInterfaces.X_Notify.1" refers to invalid object "{3D36A6CC-E87B-4ae7-BE09-3BDF338445C1}". Action Taken: No Action Taken.
Entry "HKCR\Smartbox.SmartboxCtl" refers to invalid object "{0A99FD75-B264-48FC-AE49-924A646964B8}". Action Taken: No Action Taken.
Entry "HKCR\Smartbox.SmartboxCtl.1" refers to invalid object "{0A99FD75-B264-48FC-AE49-924A646964B8}". Action Taken: No Action Taken.
Entry "HKCR\tocSock1.tocSock" refers to invalid object "{22DF8246-239C-45B1-9298-A8CFFDB410DE}". Action Taken: No Action Taken.
Entry "HKCR\vcmm.DocHostUIHandler" refers to invalid object "{3F2BBC05-40DF-11D2-9455-00104BC936FF}". Action Taken: No Action Taken.
Entry "HKCR\Wtgutils.Loader" refers to invalid object "{F42D656E-34AD-11D5-A8E0-00A0CC663B7C}". Action Taken: No Action Taken.
Entry "HKCR\Wtgutils.Loader.1" refers to invalid object "{F42D656E-34AD-11D5-A8E0-00A0CC663B7C}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl22092863d89f409ea0317f1535888f1b" refers to invalid object "{22092863-d89f-409e-a031-7f1535888f1b}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl22092863d89f409ea0317f1535888f1b.1" refers to invalid object "{22092863-d89f-409e-a031-7f1535888f1b}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl2548c0b72402486fb5b2ae0ee1614f39" refers to invalid object "{2548c0b7-2402-486f-b5b2-ae0ee1614f39}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl2548c0b72402486fb5b2ae0ee1614f39.1" refers to invalid object "{2548c0b7-2402-486f-b5b2-ae0ee1614f39}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl38f450588c1b407982edb841b1fce54b" refers to invalid object "{38f45058-8c1b-4079-82ed-b841b1fce54b}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl38f450588c1b407982edb841b1fce54b.1" refers to invalid object "{38f45058-8c1b-4079-82ed-b841b1fce54b}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl41cac8312e0a4c669a6c22cbd2ab1689" refers to invalid object "{41cac831-2e0a-4c66-9a6c-22cbd2ab1689}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl41cac8312e0a4c669a6c22cbd2ab1689.1" refers to invalid object "{41cac831-2e0a-4c66-9a6c-22cbd2ab1689}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl482fbc65d5f342eda3460c53ebd1d684" refers to invalid object "{482fbc65-d5f3-42ed-a346-0c53ebd1d684}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl482fbc65d5f342eda3460c53ebd1d684.1" refers to invalid object "{482fbc65-d5f3-42ed-a346-0c53ebd1d684}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl48788bf44a824efa81a5e784fbb54496" refers to invalid object "{48788bf4-4a82-4efa-81a5-e784fbb54496}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl48788bf44a824efa81a5e784fbb54496.1" refers to invalid object "{48788bf4-4a82-4efa-81a5-e784fbb54496}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl5779aaaf545f4e42b788426cda20c6ad" refers to invalid object "{5779aaaf-545f-4e42-b788-426cda20c6ad}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl5779aaaf545f4e42b788426cda20c6ad.1" refers to invalid object "{5779aaaf-545f-4e42-b788-426cda20c6ad}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl705a7882f697431aa9488af672bff566" refers to invalid object "{705a7882-f697-431a-a948-8af672bff566}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl705a7882f697431aa9488af672bff566.1" refers to invalid object "{705a7882-f697-431a-a948-8af672bff566}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl7a3f8cbe6bc446b4bd1ac3b45d31486e" refers to invalid object "{7a3f8cbe-6bc4-46b4-bd1a-c3b45d31486e}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl7a3f8cbe6bc446b4bd1ac3b45d31486e.1" refers to invalid object "{7a3f8cbe-6bc4-46b4-bd1a-c3b45d31486e}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl86a9a8e8c0274458b9308b97ece64f53" refers to invalid object "{86a9a8e8-c027-4458-b930-8b97ece64f53}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl86a9a8e8c0274458b9308b97ece64f53.1" refers to invalid object "{86a9a8e8-c027-4458-b930-8b97ece64f53}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl8d9c75892a754fc8a620b95192ea2090" refers to invalid object "{8d9c7589-2a75-4fc8-a620-b95192ea2090}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl8d9c75892a754fc8a620b95192ea2090.1" refers to invalid object "{8d9c7589-2a75-4fc8-a620-b95192ea2090}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl923647172c284c1daa4675b71d0e6888" refers to invalid object "{92364717-2c28-4c1d-aa46-75b71d0e6888}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl923647172c284c1daa4675b71d0e6888.1" refers to invalid object "{92364717-2c28-4c1d-aa46-75b71d0e6888}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl9e80a3c57603499098093aa58ccb8cb3" refers to invalid object "{9e80a3c5-7603-4990-9809-3aa58ccb8cb3}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl9e80a3c57603499098093aa58ccb8cb3.1" refers to invalid object "{9e80a3c5-7603-4990-9809-3aa58ccb8cb3}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl9f1db86f1f2c448d9500671f11864909" refers to invalid object "{9f1db86f-1f2c-448d-9500-671f11864909}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThl9f1db86f1f2c448d9500671f11864909.1" refers to invalid object "{9f1db86f-1f2c-448d-9500-671f11864909}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThld47963d2484645ec9c77721db1dbd2e1" refers to invalid object "{d47963d2-4846-45ec-9c77-721db1dbd2e1}". Action Taken: No Action Taken.
Entry "HKCR\Wtlaunch.WThld47963d2484645ec9c77721db1dbd2e1.1" refers to invalid object "{d47963d2-4846-45ec-9c77-721db1dbd2e1}". Action Taken: No Action Taken.
Entry "HKCR\Yauto.NSAuto" refers to invalid object "{6AE4CC6E-999C-11D4-A3F0-009027427750}". Action Taken: No Action Taken.
Entry "HKCR\Yauto.NSAuto.1" refers to invalid object "{6AE4CC6E-999C-11D4-A3F0-009027427750}". Action Taken: No Action Taken.
File C:\WINDOWS\odbs.log infected by "Trojan.JS.StartPage.x" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Owner\My Documents\Crackpack_3.rar tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken.
File C:\Program Files\BroadJump\Client Foundation\updatestaging\SBCWebInstaller-Update.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.b. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0041518F tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0075112D tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\00826731 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\00B80860 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\01083BB2 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\010B3388 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\010C65AE tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\010F0FAA tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\011239A7 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\011663A3 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\01190DA0 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\011C379C tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\011F6198 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\012654AB infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\01297EA7 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0204139C infected by "Trojan-Downloader.Win32.Dyfuca.y" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\03806B83 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\03C31960 tagged as "not-a-virus:AdWare.WebSearch.g". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\03C6435C tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\040C7E3E infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\04B16ACC tagged as "not-a-virus:AdWare.BHO.SearchAssistant.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\06F66222 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\079036B1 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\09C90534 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\09CC2F31 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0AA61ADC infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0AA944D9 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0B887D48 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C132330 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C5E2CE0 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C724F3A infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C832128 infected by "Trojan-Downloader.Win32.Agent.z" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C8D1F1E tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0C90491A tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0D736CAA infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0DD525B3 infected by "Trojan-Downloader.Win32.Delf.ep" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0DD84FB0 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0E17341E tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0E261F2F tagged as "not-a-virus:AdWare.Ipend". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0E541E99 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0E574896 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0E5A7292 infected by "Trojan-Downloader.Win32.Small.go" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\10C64E4A infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\10F66433 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\11CA7C4C tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\122B67B3 infected by "Exploit.HTML.IframeBof" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\12DE5561 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\132952BC tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\14675DF2 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\146A07EE tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\156A06A1 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\15CB0019 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\15E2684A tagged as "not-a-virus:AdWare.WebSearch.g". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\18810AA5 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D335885 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D5A4EBA tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D6F731B infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\209B1EC9 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\227244C3 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\23981A72 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\239B446E infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\23C32549 infected by "Trojan.JS.Seeker-based" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\241D05EC infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\24225D8B tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\242D57D2 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\24A241D3 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\24A66BCF infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\251A5DD0 infected by "Trojan-Downloader.VBS.Psyme.y" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\261415B6 infected by "Trojan.Win32.Small.i" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\28AF7D02 infected by "Trojan-Dropper.Win32.Delf.z" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\29427A76 infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\29B56ADD infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\29B814DA infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2A207874 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2BC009EB tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2C2B5DD8 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2C607831 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2CD027C9 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D471CD9 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2D4D465B infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2E9B3953 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2EA62D72 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2ED4337F infected by "Trojan-Clicker.Win32.Nex" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F0010EC tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F417179 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2F9410C0 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FB3198A tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FD13A18 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2FFA1A7A tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\30281094 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\306932BE infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\30BC1068 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\30F96A72 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3150103C tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\31F83A6A tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\32565019 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\32597A16 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\340031DB tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\35014F5D infected by "Trojan-Downloader.Win32.Agent.av" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36306C89 infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\365A7737 tagged as "not-a-virus:AdWare.F1Organizer.c". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\365E2134 tagged as "not-a-virus:AdWare.BHO.SearchAssistant.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36614375 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36614B30 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36E323D2 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36E64DCE tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\36F21F2B infected by "Trojan-Downloader.Win32.Dyfuca.ac" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\371201AA tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\38DF4921 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\398463A3 infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3B435589 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BC13133 infected by "Trojan.Win32.Agent.r" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BC80E33 infected by "Trojan-Downloader.Win32.Dyfuca.cn" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BE228C2 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BE82907 tagged as "not-a-virus:AdWare.F1Organizer.h". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BFC24F2 infected by "Trojan-Downloader.Win32.WinShow.ap" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3BFF4EEE infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3C57139C tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3C755033 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3E8B4637 infected by "Trojan-Downloader.Win32.Dyfuca.y" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3E8F7034 infected by "Trojan.Win32.Small.i" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3E921A30 infected by "Trojan.Win32.Small.i" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3ED84FD1 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3F906DD9 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\3FD619E3 infected by "Trojan-Dropper.Win32.Siboco.d" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\402250CF tagged as "not-a-virus:AdWare.BHO.SearchAssistant.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\409816A7 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\41047E65 tagged as "not-a-virus:AdWare.TotalVelocity.o". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\41112657 infected by "Trojan-Dropper.Win32.Small.gj" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\41177A50 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\42B824D5 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\43510985 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\44543AF8 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\463D6F2C tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\464B4531 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\46691E8A tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\466C4887 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\472F055C infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\47322F58 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\475933DD infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\47CC719B tagged as "not-a-virus:AdWare.ClientMan". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\48CE68D5 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\49FA0FDE tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4A0163D7 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4A040DD3 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4AB06BA0 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4C2C00C7 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4D3673D4 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4D3F497B infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4D5338AE infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4DA33657 infected by "Trojan-Downloader.Win32.Siboco" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4FA228A2 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\4FF022F6 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\518C09CD infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\51DB012F tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5318452F tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\533B4AAA infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\53966F5A infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\55CB65DE infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\55DF5221 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\55E6378E tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\56C45D97 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\56C70793 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\579E6F7D infected by "Trojan-Spy.Win32.Briss.e" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\57A21979 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\57A54376 infected by "Trojan-Dropper.Win32.Delf.z" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\57A7151B infected by "Exploit.HTML.CodeBaseExec" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\58401E93 tagged as "not-a-virus:AdWare.BHO.SearchAssistant.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\58431566 infected by "Trojan-Downloader.Win32.Small.en" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\59567975 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\595F6864 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5B13210D tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5B873239 infected by "Trojan-Dropper.Win32.Small.kp" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5BAA464A tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5BDB29DD infected by "Trojan-Downloader.Win32.Delf.ep" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5C9654A3 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5C997E9F tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5E6479D3 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5EAC52CC tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5F3610F3 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5F393AF0 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60AD6132 tagged as "not-a-virus:AdWare.VirtualBouncer.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60B00B2E tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60B4352A tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\60B75F27 tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\615B358E infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\615F5F8B infected by "Trojan-Spy.Win32.Briss.e" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\61620987 infected by "Trojan-Downloader.Win32.Small.go" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\61653384 infected by "Trojan-Downloader.Win32.Dyfuca.j" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\61695D80 infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\625B5B4B infected by "Trojan-Dropper.Win32.Agent.bu" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\64131D8A tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\645F4513 infected by "Trojan-Dropper.Win32.Small.gj" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\65875CF5 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\65CC24C7 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\66627FD9 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\68E6632B infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\69EB3B8B tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6B02342C infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6C9E3A9D tagged as "not-a-virus:AdWare.Ipend". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6D191A65 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6D39615C tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6EB72136 tagged as "not-a-virus:AdWare.Wintol.k". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6F0F5C0F infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6FA224E6 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\700C3CE2 infected by "Trojan-Downloader.Win32.Dyfuca.ak" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\70790276 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7179526E tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\718867EA tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\71AF5186 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\729D045F infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72A02E5C infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72A35858 infected by "Trojan.Win32.Kolweb.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72A60254 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72AA2C51 tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\72AD564D infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\757B7789 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\763110BD infected by "Trojan-Dropper.Win32.Delf.z" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\771B10B1 infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\78510F72 tagged as "not-a-virus:AdWare.Wintol.f". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\79C80FDA tagged as "not-a-virus:AdWare.Wintol.j". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7A1D24EF tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7A6C5AC7 infected by "Trojan-Downloader.Win32.Dyfuca.ak" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7CBA7D2A infected by "Trojan-Downloader.Win32.VB.ca" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7D6417B2 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7DD84617 tagged as "not-a-virus:AdWare.Wintol.d". Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7F197AC8 infected by "Trojan-Downloader.Win32.Small.fo" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\7F883E3A infected by "Email-Worm.Win32.NetSky.q" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\035A4BF6.exe infected by "Trojan-Downloader.Win32.Small.bct" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\07383971.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\07553351.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.582. No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\2008306B.exe infected by "Trojan-Downloader.Win32.Small.bct" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\26C73BDB.exe infected by "Trojan-Downloader.Win32.Small.ayl" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000008.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000009.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000010.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000011.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000012.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000013.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000014.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.582. No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000015.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000016.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000017.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000018.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000019.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000020.exe infected by "Trojan.Win32.StartPage.abc" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{F2681A7D-91E5-401A-AC8B-015335799DC0}\RP1\A0000021.dll tagged as "not-a-virus:AdWare.ToolBar.Ilookup.b". Action Taken: No Action Taken.
File C:\WINDOWS\cabsys\log.exe infected by "Backdoor.IRC.Ataka.i" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\EPXActiveX.ocx infected by "Trojan-Dropper.Win32.Agent.or" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\EPXActiveX.ocx infected by "Trojan-Dropper.Win32.Agent.or" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\odbs.log infected by "Trojan.JS.StartPage.x" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Temp\~494797.tmp tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.
File C:\WINDOWS\Temp\~757404.tmp infected by "Trojan-Downloader.Win32.Wintool.a" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Temp\~826360.tmp tagged as "not-a-virus:AdWare.Wintol.p". Action Taken: No Action Taken.








Logfile of HijackThis v1.99.1
Scan saved at 4:34:44 PM, on 7/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\System32\rundll32.exe
C:\windows\diejkli.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abcsearch4u.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\R
  • 0

Advertisements


#17
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Your HijackThis log looks incomplete. Please repost that log.
  • 0

#18
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
sorry about that
Logfile of HijackThis v1.99.1
Scan saved at 4:34:44 PM, on 7/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\WINDOWS\System32\rundll32.exe
C:\windows\diejkli.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Yahoo!\browser\YBrowser.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abcsearch4u.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [gsqkhqu] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [iejuput] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [upjivea] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [ifdlxax] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [fofaevw] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bnbfctu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [dddmtan] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bkxdnmg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cygttch] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [rbfvbxk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [qawbiku] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [urcnlek] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ikhrkct] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [gdhcolv] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ddphovd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [yaqwipt] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [omlfjao] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [mbnjbbs] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [khahjdq] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [irrkiod] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [tdramop] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [oduxsxg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bbkxfon] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [erflvks] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [dkgicrd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xhyjtdt] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [hicgymh] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xmkloyr] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [wbfyuhu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [kqjmxog] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [adxnvwf] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jqckmbk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [lhqtqtl] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ulgrsnr] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [pgnnkjw] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ipgyphb] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [hkllxyg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [imgcihm] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [yaxpiop] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [vhnmdrx] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [sojbbok] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ayssiay] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ltwanas] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xukmfky] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bjtboaj] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ccisaiu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [tukyarf] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ofymakd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jqvmfbk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [owgnwxj] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [wxbxvta] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [rbaooew] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [pdhhonc] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [nrvxxkh] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ddotajn] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cftgthp] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jykhixm] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [racomxu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cgkfkpi] c:\windows\aekxbav.exe
O4 - HKCU\..\Run: [dvxetcw] c:\windows\aekxbav.exe
O4 - HKCU\..\Run: [ouvkboi] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [dhunpvn] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [vvcmcnp] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [gfbkvmx] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [mjnkplm] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [qxlbcns] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [tymalob] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [sfcmkyc] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [xdkpnvy] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [blsadoh] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [fvqnrwe] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [jnlauyc] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [rltpfye] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [enqhdqs] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [xhcogdf] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [prfmths] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [nqptoim] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [mdvgrot] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [huyqasv] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [uahvtuv] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [lwgnuwk] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [jkbmuaa] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kyollbb] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [coewkka] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [tehvvus] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [evwaaqq] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kyhotfn] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [udrnhre] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kharnqo] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kwstqyd] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [owcrebr] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [ayefxfc] c:\windows\nmqehvn.exe
O4 - HKCU\..\Run: [fsvivaq] c:\windows\nmqehvn.exe
O4 - HKCU\..\Run: [yycbwgx] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [aornwyy] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [mghvsdc] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [hyqguyj] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [jptoent] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [sauddgg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yghbjvi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [lfooghi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fvalsae] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [bhdfvqi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yfmngsq] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yaomenr] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qqqedlg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qwhudbt] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [pyavtwd] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [nhujdtc] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fwldfwv] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [vjtotgf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [xbglldp] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [heltloq] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [wudnscn] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [iwhvqei] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qcdllcp] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ptyhdkg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [nmkebbs] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [utuqsmi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ugkroww] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qlfrkfu] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rimqajb] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ostinyv] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [iqsrrmf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [dfnqmri] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [gibdhrm] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [kojvuxh] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yxuloex] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [aiesgwf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ctlgifk] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [eirnlra] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rmspoux] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fojnvmg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [wjagaaa] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [kwvbywl] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rbaddnu] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [evkgphb] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [oyaqfnf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [glehfek] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [tdxkuch] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rkaaltd] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [xcmvuvn] c:\windows\ktqggoy.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AutoTBar.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader - http://miniclip.com/...tgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#19
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
OK, I will have to ask other experts to help me out on this one. I can't figure out why it's doing this.

Give me a day's time. I should get a response from someone by then.

Just reply back once more so that I have you in my list of unreplied posts - that way I won't lose track of your topic here :tazz:
  • 0

#20
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
allrite It's cool take your time,you helped me with my main problem of not being able to change background.Thanks :tazz:
  • 0

#21
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
OK, we got it now (hopefully) :tazz:

Download and Save Spywadfix to your computer from this link: http://www.thespykil...s/spywadfix.exe and double click on the spywadfix.exe

It will automatically extract to c:\spywad where it needs to be to run and will automatically open the remove spywad.vbs script for you ready to paste in the line mentioned below

If it doesn't open then go to c:\spywad and double click on the remove spywad.vbs Do not run any other file from there please unless asked to

If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.

It will open an Input box. Paste this line into the box

C:\windows\diejkli.exe

The script will kill that process, backup and then delete any matching files in System32 and your Windows Directory. It will create a log of all files deleted. This log file will be named Spywad.txt and be located inside the C:\Spywad Folder. The backups will also be located in two subfolders there. One named Systems and the other named Window.

The script will search the Windows Directory and delete desktop.html and popup.html if they exist. It will add entries to the log if these files are found and deleted.

It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.

It will restart Explorer.


** Script Does not remove the orphaned run entries.

Finally, it will Run hijackthis so that you can remove the orphaned run entries and anything else as instructed by your Advisor on the forums.

If hijackthis doesn't start, run it manually. Check and fix these in HijackThis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://abcsearch4u.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://abcsearch4u.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://abcsearch4u.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://abcsearch4u.com/
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKCU\..\Run: [gsqkhqu] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [iejuput] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [upjivea] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [ifdlxax] c:\windows\sddjmyv.exe
O4 - HKCU\..\Run: [fofaevw] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bnbfctu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [dddmtan] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bkxdnmg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cygttch] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [rbfvbxk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [qawbiku] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [urcnlek] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ikhrkct] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [gdhcolv] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ddphovd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [yaqwipt] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [omlfjao] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [mbnjbbs] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [khahjdq] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [irrkiod] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [tdramop] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [oduxsxg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bbkxfon] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [erflvks] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [dkgicrd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xhyjtdt] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [hicgymh] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xmkloyr] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [wbfyuhu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [kqjmxog] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [adxnvwf] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jqckmbk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [lhqtqtl] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ulgrsnr] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [pgnnkjw] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ipgyphb] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [hkllxyg] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [imgcihm] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [yaxpiop] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [vhnmdrx] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [sojbbok] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ayssiay] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ltwanas] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [xukmfky] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [bjtboaj] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ccisaiu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [tukyarf] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ofymakd] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jqvmfbk] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [owgnwxj] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [wxbxvta] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [rbaooew] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [pdhhonc] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [nrvxxkh] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [ddotajn] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cftgthp] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [jykhixm] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [racomxu] c:\windows\qnervjm.exe
O4 - HKCU\..\Run: [cgkfkpi] c:\windows\aekxbav.exe
O4 - HKCU\..\Run: [dvxetcw] c:\windows\aekxbav.exe
O4 - HKCU\..\Run: [ouvkboi] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [dhunpvn] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [vvcmcnp] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [gfbkvmx] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [mjnkplm] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [qxlbcns] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [tymalob] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [sfcmkyc] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [xdkpnvy] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [blsadoh] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [fvqnrwe] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [jnlauyc] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [rltpfye] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [enqhdqs] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [xhcogdf] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [prfmths] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [nqptoim] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [mdvgrot] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [huyqasv] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [uahvtuv] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [lwgnuwk] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [jkbmuaa] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kyollbb] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [coewkka] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [tehvvus] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [evwaaqq] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kyhotfn] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [udrnhre] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kharnqo] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [kwstqyd] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [owcrebr] c:\windows\diejkli.exe
O4 - HKCU\..\Run: [ayefxfc] c:\windows\nmqehvn.exe
O4 - HKCU\..\Run: [fsvivaq] c:\windows\nmqehvn.exe
O4 - HKCU\..\Run: [yycbwgx] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [aornwyy] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [mghvsdc] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [hyqguyj] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [jptoent] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [sauddgg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yghbjvi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [lfooghi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fvalsae] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [bhdfvqi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yfmngsq] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yaomenr] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qqqedlg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qwhudbt] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [pyavtwd] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [nhujdtc] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fwldfwv] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [vjtotgf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [xbglldp] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [heltloq] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [wudnscn] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [iwhvqei] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qcdllcp] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ptyhdkg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [nmkebbs] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [utuqsmi] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ugkroww] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [qlfrkfu] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rimqajb] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ostinyv] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [iqsrrmf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [dfnqmri] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [gibdhrm] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [kojvuxh] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [yxuloex] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [aiesgwf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [ctlgifk] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [eirnlra] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rmspoux] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [fojnvmg] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [wjagaaa] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [kwvbywl] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rbaddnu] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [evkgphb] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [oyaqfnf] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [glehfek] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [tdxkuch] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [rkaaltd] c:\windows\nevpdmq.exe
O4 - HKCU\..\Run: [xcmvuvn] c:\windows\ktqggoy.exe


Delete these files:

C:\windows\diejkli.exe
c:\windows\sddjmyv.exe
c:\windows\qnervjm.exe
c:\windows\aekxbav.exe
c:\windows\nmqehvn.exe
c:\windows\nevpdmq.exe
c:\windows\ktqggoy.exe


--------------------------
When finished, post the contents of Spywad.txt and a new Hijackthis log.

If the files deleted are all found to be part of the infection and nothing important has been deleted, you will be instructed to delete the entire Spywad Folder after you have cleaned up all other User Profiles on that system.


Once you have performed the big cleanup, each of the other Users on the System needs to be signed in to clean up their desktop and regain the right click.

I have included another vbs to do this. It is named Other Profiles Regfix.vbs

Have each User sign in and run Other Profiles Regfix.vbs
Open C:\ (Go to Start>Run and type C: Press enter) and Open the C:\Spywad folder. Double click on Other Profiles Regfix.vbs

Explorer will be ended and that user's active desktop registry entries will be repaired. Explorer will be restarted.

Then run hijackthis and remove the entries as directed by your Forum Advisor.

To restore the desktop to whatever picture you normally have right click on a blank part of desktop & select properties/desktop & select your prefered picture press apply & then ok to exit and then either reboot or log off & on again to change the desktop settings

You will need to do this step for every user account
  • 0

#22
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts

OK, we got it now (hopefully) :tazz:
Delete these files:

C:\windows\diejkli.exe
c:\windows\sddjmyv.exe
c:\windows\qnervjm.exe
c:\windows\aekxbav.exe
c:\windows\nmqehvn.exe
c:\windows\nevpdmq.exe
c:\windows\ktqggoy.exe

How do I do that?Go to my computer and then the Windows folder and deleted them manually?

7/31/2005 4:07:43 PM
C:\WINDOWS\diejkli.exe
C:\WINDOWS\dtnfbyq.exe
C:\WINDOWS\ktqggoy.exe
C:\WINDOWS\nevpdmq.exe
C:\WINDOWS\nmqehvn.exe


Logfile of HijackThis v1.99.1
Scan saved at 4:44:22 PM, on 7/31/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [myamdla] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bihbolc] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iayniof] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fehwwok] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ujgtfqp] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xpufeoa] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [udevcjy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [tbmsqfo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uecqaqk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [wdoqkdy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xuvhmii] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xtungdk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hmbktmj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [rqxivdu] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fyvstto] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [yrucxda] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vjftgjh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [mkvlesh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ffwibsn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vxkywxs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ccutkid] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oxinyar] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hhaxhfx] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [gfjulbn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ldnfsal] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nnxstpd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pbabghw] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nmqjpmn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ctbrsex] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [yefxajy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bwwelkf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pryrifj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [usovgou] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [peactfk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [enexxlb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ygangco] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [cwxofkf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [dqdeapv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [drofkcg] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ncdhske] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bbldoir] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ennohih] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pwgldsq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oypgurb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [enbkgwq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fbwctgs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [sxhvsxs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [tlexbgh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nuwcfgq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ojcjews] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ereiikx] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bjkbnas] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [mkovexd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hmowqev] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uwgaimd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nrewsaj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uixkrmm] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bssfvbw] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [wpafmwy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oddjpjv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [kaeydgv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [homcrho] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [weqrpjo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [msygkrt] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [lrigkwh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uepxkdu] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [jppwulp] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [suejowg] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hlxoedh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [aifonvf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [dnuagcb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pkduuxh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hqfiooi] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ttfvpqo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vtcgbik] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [kbvcxjf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uqqyhfe] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ggrmlff] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iawbjch] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [gmchwdd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fqhdjfh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iayucbr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xgqqsbk] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [conlnae] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cnoxvhb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xwiasqc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yvimlxc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fhywoae] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [edhclvd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bjhqulq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pofbjau] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [hrqmgkr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vsaktav] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cykmvma] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lusfhta] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ctythne] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [byuxoju] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vtwbwjv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [akttexc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [uuoxskj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [jadhboh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cwxmckb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ftsqbfq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [essunde] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xbfnwvf] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [isvnngx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [jnxonmn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vqhslfc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tnderkk] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [isdjuhl] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oxofqjd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [hhbmqgg] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vtcasww] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [akxrryg] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qfaalpp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fjyjgbr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [kikcqsy] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bganxlb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qdyfomx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oyeygio] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ylytfsj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [mtwhwvq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pgtqflf] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bggebbe] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [unhmwlp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ndinfug] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fqjuofu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tmmbewi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [smqsnny] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fofemwo] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oyqurmn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bxyxanm] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tgicfhu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yrvdbvb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [thqdyiv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yuueljw] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sgvcsds] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [offkmlb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qepudmc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ggjeoru] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [eqcdltv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ncacoma] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [mkjdnyn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sfiihiq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tcllwcs] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xbadpnr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pfgugls] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gjaagvh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fvdekdv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gddlndh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [guorlop] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [dfmiefc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ulixavq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [rbqrgnr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [awqvgoq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bruguff] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gbgevjs] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fokinup] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [rwaniqd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pnclqqt] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [dtnwand] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [caxmomu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ypoxski] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cvxiicx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ukfnjgi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lstasyh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bnwhigp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cigtoch] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cmddvbq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [imneiwj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [khhuuuq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [huwgwuv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sdxapif] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xwbwcqd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [kccoalr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [aukubfj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ibivjck] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [quvkcsi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [agriasr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [atpuxrm] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xkhrgyv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oxwmgir] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lnysjsn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [epjxgmv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qxhqjco] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ebfdcnd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ymfbhob] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ceggbck] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [onjdsek] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [epsombx] c:\windows\dtnfbyq.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AutoTBar.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader - http://miniclip.com/...tgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#23
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
You didn't delete them yet? OK, delete them now. Yes, that's what you do. Since they are all in the windows folder, you won't need to go around looking for them.

Restart and give me a new log after you delete those files.

Not sure how it's going to look afterwards. You really should try to get it fixed all in one shot. Otherwise we might have to redo this again.
  • 0

#24
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
No I didn't delete them yet,I cant find them in c:\windows,I went into C:\spywad and went into the windows folder in there and they had back up for those files in there does this mean they allready deleted them and made backups?
  • 0

#25
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
I guess it does. If you can't find it, it must have removed it for you already.

OK, I want you to give me a new HijackThis log again but before you do that, make sure you can leave your computer on (at least until you get to do the fixes). I'm not sure if these filenames will change each time you shutdown or restart your computer. So wait until you can leave it on.

If you can't do this tonight, do it tomorrow. I will be online around 8AM tomorrow. It's around 9:10PM now. I will stay for a few more hours wandering around :tazz:
  • 0

Advertisements


#26
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
I can't leave the computer on tonight,I won't be on intil friday I'am going out of town for the week.Is it cool for us to start this back up friday?
  • 0

#27
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Sure, no problem. We'll do this next week then.

Whenever you are ready :tazz:
  • 0

#28
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Allrite I'am back,Thanks for waiting
Heres my updated Hijack log.I'll leave my computer on for tonight.

Logfile of HijackThis v1.99.1
Scan saved at 8:08:51 PM, on 8/4/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\System32\cmd.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Yahoo!\browser\YBrowser.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\RealBar.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\Hewlett-Packard\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [myamdla] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bihbolc] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iayniof] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fehwwok] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ujgtfqp] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xpufeoa] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [udevcjy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [tbmsqfo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uecqaqk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [wdoqkdy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xuvhmii] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [xtungdk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hmbktmj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [rqxivdu] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fyvstto] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [yrucxda] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vjftgjh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [mkvlesh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ffwibsn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vxkywxs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ccutkid] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oxinyar] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hhaxhfx] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [gfjulbn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ldnfsal] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nnxstpd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pbabghw] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nmqjpmn] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ctbrsex] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [yefxajy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bwwelkf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pryrifj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [usovgou] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [peactfk] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [enexxlb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ygangco] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [cwxofkf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [dqdeapv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [drofkcg] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ncdhske] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bbldoir] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ennohih] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pwgldsq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oypgurb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [enbkgwq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fbwctgs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [sxhvsxs] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [tlexbgh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nuwcfgq] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ojcjews] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ereiikx] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bjkbnas] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [mkovexd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hmowqev] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uwgaimd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [nrewsaj] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uixkrmm] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [bssfvbw] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [wpafmwy] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [oddjpjv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [kaeydgv] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [homcrho] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [weqrpjo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [msygkrt] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [lrigkwh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uepxkdu] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [jppwulp] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [suejowg] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hlxoedh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [aifonvf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [dnuagcb] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [pkduuxh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [hqfiooi] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ttfvpqo] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [vtcgbik] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [kbvcxjf] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [uqqyhfe] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [ggrmlff] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iawbjch] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [gmchwdd] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [fqhdjfh] c:\windows\ktqggoy.exe
O4 - HKCU\..\Run: [iayucbr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xgqqsbk] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [conlnae] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cnoxvhb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xwiasqc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yvimlxc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fhywoae] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [edhclvd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bjhqulq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pofbjau] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [hrqmgkr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vsaktav] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cykmvma] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lusfhta] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ctythne] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [byuxoju] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vtwbwjv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [akttexc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [uuoxskj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [jadhboh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cwxmckb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ftsqbfq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [essunde] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xbfnwvf] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [isvnngx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [jnxonmn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vqhslfc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tnderkk] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [isdjuhl] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oxofqjd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [hhbmqgg] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [vtcasww] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [akxrryg] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qfaalpp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fjyjgbr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [kikcqsy] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bganxlb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qdyfomx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oyeygio] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ylytfsj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [mtwhwvq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pgtqflf] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bggebbe] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [unhmwlp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ndinfug] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fqjuofu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tmmbewi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [smqsnny] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fofemwo] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oyqurmn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bxyxanm] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tgicfhu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yrvdbvb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [thqdyiv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [yuueljw] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sgvcsds] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [offkmlb] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qepudmc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ggjeoru] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [eqcdltv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ncacoma] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [mkjdnyn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sfiihiq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [tcllwcs] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xbadpnr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pfgugls] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gjaagvh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fvdekdv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gddlndh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [guorlop] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [dfmiefc] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ulixavq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [rbqrgnr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [awqvgoq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bruguff] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [gbgevjs] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [fokinup] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [rwaniqd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [pnclqqt] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [dtnwand] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [caxmomu] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ypoxski] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cvxiicx] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ukfnjgi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lstasyh] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [bnwhigp] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cigtoch] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [cmddvbq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [imneiwj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [khhuuuq] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [huwgwuv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [sdxapif] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xwbwcqd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [kccoalr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [aukubfj] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ibivjck] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [quvkcsi] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [agriasr] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [atpuxrm] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [xkhrgyv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [oxwmgir] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [lnysjsn] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [epjxgmv] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [qxhqjco] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ebfdcnd] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ymfbhob] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [ceggbck] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [onjdsek] c:\windows\dtnfbyq.exe
O4 - HKCU\..\Run: [epsombx] c:\windows\dtnfbyq.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: AutoTBar.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader - http://miniclip.com/...tgameloader.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
  • 0

#29
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
OK, I'll try to make it a little easier on you. Let's try this method:

Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

regedit /e c:\1.txt "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"
regedit /e c:\2.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"
copy c:\1.txt+c:\2.txt c:\3.txt
del c:\1.txt
del c:\2.txt
notepad c:\3.txt
del c:\3.txt
exit


Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it. Post that notepad file that opened up automatically here. Just copy and paste the text here.
  • 0

#30
Nick Garcia

Nick Garcia

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"CamMonitor"="c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\\\Unload\\hpqcmon.exe"
"HP Software Update"="\"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd.exe\""
"HPHUPD05"="c:\\Program Files\\Hewlett-Packard\\{45B6180B-DCAB-4093-8EE8-6164457517F0}\\hphupd05.exe"
"HPHmon05"="C:\\WINDOWS\\System32\\hphmon05.exe"
"AutoTKit"="C:\\hp\\bin\\AUTOTKIT.EXE"
"Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /installquiet /keeploaded /nodetect"
"Sunkist2k"="C:\\Program Files\\Multimedia Card Reader\\shwicon2k.exe"
"AlcxMonitor"="ALCXMNTR.EXE"
"mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmtask.exe"
"QuickFinder Scheduler"="\"c:\\Program Files\\WordPerfect Office 11\\Programs\\QFSCHD110.EXE\""
"IPInSightMonitor 01"="\"C:\\Program Files\\SBC Yahoo!\\Connection Manager\\IP InSight\\IPMon32.exe\""
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"Logitech Utility"="Logi_MwX.Exe"
"Motive SmartBridge"="C:\\PROGRA~1\\SBCSEL~1\\SMARTB~1\\MotiveSB.exe"
"YBrowser"="C:\\Program Files\\Yahoo!\\browser\\ybrwicon.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"SSC_UserPrompt"="C:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BackupNotify"="c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\backupnotify.exe"
"NVIEW"="rundll32.exe nview.dll,nViewLoadHook"
"myamdla"="c:\\windows\\ktqggoy.exe"
"bihbolc"="c:\\windows\\ktqggoy.exe"
"iayniof"="c:\\windows\\ktqggoy.exe"
"fehwwok"="c:\\windows\\ktqggoy.exe"
"ujgtfqp"="c:\\windows\\ktqggoy.exe"
"xpufeoa"="c:\\windows\\ktqggoy.exe"
"udevcjy"="c:\\windows\\ktqggoy.exe"
"tbmsqfo"="c:\\windows\\ktqggoy.exe"
"uecqaqk"="c:\\windows\\ktqggoy.exe"
"wdoqkdy"="c:\\windows\\ktqggoy.exe"
"xuvhmii"="c:\\windows\\ktqggoy.exe"
"xtungdk"="c:\\windows\\ktqggoy.exe"
"hmbktmj"="c:\\windows\\ktqggoy.exe"
"rqxivdu"="c:\\windows\\ktqggoy.exe"
"fyvstto"="c:\\windows\\ktqggoy.exe"
"yrucxda"="c:\\windows\\ktqggoy.exe"
"vjftgjh"="c:\\windows\\ktqggoy.exe"
"mkvlesh"="c:\\windows\\ktqggoy.exe"
"ffwibsn"="c:\\windows\\ktqggoy.exe"
"vxkywxs"="c:\\windows\\ktqggoy.exe"
"ccutkid"="c:\\windows\\ktqggoy.exe"
"oxinyar"="c:\\windows\\ktqggoy.exe"
"hhaxhfx"="c:\\windows\\ktqggoy.exe"
"gfjulbn"="c:\\windows\\ktqggoy.exe"
"ldnfsal"="c:\\windows\\ktqggoy.exe"
"nnxstpd"="c:\\windows\\ktqggoy.exe"
"pbabghw"="c:\\windows\\ktqggoy.exe"
"nmqjpmn"="c:\\windows\\ktqggoy.exe"
"ctbrsex"="c:\\windows\\ktqggoy.exe"
"yefxajy"="c:\\windows\\ktqggoy.exe"
"bwwelkf"="c:\\windows\\ktqggoy.exe"
"pryrifj"="c:\\windows\\ktqggoy.exe"
"usovgou"="c:\\windows\\ktqggoy.exe"
"peactfk"="c:\\windows\\ktqggoy.exe"
"enexxlb"="c:\\windows\\ktqggoy.exe"
"ygangco"="c:\\windows\\ktqggoy.exe"
"cwxofkf"="c:\\windows\\ktqggoy.exe"
"dqdeapv"="c:\\windows\\ktqggoy.exe"
"drofkcg"="c:\\windows\\ktqggoy.exe"
"ncdhske"="c:\\windows\\ktqggoy.exe"
"bbldoir"="c:\\windows\\ktqggoy.exe"
"ennohih"="c:\\windows\\ktqggoy.exe"
"pwgldsq"="c:\\windows\\ktqggoy.exe"
"oypgurb"="c:\\windows\\ktqggoy.exe"
"enbkgwq"="c:\\windows\\ktqggoy.exe"
"fbwctgs"="c:\\windows\\ktqggoy.exe"
"sxhvsxs"="c:\\windows\\ktqggoy.exe"
"tlexbgh"="c:\\windows\\ktqggoy.exe"
"nuwcfgq"="c:\\windows\\ktqggoy.exe"
"ojcjews"="c:\\windows\\ktqggoy.exe"
"ereiikx"="c:\\windows\\ktqggoy.exe"
"bjkbnas"="c:\\windows\\ktqggoy.exe"
"mkovexd"="c:\\windows\\ktqggoy.exe"
"hmowqev"="c:\\windows\\ktqggoy.exe"
"uwgaimd"="c:\\windows\\ktqggoy.exe"
"nrewsaj"="c:\\windows\\ktqggoy.exe"
"uixkrmm"="c:\\windows\\ktqggoy.exe"
"bssfvbw"="c:\\windows\\ktqggoy.exe"
"wpafmwy"="c:\\windows\\ktqggoy.exe"
"oddjpjv"="c:\\windows\\ktqggoy.exe"
"kaeydgv"="c:\\windows\\ktqggoy.exe"
"homcrho"="c:\\windows\\ktqggoy.exe"
"weqrpjo"="c:\\windows\\ktqggoy.exe"
"msygkrt"="c:\\windows\\ktqggoy.exe"
"lrigkwh"="c:\\windows\\ktqggoy.exe"
"uepxkdu"="c:\\windows\\ktqggoy.exe"
"jppwulp"="c:\\windows\\ktqggoy.exe"
"suejowg"="c:\\windows\\ktqggoy.exe"
"hlxoedh"="c:\\windows\\ktqggoy.exe"
"aifonvf"="c:\\windows\\ktqggoy.exe"
"dnuagcb"="c:\\windows\\ktqggoy.exe"
"pkduuxh"="c:\\windows\\ktqggoy.exe"
"hqfiooi"="c:\\windows\\ktqggoy.exe"
"ttfvpqo"="c:\\windows\\ktqggoy.exe"
"vtcgbik"="c:\\windows\\ktqggoy.exe"
"kbvcxjf"="c:\\windows\\ktqggoy.exe"
"uqqyhfe"="c:\\windows\\ktqggoy.exe"
"ggrmlff"="c:\\windows\\ktqggoy.exe"
"iawbjch"="c:\\windows\\ktqggoy.exe"
"gmchwdd"="c:\\windows\\ktqggoy.exe"
"fqhdjfh"="c:\\windows\\ktqggoy.exe"
"iayucbr"="c:\\windows\\dtnfbyq.exe"
"xgqqsbk"="c:\\windows\\dtnfbyq.exe"
"conlnae"="c:\\windows\\dtnfbyq.exe"
"cnoxvhb"="c:\\windows\\dtnfbyq.exe"
"xwiasqc"="c:\\windows\\dtnfbyq.exe"
"yvimlxc"="c:\\windows\\dtnfbyq.exe"
"fhywoae"="c:\\windows\\dtnfbyq.exe"
"edhclvd"="c:\\windows\\dtnfbyq.exe"
"bjhqulq"="c:\\windows\\dtnfbyq.exe"
"pofbjau"="c:\\windows\\dtnfbyq.exe"
"hrqmgkr"="c:\\windows\\dtnfbyq.exe"
"vsaktav"="c:\\windows\\dtnfbyq.exe"
"cykmvma"="c:\\windows\\dtnfbyq.exe"
"lusfhta"="c:\\windows\\dtnfbyq.exe"
"ctythne"="c:\\windows\\dtnfbyq.exe"
"byuxoju"="c:\\windows\\dtnfbyq.exe"
"vtwbwjv"="c:\\windows\\dtnfbyq.exe"
"akttexc"="c:\\windows\\dtnfbyq.exe"
"uuoxskj"="c:\\windows\\dtnfbyq.exe"
"jadhboh"="c:\\windows\\dtnfbyq.exe"
"cwxmckb"="c:\\windows\\dtnfbyq.exe"
"ftsqbfq"="c:\\windows\\dtnfbyq.exe"
"essunde"="c:\\windows\\dtnfbyq.exe"
"xbfnwvf"="c:\\windows\\dtnfbyq.exe"
"isvnngx"="c:\\windows\\dtnfbyq.exe"
"jnxonmn"="c:\\windows\\dtnfbyq.exe"
"vqhslfc"="c:\\windows\\dtnfbyq.exe"
"tnderkk"="c:\\windows\\dtnfbyq.exe"
"isdjuhl"="c:\\windows\\dtnfbyq.exe"
"oxofqjd"="c:\\windows\\dtnfbyq.exe"
"hhbmqgg"="c:\\windows\\dtnfbyq.exe"
"vtcasww"="c:\\windows\\dtnfbyq.exe"
"akxrryg"="c:\\windows\\dtnfbyq.exe"
"qfaalpp"="c:\\windows\\dtnfbyq.exe"
"fjyjgbr"="c:\\windows\\dtnfbyq.exe"
"kikcqsy"="c:\\windows\\dtnfbyq.exe"
"bganxlb"="c:\\windows\\dtnfbyq.exe"
"qdyfomx"="c:\\windows\\dtnfbyq.exe"
"oyeygio"="c:\\windows\\dtnfbyq.exe"
"ylytfsj"="c:\\windows\\dtnfbyq.exe"
"mtwhwvq"="c:\\windows\\dtnfbyq.exe"
"pgtqflf"="c:\\windows\\dtnfbyq.exe"
"bggebbe"="c:\\windows\\dtnfbyq.exe"
"unhmwlp"="c:\\windows\\dtnfbyq.exe"
"ndinfug"="c:\\windows\\dtnfbyq.exe"
"fqjuofu"="c:\\windows\\dtnfbyq.exe"
"tmmbewi"="c:\\windows\\dtnfbyq.exe"
"smqsnny"="c:\\windows\\dtnfbyq.exe"
"fofemwo"="c:\\windows\\dtnfbyq.exe"
"oyqurmn"="c:\\windows\\dtnfbyq.exe"
"bxyxanm"="c:\\windows\\dtnfbyq.exe"
"tgicfhu"="c:\\windows\\dtnfbyq.exe"
"yrvdbvb"="c:\\windows\\dtnfbyq.exe"
"thqdyiv"="c:\\windows\\dtnfbyq.exe"
"yuueljw"="c:\\windows\\dtnfbyq.exe"
"sgvcsds"="c:\\windows\\dtnfbyq.exe"
"offkmlb"="c:\\windows\\dtnfbyq.exe"
"qepudmc"="c:\\windows\\dtnfbyq.exe"
"ggjeoru"="c:\\windows\\dtnfbyq.exe"
"eqcdltv"="c:\\windows\\dtnfbyq.exe"
"ncacoma"="c:\\windows\\dtnfbyq.exe"
"mkjdnyn"="c:\\windows\\dtnfbyq.exe"
"sfiihiq"="c:\\windows\\dtnfbyq.exe"
"tcllwcs"="c:\\windows\\dtnfbyq.exe"
"xbadpnr"="c:\\windows\\dtnfbyq.exe"
"pfgugls"="c:\\windows\\dtnfbyq.exe"
"gjaagvh"="c:\\windows\\dtnfbyq.exe"
"fvdekdv"="c:\\windows\\dtnfbyq.exe"
"gddlndh"="c:\\windows\\dtnfbyq.exe"
"guorlop"="c:\\windows\\dtnfbyq.exe"
"dfmiefc"="c:\\windows\\dtnfbyq.exe"
"ulixavq"="c:\\windows\\dtnfbyq.exe"
"rbqrgnr"="c:\\windows\\dtnfbyq.exe"
"awqvgoq"="c:\\windows\\dtnfbyq.exe"
"bruguff"="c:\\windows\\dtnfbyq.exe"
"gbgevjs"="c:\\windows\\dtnfbyq.exe"
"fokinup"="c:\\windows\\dtnfbyq.exe"
"rwaniqd"="c:\\windows\\dtnfbyq.exe"
"pnclqqt"="c:\\windows\\dtnfbyq.exe"
"dtnwand"="c:\\windows\\dtnfbyq.exe"
"caxmomu"="c:\\windows\\dtnfbyq.exe"
"ypoxski"="c:\\windows\\dtnfbyq.exe"
"cvxiicx"="c:\\windows\\dtnfbyq.exe"
"ukfnjgi"="c:\\windows\\dtnfbyq.exe"
"lstasyh"="c:\\windows\\dtnfbyq.exe"
"bnwhigp"="c:\\windows\\dtnfbyq.exe"
"cigtoch"="c:\\windows\\dtnfbyq.exe"
"cmddvbq"="c:\\windows\\dtnfbyq.exe"
"imneiwj"="c:\\windows\\dtnfbyq.exe"
"khhuuuq"="c:\\windows\\dtnfbyq.exe"
"huwgwuv"="c:\\windows\\dtnfbyq.exe"
"sdxapif"="c:\\windows\\dtnfbyq.exe"
"xwbwcqd"="c:\\windows\\dtnfbyq.exe"
"kccoalr"="c:\\windows\\dtnfbyq.exe"
"aukubfj"="c:\\windows\\dtnfbyq.exe"
"ibivjck"="c:\\windows\\dtnfbyq.exe"
"quvkcsi"="c:\\windows\\dtnfbyq.exe"
"agriasr"="c:\\windows\\dtnfbyq.exe"
"atpuxrm"="c:\\windows\\dtnfbyq.exe"
"xkhrgyv"="c:\\windows\\dtnfbyq.exe"
"oxwmgir"="c:\\windows\\dtnfbyq.exe"
"lnysjsn"="c:\\windows\\dtnfbyq.exe"
"epjxgmv"="c:\\windows\\dtnfbyq.exe"
"qxhqjco"="c:\\windows\\dtnfbyq.exe"
"ebfdcnd"="c:\\windows\\dtnfbyq.exe"
"ymfbhob"="c:\\windows\\dtnfbyq.exe"
"ceggbck"="c:\\windows\\dtnfbyq.exe"
"onjdsek"="c:\\windows\\dtnfbyq.exe"
"epsombx"="c:\\windows\\dtnfbyq.exe"

here is this what your looking for.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP