Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

So Many Infections, So Little Time


  • Please log in to reply

#1
PattyBaitmen

PattyBaitmen

    New Member

  • Member
  • Pip
  • 3 posts
:tazz:

Would somebody be so kind as to help me with my spyware infections. I have run every program that this forum has suggested and none of the ones that are considered unreliable. My microsoft antispyware software is still complaining on a regular basis and saying that several BHO's are attempting to alter programs, or that random .exe's are attempting to run. Also several days ago I ran CWShredder and IE doesn't run anymore. Thank god I have firefox. If somebody could go through my Hijack This log and tell me what I need to remove, I would GREATLY appreciate it. THanks all.

Logfile of HijackThis v1.99.1
Scan saved at 12:57:03 AM, on 7/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\ipoi.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Class - {D2AD2325-0119-62FA-1172-8B029FFD46EF} - C:\WINDOWS\system32\sysxa.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ipds.exe] C:\WINDOWS\ipds.exe
O4 - HKLM\..\Run: [msvq.exe] C:\WINDOWS\msvq.exe
O4 - HKLM\..\Run: [mfcku.exe] C:\WINDOWS\system32\mfcku.exe
O4 - HKLM\..\Run: [ntys32.exe] C:\WINDOWS\system32\ntys32.exe
O4 - HKLM\..\Run: [addqr32.exe] C:\WINDOWS\addqr32.exe
O4 - HKLM\..\Run: [ntwk32.exe] C:\WINDOWS\ntwk32.exe
O4 - HKLM\..\Run: [ieyu.exe] C:\WINDOWS\ieyu.exe
O4 - HKLM\..\Run: [javajs.exe] C:\WINDOWS\javajs.exe
O4 - HKLM\..\Run: [iegp32.exe] C:\WINDOWS\iegp32.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [crxi.exe] C:\WINDOWS\system32\crxi.exe
O4 - HKLM\..\Run: [ipoi.exe] C:\WINDOWS\system32\ipoi.exe
O4 - HKLM\..\RunOnce: [mfcbv.exe] C:\WINDOWS\mfcbv.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
  • 0

Advertisements


#2
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Hi PattyBaitmen and Welcome to GeekstoGo!

If you are still requiring help with your log,please post a fresh HijackThis log and avoid Restarting at all cost!
  • 0

#3
PattyBaitmen

PattyBaitmen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Thanks for replying Cretemonster.....here is my new log

Logfile of HijackThis v1.99.1
Scan saved at 10:41:53 PM, on 7/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\system32\ipoi.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {02C0DCC5-3CE6-0398-0598-65E2B62B528F} - C:\WINDOWS\system32\msid32.dll
O2 - BHO: Class - {05A55FD0-07CB-11D2-9597-D96F9FF82934} - C:\WINDOWS\ntui.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {08BEC198-7D8F-EA95-F1EA-2D7648DD4E06} - C:\WINDOWS\addwa.dll
O2 - BHO: Class - {092C0E63-121E-FA9D-1E4E-5DDAA0E963DB} - C:\WINDOWS\system32\addnm32.dll
O2 - BHO: Class - {0B661A23-D4C8-D088-322A-EA2355183008} - C:\WINDOWS\ieag.dll
O2 - BHO: Class - {13F515CF-0C52-2DB2-DD18-6D86CD3486CB} - C:\WINDOWS\system32\sdkwj.dll
O2 - BHO: Class - {1BA93373-201C-314A-722B-378A24BEFF9F} - C:\WINDOWS\system32\crvq32.dll
O2 - BHO: Class - {1BBF8296-22FF-42B6-3DEE-014A827D5E04} - C:\WINDOWS\system32\apptv32.dll
O2 - BHO: Class - {1EAD2AC4-39BA-3522-0176-BF8C4F454375} - C:\WINDOWS\system32\addga.dll
O2 - BHO: Class - {1F499D48-ECE7-D492-016F-B8A978A5D02A} - C:\WINDOWS\system32\netow.dll
O2 - BHO: Class - {3091015E-CC06-611B-E5A2-43478B041E5A} - C:\WINDOWS\sdksw32.dll
O2 - BHO: Class - {3228229A-289E-9E2F-9154-02F1DC5C463F} - C:\WINDOWS\system32\d3cy32.dll
O2 - BHO: Class - {35DDF22C-ABD8-BB4D-7430-A00C122605A3} - C:\WINDOWS\crml32.dll
O2 - BHO: Class - {3D314575-05BB-1678-B27E-04B2A966F5F1} - C:\WINDOWS\system32\netbk32.dll
O2 - BHO: Class - {3DF3AE97-927A-A988-F257-18F61D1C5ABA} - C:\WINDOWS\system32\ieub32.dll
O2 - BHO: Class - {47AC3AC5-C903-9914-10BF-BD321AC3B99B} - C:\WINDOWS\sdkov.dll
O2 - BHO: Class - {4D5086C8-1EDA-4232-0DD5-8A2FF9D9C966} - C:\WINDOWS\system32\mszp.dll
O2 - BHO: Class - {5597E50C-316E-EAAF-1D34-0D604001E92E} - C:\WINDOWS\appxv.dll
O2 - BHO: Class - {59032CD0-6861-388D-3398-80FD4CCFF228} - C:\WINDOWS\crgt32.dll
O2 - BHO: Class - {5C24F68F-330D-3834-5594-F52CB787AE93} - C:\WINDOWS\system32\ipwm32.dll
O2 - BHO: Class - {66D4D570-CA0D-A697-05AF-9C46ECFF8539} - C:\WINDOWS\netts32.dll
O2 - BHO: Class - {73676454-A932-7669-B377-AC3A0147A262} - C:\WINDOWS\addwy32.dll
O2 - BHO: Class - {7683AD2C-79FA-24D4-779F-50574258757A} - C:\WINDOWS\sdkef.dll
O2 - BHO: Class - {7E29E088-E904-C077-2FCA-B7880E438F22} - C:\WINDOWS\syszz32.dll
O2 - BHO: Class - {800E8E08-DE88-9E15-E570-254FA8F9B219} - C:\WINDOWS\javaxt32.dll
O2 - BHO: Class - {82335B62-7DEF-0FF6-3C5F-94007ED6C7B3} - C:\WINDOWS\appib32.dll
O2 - BHO: Class - {82341895-A1EE-6A36-B4A4-5394B2CED036} - C:\WINDOWS\sdkqo.dll
O2 - BHO: Class - {83971461-34F4-E677-127C-D62A91D02AD1} - C:\WINDOWS\ntbi.dll
O2 - BHO: Class - {85207839-3806-D845-DDE9-5ADD23506597} - C:\WINDOWS\apizz.dll
O2 - BHO: Class - {85D9CD8E-5A0B-5971-2E36-284D9E2E0BF4} - C:\WINDOWS\addir32.dll
O2 - BHO: Class - {869844E3-C2D7-2101-E8F9-967AA18010D5} - C:\WINDOWS\ieyc.dll
O2 - BHO: Class - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - C:\WINDOWS\ippi.dll
O2 - BHO: Class - {8B9B410F-0A67-22CE-3941-CB77C211A4A9} - C:\WINDOWS\javabp32.dll
O2 - BHO: Class - {8C7413DD-6325-E43D-BD47-63DEDEF0FC7C} - C:\WINDOWS\system32\iehj.dll
O2 - BHO: Class - {9B0F7030-AF9E-455A-F0F3-B9E15FD227AE} - C:\WINDOWS\system32\netpx32.dll
O2 - BHO: Class - {AB07D8D0-2369-881F-81AF-C71825A24FD7} - C:\WINDOWS\ntpv.dll
O2 - BHO: Class - {ACCA505A-38CA-43E7-377E-CDE48726DF7A} - C:\WINDOWS\system32\apppn.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Class - {B285152E-E0C0-8D4F-E2D7-04EB877DB035} - C:\WINDOWS\atlyz.dll
O2 - BHO: Class - {B796255B-ACA4-16C7-11F6-66CB8A35904C} - C:\WINDOWS\iekn.dll
O2 - BHO: Class - {B8542646-AFF5-94ED-2255-DD8481388BCE} - C:\WINDOWS\system32\sdkbo32.dll
O2 - BHO: Class - {BB0401E6-61A6-0344-A30F-3DFA178D6F76} - C:\WINDOWS\netut.dll
O2 - BHO: Class - {BD2572C3-91F3-D764-96F0-7518D05E9428} - C:\WINDOWS\appyp.dll
O2 - BHO: Class - {BF82252D-ABE1-E8BB-F0BF-178FB378D258} - C:\WINDOWS\mfczg.dll
O2 - BHO: Class - {C63C732D-A5FF-9CDA-B026-5AA18E9F72B5} - C:\WINDOWS\winyf.dll
O2 - BHO: Class - {C7F8F9B4-5233-5460-C2DB-34313EC35B32} - C:\WINDOWS\sdkch32.dll
O2 - BHO: Class - {CC2A66A5-539A-852C-FA22-A3BD80E37FC4} - C:\WINDOWS\system32\crwn32.dll
O2 - BHO: Class - {CC74E0B9-F6BF-A716-4F9A-98CC5AAEA235} - C:\WINDOWS\sdkkh32.dll
O2 - BHO: Class - {D197A0E1-57CF-5D1D-AB6B-C7313C71B514} - C:\WINDOWS\system32\ipoi.dll
O2 - BHO: Class - {D2AD2325-0119-62FA-1172-8B029FFD46EF} - C:\WINDOWS\system32\sysxa.dll (file missing)
O2 - BHO: Class - {D46A242B-6194-E7D0-7207-4CC5FFB11ADE} - C:\WINDOWS\system32\winia.dll
O2 - BHO: Class - {DF681A51-5F05-1F39-036E-D1C704F8F568} - C:\WINDOWS\ipmi32.dll
O2 - BHO: Class - {E0DA5911-5137-7600-E631-98A3D1D307DB} - C:\WINDOWS\iett.dll
O2 - BHO: Class - {E4FD490D-A46F-95DB-EFF2-CF0215363020} - C:\WINDOWS\atlsu.dll
O2 - BHO: Class - {EC3DDF47-5645-BD30-F6EE-3A2152B02861} - C:\WINDOWS\apizj32.dll
O2 - BHO: Class - {F0FC9C3B-CE66-41DD-5954-499FDD4FBB41} - C:\WINDOWS\system32\netzo32.dll
O2 - BHO: Class - {FBF7402B-F568-97CC-0EFF-2D7ABD52E16B} - C:\WINDOWS\netwq.dll
O2 - BHO: Class - {FEB58C92-D119-8F66-A8FA-72D46A544DA9} - C:\WINDOWS\system32\winuf32.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ipds.exe] C:\WINDOWS\ipds.exe
O4 - HKLM\..\Run: [msvq.exe] C:\WINDOWS\msvq.exe
O4 - HKLM\..\Run: [mfcku.exe] C:\WINDOWS\system32\mfcku.exe
O4 - HKLM\..\Run: [ntys32.exe] C:\WINDOWS\system32\ntys32.exe
O4 - HKLM\..\Run: [addqr32.exe] C:\WINDOWS\addqr32.exe
O4 - HKLM\..\Run: [ntwk32.exe] C:\WINDOWS\ntwk32.exe
O4 - HKLM\..\Run: [ieyu.exe] C:\WINDOWS\ieyu.exe
O4 - HKLM\..\Run: [javajs.exe] C:\WINDOWS\javajs.exe
O4 - HKLM\..\Run: [iegp32.exe] C:\WINDOWS\iegp32.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [crxi.exe] C:\WINDOWS\system32\crxi.exe
O4 - HKLM\..\Run: [ipoi.exe] C:\WINDOWS\system32\ipoi.exe
O4 - HKLM\..\RunOnce: [mfcbv.exe] C:\WINDOWS\mfcbv.exe
O4 - HKLM\..\RunOnce: [msav.exe] C:\WINDOWS\system32\msav.exe
O4 - HKLM\..\RunOnce: [sysit32.exe] C:\WINDOWS\system32\sysit32.exe
O4 - HKLM\..\RunOnce: [sysib32.exe] C:\WINDOWS\system32\sysib32.exe
O4 - HKLM\..\RunOnce: [appmg.exe] C:\WINDOWS\appmg.exe
O4 - HKLM\..\RunOnce: [addvg32.exe] C:\WINDOWS\system32\addvg32.exe
O4 - HKLM\..\RunOnce: [ntem.exe] C:\WINDOWS\system32\ntem.exe
O4 - HKLM\..\RunOnce: [ieub32.exe] C:\WINDOWS\ieub32.exe
O4 - HKLM\..\RunOnce: [addkj.exe] C:\WINDOWS\addkj.exe
O4 - HKLM\..\RunOnce: [atlyn.exe] C:\WINDOWS\atlyn.exe
O4 - HKLM\..\RunOnce: [atlsh32.exe] C:\WINDOWS\system32\atlsh32.exe
O4 - HKLM\..\RunOnce: [mfcap32.exe] C:\WINDOWS\system32\mfcap32.exe
O4 - HKLM\..\RunOnce: [ipet32.exe] C:\WINDOWS\system32\ipet32.exe
O4 - HKLM\..\RunOnce: [syseb.exe] C:\WINDOWS\system32\syseb.exe
O4 - HKLM\..\RunOnce: [d3in.exe] C:\WINDOWS\system32\d3in.exe
O4 - HKLM\..\RunOnce: [addxc32.exe] C:\WINDOWS\addxc32.exe
O4 - HKLM\..\RunOnce: [netwq.exe] C:\WINDOWS\netwq.exe
O4 - HKLM\..\RunOnce: [winvx.exe] C:\WINDOWS\winvx.exe
O4 - HKLM\..\RunOnce: [ntvf.exe] C:\WINDOWS\system32\ntvf.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [apizz.exe] C:\WINDOWS\apizz.exe
O4 - HKLM\..\RunOnce: [iett.exe] C:\WINDOWS\iett.exe
O4 - HKLM\..\RunOnce: [sdksi32.exe] C:\WINDOWS\sdksi32.exe
O4 - HKLM\..\RunOnce: [apiqy32.exe] C:\WINDOWS\system32\apiqy32.exe
O4 - HKLM\..\RunOnce: [apiqg.exe] C:\WINDOWS\system32\apiqg.exe
O4 - HKLM\..\RunOnce: [mfczg.exe] C:\WINDOWS\mfczg.exe
O4 - HKLM\..\RunOnce: [javaov32.exe] C:\WINDOWS\system32\javaov32.exe
O4 - HKLM\..\RunOnce: [netye32.exe] C:\WINDOWS\system32\netye32.exe
O4 - HKLM\..\RunOnce: [appxu.exe] C:\WINDOWS\appxu.exe
O4 - HKLM\..\RunOnce: [mfcwz32.exe] C:\WINDOWS\system32\mfcwz32.exe
O4 - HKLM\..\RunOnce: [addga.exe] C:\WINDOWS\system32\addga.exe
O4 - HKLM\..\RunOnce: [addat32.exe] C:\WINDOWS\addat32.exe
O4 - HKLM\..\RunOnce: [appib32.exe] C:\WINDOWS\appib32.exe
O4 - HKLM\..\RunOnce: [aping.exe] C:\WINDOWS\system32\aping.exe
O4 - HKLM\..\RunOnce: [mfcng32.exe] C:\WINDOWS\mfcng32.exe
O4 - HKLM\..\RunOnce: [atlcd32.exe] C:\WINDOWS\system32\atlcd32.exe
O4 - HKLM\..\RunOnce: [ipop.exe] C:\WINDOWS\system32\ipop.exe
O4 - HKLM\..\RunOnce: [netpx32.exe] C:\WINDOWS\system32\netpx32.exe
O4 - HKLM\..\RunOnce: [apiem.exe] C:\WINDOWS\system32\apiem.exe
O4 - HKLM\..\RunOnce: [sysxn.exe] C:\WINDOWS\sysxn.exe
O4 - HKLM\..\RunOnce: [ipmi32.exe] C:\WINDOWS\ipmi32.exe
O4 - HKLM\..\RunOnce: [mspu32.exe] C:\WINDOWS\mspu32.exe
O4 - HKLM\..\RunOnce: [winuy.exe] C:\WINDOWS\system32\winuy.exe
O4 - HKLM\..\RunOnce: [sysuy32.exe] C:\WINDOWS\sysuy32.exe
O4 - HKLM\..\RunOnce: [iejv.exe] C:\WINDOWS\system32\iejv.exe
O4 - HKLM\..\RunOnce: [ntco.exe] C:\WINDOWS\ntco.exe
O4 - HKLM\..\RunOnce: [sdkib.exe] C:\WINDOWS\sdkib.exe
O4 - HKLM\..\RunOnce: [addwy32.exe] C:\WINDOWS\addwy32.exe
O4 - HKLM\..\RunOnce: [netak.exe] C:\WINDOWS\system32\netak.exe
O4 - HKLM\..\RunOnce: [iexn.exe] C:\WINDOWS\system32\iexn.exe
O4 - HKLM\..\RunOnce: [mfcmc32.exe] C:\WINDOWS\mfcmc32.exe
O4 - HKLM\..\RunOnce: [sdkqo.exe] C:\WINDOWS\sdkqo.exe
O4 - HKLM\..\RunOnce: [sdkkh32.exe] C:\WINDOWS\sdkkh32.exe
O4 - HKLM\..\RunOnce: [javakp.exe] C:\WINDOWS\system32\javakp.exe
O4 - HKLM\..\RunOnce: [ipob32.exe] C:\WINDOWS\system32\ipob32.exe
O4 - HKLM\..\RunOnce: [appmr.exe] C:\WINDOWS\appmr.exe
O4 - HKLM\..\RunOnce: [mslg32.exe] C:\WINDOWS\mslg32.exe
O4 - HKLM\..\RunOnce: [sdkbo32.exe] C:\WINDOWS\system32\sdkbo32.exe
O4 - HKLM\..\RunOnce: [javaje.exe] C:\WINDOWS\javaje.exe
O4 - HKLM\..\RunOnce: [ntke.exe] C:\WINDOWS\system32\ntke.exe
O4 - HKLM\..\RunOnce: [iezt32.exe] C:\WINDOWS\iezt32.exe
O4 - HKLM\..\RunOnce: [ntsm32.exe] C:\WINDOWS\ntsm32.exe
O4 - HKLM\..\RunOnce: [ntwu.exe] C:\WINDOWS\ntwu.exe
O4 - HKLM\..\RunOnce: [apppn.exe] C:\WINDOWS\system32\apppn.exe
O4 - HKLM\..\RunOnce: [appjz32.exe] C:\WINDOWS\appjz32.exe
O4 - HKLM\..\RunOnce: [ipzw.exe] C:\WINDOWS\ipzw.exe
O4 - HKLM\..\RunOnce: [winvj.exe] C:\WINDOWS\winvj.exe
O4 - HKLM\..\RunOnce: [winpu32.exe] C:\WINDOWS\system32\winpu32.exe
O4 - HKLM\..\RunOnce: [cruy32.exe] C:\WINDOWS\cruy32.exe
O4 - HKLM\..\RunOnce: [addpk32.exe] C:\WINDOWS\system32\addpk32.exe
O4 - HKLM\..\RunOnce: [iehj.exe] C:\WINDOWS\system32\iehj.exe
O4 - HKLM\..\RunOnce: [mfcwy32.exe] C:\WINDOWS\mfcwy32.exe
O4 - HKLM\..\RunOnce: [sdkas.exe] C:\WINDOWS\sdkas.exe
O4 - HKLM\..\RunOnce: [sdkud32.exe] C:\WINDOWS\sdkud32.exe
O4 - HKLM\..\RunOnce: [mszp.exe] C:\WINDOWS\system32\mszp.exe
O4 - HKLM\..\RunOnce: [d3iy32.exe] C:\WINDOWS\system32\d3iy32.exe
O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
O4 - HKLM\..\RunOnce: [apibr.exe] C:\WINDOWS\system32\apibr.exe
O4 - HKLM\..\RunOnce: [appxv.exe] C:\WINDOWS\appxv.exe
O4 - HKLM\..\RunOnce: [ntus32.exe] C:\WINDOWS\system32\ntus32.exe
O4 - HKLM\..\RunOnce: [mfcet32.exe] C:\WINDOWS\mfcet32.exe
O4 - HKLM\..\RunOnce: [windi32.exe] C:\WINDOWS\system32\windi32.exe
O4 - HKLM\..\RunOnce: [sysmp.exe] C:\WINDOWS\sysmp.exe
O4 - HKLM\..\RunOnce: [sysgi32.exe] C:\WINDOWS\system32\sysgi32.exe
O4 - HKLM\..\RunOnce: [wingq32.exe] C:\WINDOWS\system32\wingq32.exe
O4 - HKLM\..\RunOnce: [atlsu.exe] C:\WINDOWS\atlsu.exe
O4 - HKLM\..\RunOnce: [apptv32.exe] C:\WINDOWS\system32\apptv32.exe
O4 - HKLM\..\RunOnce: [addir32.exe] C:\WINDOWS\addir32.exe
O4 - HKLM\..\RunOnce: [appih32.exe] C:\WINDOWS\appih32.exe
O4 - HKLM\..\RunOnce: [apimm.exe] C:\WINDOWS\system32\apimm.exe
O4 - HKLM\..\RunOnce: [mfcvm32.exe] C:\WINDOWS\mfcvm32.exe
O4 - HKLM\..\RunOnce: [atlkj.exe] C:\WINDOWS\system32\atlkj.exe
O4 - HKLM\..\RunOnce: [apiyl32.exe] C:\WINDOWS\system32\apiyl32.exe
O4 - HKLM\..\RunOnce: [ipcq.exe] C:\WINDOWS\system32\ipcq.exe
O4 - HKLM\..\RunOnce: [netdq32.exe] C:\WINDOWS\system32\netdq32.exe
O4 - HKLM\..\RunOnce: [netsn32.exe] C:\WINDOWS\system32\netsn32.exe
O4 - HKLM\..\RunOnce: [netzv32.exe] C:\WINDOWS\netzv32.exe
O4 - HKLM\..\RunOnce: [sdkez.exe] C:\WINDOWS\sdkez.exe
O4 - HKLM\..\RunOnce: [ntfz32.exe] C:\WINDOWS\ntfz32.exe
O4 - HKLM\..\RunOnce: [iptw32.exe] C:\WINDOWS\iptw32.exe
O4 - HKLM\..\RunOnce: [ntte32.exe] C:\WINDOWS\system32\ntte32.exe
O4 - HKLM\..\RunOnce: [crgj.exe] C:\WINDOWS\system32\crgj.exe
O4 - HKLM\..\RunOnce: [javahr32.exe] C:\WINDOWS\system32\javahr32.exe
O4 - HKLM\..\RunOnce: [sdkvg.exe] C:\WINDOWS\system32\sdkvg.exe
O4 - HKLM\..\RunOnce: [atlph.exe] C:\WINDOWS\atlph.exe
O4 - HKLM\..\RunOnce: [sdkzn.exe] C:\WINDOWS\system32\sdkzn.exe
O4 - HKLM\..\RunOnce: [sdktz32.exe] C:\WINDOWS\sdktz32.exe
O4 - HKLM\..\RunOnce: [atlyd32.exe] C:\WINDOWS\system32\atlyd32.exe
O4 - HKLM\..\RunOnce: [javabp32.exe] C:\WINDOWS\javabp32.exe
O4 - HKLM\..\RunOnce: [msft.exe] C:\WINDOWS\system32\msft.exe
O4 - HKLM\..\RunOnce: [crgt32.exe] C:\WINDOWS\crgt32.exe
O4 - HKLM\..\RunOnce: [crvq32.exe] C:\WINDOWS\system32\crvq32.exe
O4 - HKLM\..\RunOnce: [d3cy32.exe] C:\WINDOWS\system32\d3cy32.exe
O4 - HKLM\..\RunOnce: [syshd.exe] C:\WINDOWS\syshd.exe
O4 - HKLM\..\RunOnce: [msid32.exe] C:\WINDOWS\system32\msid32.exe
O4 - HKLM\..\RunOnce: [mswa.exe] C:\WINDOWS\mswa.exe
O4 - HKLM\..\RunOnce: [atlud32.exe] C:\WINDOWS\system32\atlud32.exe
O4 - HKLM\..\RunOnce: [javapo.exe] C:\WINDOWS\system32\javapo.exe
O4 - HKLM\..\RunOnce: [netts32.exe] C:\WINDOWS\netts32.exe
O4 - HKLM\..\RunOnce: [appri.exe] C:\WINDOWS\system32\appri.exe
O4 - HKLM\..\RunOnce: [msqy32.exe] C:\WINDOWS\system32\msqy32.exe
O4 - HKLM\..\RunOnce: [sdkgn32.exe] C:\WINDOWS\sdkgn32.exe
O4 - HKLM\..\RunOnce: [sdkov.exe] C:\WINDOWS\sdkov.exe
O4 - HKLM\..\RunOnce: [ntpv.exe] C:\WINDOWS\ntpv.exe
O4 - HKLM\..\RunOnce: [iees32.exe] C:\WINDOWS\iees32.exe
O4 - HKLM\..\RunOnce: [javaxt32.exe] C:\WINDOWS\javaxt32.exe
O4 - HKLM\..\RunOnce: [netnj.exe] C:\WINDOWS\system32\netnj.exe
O4 - HKLM\..\RunOnce: [winmz32.exe] C:\WINDOWS\system32\winmz32.exe
O4 - HKLM\..\RunOnce: [d3kg32.exe] C:\WINDOWS\d3kg32.exe
O4 - HKLM\..\RunOnce: [mskw32.exe] C:\WINDOWS\mskw32.exe
O4 - HKLM\..\RunOnce: [javaux.exe] C:\WINDOWS\system32\javaux.exe
O4 - HKLM\..\RunOnce: [appdd.exe] C:\WINDOWS\system32\appdd.exe
O4 - HKLM\..\RunOnce: [iehp32.exe] C:\WINDOWS\iehp32.exe
O4 - HKLM\..\RunOnce: [sysoo32.exe] C:\WINDOWS\system32\sysoo32.exe
O4 - HKLM\..\RunOnce: [addcr32.exe] C:\WINDOWS\system32\addcr32.exe
O4 - HKLM\..\RunOnce: [mfcgv32.exe] C:\WINDOWS\mfcgv32.exe
O4 - HKLM\..\RunOnce: [d3gv.exe] C:\WINDOWS\system32\d3gv.exe
O4 - HKLM\..\RunOnce: [appqd.exe] C:\WINDOWS\appqd.exe
O4 - HKLM\..\RunOnce: [d3pt32.exe] C:\WINDOWS\system32\d3pt32.exe
O4 - HKLM\..\RunOnce: [ntnj.exe] C:\WINDOWS\ntnj.exe
O4 - HKLM\..\RunOnce: [atlmy32.exe] C:\WINDOWS\atlmy32.exe
O4 - HKLM\..\RunOnce: [sysco32.exe] C:\WINDOWS\system32\sysco32.exe
O4 - HKLM\..\RunOnce: [winkw32.exe] C:\WINDOWS\system32\winkw32.exe
O4 - HKLM\..\RunOnce: [netof32.exe] C:\WINDOWS\system32\netof32.exe
O4 - HKLM\..\RunOnce: [ipnv.exe] C:\WINDOWS\ipnv.exe
O4 - HKLM\..\RunOnce: [netow.exe] C:\WINDOWS\system32\netow.exe
O4 - HKLM\..\RunOnce: [crml32.exe] C:\WINDOWS\crml32.exe
O4 - HKLM\..\RunOnce: [ipwm32.exe] C:\WINDOWS\system32\ipwm32.exe
O4 - HKLM\..\RunOnce: [atlub32.exe] C:\WINDOWS\atlub32.exe
O4 - HKLM\..\RunOnce: [mfcur.exe] C:\WINDOWS\mfcur.exe
O4 - HKLM\..\RunOnce: [atldr.exe] C:\WINDOWS\atldr.exe
O4 - HKLM\..\RunOnce: [ntsh32.exe] C:\WINDOWS\system32\ntsh32.exe
O4 - HKLM\..\RunOnce: [mfcci32.exe] C:\WINDOWS\mfcci32.exe
O4 - HKLM\..\RunOnce: [winbx32.exe] C:\WINDOWS\system32\winbx32.exe
O4 - HKLM\..\RunOnce: [d3oh32.exe] C:\WINDOWS\system32\d3oh32.exe
O4 - HKLM\..\RunOnce: [ntex32.exe] C:\WINDOWS\ntex32.exe
O4 - HKLM\..\RunOnce: [sdkef.exe] C:\WINDOWS\sdkef.exe
O4 - HKLM\..\RunOnce: [ipnf.exe] C:\WINDOWS\system32\ipnf.exe
O4 - HKLM\..\RunOnce: [mscc.exe] C:\WINDOWS\mscc.exe
O4 - HKLM\..\RunOnce: [d3lc.exe] C:\WINDOWS\system32\d3lc.exe
O4 - HKLM\..\RunOnce: [msqh.exe] C:\WINDOWS\system32\msqh.exe
O4 - HKLM\..\RunOnce: [msks32.exe] C:\WINDOWS\msks32.exe
O4 - HKLM\..\RunOnce: [ntpx32.exe] C:\WINDOWS\system32\ntpx32.exe
O4 - HKLM\..\RunOnce: [iesi32.exe] C:\WINDOWS\iesi32.exe
O4 - HKLM\..\RunOnce: [sdksw32.exe] C:\WINDOWS\sdksw32.exe
O4 - HKLM\..\RunOnce: [atllp32.exe] C:\WINDOWS\atllp32.exe
O4 - HKLM\..\RunOnce: [atllx.exe] C:\WINDOWS\system32\atllx.exe
O4 - HKLM\..\RunOnce: [ntjv32.exe] C:\WINDOWS\system32\ntjv32.exe
O4 - HKLM\..\RunOnce: [mfcbv32.exe] C:\WINDOWS\mfcbv32.exe
O4 - HKLM\..\RunOnce: [winsl32.exe] C:\WINDOWS\system32\winsl32.exe
O4 - HKLM\..\RunOnce: [addrt.exe] C:\WINDOWS\system32\addrt.exe
O4 - HKLM\..\RunOnce: [sysat.exe] C:\WINDOWS\system32\sysat.exe
O4 - HKLM\..\RunOnce: [apipq32.exe] C:\WINDOWS\apipq32.exe
O4 - HKLM\..\RunOnce: [ieel32.exe] C:\WINDOWS\ieel32.exe
O4 - HKLM\..\RunOnce: [mfcti.exe] C:\WINDOWS\system32\mfcti.exe
O4 - HKLM\..\RunOnce: [iplb32.exe] C:\WINDOWS\iplb32.exe
O4 - HKLM\..\RunOnce: [d3hv.exe] C:\WINDOWS\system32\d3hv.exe
O4 - HKLM\..\RunOnce: [msjg32.exe] C:\WINDOWS\msjg32.exe
O4 - HKLM\..\RunOnce: [msjo32.exe] C:\WINDOWS\msjo32.exe
O4 - HKLM\..\RunOnce: [winot.exe] C:\WINDOWS\system32\winot.exe
O4 - HKLM\..\RunOnce: [sysxb32.exe] C:\WINDOWS\sysxb32.exe
O4 - HKLM\..\RunOnce: [iedq32.exe] C:\WINDOWS\system32\iedq32.exe
O4 - HKLM\..\RunOnce: [syslg32.exe] C:\WINDOWS\system32\syslg32.exe
O4 - HKLM\..\RunOnce: [mfcpq32.exe] C:\WINDOWS\system32\mfcpq32.exe
O4 - HKLM\..\RunOnce: [sdktc.exe] C:\WINDOWS\system32\sdktc.exe
O4 - HKLM\..\RunOnce: [sdknv32.exe] C:\WINDOWS\system32\sdknv32.exe
O4 - HKLM\..\RunOnce: [mfcsr32.exe] C:\WINDOWS\system32\mfcsr32.exe
O4 - HKLM\..\RunOnce: [javavd.exe] C:\WINDOWS\system32\javavd.exe
O4 - HKLM\..\RunOnce: [iprp32.exe] C:\WINDOWS\iprp32.exe
O4 - HKLM\..\RunOnce: [atlpe.exe] C:\WINDOWS\system32\atlpe.exe
O4 - HKLM\..\RunOnce: [msom32.exe] C:\WINDOWS\system32\msom32.exe
O4 - HKLM\..\RunOnce: [javams.exe] C:\WINDOWS\javams.exe
O4 - HKLM\..\RunOnce: [iech32.exe] C:\WINDOWS\iech32.exe
O4 - HKLM\..\RunOnce: [ntqk32.exe] C:\WINDOWS\system32\ntqk32.exe
O4 - HKLM\..\RunOnce: [msgz.exe] C:\WINDOWS\msgz.exe
O4 - HKLM\..\RunOnce: [addya32.exe] C:\WINDOWS\addya32.exe
O4 - HKLM\..\RunOnce: [netcm.exe] C:\WINDOWS\netcm.exe
O4 - HKLM\..\RunOnce: [netwx32.exe] C:\WINDOWS\system32\netwx32.exe
O4 - HKLM\..\RunOnce: [ipwn32.exe] C:\WINDOWS\system32\ipwn32.exe
O4 - HKLM\..\RunOnce: [javabr.exe] C:\WINDOWS\javabr.exe
O4 - HKLM\..\RunOnce: [sdkks32.exe] C:\WINDOWS\system32\sdkks32.exe
O4 - HKLM\..\RunOnce: [ntyo32.exe] C:\WINDOWS\ntyo32.exe
O4 - HKLM\..\RunOnce: [addtg.exe] C:\WINDOWS\system32\addtg.exe
O4 - HKLM\..\RunOnce: [javagk32.exe] C:\WINDOWS\javagk32.exe
O4 - HKLM\..\RunOnce: [winbw32.exe] C:\WINDOWS\system32\winbw32.exe
O4 - HKLM\..\RunOnce: [atlga.exe] C:\WINDOWS\system32\atlga.exe
O4 - HKLM\..\RunOnce: [apppb32.exe] C:\WINDOWS\system32\apppb32.exe
O4 - HKLM\..\RunOnce: [adddy.exe] C:\WINDOWS\system32\adddy.exe
O4 - HKLM\..\RunOnce: [crxr.exe] C:\WINDOWS\crxr.exe
O4 - HKLM\..\RunOnce: [crrc32.exe] C:\WINDOWS\crrc32.exe
O4 - HKLM\..\RunOnce: [addgz.exe] C:\WINDOWS\system32\addgz.exe
O4 - HKLM\..\RunOnce: [netkj32.exe] C:\WINDOWS\system32\netkj32.exe
O4 - HKLM\..\RunOnce: [atlih.exe] C:\WINDOWS\atlih.exe
O4 - HKLM\..\RunOnce: [addrh.exe] C:\WINDOWS\system32\addrh.exe
O4 - HKLM\..\RunOnce: [iphe32.exe] C:\WINDOWS\iphe32.exe
O4 - HKLM\..\RunOnce: [atlrf32.exe] C:\WINDOWS\atlrf32.exe
O4 - HKLM\..\RunOnce: [syspu32.exe] C:\WINDOWS\system32\syspu32.exe
O4 - HKLM\..\RunOnce: [winpc.exe] C:\WINDOWS\system32\winpc.exe
O4 - HKLM\..\RunOnce: [ieyd.exe] C:\WINDOWS\ieyd.exe
O4 - HKLM\..\RunOnce: [mfcna32.exe] C:\WINDOWS\system32\mfcna32.exe
O4 - HKLM\..\RunOnce: [winxb32.exe] C:\WINDOWS\system32\winxb32.exe
O4 - HKLM\..\RunOnce: [d3wq32.exe] C:\WINDOWS\d3wq32.exe
O4 - HKLM\..\RunOnce: [ipja32.exe] C:\WINDOWS\system32\ipja32.exe
O4 - HKLM\..\RunOnce: [atlzi.exe] C:\WINDOWS\atlzi.exe
O4 - HKLM\..\RunOnce: [ieyx32.exe] C:\WINDOWS\ieyx32.exe
O4 - HKLM\..\RunOnce: [netsz32.exe] C:\WINDOWS\netsz32.exe
O4 - HKLM\..\RunOnce: [appqg32.exe] C:\WINDOWS\system32\appqg32.exe
O4 - HKLM\..\RunOnce: [atlqw.exe] C:\WINDOWS\system32\atlqw.exe
O4 - HKLM\..\RunOnce: [appzx.exe] C:\WINDOWS\system32\appzx.exe
O4 - HKLM\..\RunOnce: [ipom32.exe] C:\WINDOWS\system32\ipom32.exe
O4 - HKLM\..\RunOnce: [atlhv32.exe] C:\WINDOWS\system32\atlhv32.exe
O4 - HKLM\..\RunOnce: [sysxc32.exe] C:\WINDOWS\sysxc32.exe
O4 - HKLM\..\RunOnce: [winfs.exe] C:\WINDOWS\winfs.exe
O4 - HKLM\..\RunOnce: [sysfs.exe] C:\WINDOWS\system32\sysfs.exe
O4 - HKLM\..\RunOnce: [apivi32.exe] C:\WINDOWS\apivi32.exe
O4 - HKLM\..\RunOnce: [iejk32.exe] C:\WINDOWS\system32\iejk32.exe
O4 - HKLM\..\RunOnce: [atlyz.exe] C:\WINDOWS\atlyz.exe
O4 - HKLM\..\RunOnce: [ipra32.exe] C:\WINDOWS\ipra32.exe
O4 - HKLM\..\RunOnce: [d3um.exe] C:\WINDOWS\d3um.exe
O4 - HKLM\..\RunOnce: [mson32.exe] C:\WINDOWS\system32\mson32.exe
O4 - HKLM\..\RunOnce: [wints.exe] C:\WINDOWS\wints.exe
O4 - HKLM\..\RunOnce: [syscs32.exe] C:\WINDOWS\system32\syscs32.exe
O4 - HKLM\..\RunOnce: [ieqp32.exe] C:\WINDOWS\ieqp32.exe
O4 - HKLM\..\RunOnce: [iplg.exe] C:\WINDOWS\system32\iplg.exe
O4 - HKLM\..\RunOnce: [sdkql32.exe] C:\WINDOWS\sdkql32.exe
O4 - HKLM\..\RunOnce: [atlje32.exe] C:\WINDOWS\atlje32.exe
O4 - HKLM\..\RunOnce: [mfcju32.exe] C:\WINDOWS\system32\mfcju32.exe
O4 - HKLM\..\RunOnce: [appsu32.exe] C:\WINDOWS\system32\appsu32.exe
O4 - HKLM\..\RunOnce: [ntvg32.exe] C:\WINDOWS\ntvg32.exe
O4 - HKLM\..\RunOnce: [crak.exe] C:\WINDOWS\crak.exe
O4 - HKLM\..\RunOnce: [msre32.exe] C:\WINDOWS\msre32.exe
O4 - HKLM\..\RunOnce: [mfcid.exe] C:\WINDOWS\mfcid.exe
O4 - HKLM\..\RunOnce: [javafa32.exe] C:\WINDOWS\system32\javafa32.exe
O4 - HKLM\..\RunOnce: [netqb32.exe] C:\WINDOWS\system32\netqb32.exe
O4 - HKLM\..\RunOnce: [appor.exe] C:\WINDOWS\appor.exe
O4 - HKLM\..\RunOnce: [msng32.exe] C:\WINDOWS\msng32.exe
O4 - HKLM\..\RunOnce: [winyf.exe] C:\WINDOWS\winyf.exe
O4 - HKLM\..\RunOnce: [applk.exe] C:\WINDOWS\applk.exe
O4 - HKLM\..\RunOnce: [atlzo.exe] C:\WINDOWS\atlzo.exe
O4 - HKLM\..\RunOnce: [atlta32.exe] C:\WINDOWS\atlta32.exe
O4 - HKLM\..\RunOnce: [sysgk.exe] C:\WINDOWS\sysgk.exe
O4 - HKLM\..\RunOnce: [addxs.exe] C:\WINDOWS\system32\addxs.exe
O4 - HKLM\..\RunOnce: [apiqs32.exe] C:\WINDOWS\apiqs32.exe
O4 - HKLM\..\RunOnce: [winuf32.exe] C:\WINDOWS\system32\winuf32.exe
O4 - HKLM\..\RunOnce: [atllm.exe] C:\WINDOWS\system32\atllm.exe
O4 - HKLM\..\RunOnce: [apiyr.exe] C:\WINDOWS\system32\apiyr.exe
O4 - HKLM\..\RunOnce: [apisk32.exe] C:\WINDOWS\apisk32.exe
O4 - HKLM\..\RunOnce: [netas32.exe] C:\WINDOWS\netas32.exe
O4 - HKLM\..\RunOnce: [sdkfw.exe] C:\WINDOWS\system32\sdkfw.exe
O4 - HKLM\..\RunOnce: [ntgx32.exe] C:\WINDOWS\ntgx32.exe
O4 - HKLM\..\RunOnce: [ipuu32.exe] C:\WINDOWS\system32\ipuu32.exe
O4 - HKLM\..\RunOnce: [winxl.exe] C:\WINDOWS\winxl.exe
O4 - HKLM\..\RunOnce: [d3vq32.exe] C:\WINDOWS\d3vq32.exe
O4 - HKLM\..\RunOnce: [apper32.exe] C:\WINDOWS\system32\apper32.exe
O4 - HKLM\..\RunOnce: [javaez32.exe] C:\WINDOWS\javaez32.exe
O4 - HKLM\..\RunOnce: [addzl32.exe] C:\WINDOWS\system32\addzl32.exe
O4 - HKLM\..\RunOnce: [mfcmp.exe] C:\WINDOWS\system32\mfcmp.exe
O4 - HKLM\..\RunOnce: [appnp32.exe] C:\WINDOWS\system32\appnp32.exe
O4 - HKLM\..\RunOnce: [appbm.exe] C:\WINDOWS\system32\appbm.exe
O4 - HKLM\..\RunOnce: [d3vf.exe] C:\WINDOWS\d3vf.exe
O4 - HKLM\..\RunOnce: [d3pz32.exe] C:\WINDOWS\d3pz32.exe
O4 - HKLM\..\RunOnce: [sdkzx.exe] C:\WINDOWS\system32\sdkzx.exe
O4 - HKLM\..\RunOnce: [addnc32.exe] C:\WINDOWS\system32\addnc32.exe
O4 - HKLM\..\RunOnce: [d3ao32.exe] C:\WINDOWS\system32\d3ao32.exe
O4 - HKLM\..\RunOnce: [addwa.exe] C:\WINDOWS\addwa.exe
O4 - HKLM\..\RunOnce: [appym32.exe] C:\WINDOWS\system32\appym32.exe
O4 - HKLM\..\RunOnce: [appyc32.exe] C:\WINDOWS\system32\appyc32.exe
O4 - HKLM\..\RunOnce: [apicg.exe] C:\WINDOWS\apicg.exe
O4 - HKLM\..\RunOnce: [mfclg32.exe] C:\WINDOWS\system32\mfclg32.exe
O4 - HKLM\..\RunOnce: [atlsd32.exe] C:\WINDOWS\atlsd32.exe
O4 - HKLM\..\RunOnce: [d3uv.exe] C:\WINDOWS\system32\d3uv.exe
O4 - HKLM\..\RunOnce: [syszz32.exe] C:\WINDOWS\syszz32.exe
O4 - HKLM\..\RunOnce: [sdkss32.exe] C:\WINDOWS\system32\sdkss32.exe
O4 - HKLM\..\RunOnce: [javasi.exe] C:\WINDOWS\system32\javasi.exe
O4 - HKLM\..\RunOnce: [ntbi.exe] C:\WINDOWS\ntbi.exe
O4 - HKLM\..\RunOnce: [ieqx32.exe] C:\WINDOWS\system32\ieqx32.exe
O4 - HKLM\..\RunOnce: [javajy32.exe] C:\WINDOWS\javajy32.exe
O4 - HKLM\..\RunOnce: [netzo32.exe] C:\WINDOWS\system32\netzo32.exe
O4 - HKLM\..\RunOnce: [iphe.exe] C:\WINDOWS\iphe.exe
O4 - HKLM\..\RunOnce: [apihe.exe] C:\WINDOWS\system32\apihe.exe
O4 - HKLM\..\RunOnce: [crxt32.exe] C:\WINDOWS\crxt32.exe
O4 - HKLM\..\RunOnce: [mfclw32.exe] C:\WINDOWS\mfclw32.exe
O4 - HKLM\..\RunOnce: [javaal.exe] C:\WINDOWS\system32\javaal.exe
O4 - HKLM\..\RunOnce: [mstm32.exe] C:\WINDOWS\mstm32.exe
O4 - HKLM\..\RunOnce: [ipef.exe] C:\WINDOWS\ipef.exe
O4 - HKLM\..\RunOnce: [ienn.exe] C:\WINDOWS\ienn.exe
O4 - HKLM\..\RunOnce: [atlwg.exe] C:\WINDOWS\atlwg.exe
O4 - HKLM\..\RunOnce: [winas.exe] C:\WINDOWS\winas.exe
O4 - HKLM\..\RunOnce: [ntpp32.exe] C:\WINDOWS\ntpp32.exe
O4 - HKLM\..\RunOnce: [mssb.exe] C:\WINDOWS\mssb.exe
O4 - HKLM\..\RunOnce: [apihd.exe] C:\WINDOWS\apihd.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe
  • 0

#4
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,Hopefully the PC hasnt been Shut Down or Logged Off!

Thats a nasty CWS Infection you have there!!

Copy these Instructions to Notepad and Save them to your Desktop,you will need them in Safe Mode!

Please go to Add\Remove Programs and Remove these

BearShare
ZoneAlarm
<-- Sygate is more than enough!

Please Download these utilities but dont run them until I ask you to!

Download Pocket KillBox from here
http://www.atribune....llBox_beta_.exe

Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

CWShredder
http://cwshredder.ne.../CWShredder.exe

Double Click CWShredder.exe to run it>>Click Check Check For Update
Close it out once updated,We will run it in Safe Mode!

ABout Buster
http://www.besttechi...?showtopic=1488

Follow the Instructions inside the link to Update it,We will run it it Safe Mode!

CleanUp!
http://downloads.ste...p/CleanUp40.exe

Open up Pocket KillBox

Highlight the list below and press Ctrl+C at the same time to Copy

O2 - BHO: Class - {02C0DCC5-3CE6-0398-0598-65E2B62B528F} - C:\WINDOWS\system32\msid32.dll
O2 - BHO: Class - {05A55FD0-07CB-11D2-9597-D96F9FF82934} - C:\WINDOWS\ntui.dll
O2 - BHO: Class - {08BEC198-7D8F-EA95-F1EA-2D7648DD4E06} - C:\WINDOWS\addwa.dll
O2 - BHO: Class - {092C0E63-121E-FA9D-1E4E-5DDAA0E963DB} - C:\WINDOWS\system32\addnm32.dll
O2 - BHO: Class - {0B661A23-D4C8-D088-322A-EA2355183008} - C:\WINDOWS\ieag.dll
O2 - BHO: Class - {13F515CF-0C52-2DB2-DD18-6D86CD3486CB} - C:\WINDOWS\system32\sdkwj.dll
O2 - BHO: Class - {1BA93373-201C-314A-722B-378A24BEFF9F} - C:\WINDOWS\system32\crvq32.dll
O2 - BHO: Class - {1BBF8296-22FF-42B6-3DEE-014A827D5E04} - C:\WINDOWS\system32\apptv32.dll
O2 - BHO: Class - {1EAD2AC4-39BA-3522-0176-BF8C4F454375} - C:\WINDOWS\system32\addga.dll
O2 - BHO: Class - {1F499D48-ECE7-D492-016F-B8A978A5D02A} - C:\WINDOWS\system32\netow.dll
O2 - BHO: Class - {3091015E-CC06-611B-E5A2-43478B041E5A} - C:\WINDOWS\sdksw32.dll
O2 - BHO: Class - {3228229A-289E-9E2F-9154-02F1DC5C463F} - C:\WINDOWS\system32\d3cy32.dll
O2 - BHO: Class - {35DDF22C-ABD8-BB4D-7430-A00C122605A3} - C:\WINDOWS\crml32.dll
O2 - BHO: Class - {3D314575-05BB-1678-B27E-04B2A966F5F1} - C:\WINDOWS\system32\netbk32.dll
O2 - BHO: Class - {3DF3AE97-927A-A988-F257-18F61D1C5ABA} - C:\WINDOWS\system32\ieub32.dll
O2 - BHO: Class - {47AC3AC5-C903-9914-10BF-BD321AC3B99B} - C:\WINDOWS\sdkov.dll
O2 - BHO: Class - {4D5086C8-1EDA-4232-0DD5-8A2FF9D9C966} - C:\WINDOWS\system32\mszp.dll
O2 - BHO: Class - {5597E50C-316E-EAAF-1D34-0D604001E92E} - C:\WINDOWS\appxv.dll
O2 - BHO: Class - {59032CD0-6861-388D-3398-80FD4CCFF228} - C:\WINDOWS\crgt32.dll
O2 - BHO: Class - {5C24F68F-330D-3834-5594-F52CB787AE93} - C:\WINDOWS\system32\ipwm32.dll
O2 - BHO: Class - {66D4D570-CA0D-A697-05AF-9C46ECFF8539} - C:\WINDOWS\netts32.dll
O2 - BHO: Class - {73676454-A932-7669-B377-AC3A0147A262} - C:\WINDOWS\addwy32.dll
O2 - BHO: Class - {7683AD2C-79FA-24D4-779F-50574258757A} - C:\WINDOWS\sdkef.dll
O2 - BHO: Class - {7E29E088-E904-C077-2FCA-B7880E438F22} - C:\WINDOWS\syszz32.dll
O2 - BHO: Class - {800E8E08-DE88-9E15-E570-254FA8F9B219} - C:\WINDOWS\javaxt32.dll
O2 - BHO: Class - {82335B62-7DEF-0FF6-3C5F-94007ED6C7B3} - C:\WINDOWS\appib32.dll
O2 - BHO: Class - {82341895-A1EE-6A36-B4A4-5394B2CED036} - C:\WINDOWS\sdkqo.dll
O2 - BHO: Class - {83971461-34F4-E677-127C-D62A91D02AD1} - C:\WINDOWS\ntbi.dll
O2 - BHO: Class - {85207839-3806-D845-DDE9-5ADD23506597} - C:\WINDOWS\apizz.dll
O2 - BHO: Class - {85D9CD8E-5A0B-5971-2E36-284D9E2E0BF4} - C:\WINDOWS\addir32.dll
O2 - BHO: Class - {869844E3-C2D7-2101-E8F9-967AA18010D5} - C:\WINDOWS\ieyc.dll
O2 - BHO: Class - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - C:\WINDOWS\ippi.dll
O2 - BHO: Class - {8B9B410F-0A67-22CE-3941-CB77C211A4A9} - C:\WINDOWS\javabp32.dll
O2 - BHO: Class - {8C7413DD-6325-E43D-BD47-63DEDEF0FC7C} - C:\WINDOWS\system32\iehj.dll
O2 - BHO: Class - {9B0F7030-AF9E-455A-F0F3-B9E15FD227AE} - C:\WINDOWS\system32\netpx32.dll
O2 - BHO: Class - {AB07D8D0-2369-881F-81AF-C71825A24FD7} - C:\WINDOWS\ntpv.dll
O2 - BHO: Class - {ACCA505A-38CA-43E7-377E-CDE48726DF7A} - C:\WINDOWS\system32\apppn.dll
O2 - BHO: Class - {B285152E-E0C0-8D4F-E2D7-04EB877DB035} - C:\WINDOWS\atlyz.dll
O2 - BHO: Class - {B796255B-ACA4-16C7-11F6-66CB8A35904C} - C:\WINDOWS\iekn.dll
O2 - BHO: Class - {B8542646-AFF5-94ED-2255-DD8481388BCE} - C:\WINDOWS\system32\sdkbo32.dll
O2 - BHO: Class - {BB0401E6-61A6-0344-A30F-3DFA178D6F76} - C:\WINDOWS\netut.dll
O2 - BHO: Class - {BD2572C3-91F3-D764-96F0-7518D05E9428} - C:\WINDOWS\appyp.dll
O2 - BHO: Class - {BF82252D-ABE1-E8BB-F0BF-178FB378D258} - C:\WINDOWS\mfczg.dll
O2 - BHO: Class - {C63C732D-A5FF-9CDA-B026-5AA18E9F72B5} - C:\WINDOWS\winyf.dll
O2 - BHO: Class - {C7F8F9B4-5233-5460-C2DB-34313EC35B32} - C:\WINDOWS\sdkch32.dll
O2 - BHO: Class - {CC2A66A5-539A-852C-FA22-A3BD80E37FC4} - C:\WINDOWS\system32\crwn32.dll
O2 - BHO: Class - {CC74E0B9-F6BF-A716-4F9A-98CC5AAEA235} - C:\WINDOWS\sdkkh32.dll
O2 - BHO: Class - {D197A0E1-57CF-5D1D-AB6B-C7313C71B514} - C:\WINDOWS\system32\ipoi.dll
O2 - BHO: Class - {D2AD2325-0119-62FA-1172-8B029FFD46EF} - C:\WINDOWS\system32\sysxa.dll (file missing)
O2 - BHO: Class - {D46A242B-6194-E7D0-7207-4CC5FFB11ADE} - C:\WINDOWS\system32\winia.dll
O2 - BHO: Class - {DF681A51-5F05-1F39-036E-D1C704F8F568} - C:\WINDOWS\ipmi32.dll
O2 - BHO: Class - {E0DA5911-5137-7600-E631-98A3D1D307DB} - C:\WINDOWS\iett.dll
O2 - BHO: Class - {E4FD490D-A46F-95DB-EFF2-CF0215363020} - C:\WINDOWS\atlsu.dll
O2 - BHO: Class - {EC3DDF47-5645-BD30-F6EE-3A2152B02861} - C:\WINDOWS\apizj32.dll
O2 - BHO: Class - {F0FC9C3B-CE66-41DD-5954-499FDD4FBB41} - C:\WINDOWS\system32\netzo32.dll
O2 - BHO: Class - {FBF7402B-F568-97CC-0EFF-2D7ABD52E16B} - C:\WINDOWS\netwq.dll
O2 - BHO: Class - {FEB58C92-D119-8F66-A8FA-72D46A544DA9} - C:\WINDOWS\system32\winuf32.dll
O4 - HKLM\..\Run: [ipds.exe] C:\WINDOWS\ipds.exe
O4 - HKLM\..\Run: [msvq.exe] C:\WINDOWS\msvq.exe
O4 - HKLM\..\Run: [mfcku.exe] C:\WINDOWS\system32\mfcku.exe
O4 - HKLM\..\Run: [ntys32.exe] C:\WINDOWS\system32\ntys32.exe
O4 - HKLM\..\Run: [addqr32.exe] C:\WINDOWS\addqr32.exe
O4 - HKLM\..\Run: [ntwk32.exe] C:\WINDOWS\ntwk32.exe
O4 - HKLM\..\Run: [ieyu.exe] C:\WINDOWS\ieyu.exe
O4 - HKLM\..\Run: [javajs.exe] C:\WINDOWS\javajs.exe
O4 - HKLM\..\Run: [iegp32.exe] C:\WINDOWS\iegp32.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [crxi.exe] C:\WINDOWS\system32\crxi.exe
O4 - HKLM\..\Run: [ipoi.exe] C:\WINDOWS\system32\ipoi.exe
O4 - HKLM\..\RunOnce: [mfcbv.exe] C:\WINDOWS\mfcbv.exe
O4 - HKLM\..\RunOnce: [msav.exe] C:\WINDOWS\system32\msav.exe
O4 - HKLM\..\RunOnce: [sysit32.exe] C:\WINDOWS\system32\sysit32.exe
O4 - HKLM\..\RunOnce: [sysib32.exe] C:\WINDOWS\system32\sysib32.exe
O4 - HKLM\..\RunOnce: [appmg.exe] C:\WINDOWS\appmg.exe
O4 - HKLM\..\RunOnce: [addvg32.exe] C:\WINDOWS\system32\addvg32.exe
O4 - HKLM\..\RunOnce: [ntem.exe] C:\WINDOWS\system32\ntem.exe
O4 - HKLM\..\RunOnce: [ieub32.exe] C:\WINDOWS\ieub32.exe
O4 - HKLM\..\RunOnce: [addkj.exe] C:\WINDOWS\addkj.exe
O4 - HKLM\..\RunOnce: [atlyn.exe] C:\WINDOWS\atlyn.exe
O4 - HKLM\..\RunOnce: [atlsh32.exe] C:\WINDOWS\system32\atlsh32.exe
O4 - HKLM\..\RunOnce: [mfcap32.exe] C:\WINDOWS\system32\mfcap32.exe
O4 - HKLM\..\RunOnce: [ipet32.exe] C:\WINDOWS\system32\ipet32.exe
O4 - HKLM\..\RunOnce: [syseb.exe] C:\WINDOWS\system32\syseb.exe
O4 - HKLM\..\RunOnce: [d3in.exe] C:\WINDOWS\system32\d3in.exe
O4 - HKLM\..\RunOnce: [addxc32.exe] C:\WINDOWS\addxc32.exe
O4 - HKLM\..\RunOnce: [netwq.exe] C:\WINDOWS\netwq.exe
O4 - HKLM\..\RunOnce: [winvx.exe] C:\WINDOWS\winvx.exe
O4 - HKLM\..\RunOnce: [ntvf.exe] C:\WINDOWS\system32\ntvf.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [apizz.exe] C:\WINDOWS\apizz.exe
O4 - HKLM\..\RunOnce: [iett.exe] C:\WINDOWS\iett.exe
O4 - HKLM\..\RunOnce: [sdksi32.exe] C:\WINDOWS\sdksi32.exe
O4 - HKLM\..\RunOnce: [apiqy32.exe] C:\WINDOWS\system32\apiqy32.exe
O4 - HKLM\..\RunOnce: [apiqg.exe] C:\WINDOWS\system32\apiqg.exe
O4 - HKLM\..\RunOnce: [mfczg.exe] C:\WINDOWS\mfczg.exe
O4 - HKLM\..\RunOnce: [javaov32.exe] C:\WINDOWS\system32\javaov32.exe
O4 - HKLM\..\RunOnce: [netye32.exe] C:\WINDOWS\system32\netye32.exe
O4 - HKLM\..\RunOnce: [appxu.exe] C:\WINDOWS\appxu.exe
O4 - HKLM\..\RunOnce: [mfcwz32.exe] C:\WINDOWS\system32\mfcwz32.exe
O4 - HKLM\..\RunOnce: [addga.exe] C:\WINDOWS\system32\addga.exe
O4 - HKLM\..\RunOnce: [addat32.exe] C:\WINDOWS\addat32.exe
O4 - HKLM\..\RunOnce: [appib32.exe] C:\WINDOWS\appib32.exe
O4 - HKLM\..\RunOnce: [aping.exe] C:\WINDOWS\system32\aping.exe
O4 - HKLM\..\RunOnce: [mfcng32.exe] C:\WINDOWS\mfcng32.exe
O4 - HKLM\..\RunOnce: [atlcd32.exe] C:\WINDOWS\system32\atlcd32.exe
O4 - HKLM\..\RunOnce: [ipop.exe] C:\WINDOWS\system32\ipop.exe
O4 - HKLM\..\RunOnce: [netpx32.exe] C:\WINDOWS\system32\netpx32.exe
O4 - HKLM\..\RunOnce: [apiem.exe] C:\WINDOWS\system32\apiem.exe
O4 - HKLM\..\RunOnce: [sysxn.exe] C:\WINDOWS\sysxn.exe
O4 - HKLM\..\RunOnce: [ipmi32.exe] C:\WINDOWS\ipmi32.exe
O4 - HKLM\..\RunOnce: [mspu32.exe] C:\WINDOWS\mspu32.exe
O4 - HKLM\..\RunOnce: [winuy.exe] C:\WINDOWS\system32\winuy.exe
O4 - HKLM\..\RunOnce: [sysuy32.exe] C:\WINDOWS\sysuy32.exe
O4 - HKLM\..\RunOnce: [iejv.exe] C:\WINDOWS\system32\iejv.exe
O4 - HKLM\..\RunOnce: [ntco.exe] C:\WINDOWS\ntco.exe
O4 - HKLM\..\RunOnce: [sdkib.exe] C:\WINDOWS\sdkib.exe
O4 - HKLM\..\RunOnce: [addwy32.exe] C:\WINDOWS\addwy32.exe
O4 - HKLM\..\RunOnce: [netak.exe] C:\WINDOWS\system32\netak.exe
O4 - HKLM\..\RunOnce: [iexn.exe] C:\WINDOWS\system32\iexn.exe
O4 - HKLM\..\RunOnce: [mfcmc32.exe] C:\WINDOWS\mfcmc32.exe
O4 - HKLM\..\RunOnce: [sdkqo.exe] C:\WINDOWS\sdkqo.exe
O4 - HKLM\..\RunOnce: [sdkkh32.exe] C:\WINDOWS\sdkkh32.exe
O4 - HKLM\..\RunOnce: [javakp.exe] C:\WINDOWS\system32\javakp.exe
O4 - HKLM\..\RunOnce: [ipob32.exe] C:\WINDOWS\system32\ipob32.exe
O4 - HKLM\..\RunOnce: [appmr.exe] C:\WINDOWS\appmr.exe
O4 - HKLM\..\RunOnce: [mslg32.exe] C:\WINDOWS\mslg32.exe
O4 - HKLM\..\RunOnce: [sdkbo32.exe] C:\WINDOWS\system32\sdkbo32.exe
O4 - HKLM\..\RunOnce: [javaje.exe] C:\WINDOWS\javaje.exe
O4 - HKLM\..\RunOnce: [ntke.exe] C:\WINDOWS\system32\ntke.exe
O4 - HKLM\..\RunOnce: [iezt32.exe] C:\WINDOWS\iezt32.exe
O4 - HKLM\..\RunOnce: [ntsm32.exe] C:\WINDOWS\ntsm32.exe
O4 - HKLM\..\RunOnce: [ntwu.exe] C:\WINDOWS\ntwu.exe
O4 - HKLM\..\RunOnce: [apppn.exe] C:\WINDOWS\system32\apppn.exe
O4 - HKLM\..\RunOnce: [appjz32.exe] C:\WINDOWS\appjz32.exe
O4 - HKLM\..\RunOnce: [ipzw.exe] C:\WINDOWS\ipzw.exe
O4 - HKLM\..\RunOnce: [winvj.exe] C:\WINDOWS\winvj.exe
O4 - HKLM\..\RunOnce: [winpu32.exe] C:\WINDOWS\system32\winpu32.exe
O4 - HKLM\..\RunOnce: [cruy32.exe] C:\WINDOWS\cruy32.exe
O4 - HKLM\..\RunOnce: [addpk32.exe] C:\WINDOWS\system32\addpk32.exe
O4 - HKLM\..\RunOnce: [iehj.exe] C:\WINDOWS\system32\iehj.exe
O4 - HKLM\..\RunOnce: [mfcwy32.exe] C:\WINDOWS\mfcwy32.exe
O4 - HKLM\..\RunOnce: [sdkas.exe] C:\WINDOWS\sdkas.exe
O4 - HKLM\..\RunOnce: [sdkud32.exe] C:\WINDOWS\sdkud32.exe
O4 - HKLM\..\RunOnce: [mszp.exe] C:\WINDOWS\system32\mszp.exe
O4 - HKLM\..\RunOnce: [d3iy32.exe] C:\WINDOWS\system32\d3iy32.exe
O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
O4 - HKLM\..\RunOnce: [apibr.exe] C:\WINDOWS\system32\apibr.exe
O4 - HKLM\..\RunOnce: [appxv.exe] C:\WINDOWS\appxv.exe
O4 - HKLM\..\RunOnce: [ntus32.exe] C:\WINDOWS\system32\ntus32.exe
O4 - HKLM\..\RunOnce: [mfcet32.exe] C:\WINDOWS\mfcet32.exe
O4 - HKLM\..\RunOnce: [windi32.exe] C:\WINDOWS\system32\windi32.exe
O4 - HKLM\..\RunOnce: [sysmp.exe] C:\WINDOWS\sysmp.exe
O4 - HKLM\..\RunOnce: [sysgi32.exe] C:\WINDOWS\system32\sysgi32.exe
O4 - HKLM\..\RunOnce: [wingq32.exe] C:\WINDOWS\system32\wingq32.exe
O4 - HKLM\..\RunOnce: [atlsu.exe] C:\WINDOWS\atlsu.exe
O4 - HKLM\..\RunOnce: [apptv32.exe] C:\WINDOWS\system32\apptv32.exe
O4 - HKLM\..\RunOnce: [addir32.exe] C:\WINDOWS\addir32.exe
O4 - HKLM\..\RunOnce: [appih32.exe] C:\WINDOWS\appih32.exe
O4 - HKLM\..\RunOnce: [apimm.exe] C:\WINDOWS\system32\apimm.exe
O4 - HKLM\..\RunOnce: [mfcvm32.exe] C:\WINDOWS\mfcvm32.exe
O4 - HKLM\..\RunOnce: [atlkj.exe] C:\WINDOWS\system32\atlkj.exe
O4 - HKLM\..\RunOnce: [apiyl32.exe] C:\WINDOWS\system32\apiyl32.exe
O4 - HKLM\..\RunOnce: [ipcq.exe] C:\WINDOWS\system32\ipcq.exe
O4 - HKLM\..\RunOnce: [netdq32.exe] C:\WINDOWS\system32\netdq32.exe
O4 - HKLM\..\RunOnce: [netsn32.exe] C:\WINDOWS\system32\netsn32.exe
O4 - HKLM\..\RunOnce: [netzv32.exe] C:\WINDOWS\netzv32.exe
O4 - HKLM\..\RunOnce: [sdkez.exe] C:\WINDOWS\sdkez.exe
O4 - HKLM\..\RunOnce: [ntfz32.exe] C:\WINDOWS\ntfz32.exe
O4 - HKLM\..\RunOnce: [iptw32.exe] C:\WINDOWS\iptw32.exe
O4 - HKLM\..\RunOnce: [ntte32.exe] C:\WINDOWS\system32\ntte32.exe
O4 - HKLM\..\RunOnce: [crgj.exe] C:\WINDOWS\system32\crgj.exe
O4 - HKLM\..\RunOnce: [javahr32.exe] C:\WINDOWS\system32\javahr32.exe
O4 - HKLM\..\RunOnce: [sdkvg.exe] C:\WINDOWS\system32\sdkvg.exe
O4 - HKLM\..\RunOnce: [atlph.exe] C:\WINDOWS\atlph.exe
O4 - HKLM\..\RunOnce: [sdkzn.exe] C:\WINDOWS\system32\sdkzn.exe
O4 - HKLM\..\RunOnce: [sdktz32.exe] C:\WINDOWS\sdktz32.exe
O4 - HKLM\..\RunOnce: [atlyd32.exe] C:\WINDOWS\system32\atlyd32.exe
O4 - HKLM\..\RunOnce: [javabp32.exe] C:\WINDOWS\javabp32.exe
O4 - HKLM\..\RunOnce: [msft.exe] C:\WINDOWS\system32\msft.exe
O4 - HKLM\..\RunOnce: [crgt32.exe] C:\WINDOWS\crgt32.exe
O4 - HKLM\..\RunOnce: [crvq32.exe] C:\WINDOWS\system32\crvq32.exe
O4 - HKLM\..\RunOnce: [d3cy32.exe] C:\WINDOWS\system32\d3cy32.exe
O4 - HKLM\..\RunOnce: [syshd.exe] C:\WINDOWS\syshd.exe
O4 - HKLM\..\RunOnce: [msid32.exe] C:\WINDOWS\system32\msid32.exe
O4 - HKLM\..\RunOnce: [mswa.exe] C:\WINDOWS\mswa.exe
O4 - HKLM\..\RunOnce: [atlud32.exe] C:\WINDOWS\system32\atlud32.exe
O4 - HKLM\..\RunOnce: [javapo.exe] C:\WINDOWS\system32\javapo.exe
O4 - HKLM\..\RunOnce: [netts32.exe] C:\WINDOWS\netts32.exe
O4 - HKLM\..\RunOnce: [appri.exe] C:\WINDOWS\system32\appri.exe
O4 - HKLM\..\RunOnce: [msqy32.exe] C:\WINDOWS\system32\msqy32.exe
O4 - HKLM\..\RunOnce: [sdkgn32.exe] C:\WINDOWS\sdkgn32.exe
O4 - HKLM\..\RunOnce: [sdkov.exe] C:\WINDOWS\sdkov.exe
O4 - HKLM\..\RunOnce: [ntpv.exe] C:\WINDOWS\ntpv.exe
O4 - HKLM\..\RunOnce: [iees32.exe] C:\WINDOWS\iees32.exe
O4 - HKLM\..\RunOnce: [javaxt32.exe] C:\WINDOWS\javaxt32.exe
O4 - HKLM\..\RunOnce: [netnj.exe] C:\WINDOWS\system32\netnj.exe
O4 - HKLM\..\RunOnce: [winmz32.exe] C:\WINDOWS\system32\winmz32.exe
O4 - HKLM\..\RunOnce: [d3kg32.exe] C:\WINDOWS\d3kg32.exe
O4 - HKLM\..\RunOnce: [mskw32.exe] C:\WINDOWS\mskw32.exe
O4 - HKLM\..\RunOnce: [javaux.exe] C:\WINDOWS\system32\javaux.exe
O4 - HKLM\..\RunOnce: [appdd.exe] C:\WINDOWS\system32\appdd.exe
O4 - HKLM\..\RunOnce: [iehp32.exe] C:\WINDOWS\iehp32.exe
O4 - HKLM\..\RunOnce: [sysoo32.exe] C:\WINDOWS\system32\sysoo32.exe
O4 - HKLM\..\RunOnce: [addcr32.exe] C:\WINDOWS\system32\addcr32.exe
O4 - HKLM\..\RunOnce: [mfcgv32.exe] C:\WINDOWS\mfcgv32.exe
O4 - HKLM\..\RunOnce: [d3gv.exe] C:\WINDOWS\system32\d3gv.exe
O4 - HKLM\..\RunOnce: [appqd.exe] C:\WINDOWS\appqd.exe
O4 - HKLM\..\RunOnce: [d3pt32.exe] C:\WINDOWS\system32\d3pt32.exe
O4 - HKLM\..\RunOnce: [ntnj.exe] C:\WINDOWS\ntnj.exe
O4 - HKLM\..\RunOnce: [atlmy32.exe] C:\WINDOWS\atlmy32.exe
O4 - HKLM\..\RunOnce: [sysco32.exe] C:\WINDOWS\system32\sysco32.exe
O4 - HKLM\..\RunOnce: [winkw32.exe] C:\WINDOWS\system32\winkw32.exe
O4 - HKLM\..\RunOnce: [netof32.exe] C:\WINDOWS\system32\netof32.exe
O4 - HKLM\..\RunOnce: [ipnv.exe] C:\WINDOWS\ipnv.exe
O4 - HKLM\..\RunOnce: [netow.exe] C:\WINDOWS\system32\netow.exe
O4 - HKLM\..\RunOnce: [crml32.exe] C:\WINDOWS\crml32.exe
O4 - HKLM\..\RunOnce: [ipwm32.exe] C:\WINDOWS\system32\ipwm32.exe
O4 - HKLM\..\RunOnce: [atlub32.exe] C:\WINDOWS\atlub32.exe
O4 - HKLM\..\RunOnce: [mfcur.exe] C:\WINDOWS\mfcur.exe
O4 - HKLM\..\RunOnce: [atldr.exe] C:\WINDOWS\atldr.exe
O4 - HKLM\..\RunOnce: [ntsh32.exe] C:\WINDOWS\system32\ntsh32.exe
O4 - HKLM\..\RunOnce: [mfcci32.exe] C:\WINDOWS\mfcci32.exe
O4 - HKLM\..\RunOnce: [winbx32.exe] C:\WINDOWS\system32\winbx32.exe
O4 - HKLM\..\RunOnce: [d3oh32.exe] C:\WINDOWS\system32\d3oh32.exe
O4 - HKLM\..\RunOnce: [ntex32.exe] C:\WINDOWS\ntex32.exe
O4 - HKLM\..\RunOnce: [sdkef.exe] C:\WINDOWS\sdkef.exe
O4 - HKLM\..\RunOnce: [ipnf.exe] C:\WINDOWS\system32\ipnf.exe
O4 - HKLM\..\RunOnce: [mscc.exe] C:\WINDOWS\mscc.exe
O4 - HKLM\..\RunOnce: [d3lc.exe] C:\WINDOWS\system32\d3lc.exe
O4 - HKLM\..\RunOnce: [msqh.exe] C:\WINDOWS\system32\msqh.exe
O4 - HKLM\..\RunOnce: [msks32.exe] C:\WINDOWS\msks32.exe
O4 - HKLM\..\RunOnce: [ntpx32.exe] C:\WINDOWS\system32\ntpx32.exe
O4 - HKLM\..\RunOnce: [iesi32.exe] C:\WINDOWS\iesi32.exe
O4 - HKLM\..\RunOnce: [sdksw32.exe] C:\WINDOWS\sdksw32.exe
O4 - HKLM\..\RunOnce: [atllp32.exe] C:\WINDOWS\atllp32.exe
O4 - HKLM\..\RunOnce: [atllx.exe] C:\WINDOWS\system32\atllx.exe
O4 - HKLM\..\RunOnce: [ntjv32.exe] C:\WINDOWS\system32\ntjv32.exe
O4 - HKLM\..\RunOnce: [mfcbv32.exe] C:\WINDOWS\mfcbv32.exe
O4 - HKLM\..\RunOnce: [winsl32.exe] C:\WINDOWS\system32\winsl32.exe
O4 - HKLM\..\RunOnce: [addrt.exe] C:\WINDOWS\system32\addrt.exe
O4 - HKLM\..\RunOnce: [sysat.exe] C:\WINDOWS\system32\sysat.exe
O4 - HKLM\..\RunOnce: [apipq32.exe] C:\WINDOWS\apipq32.exe
O4 - HKLM\..\RunOnce: [ieel32.exe] C:\WINDOWS\ieel32.exe
O4 - HKLM\..\RunOnce: [mfcti.exe] C:\WINDOWS\system32\mfcti.exe
O4 - HKLM\..\RunOnce: [iplb32.exe] C:\WINDOWS\iplb32.exe
O4 - HKLM\..\RunOnce: [d3hv.exe] C:\WINDOWS\system32\d3hv.exe
O4 - HKLM\..\RunOnce: [msjg32.exe] C:\WINDOWS\msjg32.exe
O4 - HKLM\..\RunOnce: [msjo32.exe] C:\WINDOWS\msjo32.exe
O4 - HKLM\..\RunOnce: [winot.exe] C:\WINDOWS\system32\winot.exe
O4 - HKLM\..\RunOnce: [sysxb32.exe] C:\WINDOWS\sysxb32.exe
O4 - HKLM\..\RunOnce: [iedq32.exe] C:\WINDOWS\system32\iedq32.exe
O4 - HKLM\..\RunOnce: [syslg32.exe] C:\WINDOWS\system32\syslg32.exe
O4 - HKLM\..\RunOnce: [mfcpq32.exe] C:\WINDOWS\system32\mfcpq32.exe
O4 - HKLM\..\RunOnce: [sdktc.exe] C:\WINDOWS\system32\sdktc.exe
O4 - HKLM\..\RunOnce: [sdknv32.exe] C:\WINDOWS\system32\sdknv32.exe
O4 - HKLM\..\RunOnce: [mfcsr32.exe] C:\WINDOWS\system32\mfcsr32.exe
O4 - HKLM\..\RunOnce: [javavd.exe] C:\WINDOWS\system32\javavd.exe
O4 - HKLM\..\RunOnce: [iprp32.exe] C:\WINDOWS\iprp32.exe
O4 - HKLM\..\RunOnce: [atlpe.exe] C:\WINDOWS\system32\atlpe.exe
O4 - HKLM\..\RunOnce: [msom32.exe] C:\WINDOWS\system32\msom32.exe
O4 - HKLM\..\RunOnce: [javams.exe] C:\WINDOWS\javams.exe
O4 - HKLM\..\RunOnce: [iech32.exe] C:\WINDOWS\iech32.exe
O4 - HKLM\..\RunOnce: [ntqk32.exe] C:\WINDOWS\system32\ntqk32.exe
O4 - HKLM\..\RunOnce: [msgz.exe] C:\WINDOWS\msgz.exe
O4 - HKLM\..\RunOnce: [addya32.exe] C:\WINDOWS\addya32.exe
O4 - HKLM\..\RunOnce: [netcm.exe] C:\WINDOWS\netcm.exe
O4 - HKLM\..\RunOnce: [netwx32.exe] C:\WINDOWS\system32\netwx32.exe
O4 - HKLM\..\RunOnce: [ipwn32.exe] C:\WINDOWS\system32\ipwn32.exe
O4 - HKLM\..\RunOnce: [javabr.exe] C:\WINDOWS\javabr.exe
O4 - HKLM\..\RunOnce: [sdkks32.exe] C:\WINDOWS\system32\sdkks32.exe
O4 - HKLM\..\RunOnce: [ntyo32.exe] C:\WINDOWS\ntyo32.exe
O4 - HKLM\..\RunOnce: [addtg.exe] C:\WINDOWS\system32\addtg.exe
O4 - HKLM\..\RunOnce: [javagk32.exe] C:\WINDOWS\javagk32.exe
O4 - HKLM\..\RunOnce: [winbw32.exe] C:\WINDOWS\system32\winbw32.exe
O4 - HKLM\..\RunOnce: [atlga.exe] C:\WINDOWS\system32\atlga.exe
O4 - HKLM\..\RunOnce: [apppb32.exe] C:\WINDOWS\system32\apppb32.exe
O4 - HKLM\..\RunOnce: [adddy.exe] C:\WINDOWS\system32\adddy.exe
O4 - HKLM\..\RunOnce: [crxr.exe] C:\WINDOWS\crxr.exe
O4 - HKLM\..\RunOnce: [crrc32.exe] C:\WINDOWS\crrc32.exe
O4 - HKLM\..\RunOnce: [addgz.exe] C:\WINDOWS\system32\addgz.exe
O4 - HKLM\..\RunOnce: [netkj32.exe] C:\WINDOWS\system32\netkj32.exe
O4 - HKLM\..\RunOnce: [atlih.exe] C:\WINDOWS\atlih.exe
O4 - HKLM\..\RunOnce: [addrh.exe] C:\WINDOWS\system32\addrh.exe
O4 - HKLM\..\RunOnce: [iphe32.exe] C:\WINDOWS\iphe32.exe
O4 - HKLM\..\RunOnce: [atlrf32.exe] C:\WINDOWS\atlrf32.exe
O4 - HKLM\..\RunOnce: [syspu32.exe] C:\WINDOWS\system32\syspu32.exe
O4 - HKLM\..\RunOnce: [winpc.exe] C:\WINDOWS\system32\winpc.exe
O4 - HKLM\..\RunOnce: [ieyd.exe] C:\WINDOWS\ieyd.exe
O4 - HKLM\..\RunOnce: [mfcna32.exe] C:\WINDOWS\system32\mfcna32.exe
O4 - HKLM\..\RunOnce: [winxb32.exe] C:\WINDOWS\system32\winxb32.exe
O4 - HKLM\..\RunOnce: [d3wq32.exe] C:\WINDOWS\d3wq32.exe
O4 - HKLM\..\RunOnce: [ipja32.exe] C:\WINDOWS\system32\ipja32.exe
O4 - HKLM\..\RunOnce: [atlzi.exe] C:\WINDOWS\atlzi.exe
O4 - HKLM\..\RunOnce: [ieyx32.exe] C:\WINDOWS\ieyx32.exe
O4 - HKLM\..\RunOnce: [netsz32.exe] C:\WINDOWS\netsz32.exe
O4 - HKLM\..\RunOnce: [appqg32.exe] C:\WINDOWS\system32\appqg32.exe
O4 - HKLM\..\RunOnce: [atlqw.exe] C:\WINDOWS\system32\atlqw.exe
O4 - HKLM\..\RunOnce: [appzx.exe] C:\WINDOWS\system32\appzx.exe
O4 - HKLM\..\RunOnce: [ipom32.exe] C:\WINDOWS\system32\ipom32.exe
O4 - HKLM\..\RunOnce: [atlhv32.exe] C:\WINDOWS\system32\atlhv32.exe
O4 - HKLM\..\RunOnce: [sysxc32.exe] C:\WINDOWS\sysxc32.exe
O4 - HKLM\..\RunOnce: [winfs.exe] C:\WINDOWS\winfs.exe
O4 - HKLM\..\RunOnce: [sysfs.exe] C:\WINDOWS\system32\sysfs.exe
O4 - HKLM\..\RunOnce: [apivi32.exe] C:\WINDOWS\apivi32.exe
O4 - HKLM\..\RunOnce: [iejk32.exe] C:\WINDOWS\system32\iejk32.exe
O4 - HKLM\..\RunOnce: [atlyz.exe] C:\WINDOWS\atlyz.exe
O4 - HKLM\..\RunOnce: [ipra32.exe] C:\WINDOWS\ipra32.exe
O4 - HKLM\..\RunOnce: [d3um.exe] C:\WINDOWS\d3um.exe
O4 - HKLM\..\RunOnce: [mson32.exe] C:\WINDOWS\system32\mson32.exe
O4 - HKLM\..\RunOnce: [wints.exe] C:\WINDOWS\wints.exe
O4 - HKLM\..\RunOnce: [syscs32.exe] C:\WINDOWS\system32\syscs32.exe
O4 - HKLM\..\RunOnce: [ieqp32.exe] C:\WINDOWS\ieqp32.exe
O4 - HKLM\..\RunOnce: [iplg.exe] C:\WINDOWS\system32\iplg.exe
O4 - HKLM\..\RunOnce: [sdkql32.exe] C:\WINDOWS\sdkql32.exe
O4 - HKLM\..\RunOnce: [atlje32.exe] C:\WINDOWS\atlje32.exe
O4 - HKLM\..\RunOnce: [mfcju32.exe] C:\WINDOWS\system32\mfcju32.exe
O4 - HKLM\..\RunOnce: [appsu32.exe] C:\WINDOWS\system32\appsu32.exe
O4 - HKLM\..\RunOnce: [ntvg32.exe] C:\WINDOWS\ntvg32.exe
O4 - HKLM\..\RunOnce: [crak.exe] C:\WINDOWS\crak.exe
O4 - HKLM\..\RunOnce: [msre32.exe] C:\WINDOWS\msre32.exe
O4 - HKLM\..\RunOnce: [mfcid.exe] C:\WINDOWS\mfcid.exe
O4 - HKLM\..\RunOnce: [javafa32.exe] C:\WINDOWS\system32\javafa32.exe
O4 - HKLM\..\RunOnce: [netqb32.exe] C:\WINDOWS\system32\netqb32.exe
O4 - HKLM\..\RunOnce: [appor.exe] C:\WINDOWS\appor.exe
O4 - HKLM\..\RunOnce: [msng32.exe] C:\WINDOWS\msng32.exe
O4 - HKLM\..\RunOnce: [winyf.exe] C:\WINDOWS\winyf.exe
O4 - HKLM\..\RunOnce: [applk.exe] C:\WINDOWS\applk.exe
O4 - HKLM\..\RunOnce: [atlzo.exe] C:\WINDOWS\atlzo.exe
O4 - HKLM\..\RunOnce: [atlta32.exe] C:\WINDOWS\atlta32.exe
O4 - HKLM\..\RunOnce: [sysgk.exe] C:\WINDOWS\sysgk.exe
O4 - HKLM\..\RunOnce: [addxs.exe] C:\WINDOWS\system32\addxs.exe
O4 - HKLM\..\RunOnce: [apiqs32.exe] C:\WINDOWS\apiqs32.exe
O4 - HKLM\..\RunOnce: [winuf32.exe] C:\WINDOWS\system32\winuf32.exe
O4 - HKLM\..\RunOnce: [atllm.exe] C:\WINDOWS\system32\atllm.exe
O4 - HKLM\..\RunOnce: [apiyr.exe] C:\WINDOWS\system32\apiyr.exe
O4 - HKLM\..\RunOnce: [apisk32.exe] C:\WINDOWS\apisk32.exe
O4 - HKLM\..\RunOnce: [netas32.exe] C:\WINDOWS\netas32.exe
O4 - HKLM\..\RunOnce: [sdkfw.exe] C:\WINDOWS\system32\sdkfw.exe
O4 - HKLM\..\RunOnce: [ntgx32.exe] C:\WINDOWS\ntgx32.exe
O4 - HKLM\..\RunOnce: [ipuu32.exe] C:\WINDOWS\system32\ipuu32.exe
O4 - HKLM\..\RunOnce: [winxl.exe] C:\WINDOWS\winxl.exe
O4 - HKLM\..\RunOnce: [d3vq32.exe] C:\WINDOWS\d3vq32.exe
O4 - HKLM\..\RunOnce: [apper32.exe] C:\WINDOWS\system32\apper32.exe
O4 - HKLM\..\RunOnce: [javaez32.exe] C:\WINDOWS\javaez32.exe
O4 - HKLM\..\RunOnce: [addzl32.exe] C:\WINDOWS\system32\addzl32.exe
O4 - HKLM\..\RunOnce: [mfcmp.exe] C:\WINDOWS\system32\mfcmp.exe
O4 - HKLM\..\RunOnce: [appnp32.exe] C:\WINDOWS\system32\appnp32.exe
O4 - HKLM\..\RunOnce: [appbm.exe] C:\WINDOWS\system32\appbm.exe
O4 - HKLM\..\RunOnce: [d3vf.exe] C:\WINDOWS\d3vf.exe
O4 - HKLM\..\RunOnce: [d3pz32.exe] C:\WINDOWS\d3pz32.exe
O4 - HKLM\..\RunOnce: [sdkzx.exe] C:\WINDOWS\system32\sdkzx.exe
O4 - HKLM\..\RunOnce: [addnc32.exe] C:\WINDOWS\system32\addnc32.exe
O4 - HKLM\..\RunOnce: [d3ao32.exe] C:\WINDOWS\system32\d3ao32.exe
O4 - HKLM\..\RunOnce: [addwa.exe] C:\WINDOWS\addwa.exe
O4 - HKLM\..\RunOnce: [appym32.exe] C:\WINDOWS\system32\appym32.exe
O4 - HKLM\..\RunOnce: [appyc32.exe] C:\WINDOWS\system32\appyc32.exe
O4 - HKLM\..\RunOnce: [apicg.exe] C:\WINDOWS\apicg.exe
O4 - HKLM\..\RunOnce: [mfclg32.exe] C:\WINDOWS\system32\mfclg32.exe
O4 - HKLM\..\RunOnce: [atlsd32.exe] C:\WINDOWS\atlsd32.exe
O4 - HKLM\..\RunOnce: [d3uv.exe] C:\WINDOWS\system32\d3uv.exe
O4 - HKLM\..\RunOnce: [syszz32.exe] C:\WINDOWS\syszz32.exe
O4 - HKLM\..\RunOnce: [sdkss32.exe] C:\WINDOWS\system32\sdkss32.exe
O4 - HKLM\..\RunOnce: [javasi.exe] C:\WINDOWS\system32\javasi.exe
O4 - HKLM\..\RunOnce: [ntbi.exe] C:\WINDOWS\ntbi.exe
O4 - HKLM\..\RunOnce: [ieqx32.exe] C:\WINDOWS\system32\ieqx32.exe
O4 - HKLM\..\RunOnce: [javajy32.exe] C:\WINDOWS\javajy32.exe
O4 - HKLM\..\RunOnce: [netzo32.exe] C:\WINDOWS\system32\netzo32.exe
O4 - HKLM\..\RunOnce: [iphe.exe] C:\WINDOWS\iphe.exe
O4 - HKLM\..\RunOnce: [apihe.exe] C:\WINDOWS\system32\apihe.exe
O4 - HKLM\..\RunOnce: [crxt32.exe] C:\WINDOWS\crxt32.exe
O4 - HKLM\..\RunOnce: [mfclw32.exe] C:\WINDOWS\mfclw32.exe
O4 - HKLM\..\RunOnce: [javaal.exe] C:\WINDOWS\system32\javaal.exe
O4 - HKLM\..\RunOnce: [mstm32.exe] C:\WINDOWS\mstm32.exe
O4 - HKLM\..\RunOnce: [ipef.exe] C:\WINDOWS\ipef.exe
O4 - HKLM\..\RunOnce: [ienn.exe] C:\WINDOWS\ienn.exe
O4 - HKLM\..\RunOnce: [atlwg.exe] C:\WINDOWS\atlwg.exe
O4 - HKLM\..\RunOnce: [winas.exe] C:\WINDOWS\winas.exe
O4 - HKLM\..\RunOnce: [ntpp32.exe] C:\WINDOWS\ntpp32.exe
O4 - HKLM\..\RunOnce: [mssb.exe] C:\WINDOWS\mssb.exe
O4 - HKLM\..\RunOnce: [apihd.exe] C:\WINDOWS\apihd.exe


In KillBox-> Click File-> Paste from Clipboard

Now put a Tick By "Delete on Reboot"-> Click the Red Circle to Delete!

Reboot into SAFE MODE(Tap F8 when restarting)
Here is a link on how to boot into Safe Mode:
http://service1.syma...src=sec_doc_nam


Run CWShredder

Click "Fix ->" and click "OK" at the prompt.
CWShredder will scan and clean your system of CWS files.
Click "Next->" and then "Exit"

Run ABout Buster just as described in the link!

Please run it until you get these Results:

No ADS found on system
Attempted Clean Of Temp folder.
Pages Reset... Done!


Run CleanUp!

Click on the "CleanUp!" Tab and let it do its thing!

Run Ewido-> Clean everything it finds-> Be sure to click the tab to Save a Report!

Open HijackThis and put a check by these but DO NOT hit the Fix Checked button yet!

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - Default URLSearchHook is missing

O2 - BHO: Class - {02C0DCC5-3CE6-0398-0598-65E2B62B528F} - C:\WINDOWS\system32\msid32.dll
O2 - BHO: Class - {05A55FD0-07CB-11D2-9597-D96F9FF82934} - C:\WINDOWS\ntui.dll
O2 - BHO: Class - {08BEC198-7D8F-EA95-F1EA-2D7648DD4E06} - C:\WINDOWS\addwa.dll
O2 - BHO: Class - {092C0E63-121E-FA9D-1E4E-5DDAA0E963DB} - C:\WINDOWS\system32\addnm32.dll
O2 - BHO: Class - {0B661A23-D4C8-D088-322A-EA2355183008} - C:\WINDOWS\ieag.dll
O2 - BHO: Class - {13F515CF-0C52-2DB2-DD18-6D86CD3486CB} - C:\WINDOWS\system32\sdkwj.dll
O2 - BHO: Class - {1BA93373-201C-314A-722B-378A24BEFF9F} - C:\WINDOWS\system32\crvq32.dll
O2 - BHO: Class - {1BBF8296-22FF-42B6-3DEE-014A827D5E04} - C:\WINDOWS\system32\apptv32.dll
O2 - BHO: Class - {1EAD2AC4-39BA-3522-0176-BF8C4F454375} - C:\WINDOWS\system32\addga.dll
O2 - BHO: Class - {1F499D48-ECE7-D492-016F-B8A978A5D02A} - C:\WINDOWS\system32\netow.dll
O2 - BHO: Class - {3091015E-CC06-611B-E5A2-43478B041E5A} - C:\WINDOWS\sdksw32.dll
O2 - BHO: Class - {3228229A-289E-9E2F-9154-02F1DC5C463F} - C:\WINDOWS\system32\d3cy32.dll
O2 - BHO: Class - {35DDF22C-ABD8-BB4D-7430-A00C122605A3} - C:\WINDOWS\crml32.dll
O2 - BHO: Class - {3D314575-05BB-1678-B27E-04B2A966F5F1} - C:\WINDOWS\system32\netbk32.dll
O2 - BHO: Class - {3DF3AE97-927A-A988-F257-18F61D1C5ABA} - C:\WINDOWS\system32\ieub32.dll
O2 - BHO: Class - {47AC3AC5-C903-9914-10BF-BD321AC3B99B} - C:\WINDOWS\sdkov.dll
O2 - BHO: Class - {4D5086C8-1EDA-4232-0DD5-8A2FF9D9C966} - C:\WINDOWS\system32\mszp.dll
O2 - BHO: Class - {5597E50C-316E-EAAF-1D34-0D604001E92E} - C:\WINDOWS\appxv.dll
O2 - BHO: Class - {59032CD0-6861-388D-3398-80FD4CCFF228} - C:\WINDOWS\crgt32.dll
O2 - BHO: Class - {5C24F68F-330D-3834-5594-F52CB787AE93} - C:\WINDOWS\system32\ipwm32.dll
O2 - BHO: Class - {66D4D570-CA0D-A697-05AF-9C46ECFF8539} - C:\WINDOWS\netts32.dll
O2 - BHO: Class - {73676454-A932-7669-B377-AC3A0147A262} - C:\WINDOWS\addwy32.dll
O2 - BHO: Class - {7683AD2C-79FA-24D4-779F-50574258757A} - C:\WINDOWS\sdkef.dll
O2 - BHO: Class - {7E29E088-E904-C077-2FCA-B7880E438F22} - C:\WINDOWS\syszz32.dll
O2 - BHO: Class - {800E8E08-DE88-9E15-E570-254FA8F9B219} - C:\WINDOWS\javaxt32.dll
O2 - BHO: Class - {82335B62-7DEF-0FF6-3C5F-94007ED6C7B3} - C:\WINDOWS\appib32.dll
O2 - BHO: Class - {82341895-A1EE-6A36-B4A4-5394B2CED036} - C:\WINDOWS\sdkqo.dll
O2 - BHO: Class - {83971461-34F4-E677-127C-D62A91D02AD1} - C:\WINDOWS\ntbi.dll
O2 - BHO: Class - {85207839-3806-D845-DDE9-5ADD23506597} - C:\WINDOWS\apizz.dll
O2 - BHO: Class - {85D9CD8E-5A0B-5971-2E36-284D9E2E0BF4} - C:\WINDOWS\addir32.dll
O2 - BHO: Class - {869844E3-C2D7-2101-E8F9-967AA18010D5} - C:\WINDOWS\ieyc.dll
O2 - BHO: Class - {89C52F8E-6421-B53A-EBC0-9EFEAF3E7FCD} - C:\WINDOWS\ippi.dll
O2 - BHO: Class - {8B9B410F-0A67-22CE-3941-CB77C211A4A9} - C:\WINDOWS\javabp32.dll
O2 - BHO: Class - {8C7413DD-6325-E43D-BD47-63DEDEF0FC7C} - C:\WINDOWS\system32\iehj.dll
O2 - BHO: Class - {9B0F7030-AF9E-455A-F0F3-B9E15FD227AE} - C:\WINDOWS\system32\netpx32.dll
O2 - BHO: Class - {AB07D8D0-2369-881F-81AF-C71825A24FD7} - C:\WINDOWS\ntpv.dll
O2 - BHO: Class - {ACCA505A-38CA-43E7-377E-CDE48726DF7A} - C:\WINDOWS\system32\apppn.dll
O2 - BHO: Class - {B285152E-E0C0-8D4F-E2D7-04EB877DB035} - C:\WINDOWS\atlyz.dll
O2 - BHO: Class - {B796255B-ACA4-16C7-11F6-66CB8A35904C} - C:\WINDOWS\iekn.dll
O2 - BHO: Class - {B8542646-AFF5-94ED-2255-DD8481388BCE} - C:\WINDOWS\system32\sdkbo32.dll
O2 - BHO: Class - {BB0401E6-61A6-0344-A30F-3DFA178D6F76} - C:\WINDOWS\netut.dll
O2 - BHO: Class - {BD2572C3-91F3-D764-96F0-7518D05E9428} - C:\WINDOWS\appyp.dll
O2 - BHO: Class - {BF82252D-ABE1-E8BB-F0BF-178FB378D258} - C:\WINDOWS\mfczg.dll
O2 - BHO: Class - {C63C732D-A5FF-9CDA-B026-5AA18E9F72B5} - C:\WINDOWS\winyf.dll
O2 - BHO: Class - {C7F8F9B4-5233-5460-C2DB-34313EC35B32} - C:\WINDOWS\sdkch32.dll
O2 - BHO: Class - {CC2A66A5-539A-852C-FA22-A3BD80E37FC4} - C:\WINDOWS\system32\crwn32.dll
O2 - BHO: Class - {CC74E0B9-F6BF-A716-4F9A-98CC5AAEA235} - C:\WINDOWS\sdkkh32.dll
O2 - BHO: Class - {D197A0E1-57CF-5D1D-AB6B-C7313C71B514} - C:\WINDOWS\system32\ipoi.dll
O2 - BHO: Class - {D2AD2325-0119-62FA-1172-8B029FFD46EF} - C:\WINDOWS\system32\sysxa.dll (file missing)
O2 - BHO: Class - {D46A242B-6194-E7D0-7207-4CC5FFB11ADE} - C:\WINDOWS\system32\winia.dll
O2 - BHO: Class - {DF681A51-5F05-1F39-036E-D1C704F8F568} - C:\WINDOWS\ipmi32.dll
O2 - BHO: Class - {E0DA5911-5137-7600-E631-98A3D1D307DB} - C:\WINDOWS\iett.dll
O2 - BHO: Class - {E4FD490D-A46F-95DB-EFF2-CF0215363020} - C:\WINDOWS\atlsu.dll
O2 - BHO: Class - {EC3DDF47-5645-BD30-F6EE-3A2152B02861} - C:\WINDOWS\apizj32.dll
O2 - BHO: Class - {F0FC9C3B-CE66-41DD-5954-499FDD4FBB41} - C:\WINDOWS\system32\netzo32.dll
O2 - BHO: Class - {FBF7402B-F568-97CC-0EFF-2D7ABD52E16B} - C:\WINDOWS\netwq.dll
O2 - BHO: Class - {FEB58C92-D119-8F66-A8FA-72D46A544DA9} - C:\WINDOWS\system32\winuf32.dll

O4 - HKLM\..\Run: [ipds.exe] C:\WINDOWS\ipds.exe
O4 - HKLM\..\Run: [msvq.exe] C:\WINDOWS\msvq.exe
O4 - HKLM\..\Run: [mfcku.exe] C:\WINDOWS\system32\mfcku.exe
O4 - HKLM\..\Run: [ntys32.exe] C:\WINDOWS\system32\ntys32.exe
O4 - HKLM\..\Run: [addqr32.exe] C:\WINDOWS\addqr32.exe
O4 - HKLM\..\Run: [ntwk32.exe] C:\WINDOWS\ntwk32.exe
O4 - HKLM\..\Run: [ieyu.exe] C:\WINDOWS\ieyu.exe
O4 - HKLM\..\Run: [javajs.exe] C:\WINDOWS\javajs.exe
O4 - HKLM\..\Run: [iegp32.exe] C:\WINDOWS\iegp32.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [crxi.exe] C:\WINDOWS\system32\crxi.exe
O4 - HKLM\..\Run: [ipoi.exe] C:\WINDOWS\system32\ipoi.exe
O4 - HKLM\..\RunOnce: [mfcbv.exe] C:\WINDOWS\mfcbv.exe
O4 - HKLM\..\RunOnce: [msav.exe] C:\WINDOWS\system32\msav.exe
O4 - HKLM\..\RunOnce: [sysit32.exe] C:\WINDOWS\system32\sysit32.exe
O4 - HKLM\..\RunOnce: [sysib32.exe] C:\WINDOWS\system32\sysib32.exe
O4 - HKLM\..\RunOnce: [appmg.exe] C:\WINDOWS\appmg.exe
O4 - HKLM\..\RunOnce: [addvg32.exe] C:\WINDOWS\system32\addvg32.exe
O4 - HKLM\..\RunOnce: [ntem.exe] C:\WINDOWS\system32\ntem.exe
O4 - HKLM\..\RunOnce: [ieub32.exe] C:\WINDOWS\ieub32.exe
O4 - HKLM\..\RunOnce: [addkj.exe] C:\WINDOWS\addkj.exe
O4 - HKLM\..\RunOnce: [atlyn.exe] C:\WINDOWS\atlyn.exe
O4 - HKLM\..\RunOnce: [atlsh32.exe] C:\WINDOWS\system32\atlsh32.exe
O4 - HKLM\..\RunOnce: [mfcap32.exe] C:\WINDOWS\system32\mfcap32.exe
O4 - HKLM\..\RunOnce: [ipet32.exe] C:\WINDOWS\system32\ipet32.exe
O4 - HKLM\..\RunOnce: [syseb.exe] C:\WINDOWS\system32\syseb.exe
O4 - HKLM\..\RunOnce: [d3in.exe] C:\WINDOWS\system32\d3in.exe
O4 - HKLM\..\RunOnce: [addxc32.exe] C:\WINDOWS\addxc32.exe
O4 - HKLM\..\RunOnce: [netwq.exe] C:\WINDOWS\netwq.exe
O4 - HKLM\..\RunOnce: [winvx.exe] C:\WINDOWS\winvx.exe
O4 - HKLM\..\RunOnce: [ntvf.exe] C:\WINDOWS\system32\ntvf.exe
O4 - HKLM\..\RunOnce: [apizj32.exe] C:\WINDOWS\apizj32.exe
O4 - HKLM\..\RunOnce: [apizz.exe] C:\WINDOWS\apizz.exe
O4 - HKLM\..\RunOnce: [iett.exe] C:\WINDOWS\iett.exe
O4 - HKLM\..\RunOnce: [sdksi32.exe] C:\WINDOWS\sdksi32.exe
O4 - HKLM\..\RunOnce: [apiqy32.exe] C:\WINDOWS\system32\apiqy32.exe
O4 - HKLM\..\RunOnce: [apiqg.exe] C:\WINDOWS\system32\apiqg.exe
O4 - HKLM\..\RunOnce: [mfczg.exe] C:\WINDOWS\mfczg.exe
O4 - HKLM\..\RunOnce: [javaov32.exe] C:\WINDOWS\system32\javaov32.exe
O4 - HKLM\..\RunOnce: [netye32.exe] C:\WINDOWS\system32\netye32.exe
O4 - HKLM\..\RunOnce: [appxu.exe] C:\WINDOWS\appxu.exe
O4 - HKLM\..\RunOnce: [mfcwz32.exe] C:\WINDOWS\system32\mfcwz32.exe
O4 - HKLM\..\RunOnce: [addga.exe] C:\WINDOWS\system32\addga.exe
O4 - HKLM\..\RunOnce: [addat32.exe] C:\WINDOWS\addat32.exe
O4 - HKLM\..\RunOnce: [appib32.exe] C:\WINDOWS\appib32.exe
O4 - HKLM\..\RunOnce: [aping.exe] C:\WINDOWS\system32\aping.exe
O4 - HKLM\..\RunOnce: [mfcng32.exe] C:\WINDOWS\mfcng32.exe
O4 - HKLM\..\RunOnce: [atlcd32.exe] C:\WINDOWS\system32\atlcd32.exe
O4 - HKLM\..\RunOnce: [ipop.exe] C:\WINDOWS\system32\ipop.exe
O4 - HKLM\..\RunOnce: [netpx32.exe] C:\WINDOWS\system32\netpx32.exe
O4 - HKLM\..\RunOnce: [apiem.exe] C:\WINDOWS\system32\apiem.exe
O4 - HKLM\..\RunOnce: [sysxn.exe] C:\WINDOWS\sysxn.exe
O4 - HKLM\..\RunOnce: [ipmi32.exe] C:\WINDOWS\ipmi32.exe
O4 - HKLM\..\RunOnce: [mspu32.exe] C:\WINDOWS\mspu32.exe
O4 - HKLM\..\RunOnce: [winuy.exe] C:\WINDOWS\system32\winuy.exe
O4 - HKLM\..\RunOnce: [sysuy32.exe] C:\WINDOWS\sysuy32.exe
O4 - HKLM\..\RunOnce: [iejv.exe] C:\WINDOWS\system32\iejv.exe
O4 - HKLM\..\RunOnce: [ntco.exe] C:\WINDOWS\ntco.exe
O4 - HKLM\..\RunOnce: [sdkib.exe] C:\WINDOWS\sdkib.exe
O4 - HKLM\..\RunOnce: [addwy32.exe] C:\WINDOWS\addwy32.exe
O4 - HKLM\..\RunOnce: [netak.exe] C:\WINDOWS\system32\netak.exe
O4 - HKLM\..\RunOnce: [iexn.exe] C:\WINDOWS\system32\iexn.exe
O4 - HKLM\..\RunOnce: [mfcmc32.exe] C:\WINDOWS\mfcmc32.exe
O4 - HKLM\..\RunOnce: [sdkqo.exe] C:\WINDOWS\sdkqo.exe
O4 - HKLM\..\RunOnce: [sdkkh32.exe] C:\WINDOWS\sdkkh32.exe
O4 - HKLM\..\RunOnce: [javakp.exe] C:\WINDOWS\system32\javakp.exe
O4 - HKLM\..\RunOnce: [ipob32.exe] C:\WINDOWS\system32\ipob32.exe
O4 - HKLM\..\RunOnce: [appmr.exe] C:\WINDOWS\appmr.exe
O4 - HKLM\..\RunOnce: [mslg32.exe] C:\WINDOWS\mslg32.exe
O4 - HKLM\..\RunOnce: [sdkbo32.exe] C:\WINDOWS\system32\sdkbo32.exe
O4 - HKLM\..\RunOnce: [javaje.exe] C:\WINDOWS\javaje.exe
O4 - HKLM\..\RunOnce: [ntke.exe] C:\WINDOWS\system32\ntke.exe
O4 - HKLM\..\RunOnce: [iezt32.exe] C:\WINDOWS\iezt32.exe
O4 - HKLM\..\RunOnce: [ntsm32.exe] C:\WINDOWS\ntsm32.exe
O4 - HKLM\..\RunOnce: [ntwu.exe] C:\WINDOWS\ntwu.exe
O4 - HKLM\..\RunOnce: [apppn.exe] C:\WINDOWS\system32\apppn.exe
O4 - HKLM\..\RunOnce: [appjz32.exe] C:\WINDOWS\appjz32.exe
O4 - HKLM\..\RunOnce: [ipzw.exe] C:\WINDOWS\ipzw.exe
O4 - HKLM\..\RunOnce: [winvj.exe] C:\WINDOWS\winvj.exe
O4 - HKLM\..\RunOnce: [winpu32.exe] C:\WINDOWS\system32\winpu32.exe
O4 - HKLM\..\RunOnce: [cruy32.exe] C:\WINDOWS\cruy32.exe
O4 - HKLM\..\RunOnce: [addpk32.exe] C:\WINDOWS\system32\addpk32.exe
O4 - HKLM\..\RunOnce: [iehj.exe] C:\WINDOWS\system32\iehj.exe
O4 - HKLM\..\RunOnce: [mfcwy32.exe] C:\WINDOWS\mfcwy32.exe
O4 - HKLM\..\RunOnce: [sdkas.exe] C:\WINDOWS\sdkas.exe
O4 - HKLM\..\RunOnce: [sdkud32.exe] C:\WINDOWS\sdkud32.exe
O4 - HKLM\..\RunOnce: [mszp.exe] C:\WINDOWS\system32\mszp.exe
O4 - HKLM\..\RunOnce: [d3iy32.exe] C:\WINDOWS\system32\d3iy32.exe
O4 - HKLM\..\RunOnce: [crwn32.exe] C:\WINDOWS\system32\crwn32.exe
O4 - HKLM\..\RunOnce: [apibr.exe] C:\WINDOWS\system32\apibr.exe
O4 - HKLM\..\RunOnce: [appxv.exe] C:\WINDOWS\appxv.exe
O4 - HKLM\..\RunOnce: [ntus32.exe] C:\WINDOWS\system32\ntus32.exe
O4 - HKLM\..\RunOnce: [mfcet32.exe] C:\WINDOWS\mfcet32.exe
O4 - HKLM\..\RunOnce: [windi32.exe] C:\WINDOWS\system32\windi32.exe
O4 - HKLM\..\RunOnce: [sysmp.exe] C:\WINDOWS\sysmp.exe
O4 - HKLM\..\RunOnce: [sysgi32.exe] C:\WINDOWS\system32\sysgi32.exe
O4 - HKLM\..\RunOnce: [wingq32.exe] C:\WINDOWS\system32\wingq32.exe
O4 - HKLM\..\RunOnce: [atlsu.exe] C:\WINDOWS\atlsu.exe
O4 - HKLM\..\RunOnce: [apptv32.exe] C:\WINDOWS\system32\apptv32.exe
O4 - HKLM\..\RunOnce: [addir32.exe] C:\WINDOWS\addir32.exe
O4 - HKLM\..\RunOnce: [appih32.exe] C:\WINDOWS\appih32.exe
O4 - HKLM\..\RunOnce: [apimm.exe] C:\WINDOWS\system32\apimm.exe
O4 - HKLM\..\RunOnce: [mfcvm32.exe] C:\WINDOWS\mfcvm32.exe
O4 - HKLM\..\RunOnce: [atlkj.exe] C:\WINDOWS\system32\atlkj.exe
O4 - HKLM\..\RunOnce: [apiyl32.exe] C:\WINDOWS\system32\apiyl32.exe
O4 - HKLM\..\RunOnce: [ipcq.exe] C:\WINDOWS\system32\ipcq.exe
O4 - HKLM\..\RunOnce: [netdq32.exe] C:\WINDOWS\system32\netdq32.exe
O4 - HKLM\..\RunOnce: [netsn32.exe] C:\WINDOWS\system32\netsn32.exe
O4 - HKLM\..\RunOnce: [netzv32.exe] C:\WINDOWS\netzv32.exe
O4 - HKLM\..\RunOnce: [sdkez.exe] C:\WINDOWS\sdkez.exe
O4 - HKLM\..\RunOnce: [ntfz32.exe] C:\WINDOWS\ntfz32.exe
O4 - HKLM\..\RunOnce: [iptw32.exe] C:\WINDOWS\iptw32.exe
O4 - HKLM\..\RunOnce: [ntte32.exe] C:\WINDOWS\system32\ntte32.exe
O4 - HKLM\..\RunOnce: [crgj.exe] C:\WINDOWS\system32\crgj.exe
O4 - HKLM\..\RunOnce: [javahr32.exe] C:\WINDOWS\system32\javahr32.exe
O4 - HKLM\..\RunOnce: [sdkvg.exe] C:\WINDOWS\system32\sdkvg.exe
O4 - HKLM\..\RunOnce: [atlph.exe] C:\WINDOWS\atlph.exe
O4 - HKLM\..\RunOnce: [sdkzn.exe] C:\WINDOWS\system32\sdkzn.exe
O4 - HKLM\..\RunOnce: [sdktz32.exe] C:\WINDOWS\sdktz32.exe
O4 - HKLM\..\RunOnce: [atlyd32.exe] C:\WINDOWS\system32\atlyd32.exe
O4 - HKLM\..\RunOnce: [javabp32.exe] C:\WINDOWS\javabp32.exe
O4 - HKLM\..\RunOnce: [msft.exe] C:\WINDOWS\system32\msft.exe
O4 - HKLM\..\RunOnce: [crgt32.exe] C:\WINDOWS\crgt32.exe
O4 - HKLM\..\RunOnce: [crvq32.exe] C:\WINDOWS\system32\crvq32.exe
O4 - HKLM\..\RunOnce: [d3cy32.exe] C:\WINDOWS\system32\d3cy32.exe
O4 - HKLM\..\RunOnce: [syshd.exe] C:\WINDOWS\syshd.exe
O4 - HKLM\..\RunOnce: [msid32.exe] C:\WINDOWS\system32\msid32.exe
O4 - HKLM\..\RunOnce: [mswa.exe] C:\WINDOWS\mswa.exe
O4 - HKLM\..\RunOnce: [atlud32.exe] C:\WINDOWS\system32\atlud32.exe
O4 - HKLM\..\RunOnce: [javapo.exe] C:\WINDOWS\system32\javapo.exe
O4 - HKLM\..\RunOnce: [netts32.exe] C:\WINDOWS\netts32.exe
O4 - HKLM\..\RunOnce: [appri.exe] C:\WINDOWS\system32\appri.exe
O4 - HKLM\..\RunOnce: [msqy32.exe] C:\WINDOWS\system32\msqy32.exe
O4 - HKLM\..\RunOnce: [sdkgn32.exe] C:\WINDOWS\sdkgn32.exe
O4 - HKLM\..\RunOnce: [sdkov.exe] C:\WINDOWS\sdkov.exe
O4 - HKLM\..\RunOnce: [ntpv.exe] C:\WINDOWS\ntpv.exe
O4 - HKLM\..\RunOnce: [iees32.exe] C:\WINDOWS\iees32.exe
O4 - HKLM\..\RunOnce: [javaxt32.exe] C:\WINDOWS\javaxt32.exe
O4 - HKLM\..\RunOnce: [netnj.exe] C:\WINDOWS\system32\netnj.exe
O4 - HKLM\..\RunOnce: [winmz32.exe] C:\WINDOWS\system32\winmz32.exe
O4 - HKLM\..\RunOnce: [d3kg32.exe] C:\WINDOWS\d3kg32.exe
O4 - HKLM\..\RunOnce: [mskw32.exe] C:\WINDOWS\mskw32.exe
O4 - HKLM\..\RunOnce: [javaux.exe] C:\WINDOWS\system32\javaux.exe
O4 - HKLM\..\RunOnce: [appdd.exe] C:\WINDOWS\system32\appdd.exe
O4 - HKLM\..\RunOnce: [iehp32.exe] C:\WINDOWS\iehp32.exe
O4 - HKLM\..\RunOnce: [sysoo32.exe] C:\WINDOWS\system32\sysoo32.exe
O4 - HKLM\..\RunOnce: [addcr32.exe] C:\WINDOWS\system32\addcr32.exe
O4 - HKLM\..\RunOnce: [mfcgv32.exe] C:\WINDOWS\mfcgv32.exe
O4 - HKLM\..\RunOnce: [d3gv.exe] C:\WINDOWS\system32\d3gv.exe
O4 - HKLM\..\RunOnce: [appqd.exe] C:\WINDOWS\appqd.exe
O4 - HKLM\..\RunOnce: [d3pt32.exe] C:\WINDOWS\system32\d3pt32.exe
O4 - HKLM\..\RunOnce: [ntnj.exe] C:\WINDOWS\ntnj.exe
O4 - HKLM\..\RunOnce: [atlmy32.exe] C:\WINDOWS\atlmy32.exe
O4 - HKLM\..\RunOnce: [sysco32.exe] C:\WINDOWS\system32\sysco32.exe
O4 - HKLM\..\RunOnce: [winkw32.exe] C:\WINDOWS\system32\winkw32.exe
O4 - HKLM\..\RunOnce: [netof32.exe] C:\WINDOWS\system32\netof32.exe
O4 - HKLM\..\RunOnce: [ipnv.exe] C:\WINDOWS\ipnv.exe
O4 - HKLM\..\RunOnce: [netow.exe] C:\WINDOWS\system32\netow.exe
O4 - HKLM\..\RunOnce: [crml32.exe] C:\WINDOWS\crml32.exe
O4 - HKLM\..\RunOnce: [ipwm32.exe] C:\WINDOWS\system32\ipwm32.exe
O4 - HKLM\..\RunOnce: [atlub32.exe] C:\WINDOWS\atlub32.exe
O4 - HKLM\..\RunOnce: [mfcur.exe] C:\WINDOWS\mfcur.exe
O4 - HKLM\..\RunOnce: [atldr.exe] C:\WINDOWS\atldr.exe
O4 - HKLM\..\RunOnce: [ntsh32.exe] C:\WINDOWS\system32\ntsh32.exe
O4 - HKLM\..\RunOnce: [mfcci32.exe] C:\WINDOWS\mfcci32.exe
O4 - HKLM\..\RunOnce: [winbx32.exe] C:\WINDOWS\system32\winbx32.exe
O4 - HKLM\..\RunOnce: [d3oh32.exe] C:\WINDOWS\system32\d3oh32.exe
O4 - HKLM\..\RunOnce: [ntex32.exe] C:\WINDOWS\ntex32.exe
O4 - HKLM\..\RunOnce: [sdkef.exe] C:\WINDOWS\sdkef.exe
O4 - HKLM\..\RunOnce: [ipnf.exe] C:\WINDOWS\system32\ipnf.exe
O4 - HKLM\..\RunOnce: [mscc.exe] C:\WINDOWS\mscc.exe
O4 - HKLM\..\RunOnce: [d3lc.exe] C:\WINDOWS\system32\d3lc.exe
O4 - HKLM\..\RunOnce: [msqh.exe] C:\WINDOWS\system32\msqh.exe
O4 - HKLM\..\RunOnce: [msks32.exe] C:\WINDOWS\msks32.exe
O4 - HKLM\..\RunOnce: [ntpx32.exe] C:\WINDOWS\system32\ntpx32.exe
O4 - HKLM\..\RunOnce: [iesi32.exe] C:\WINDOWS\iesi32.exe
O4 - HKLM\..\RunOnce: [sdksw32.exe] C:\WINDOWS\sdksw32.exe
O4 - HKLM\..\RunOnce: [atllp32.exe] C:\WINDOWS\atllp32.exe
O4 - HKLM\..\RunOnce: [atllx.exe] C:\WINDOWS\system32\atllx.exe
O4 - HKLM\..\RunOnce: [ntjv32.exe] C:\WINDOWS\system32\ntjv32.exe
O4 - HKLM\..\RunOnce: [mfcbv32.exe] C:\WINDOWS\mfcbv32.exe
O4 - HKLM\..\RunOnce: [winsl32.exe] C:\WINDOWS\system32\winsl32.exe
O4 - HKLM\..\RunOnce: [addrt.exe] C:\WINDOWS\system32\addrt.exe
O4 - HKLM\..\RunOnce: [sysat.exe] C:\WINDOWS\system32\sysat.exe
O4 - HKLM\..\RunOnce: [apipq32.exe] C:\WINDOWS\apipq32.exe
O4 - HKLM\..\RunOnce: [ieel32.exe] C:\WINDOWS\ieel32.exe
O4 - HKLM\..\RunOnce: [mfcti.exe] C:\WINDOWS\system32\mfcti.exe
O4 - HKLM\..\RunOnce: [iplb32.exe] C:\WINDOWS\iplb32.exe
O4 - HKLM\..\RunOnce: [d3hv.exe] C:\WINDOWS\system32\d3hv.exe
O4 - HKLM\..\RunOnce: [msjg32.exe] C:\WINDOWS\msjg32.exe
O4 - HKLM\..\RunOnce: [msjo32.exe] C:\WINDOWS\msjo32.exe
O4 - HKLM\..\RunOnce: [winot.exe] C:\WINDOWS\system32\winot.exe
O4 - HKLM\..\RunOnce: [sysxb32.exe] C:\WINDOWS\sysxb32.exe
O4 - HKLM\..\RunOnce: [iedq32.exe] C:\WINDOWS\system32\iedq32.exe
O4 - HKLM\..\RunOnce: [syslg32.exe] C:\WINDOWS\system32\syslg32.exe
O4 - HKLM\..\RunOnce: [mfcpq32.exe] C:\WINDOWS\system32\mfcpq32.exe
O4 - HKLM\..\RunOnce: [sdktc.exe] C:\WINDOWS\system32\sdktc.exe
O4 - HKLM\..\RunOnce: [sdknv32.exe] C:\WINDOWS\system32\sdknv32.exe
O4 - HKLM\..\RunOnce: [mfcsr32.exe] C:\WINDOWS\system32\mfcsr32.exe
O4 - HKLM\..\RunOnce: [javavd.exe] C:\WINDOWS\system32\javavd.exe
O4 - HKLM\..\RunOnce: [iprp32.exe] C:\WINDOWS\iprp32.exe
O4 - HKLM\..\RunOnce: [atlpe.exe] C:\WINDOWS\system32\atlpe.exe
O4 - HKLM\..\RunOnce: [msom32.exe] C:\WINDOWS\system32\msom32.exe
O4 - HKLM\..\RunOnce: [javams.exe] C:\WINDOWS\javams.exe
O4 - HKLM\..\RunOnce: [iech32.exe] C:\WINDOWS\iech32.exe
O4 - HKLM\..\RunOnce: [ntqk32.exe] C:\WINDOWS\system32\ntqk32.exe
O4 - HKLM\..\RunOnce: [msgz.exe] C:\WINDOWS\msgz.exe
O4 - HKLM\..\RunOnce: [addya32.exe] C:\WINDOWS\addya32.exe
O4 - HKLM\..\RunOnce: [netcm.exe] C:\WINDOWS\netcm.exe
O4 - HKLM\..\RunOnce: [netwx32.exe] C:\WINDOWS\system32\netwx32.exe
O4 - HKLM\..\RunOnce: [ipwn32.exe] C:\WINDOWS\system32\ipwn32.exe
O4 - HKLM\..\RunOnce: [javabr.exe] C:\WINDOWS\javabr.exe
O4 - HKLM\..\RunOnce: [sdkks32.exe] C:\WINDOWS\system32\sdkks32.exe
O4 - HKLM\..\RunOnce: [ntyo32.exe] C:\WINDOWS\ntyo32.exe
O4 - HKLM\..\RunOnce: [addtg.exe] C:\WINDOWS\system32\addtg.exe
O4 - HKLM\..\RunOnce: [javagk32.exe] C:\WINDOWS\javagk32.exe
O4 - HKLM\..\RunOnce: [winbw32.exe] C:\WINDOWS\system32\winbw32.exe
O4 - HKLM\..\RunOnce: [atlga.exe] C:\WINDOWS\system32\atlga.exe
O4 - HKLM\..\RunOnce: [apppb32.exe] C:\WINDOWS\system32\apppb32.exe
O4 - HKLM\..\RunOnce: [adddy.exe] C:\WINDOWS\system32\adddy.exe
O4 - HKLM\..\RunOnce: [crxr.exe] C:\WINDOWS\crxr.exe
O4 - HKLM\..\RunOnce: [crrc32.exe] C:\WINDOWS\crrc32.exe
O4 - HKLM\..\RunOnce: [addgz.exe] C:\WINDOWS\system32\addgz.exe
O4 - HKLM\..\RunOnce: [netkj32.exe] C:\WINDOWS\system32\netkj32.exe
O4 - HKLM\..\RunOnce: [atlih.exe] C:\WINDOWS\atlih.exe
O4 - HKLM\..\RunOnce: [addrh.exe] C:\WINDOWS\system32\addrh.exe
O4 - HKLM\..\RunOnce: [iphe32.exe] C:\WINDOWS\iphe32.exe
O4 - HKLM\..\RunOnce: [atlrf32.exe] C:\WINDOWS\atlrf32.exe
O4 - HKLM\..\RunOnce: [syspu32.exe] C:\WINDOWS\system32\syspu32.exe
O4 - HKLM\..\RunOnce: [winpc.exe] C:\WINDOWS\system32\winpc.exe
O4 - HKLM\..\RunOnce: [ieyd.exe] C:\WINDOWS\ieyd.exe
O4 - HKLM\..\RunOnce: [mfcna32.exe] C:\WINDOWS\system32\mfcna32.exe
O4 - HKLM\..\RunOnce: [winxb32.exe] C:\WINDOWS\system32\winxb32.exe
O4 - HKLM\..\RunOnce: [d3wq32.exe] C:\WINDOWS\d3wq32.exe
O4 - HKLM\..\RunOnce: [ipja32.exe] C:\WINDOWS\system32\ipja32.exe
O4 - HKLM\..\RunOnce: [atlzi.exe] C:\WINDOWS\atlzi.exe
O4 - HKLM\..\RunOnce: [ieyx32.exe] C:\WINDOWS\ieyx32.exe
O4 - HKLM\..\RunOnce: [netsz32.exe] C:\WINDOWS\netsz32.exe
O4 - HKLM\..\RunOnce: [appqg32.exe] C:\WINDOWS\system32\appqg32.exe
O4 - HKLM\..\RunOnce: [atlqw.exe] C:\WINDOWS\system32\atlqw.exe
O4 - HKLM\..\RunOnce: [appzx.exe] C:\WINDOWS\system32\appzx.exe
O4 - HKLM\..\RunOnce: [ipom32.exe] C:\WINDOWS\system32\ipom32.exe
O4 - HKLM\..\RunOnce: [atlhv32.exe] C:\WINDOWS\system32\atlhv32.exe
O4 - HKLM\..\RunOnce: [sysxc32.exe] C:\WINDOWS\sysxc32.exe
O4 - HKLM\..\RunOnce: [winfs.exe] C:\WINDOWS\winfs.exe
O4 - HKLM\..\RunOnce: [sysfs.exe] C:\WINDOWS\
  • 0

#5
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
O4 - HKLM\..\RunOnce: [sysfs.exe] C:\WINDOWS\system32\sysfs.exe
O4 - HKLM\..\RunOnce: [apivi32.exe] C:\WINDOWS\apivi32.exe
O4 - HKLM\..\RunOnce: [iejk32.exe] C:\WINDOWS\system32\iejk32.exe
O4 - HKLM\..\RunOnce: [atlyz.exe] C:\WINDOWS\atlyz.exe
O4 - HKLM\..\RunOnce: [ipra32.exe] C:\WINDOWS\ipra32.exe
O4 - HKLM\..\RunOnce: [d3um.exe] C:\WINDOWS\d3um.exe
O4 - HKLM\..\RunOnce: [mson32.exe] C:\WINDOWS\system32\mson32.exe
O4 - HKLM\..\RunOnce: [wints.exe] C:\WINDOWS\wints.exe
O4 - HKLM\..\RunOnce: [syscs32.exe] C:\WINDOWS\system32\syscs32.exe
O4 - HKLM\..\RunOnce: [ieqp32.exe] C:\WINDOWS\ieqp32.exe
O4 - HKLM\..\RunOnce: [iplg.exe] C:\WINDOWS\system32\iplg.exe
O4 - HKLM\..\RunOnce: [sdkql32.exe] C:\WINDOWS\sdkql32.exe
O4 - HKLM\..\RunOnce: [atlje32.exe] C:\WINDOWS\atlje32.exe
O4 - HKLM\..\RunOnce: [mfcju32.exe] C:\WINDOWS\system32\mfcju32.exe
O4 - HKLM\..\RunOnce: [appsu32.exe] C:\WINDOWS\system32\appsu32.exe
O4 - HKLM\..\RunOnce: [ntvg32.exe] C:\WINDOWS\ntvg32.exe
O4 - HKLM\..\RunOnce: [crak.exe] C:\WINDOWS\crak.exe
O4 - HKLM\..\RunOnce: [msre32.exe] C:\WINDOWS\msre32.exe
O4 - HKLM\..\RunOnce: [mfcid.exe] C:\WINDOWS\mfcid.exe
O4 - HKLM\..\RunOnce: [javafa32.exe] C:\WINDOWS\system32\javafa32.exe
O4 - HKLM\..\RunOnce: [netqb32.exe] C:\WINDOWS\system32\netqb32.exe
O4 - HKLM\..\RunOnce: [appor.exe] C:\WINDOWS\appor.exe
O4 - HKLM\..\RunOnce: [msng32.exe] C:\WINDOWS\msng32.exe
O4 - HKLM\..\RunOnce: [winyf.exe] C:\WINDOWS\winyf.exe
O4 - HKLM\..\RunOnce: [applk.exe] C:\WINDOWS\applk.exe
O4 - HKLM\..\RunOnce: [atlzo.exe] C:\WINDOWS\atlzo.exe
O4 - HKLM\..\RunOnce: [atlta32.exe] C:\WINDOWS\atlta32.exe
O4 - HKLM\..\RunOnce: [sysgk.exe] C:\WINDOWS\sysgk.exe
O4 - HKLM\..\RunOnce: [addxs.exe] C:\WINDOWS\system32\addxs.exe
O4 - HKLM\..\RunOnce: [apiqs32.exe] C:\WINDOWS\apiqs32.exe
O4 - HKLM\..\RunOnce: [winuf32.exe] C:\WINDOWS\system32\winuf32.exe
O4 - HKLM\..\RunOnce: [atllm.exe] C:\WINDOWS\system32\atllm.exe
O4 - HKLM\..\RunOnce: [apiyr.exe] C:\WINDOWS\system32\apiyr.exe
O4 - HKLM\..\RunOnce: [apisk32.exe] C:\WINDOWS\apisk32.exe
O4 - HKLM\..\RunOnce: [netas32.exe] C:\WINDOWS\netas32.exe
O4 - HKLM\..\RunOnce: [sdkfw.exe] C:\WINDOWS\system32\sdkfw.exe
O4 - HKLM\..\RunOnce: [ntgx32.exe] C:\WINDOWS\ntgx32.exe
O4 - HKLM\..\RunOnce: [ipuu32.exe] C:\WINDOWS\system32\ipuu32.exe
O4 - HKLM\..\RunOnce: [winxl.exe] C:\WINDOWS\winxl.exe
O4 - HKLM\..\RunOnce: [d3vq32.exe] C:\WINDOWS\d3vq32.exe
O4 - HKLM\..\RunOnce: [apper32.exe] C:\WINDOWS\system32\apper32.exe
O4 - HKLM\..\RunOnce: [javaez32.exe] C:\WINDOWS\javaez32.exe
O4 - HKLM\..\RunOnce: [addzl32.exe] C:\WINDOWS\system32\addzl32.exe
O4 - HKLM\..\RunOnce: [mfcmp.exe] C:\WINDOWS\system32\mfcmp.exe
O4 - HKLM\..\RunOnce: [appnp32.exe] C:\WINDOWS\system32\appnp32.exe
O4 - HKLM\..\RunOnce: [appbm.exe] C:\WINDOWS\system32\appbm.exe
O4 - HKLM\..\RunOnce: [d3vf.exe] C:\WINDOWS\d3vf.exe
O4 - HKLM\..\RunOnce: [d3pz32.exe] C:\WINDOWS\d3pz32.exe
O4 - HKLM\..\RunOnce: [sdkzx.exe] C:\WINDOWS\system32\sdkzx.exe
O4 - HKLM\..\RunOnce: [addnc32.exe] C:\WINDOWS\system32\addnc32.exe
O4 - HKLM\..\RunOnce: [d3ao32.exe] C:\WINDOWS\system32\d3ao32.exe
O4 - HKLM\..\RunOnce: [addwa.exe] C:\WINDOWS\addwa.exe
O4 - HKLM\..\RunOnce: [appym32.exe] C:\WINDOWS\system32\appym32.exe
O4 - HKLM\..\RunOnce: [appyc32.exe] C:\WINDOWS\system32\appyc32.exe
O4 - HKLM\..\RunOnce: [apicg.exe] C:\WINDOWS\apicg.exe
O4 - HKLM\..\RunOnce: [mfclg32.exe] C:\WINDOWS\system32\mfclg32.exe
O4 - HKLM\..\RunOnce: [atlsd32.exe] C:\WINDOWS\atlsd32.exe
O4 - HKLM\..\RunOnce: [d3uv.exe] C:\WINDOWS\system32\d3uv.exe
O4 - HKLM\..\RunOnce: [syszz32.exe] C:\WINDOWS\syszz32.exe
O4 - HKLM\..\RunOnce: [sdkss32.exe] C:\WINDOWS\system32\sdkss32.exe
O4 - HKLM\..\RunOnce: [javasi.exe] C:\WINDOWS\system32\javasi.exe
O4 - HKLM\..\RunOnce: [ntbi.exe] C:\WINDOWS\ntbi.exe
O4 - HKLM\..\RunOnce: [ieqx32.exe] C:\WINDOWS\system32\ieqx32.exe
O4 - HKLM\..\RunOnce: [javajy32.exe] C:\WINDOWS\javajy32.exe
O4 - HKLM\..\RunOnce: [netzo32.exe] C:\WINDOWS\system32\netzo32.exe
O4 - HKLM\..\RunOnce: [iphe.exe] C:\WINDOWS\iphe.exe
O4 - HKLM\..\RunOnce: [apihe.exe] C:\WINDOWS\system32\apihe.exe
O4 - HKLM\..\RunOnce: [crxt32.exe] C:\WINDOWS\crxt32.exe
O4 - HKLM\..\RunOnce: [mfclw32.exe] C:\WINDOWS\mfclw32.exe
O4 - HKLM\..\RunOnce: [javaal.exe] C:\WINDOWS\system32\javaal.exe
O4 - HKLM\..\RunOnce: [mstm32.exe] C:\WINDOWS\mstm32.exe
O4 - HKLM\..\RunOnce: [ipef.exe] C:\WINDOWS\ipef.exe
O4 - HKLM\..\RunOnce: [ienn.exe] C:\WINDOWS\ienn.exe
O4 - HKLM\..\RunOnce: [atlwg.exe] C:\WINDOWS\atlwg.exe
O4 - HKLM\..\RunOnce: [winas.exe] C:\WINDOWS\winas.exe
O4 - HKLM\..\RunOnce: [ntpp32.exe] C:\WINDOWS\ntpp32.exe
O4 - HKLM\..\RunOnce: [mssb.exe] C:\WINDOWS\mssb.exe
O4 - HKLM\..\RunOnce: [apihd.exe] C:\WINDOWS\apihd.exe

Now Make sure ALL WINDOWS and BROWSERS are CLOSED and hit the Fix Checked Button!!


Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK!

Under the "General" Tab
Make Sure Normal Startup is Checked!!

Click Apply>>Close>>Follow the Prompts to Restart!!

Restart Normal and have the PC Scanned here:
Panda Active Scan

You will need to be using Internet Explorer for the Scan to work!

Save the Report it generates


Post back with a fresh HijackThis log and the reports from Ewido and Panda!
  • 0

#6
PattyBaitmen

PattyBaitmen

    New Member

  • Topic Starter
  • Member
  • Pip
  • 3 posts
Hey Thanks alot man, Your a life saver. At the very least I have IE back. There are one or two entries in my latest Hijack This log that concern me however. I have the marked with an * below. Tell me what you think of them. I also forgot to get a log from panda but it said my box was clean. Thanks again for your help. You are too kind

New Hijack This log

Logfile of HijackThis v1.99.1
Scan saved at 6:11:05 PM, on 7/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wwSecure.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\Hijack\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
*O2 - BHO: Class - {8C7413DD-6325-E43D-BD47-63DEDEF0FC7C} - C:\WINDOWS\system32\iehj.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
*O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
*O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Washer Security Access (wwSecSvc) - Webroot Software, Inc. - C:\WINDOWS\system32\wwSecure.exe

Here is My Ewido Log


---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:51:18 PM, 7/3/2005
+ Report-Checksum: FC994C53

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{1D232F9D-941D-5CD9-732F-8F6EC1977CF2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2A97DB56-E2B4-967C-AF9F-07FDF74289C2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{38EA95B6-06DF-844E-6763-813A152D6F74} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{43372D0D-6EAD-977A-99EE-8DFB043153ED} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5F1C7FC6-359E-6D58-42B3-3E410DB4CADB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6A389597-708B-6F9D-B6EC-8D1A3EC9DFAF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6D793FE9-8675-897B-589B-5BCAB9D3CFEF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{763FC5CF-92D8-A8BE-597E-1C53C8D18D56} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7658C68E-7ED4-8476-AC96-729091012307} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7868EC16-8C67-1DBD-6D5A-EBB325881BD9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7E2B347A-52AA-597F-9371-80822A8D1263} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{83F01EC6-1966-280C-39C0-52CF1BB626F6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{85F1C7FC-7359-D6D5-C42B-F3E410DB4CAD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8A71C47B-9917-B588-625B-79254D40A325} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{90DEE38B-0DB3-A3CA-6F69-126542AD0FA1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{96EEA21B-4AA3-4627-EA0A-176241DBD1A4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A01394EE-8B14-B1D4-AE65-22E7424A71D0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B33C5B98-F4B9-B550-C81A-4EE9720874BF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B6233EB3-872F-7898-F4A8-3F6A3BAA6D57} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BD00AB82-F105-58F8-2B31-B600383177E6} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BD757058-7180-2CE5-E5B6-8C70AEF236CC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BE5DCDBC-54D3-95EA-B258-2D53BD817431} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C2E5E32B-0FD0-16A5-10FE-EDA2D4478683} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D46A242B-6194-E7D0-7207-4CC5FFB11ADE} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E4FD490D-A46F-95DB-EFF2-CF0215363020} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1B10CDC-1975-EC0C-C522-2571525E92CF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D46A242B-6194-E7D0-7207-4CC5FFB11ADE} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E4FD490D-A46F-95DB-EFF2-CF0215363020} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-299502267-688789844-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-299502267-688789844-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83F01EC6-1966-280C-39C0-52CF1BB626F6} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-299502267-688789844-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D46A242B-6194-E7D0-7207-4CC5FFB11ADE} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-299502267-688789844-725345543-500\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E4FD490D-A46F-95DB-EFF2-CF0215363020} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Programming\cracksearcher.exe -> Not-A-Virus.HackTool.CrackSearch.a : Cleaned with backup
C:\WINDOWS\addax32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addbb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addda32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addlp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addzq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apids.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apizn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appco32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appho.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appjp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appry32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appty32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appup32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appwj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlbl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlzm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:csghqi -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:muiko -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:nnmnh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:oiaat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:peiim -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:vrwlw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Blue Lace 16.bmp:wiekd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bootstat.dat:hcbuo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bootstat.dat:mzxyf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bootstat.dat:wbvuy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bootstat.dat:yrclg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bootstat.dat:yyxpv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\chipset.log:dwdsw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\chipset.log:hihxu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\chipset.log:plmnv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\chipset.log:viqhmr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\clock.avi:agywo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\clock.avi:qhqhe -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\clock.avi:rmgwa -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\cmsetacl.log:kvckz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\cmsetacl.log:ssugi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\cmsetacl.log:ydesz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\cmsetacl.log:ytzqa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Coffee Bean.bmp:uuhxp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\comsetup.log:cdpmh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\comsetup.log:vruid -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\comsetup.log:xvmvk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(2).ini:crzkr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(2).ini:gthvs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(2).ini:pqssu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(2).ini:rjdlp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(2).ini:wcddd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control(3).ini:hvyeu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(3).ini:jtned -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(3).ini:pqssu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(3).ini:vylxb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(4).ini:cgkox -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(4).ini:jfqov -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control(4).ini:pqssu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control(4).ini:vabyc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control(4).ini:woxow -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:bjtra -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control.ini:duyye -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control.ini:pqssu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crfw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\croj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crrl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crrp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crwf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3dq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ez.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3io32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3kb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3nw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3qj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3tj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3tn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\desktop.ini:fyhry -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\desktop.ini:rfbpn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\DHCPUPG.LOG:xsfbz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DHCPUPG.LOG:zgpwz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\dmtlq.txt:hdovz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DtcInstall.log:liboc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exlink.ini:bxkmp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exlink.ini:vpfvv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\explorer.scf:gueqy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\explorer.scf:hpahs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\explorer.scf:tkovd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\explorer.scf:vlbmc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\FaxSetup.log:bdfvr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:cgeik -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:cispw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:ngsvj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\FeatherTexture.bmp:qstjv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:eanqb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:hepkkh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:kvlti -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Gone Fishing.bmp:qlads -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Greenstone.bmp:vutpx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iecv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iedk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieha32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieix32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iejr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iejr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieke.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieub.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iis6.log:gmgtkr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iis6.log:pczyc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipcj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipii32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipmf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipnv.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipoc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iptc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\jautoexp.dat:emros -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\jautoexp.dat:gmexy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javade.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javads.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javafw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javagg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javahh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javaqq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javarj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javate32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javawk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javayt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\KB873339.log:bigqo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB873339.log:ddcmf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB873339.log:yzvff -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB873339.log:znryfc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\KB885250.log:adkry -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB885250.log:gnwim -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB885250.log:hbrbx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB885250.log:rarso -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB885250.log:uwwme -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB885250.log:xbitz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB886185.log:lqfuv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB886185.log:qmhmy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB886185.log:xtpks -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB887742.log:ebkrp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB887742.log:jlokv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB888113.log:icllv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB888113.log:mkjbk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB888302.log:qofib -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB890046.log:sgqpr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB890859.log:mbasd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB891781.log:bnkwv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB891781.log:wrinr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB893066.log:qvzts -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB893066.log:umzcs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB893086.log:pcnkl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB894391.log:wrazw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB894391.log:wudlz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB894391.log:zbczt -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB896422.log:oqcdj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB896727.log:hqyzi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB898461.log:aiwxi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB898461.log:jhpfx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB898461.log:lfmlx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899587.log:csxer -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899587.log:gsdrs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB899587.log:kvnsp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB899587.log:mbajo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899587.log:mbjvg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899588.log:hrjur -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899588.log:nkycj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB899588.log:trgty -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\KB899588.log:zrnwf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\KB899591.log:hogjg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\kobkt.dat:fxbkp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\kobkt.dat:ssbke -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\kobkt.dat:wzydt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:lsdqx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:qsiha -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:ujaqu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:veqtw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:vkqdr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\MedCtrOC.log:xcmgc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcbt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcdk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcey32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mfcey32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mfcms32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcno.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcnx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcpd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcph.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqh.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcrd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mfcvr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfczz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mozver.dat:nuapn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mozver.dat:stmng -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mozver.dat:xcdul -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msaa.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msaj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:yjbjg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msgc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgsocm.log:awshz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msgsocm.log:mgwfi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mslm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msmqinst.log:bifzf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msmqinst.log:hhjux -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msmx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mssl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msua.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msza32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nero.INI:iymdm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netbd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\neteh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netfxocm.log:dmkch -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netfxocm.log:ojugi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netfxocm.log:ssclv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netfxocm.log:uacga -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netfxocm.log:ygtmt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netgq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netme.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\neton32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netzg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nqevq.log:gmtno -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nqevq.log:tfrkw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nqevq.log:wugju -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nsreg.dat:bwcqy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\nsreg.dat:jleuc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nsreg.dat:pwyzm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntbc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:jbuem -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:lyvrn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:vccyr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:whzye -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntdtcsetup.log:dcbpy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntdtcsetup.log:murwy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntga.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntpj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntrt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nttg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nttp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntwi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\NuNinst.cfg:bdbsl -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\NuNinst.cfg:jkmav -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\NuNinst.cfg:mjjsc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nxqji.dat:fbnyw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nxqji.dat:gkcjd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\n_ldigeg.log -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ocgen.log:exfbu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ocmsn.log:gvfrn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBC.INI:ctqud -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBC.INI:tcfwj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBC.INI:wvuhu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:tczbi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:tqpyp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:zkfqe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:anzay -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:axbsj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:gfkap -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:mmxts -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:oweam -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:usmsw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pibsz.txt:cjnvj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pibsz.txt:ujhtz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:ektql -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:jofel -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Prairie Wind.bmp:zpvoh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pss\system.ini.backup:vzayg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\pss\win.ini.backup:ljivu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS(2).OLD:fxxqb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\REGLOCS(2).OLD:hffxv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS(2).OLD:kambr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS(3).OLD:lmsdtb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS(3).OLD:yxvsv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\REGLOCS.OLD:lmsdtb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\REGLOCS.OLD:nvtnz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\regopt.log:igybf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\regopt.log:lucuy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Rhododendron.bmp:jllxl -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Rhododendron.bmp:nkqff -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Rhododendron.bmp:slrvf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\River Sumida.bmp:fhjpj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\rrlhz.log:kqyyd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\rrlhz.log:uqqoi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Santa Fe Stucco.bmp:oyvov -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Santa Fe Stucco.bmp:vbyln -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkcg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkec32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkiu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdklo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkot32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkph.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkrz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sessmgr.setup.log:cqiwwx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sessmgr.setup.log:etssh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sessmgr.setup.log:hhpemh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sessmgr.setup.log:vfvop -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sessmgr.setup.log:vvfnv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupact.log:cmugc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupact.log:dirzg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setupact.log:iyxdw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setupact.log:qjmif -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupact.log:tqhpo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setupapi.log:nsnee -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setupapi.log:ufohh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\setuperr.log:gzoir -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\setuplog.txt:ikfni -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\siebc.log:zayzs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:crukj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:ersil -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:hznmfs -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:pvvkd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\Sti_Trace.log:taavt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\svcpack.log:exmqy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\syscs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysja32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syskj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syslw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysoo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sysoo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32:hjaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addcv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addeg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addgc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addip.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addkg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\addkg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addml.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiat32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiem32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apilj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apity.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiuf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\appco32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\appcp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appki32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\applw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appny32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atldl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atldw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlgy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crci.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crdt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\cret32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crij.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crkb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crma.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crsm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cryd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3fq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ke.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3rr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iedl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieed32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieft32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iemi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iemn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iemx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ievd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iexa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieyk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipch.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipdh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipls.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\iprn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsa.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ipwo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javabc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javagz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javale32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javamc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javamh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javask.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javasn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaul32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javauo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaxs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javazu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfckl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcpx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcsl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcva32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msar.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mscw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msed32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mset.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msin.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msjj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msmp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msvj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mswi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mswn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netaq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\neten32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netin.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netio.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nettc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntnl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntnm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntsq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkid32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkjl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkko32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdklr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdknq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkns.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkpj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkuj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkwx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysam.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syshz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysym32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysyq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winaq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wincn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winco.exe -> Trojan.Agent.bi : Cleaned with backup
C:&#
  • 0

#7
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Wow,I havent seen a CWS Infection that thick in a long time!

If you dont mind,I wanna play it extra Safe!

Disable System Restore
http://service1.syma...src=sec_doc_nam

Get Ewido Updated!

Download WinPFind:
http://www.bleepingc...es/winpfind.php

Right Click the Zip Folder and Select "Extract All"

Don't use it yet!

Restart in Safe Mode

Scan the System again with Ewido,just as you did before,Save a report please!

From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan"

It will scan the entire System, so please be patient!

One you see "Scan Complete"-> a log (WinPFind.txt) will be automatically generated in the WinPFind folder!

Restart Normal and Have the PC Scanned here
http://support.f-sec.../home/ols.shtml

Save the Report if one is generated!

Post back with the reports from WinPFind-> Ewido and F-Secure!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP