Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

hijack by abcsearch4u [RESOLVED]


  • This topic is locked This topic is locked

#1
kelvindou

kelvindou

    Member

  • Member
  • PipPip
  • 41 posts
here is the log, please help......


Logfile of HijackThis v1.99.1
Scan saved at AM 01:46:31, on 2005/9/30
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINPENJR\WIN32\PPHIDPAD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\TOOLS\NCLTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\AJVOEOJ.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [lrujmdv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [ldtgceb] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [wbdiukj] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [fthxsym] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [rmijync] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [neinrqv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [hqkpsuu] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [qlhlckn] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [qjjfdde] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [jdrfysd] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [axprjtm] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [lwxneko] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [vjtxthi] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [dbdpoxp] c:\windows\yxyrjwd.exe
O4 - HKCU\..\Run: [ilapdmt] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [pwbahlu] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [yviaeoe] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [rvohtcc] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [kphnsap] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [stagymd] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vexncpb] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cxmhqby] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [tqvaqct] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nyeuupu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jolseyt] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kqbmkpx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ufaortc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jwvwfcy] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kfushsa] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jlurqyj] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jtipcjv] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [wuivlvx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vxtpkqi] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [gowpjto] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [xmcwnhm] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [yeaggsu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vvvqenc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ysxqqdr] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [anfmmcp] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [fgerctk] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [hpchioc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ehbmbyl] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kcegsww] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kwfkvgf] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [epdncks] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cprvdci] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [xsxptfw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [wcgyyci] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [bdbuolx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [qaqbalg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nlxfhmg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cxgwcuj] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nkjrixw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [acdvlhu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [byapndi] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vuyokwm] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [qexkrdg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cwjasiw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [sdpalfs] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [knxtlhj] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [cvhwhlr] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dcurbmx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [fsbqtsa] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nvugqwe] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [vhlprtm] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [sckehyo] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [clwtgbr] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [hhmgxvn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ctsaitc] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [tnfaboy] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ejgvcij] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rdghnel] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qyvejxx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dqsolns] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [efytlub] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qdrfycf] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [mirsqis] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [gtvmgli] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [chnnyyy] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [hsoenji] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dygydxp] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rkpkcjv] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [vxwxftt] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rcxymhn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [bdocnsw] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [locqufa] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [lmpexug] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ynvctyn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [gfpfmyd] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nupvfqb] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qsoptol] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ylkbioc] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nxfydjb] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [eoksfnt] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [erdopml] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [outillx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [bqdcoei] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nepslbj] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [elhcpin] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [gsvajxe] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [qdybuao] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [motptvy] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [axffdpd] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [rmrhiux] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [ipugivp] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [uoaaous] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [kbmjism] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [jpsasqg] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [gfumndu] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [ugktvmj] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [jqkntmt] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [umtmeru] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [yvyhrdj] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [oqesmwv] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [offaxid] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [woskhgo] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [fahjayb] c:\windows\pybqgqe.exe
O4 - HKCU\..\Run: [lpvwqby] c:\windows\pybqgqe.exe
O4 - HKCU\..\Run: [necybof] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xwmmuci] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lxtwlwd] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yhxjdul] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [falfjig] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mpumhrf] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ifoaewh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mtliggu] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ndrimbh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ydaupej] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yetvcjj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [apiwmkm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dwcjkqs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fvgngnn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [evtgcdo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [avtwooj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ykpmuhh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [iwqxjcr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [kexqbtk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xsieyny] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uoprbqa] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gesbfxx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [extmpbr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [twngpvl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rncjaae] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cpxnquk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ihrchvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jpbwewn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gpkceme] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [pkvcnpj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qqxegop] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [aypclgk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [frggihp] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [pbbldja] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fbstneo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [saukcss] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [wgswvrb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [msxuplj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uhxrmll] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tbfwqol] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mpbcgma] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oiuslvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oafjhdk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cpcritx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [setxnay] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mrupugs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [advkkgl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uwnthdr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [aokbpig] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vutpfkt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yurlvbk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ltjnbmm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ftpkuoy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jccdpbq] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oreqwjx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qcypawe] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tlbxiwy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [piypdiw] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yddngwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [kukjuup] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jxgdpws] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fcyejwt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tjupqcm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qdcxwis] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [hrqwunk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ivfjwyu] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ftudgpy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lubkuij] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tfmeero] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [heftpvb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xuaocjt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vfoyqof] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ojtooxk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rvvsgsw] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gomqmwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [urikpcs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jpdewcl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [feictey] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mrkrlfn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cmfsjfg] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fcvbleo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rcytvcb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qnfmghn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [keiylup] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uutflpx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vgkphcf] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [sqdbrft] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [auyvsmk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fafxnna] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [nngumpm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dqmaqfv] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [axjjyus] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dcytxxh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [iwfwsba] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dpmsmam] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yxwryhe] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fxddetn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tqygwyv] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [hbfnovp] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lefurdo] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [hxkatpm] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [mswbfvo] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [sfddokl] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [yguurbe] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [lydvuui] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [bwdkvnv] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [ltmyrbc] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [krscxtc] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [ioqjime] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [xdofaks] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [vjbtefr] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [utsgpau] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [lcukxdw] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [faldqnk] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [kvcmagd] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [lqgkpwn] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [fthjudk] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [otaauik] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [asxvlrb] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [irmfuiq] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [kimyjik] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [cotxvqj] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [yhlvypp] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [obvngrp] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [tvrxibc] c:\windows\kgjafnw.exe
O4 - HKCU\..\Run: [vxtbpko] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [yyouxeu] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [twblros] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [erobjky] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [kwjyuul] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [mebqqqd] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [fjyoqmb] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [sxgfldm] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [fabrpvd] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [qlsmeio] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [tbgrxhl] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [jjssqlu] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [heukvyi] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [qhegvbh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [icsddfy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [hgawnsa] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [dmygjnu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [upigjlo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [qylvywv] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [aguwklh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ienwpxh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wmocnoo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ghuvewu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [oagsarx] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [yuihass] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [uaupybw] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [fgtftij] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ytvxcqc] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [umtnpdg] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wnfjdcj] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [mejribo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [rqpyuoy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wqfauuq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [xfjxkhq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [qagxxhk] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [nqggthe] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [decmywt] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [pkfqnqb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [yhdyiur] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [igvsebb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [beglxlb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [vooriqo] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [lilooco] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [rwscbkm] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ijwgbgu] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [eacnshb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [jrihqas] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nyickje] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [gbfcbqt] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [xrnxgbg] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nvgtevi] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nnulsan] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [wkjtgtb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [brxpkub] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [lxrkucn] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ngdqgqf] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ahndulo] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [eewwmou] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [jrmsofb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [dvjoaxf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ectsgjd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [yxhsmnr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hpmsgds] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lsegxuw] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [drwffrc] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [mmactuv] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gcyrdsd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hfolosw] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [pgkygym] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [uedtjld] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [fbrgbuq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [untangb] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [evtmsjn] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [tainfce] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lvauaov] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [vxsylqx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gqfnwvq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [vgfmtkh] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qhrjqtt] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [porrejr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gkhapou] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ysbgaqx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wboxghi] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [cgrhivf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lgfngvd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [prybmjc] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qoyqqwp] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [luvprfq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [xhjhvne] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qklcycr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [opxwfuo] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [kewjsww] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [nkrlwam] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hbvosde] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qbvosqf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [atpouiy] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [svfggpa] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [bbsaebs] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wlxhlud] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [mkfmbsl] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ryhcdoj] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qdiibny] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [nwlmvha] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [guvberx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [bxhaclp] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [aucceae] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [rmjpqna] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wkbspwn] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [agvnwai] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [rpqrkii] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ovoykia] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fiheuhk] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ttfsxqx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gmidtfq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [beesngh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nfjjntb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [hcngucj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cwjagwh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [niuknss] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [euiidcf] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ncjcaqt] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pjyyavy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [iodvmaj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ulvdpop] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bdhgrlo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [afepjqn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [uqvqhom] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [tcuqsbv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [djqbtmv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dglmywh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lrykrue] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ecryvrp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lstjwso] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lmgnmrn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [srkwaus] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [rucmynj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fhrtmpc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ctcwojy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ajgcjyy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mfacmgq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [afiwnpq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [qljkakd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [otipmsv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [irmjluo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [rjaiqeu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [beosmts] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mxrsncv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fvwseee] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nyybxht] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [uktllui] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [opwpgqi] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ruitiby] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [xgrnwex] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pkeihym] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [hblosxb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ljifvmi] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [jgmvmwg] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [knhmchm] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [tmldlgp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lhyianx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pltaydu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lfrmoil] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [qxugelu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [winxacd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fjocuaa] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bnfucqd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dauovje] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [yptsjjn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vjyjrkj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [oxmppqc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [thlorti] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [xmnkkug] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cknmncn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lxijnfe] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mhxtxym] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cgctppo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fntveab] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [asirsgc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pddvvjv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ptndgne] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kqmnngr] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lxaslrq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pabwshb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mdiiljs] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ogjqnpu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vhngdvl] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ebcotsq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [njrvdye] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dcinvix] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bjaypha] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ccrjyul] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [iexgvqj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fvwtbrc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [neamvom] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gbrqera] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bpdeyxg] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kuspnuh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lwuswsw] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mbqyydd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mqhpgip] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [upbaghx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mobbvcq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [opohoff] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bcbydae] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vvctwxf] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vueivbd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [euywtbs] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nywlljj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kulyris] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gkqgxmu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [spraylp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dnqclwn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fibqnxw] c:\windows\fkynecs.exe
O4 - HKCU\..\Run: [lglereq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [cdarnab] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ryfwufd] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [gbxbmfh] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [fpobqym] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mapfdpy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [gllfrwi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [xptjwjk] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ismylyf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mcxmbdk] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mswvaha] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [nwmrpeg] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [vhyetvy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [jaqlabt] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ipgjjug] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [winpbhf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [wissrbv] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [amgyusr] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [scifmyq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [swbftxa] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [oymvwoe] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ofmvnai] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [txjdyaw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [quxcjre] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [xxtbklc] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mgrecxw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [grlfhvf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [abntmhi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yndisqy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mxfinly] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yyydviq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [vgxsscw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [kbriopr] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [noajsbc] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [kldhsls] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yennoxi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [uqmnwak] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [uhxxlrk] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [jheocjg] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [fjvhjdp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [vgikxsk] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ucnriao] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [dvyyjev] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [danjwui] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ccwmhxm] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [wugxlvt] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [akjmryh] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ufxkvfp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [tegjjbp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [nkaqnif] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [segsjcv] c:\windows\ahuohjr.exe
O4 - HKCU\..\Run: [jwjfrun] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [bxqdbva] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [eihjymo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [dgvqolw] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jelwhjo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [ikyrvag] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [cchvnph] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [vlsywvo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [xofcbry] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [apbgjnx] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [urmxhkm] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [vjudlsp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [clpknwp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [mwycgrj] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [hcdsnyb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [rmcbylb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jaliqux] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [krbyldc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [qwmpigy] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [opmvnpf] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jwsrprc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [pfmglkd] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [lvfdmdt] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jrjuoih] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [evhvtup] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [wcmhyrq] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [iwxonsa] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [assnudw] c:\windows\qfarcaj.exe
O4 - HKCU\..\Run: [gqvthyy] c:\windows\cyfodva.exe
O4 - HKCU\..\Run: [cdlgtnk] c:\windows\lxtwehg.exe
O4 - HKCU\..\Run: [eqvlihk] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [ndkjoux] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [afdkmes] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [akernqe] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [hrwriku] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [sfsysfb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [gsyhbel] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [swycdgb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [rhqrelx] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [xrxvwsn] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [klrdrim] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [njbuusw] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [cqvchdc] c:\windows\yslnhau.exe
O4 - HKCU\..\Run: [lhyfoxu] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [vqjeuhs] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pexhlxq] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pfrfxye] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [waamrnh] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [fdjbfeb] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [gnajiyi] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [wfcyblh] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [sdssdvq] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pgwhxxu] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [qwllyqw] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [qvjscwy] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [gogygvb] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [erxkoyo] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [eeudcdy] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [ufytutl] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [iordvja] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [ftutjfi] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [mwsslll] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [ahxdkfh] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [pbilvsk] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [qsxyegj] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [kpjjnvb] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hbfvher] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hfcevsc] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hpjjjti] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [huvrbxp] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [tfpveot] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [jtlqlfk] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [vhxjxhh] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [jncntlx] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [vrliyfh] c:\windows\okpkgpl.exe
O4 - HKCU\..\Run: [ykcaopp] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [itrpgel] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [iqpfilo] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [jxsvbyx] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [pcvgfus] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [gvrhxal] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [vtqxgjn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [sjglldm] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [quasbas] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [knpiwjb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [hlgvxia] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nbertrn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [avrdnnw] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [acdraig] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lipjtok] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [rtsxbrf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [wkrlccr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cohnksf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [ujmlskr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [yidrkjd] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [yuwqlud] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [feunuhf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lxubypd] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [jixcudp] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [studluo] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [umswxvr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [sarykrn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [llwovpu] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cwomfku] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [swixlsl] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kmijdyv] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [tramxdm] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [rnwwwnx] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lmavxxi] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kexnwwl] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [mkkytpc] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [khafwqf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [tjigqfg] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [acqpjct] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [pngjayq] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [uyogkcb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cywawjg] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [iqqfwpn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nwtfjfn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nunvveb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [wafwgif] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [vuseodi] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kfcrinr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [hbrfsks] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [vmhxjft] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [djwlvjs] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [eofvcun] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [oopsglx] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [tlmfoud] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [taexkkb] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [tlmpdhw] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [hiwrojy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [wisjfhn] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [lfewojd] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [jmstlku] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [mkddjws] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [pwjsciy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [noamgwt] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [ifpxqmu] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [faexihe] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [pqayfjc] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [fdpcvme] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vriiync] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [xaxnnqq] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dnbdkri] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [ajddcvn] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [gpaucjh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [jqruuve] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [aogmxlb] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [qulqxwe] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vgsebmg] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [latepdr] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [sngugcv] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [axpfkeh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dwhdbqf] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [hatsewp] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dscldiy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [bpdgrse] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [kqptooh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [atambfg] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [onoplqu] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vyogart] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [auagmnm] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [dcdllls] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [yixyctm] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [hfdsvik] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [nwiqevu] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [gshrjjh] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [mdblucu] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [lcdvebt] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [lfraurg] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [jwbjgyh] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [kjolyoq] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [yifdlyb] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [rqqwapb] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [apjatpv] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [viyayhr] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [ouulkye] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [tdndkrp] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [oyfjhle] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [rylrogx] c:\windows\ojgphmu.exe
O4 - HKCU\..\Run: [wspjhco] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [jodyigt] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [kqubgny] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [dwihcic] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [watwobc] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [gblklqr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [apidcpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [cxyjvrr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [imfsohb] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [gcxscgh] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [yfyohsd] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wmmbhmb] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ouxuwtw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [jmewaqq] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [nadexwa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iegtxnv] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wuqpecm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [frftgls] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [dsxdjna] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ovouuyu] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iugrccm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [teneorg] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wsesjpm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [feqjope] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bgbysxt] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iyterka] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qwqgdad] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ygucxoy] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ngwbrou] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ljxdail] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ucoeenm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [agfxxeo] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ekynrpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ysayppx] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [jbboihi] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [lhymqjc] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [nlbwwyj] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [rahhenk] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [uxpbrqc] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [rwwfknu] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [axvynnr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qnvqybp] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bakemql] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [awtolho] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ytrxbwf] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [urbrtqq] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [klxjbbm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [uvseywh] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qhsrxwv] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [couirbk] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [kxfjspj] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [hcxachl] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ymovqmw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [hreyiqw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [xjkhwcs] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [obsstli] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qbnbpkd] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bstromw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ailrtwu] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [ojfjhos] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [cpxjwxt] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [etonvpx] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [amnpvxv] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [tkaspke] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [mfmblip] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [iianaaw] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [wtpterm] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [tuidepa] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [diqqhps] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [cbmjhya] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [xxoakbv] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [hogiksn] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [sabvuuj] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [mrgekca] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [dtmujby] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [yusjhxv] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [yfcdsqg] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [bdtjrvc] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [xuinkvt] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [pbpuugb] c:\windows\alfccqj.exe
O4 - HKCU\..\Run: [bvxvclb] c:\windows\pjecfhk.exe
O4 - HKCU\..\Run: [cuwurri] c:\windows\njepvgx.exe
O4 - HKCU\..\Run: [gnfyqcm] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [nymhnej] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [dnffmke] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [ydlrppq] c:\windows\xlqqlxf.exe
O4 - HKCU\..\Run: [suqmgcn] c:\windows\xlqqlxf.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [ssxufcv] c:\windows\vpkjpyv.exe
O4 - HKCU\..\Run: [afcsclg] c:\windows\vpkjpyv.exe
O4 - HKCU\..\Run: [lcelbdh] c:\windows\dmcdyrt.exe
O4 - HKCU\..&
  • 0

Advertisements


#2
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Welcome to GTG.

Is the log too big to fit in your post? Please try to get me your whole log again.

Then do this afterwards:

Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

regedit /e c:\1.txt "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run"
regedit /e c:\2.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run"
copy c:\1.txt+c:\2.txt c:\3.txt
del c:\1.txt
del c:\2.txt
notepad c:\3.txt
del c:\3.txt
del delete.bat
exit


Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it to run it. Post the whole log that opened up during this time.
  • 0

#3
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
greyknight17 thanks for your help, i will get the whole log file again.
  • 0

#4
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
i split into 3 parts.

Logfile of HijackThis v1.99.1
Scan saved at PM 11:59:41, on 2005/9/30
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINPENJR\WIN32\PPHIDPAD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\TOOLS\NCLTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\AJVOEOJ.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [lrujmdv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [ldtgceb] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [wbdiukj] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [fthxsym] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [rmijync] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [neinrqv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [hqkpsuu] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [qlhlckn] c:\windows\ajvoeoj.exe
O4 - HKCU\..\Run: [qjjfdde] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [jdrfysd] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [axprjtm] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [lwxneko] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [vjtxthi] c:\windows\fquwaty.exe
O4 - HKCU\..\Run: [dbdpoxp] c:\windows\yxyrjwd.exe
O4 - HKCU\..\Run: [ilapdmt] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [pwbahlu] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [yviaeoe] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [rvohtcc] c:\windows\pghfgcw.exe
O4 - HKCU\..\Run: [kphnsap] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [stagymd] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vexncpb] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cxmhqby] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [tqvaqct] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nyeuupu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jolseyt] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kqbmkpx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ufaortc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jwvwfcy] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kfushsa] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jlurqyj] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [jtipcjv] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [wuivlvx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vxtpkqi] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [gowpjto] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [xmcwnhm] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [yeaggsu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vvvqenc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ysxqqdr] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [anfmmcp] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [fgerctk] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [hpchioc] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [ehbmbyl] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kcegsww] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [kwfkvgf] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [epdncks] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cprvdci] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [xsxptfw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [wcgyyci] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [bdbuolx] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [qaqbalg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nlxfhmg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cxgwcuj] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [nkjrixw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [acdvlhu] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [byapndi] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [vuyokwm] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [qexkrdg] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [cwjasiw] c:\windows\wgqkacq.exe
O4 - HKCU\..\Run: [sdpalfs] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [knxtlhj] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [cvhwhlr] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dcurbmx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [fsbqtsa] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nvugqwe] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [vhlprtm] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [sckehyo] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [clwtgbr] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [hhmgxvn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ctsaitc] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [tnfaboy] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ejgvcij] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rdghnel] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qyvejxx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dqsolns] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [efytlub] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qdrfycf] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [mirsqis] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [gtvmgli] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [chnnyyy] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [hsoenji] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [dygydxp] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rkpkcjv] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [vxwxftt] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [rcxymhn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [bdocnsw] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [locqufa] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [lmpexug] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ynvctyn] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [gfpfmyd] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nupvfqb] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [qsoptol] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [ylkbioc] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nxfydjb] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [eoksfnt] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [erdopml] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [outillx] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [bqdcoei] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [nepslbj] c:\windows\ewaumdk.exe
O4 - HKCU\..\Run: [elhcpin] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [gsvajxe] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [qdybuao] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [motptvy] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [axffdpd] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [rmrhiux] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [ipugivp] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [uoaaous] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [kbmjism] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [jpsasqg] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [gfumndu] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [ugktvmj] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [jqkntmt] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [umtmeru] c:\windows\eemeiow.exe
O4 - HKCU\..\Run: [yvyhrdj] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [oqesmwv] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [offaxid] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [woskhgo] c:\windows\jfwegil.exe
O4 - HKCU\..\Run: [fahjayb] c:\windows\pybqgqe.exe
O4 - HKCU\..\Run: [lpvwqby] c:\windows\pybqgqe.exe
O4 - HKCU\..\Run: [necybof] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xwmmuci] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lxtwlwd] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yhxjdul] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [falfjig] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mpumhrf] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ifoaewh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mtliggu] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ndrimbh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ydaupej] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yetvcjj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [apiwmkm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dwcjkqs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fvgngnn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [evtgcdo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [avtwooj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ykpmuhh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [iwqxjcr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [kexqbtk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xsieyny] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uoprbqa] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gesbfxx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [extmpbr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [twngpvl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rncjaae] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cpxnquk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ihrchvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jpbwewn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gpkceme] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [pkvcnpj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qqxegop] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [aypclgk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [frggihp] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [pbbldja] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fbstneo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [saukcss] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [wgswvrb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [msxuplj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uhxrmll] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tbfwqol] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mpbcgma] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oiuslvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oafjhdk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cpcritx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [setxnay] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mrupugs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [advkkgl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uwnthdr] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [aokbpig] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vutpfkt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yurlvbk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ltjnbmm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ftpkuoy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jccdpbq] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [oreqwjx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qcypawe] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tlbxiwy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [piypdiw] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yddngwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [kukjuup] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jxgdpws] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fcyejwt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tjupqcm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qdcxwis] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [hrqwunk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ivfjwyu] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ftudgpy] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lubkuij] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tfmeero] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [heftpvb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [xuaocjt] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vfoyqof] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [ojtooxk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rvvsgsw] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [gomqmwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [urikpcs] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [jpdewcl] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [feictey] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [mrkrlfn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [cmfsjfg] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fcvbleo] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [rcytvcb] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [qnfmghn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [keiylup] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [uutflpx] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [vgkphcf] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [sqdbrft] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [auyvsmk] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fafxnna] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [nngumpm] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dqmaqfv] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [axjjyus] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dcytxxh] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [iwfwsba] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [dpmsmam] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [yxwryhe] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [fxddetn] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [tqygwyv] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [hbfnovp] c:\windows\uikpxxl.exe
O4 - HKCU\..\Run: [lefurdo] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [hxkatpm] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [mswbfvo] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [sfddokl] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [yguurbe] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [lydvuui] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [bwdkvnv] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [ltmyrbc] c:\windows\mvdqves.exe
O4 - HKCU\..\Run: [krscxtc] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [ioqjime] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [xdofaks] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [vjbtefr] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [utsgpau] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [lcukxdw] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [faldqnk] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [kvcmagd] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [lqgkpwn] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [fthjudk] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [otaauik] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [asxvlrb] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [irmfuiq] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [kimyjik] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [cotxvqj] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [yhlvypp] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [obvngrp] c:\windows\atiyiac.exe
O4 - HKCU\..\Run: [tvrxibc] c:\windows\kgjafnw.exe
O4 - HKCU\..\Run: [vxtbpko] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [yyouxeu] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [twblros] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [erobjky] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [kwjyuul] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [mebqqqd] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [fjyoqmb] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [sxgfldm] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [fabrpvd] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [qlsmeio] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [tbgrxhl] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [jjssqlu] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [heukvyi] c:\windows\grtpciw.exe
O4 - HKCU\..\Run: [qhegvbh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [icsddfy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [hgawnsa] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [dmygjnu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [upigjlo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [qylvywv] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [aguwklh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ienwpxh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wmocnoo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ghuvewu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [oagsarx] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [yuihass] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [uaupybw] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [fgtftij] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [ytvxcqc] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [umtnpdg] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wnfjdcj] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [mejribo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [rqpyuoy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [wqfauuq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [xfjxkhq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [qagxxhk] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [nqggthe] c:\windows\tuqvsyf.exe
O4 - HKCU\..\Run: [decmywt] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [pkfqnqb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [yhdyiur] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [igvsebb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [beglxlb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [vooriqo] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [lilooco] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [rwscbkm] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ijwgbgu] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [eacnshb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [jrihqas] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nyickje] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [gbfcbqt] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [xrnxgbg] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nvgtevi] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [nnulsan] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [wkjtgtb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [brxpkub] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [lxrkucn] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ngdqgqf] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [ahndulo] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [eewwmou] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [jrmsofb] c:\windows\duismvq.exe
O4 - HKCU\..\Run: [dvjoaxf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ectsgjd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [yxhsmnr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hpmsgds] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lsegxuw] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [drwffrc] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [mmactuv] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gcyrdsd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hfolosw] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [pgkygym] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [uedtjld] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [fbrgbuq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [untangb] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [evtmsjn] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [tainfce] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lvauaov] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [vxsylqx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gqfnwvq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [vgfmtkh] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qhrjqtt] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [porrejr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [gkhapou] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ysbgaqx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wboxghi] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [cgrhivf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [lgfngvd] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [prybmjc] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qoyqqwp] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [luvprfq] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [xhjhvne] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qklcycr] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [opxwfuo] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [kewjsww] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [nkrlwam] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [hbvosde] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qbvosqf] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [atpouiy] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [svfggpa] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [bbsaebs] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wlxhlud] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [mkfmbsl] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [ryhcdoj] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [qdiibny] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [nwlmvha] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [guvberx] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [bxhaclp] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [aucceae] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [rmjpqna] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [wkbspwn] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [agvnwai] c:\windows\msyityk.exe
O4 - HKCU\..\Run: [rpqrkii] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ovoykia] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fiheuhk] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ttfsxqx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gmidtfq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [beesngh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nfjjntb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [hcngucj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cwjagwh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [niuknss] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [euiidcf] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ncjcaqt] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pjyyavy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [iodvmaj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ulvdpop] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bdhgrlo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [afepjqn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [uqvqhom] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [tcuqsbv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [djqbtmv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dglmywh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lrykrue] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ecryvrp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lstjwso] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lmgnmrn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [srkwaus] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [rucmynj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fhrtmpc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ctcwojy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ajgcjyy] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mfacmgq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [afiwnpq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [qljkakd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [otipmsv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [irmjluo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [rjaiqeu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [beosmts] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mxrsncv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fvwseee] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nyybxht] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [uktllui] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [opwpgqi] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ruitiby] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [xgrnwex] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pkeihym] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [hblosxb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ljifvmi] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [jgmvmwg] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [knhmchm] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [tmldlgp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lhyianx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pltaydu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lfrmoil] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [qxugelu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [winxacd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fjocuaa] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bnfucqd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dauovje] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [yptsjjn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vjyjrkj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [oxmppqc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [thlorti] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [xmnkkug] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cknmncn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lxijnfe] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mhxtxym] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [cgctppo] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fntveab] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [asirsgc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pddvvjv] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ptndgne] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kqmnngr] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lxaslrq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [pabwshb] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mdiiljs] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ogjqnpu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vhngdvl] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ebcotsq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [njrvdye] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dcinvix] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bjaypha] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [ccrjyul] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [iexgvqj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fvwtbrc] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [neamvom] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gbrqera] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bpdeyxg] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kuspnuh] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [lwuswsw] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mbqyydd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mqhpgip] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [upbaghx] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [mobbvcq] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [opohoff] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [bcbydae] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vvctwxf] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [vueivbd] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [euywtbs] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [nywlljj] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [kulyris] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [gkqgxmu] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [spraylp] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [dnqclwn] c:\windows\pydrhlr.exe
O4 - HKCU\..\Run: [fibqnxw] c:\windows\fkynecs.exe
O4 - HKCU\..\Run: [lglereq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [cdarnab] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ryfwufd] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [gbxbmfh] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [fpobqym] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mapfdpy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [gllfrwi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [xptjwjk] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ismylyf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mcxmbdk] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mswvaha] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [nwmrpeg] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [vhyetvy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [jaqlabt] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ipgjjug] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [winpbhf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [wissrbv] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [amgyusr] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [scifmyq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [swbftxa] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [oymvwoe] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [ofmvnai] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [txjdyaw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [quxcjre] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [xxtbklc] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mgrecxw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [grlfhvf] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [abntmhi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yndisqy] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [mxfinly] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yyydviq] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [vgxsscw] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [kbriopr] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [noajsbc] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [kldhsls] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [yennoxi] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [uqmnwak] c:\windows\rebardy.exe
O4 - HKCU\..\Run: [uhxxlrk] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [jheocjg] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [fjvhjdp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [vgikxsk] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ucnriao] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [dvyyjev] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [danjwui] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ccwmhxm] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [wugxlvt] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [akjmryh] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [ufxkvfp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [tegjjbp] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [nkaqnif] c:\windows\wpsedws.exe
O4 - HKCU\..\Run: [segsjcv] c:\windows\ahuohjr.exe
O4 - HKCU\..\Run: [jwjfrun] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [bxqdbva] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [eihjymo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [dgvqolw] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jelwhjo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [ikyrvag] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [cchvnph] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [vlsywvo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [xofcbry] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [apbgjnx] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [urmxhkm] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [vjudlsp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [clpknwp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [mwycgrj] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [hcdsnyb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [rmcbylb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jaliqux] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [krbyldc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [qwmpigy] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [opmvnpf] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jwsrprc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [pfmglkd] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [lvfdmdt] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [jrjuoih] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [evhvtup] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [wcmhyrq] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [iwxonsa] c:\windows\mlgfnwk.exe
O4 - HKCU\..\Run: [assnudw] c:\windows\qfarcaj.exe
O4 - HKCU\..\Run: [gqvthyy] c:\windows\cyfodva.exe
O4 - HKCU\..\Run: [cdlgtnk] c:\windows\lxtwehg.exe
O4 - HKCU\..\Run: [eqvlihk] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [ndkjoux] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [afdkmes] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [akernqe] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [hrwriku] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [sfsysfb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [gsyhbel] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [swycdgb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [rhqrelx] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [xrxvwsn] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [klrdrim] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [njbuusw] c:\windows\rsdgdpr.exe
O4 - HKCU\..\Run: [cqvchdc] c:\windows\yslnhau.exe
O4 - HKCU\..\Run: [lhyfoxu] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [vqjeuhs] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pexhlxq] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pfrfxye] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [waamrnh] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [fdjbfeb] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [gnajiyi] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [wfcyblh] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [sdssdvq] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [pgwhxxu] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [qwllyqw] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [qvjscwy] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [gogygvb] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [erxkoyo] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [eeudcdy] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [ufytutl] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [iordvja] c:\windows\snvsrer.exe
O4 - HKCU\..\Run: [ftutjfi] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [mwsslll] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [ahxdkfh] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [pbilvsk] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [qsxyegj] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [kpjjnvb] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hbfvher] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hfcevsc] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [hpjjjti] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [huvrbxp] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [tfpveot] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [jtlqlfk] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [vhxjxhh] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [jncntlx] c:\windows\sxtadqi.exe
O4 - HKCU\..\Run: [vrliyfh] c:\windows\okpkgpl.exe
O4 - HKCU\..\Run: [ykcaopp] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [itrpgel] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [iqpfilo] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [jxsvbyx] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [pcvgfus] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [gvrhxal] c:\windows\wefaudv.exe
O4 - HKCU\..\Run: [vtqxgjn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [sjglldm] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [quasbas] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [knpiwjb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [hlgvxia] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nbertrn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [avrdnnw] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [acdraig] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lipjtok] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [rtsxbrf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [wkrlccr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cohnksf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [ujmlskr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [yidrkjd] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [yuwqlud] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [feunuhf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lxubypd] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [jixcudp] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [studluo] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [umswxvr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [sarykrn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [llwovpu] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cwomfku] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [swixlsl] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kmijdyv] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [tramxdm] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [rnwwwnx] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [lmavxxi] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kexnwwl] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [mkkytpc] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [khafwqf] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [tjigqfg] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [acqpjct] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [pngjayq] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [uyogkcb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [cywawjg] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [iqqfwpn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nwtfjfn] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [nunvveb] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [wafwgif] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [vuseodi] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [kfcrinr] c:\windows\vqoukes.exe
O4 - HKCU\..\Run: [hbrfsks] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [vmhxjft] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [djwlvjs] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [eofvcun] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [oopsglx] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [tlmfoud] c:\windows\leaoqpj.exe
O4 - HKCU\..\Run: [taexkkb] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [tlmpdhw] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [hiwrojy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [wisjfhn] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [lfewojd] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [jmstlku] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [mkddjws] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [pwjsciy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [noamgwt] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [ifpxqmu] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [faexihe] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [pqayfjc] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [fdpcvme] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vriiync] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [xaxnnqq] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dnbdkri] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [ajddcvn] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [gpaucjh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [jqruuve] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [aogmxlb] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [qulqxwe] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vgsebmg] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [latepdr] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [sngugcv] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [axpfkeh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dwhdbqf] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [hatsewp] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [dscldiy] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [bpdgrse] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [kqptooh] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [atambfg] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [onoplqu] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [vyogart] c:\windows\hfbbynp.exe
O4 - HKCU\..\Run: [auagmnm] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [dcdllls] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [yixyctm] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [hfdsvik] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [nwiqevu] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [gshrjjh] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [mdblucu] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [lcdvebt] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [lfraurg] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [jwbjgyh] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [kjolyoq] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [yifdlyb] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [rqqwapb] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [apjatpv] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [viyayhr] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [ouulkye] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [tdndkrp] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [oyfjhle] c:\windows\hdmvptv.exe
O4 - HKCU\..\Run: [rylrogx] c:\windows\ojgphmu.exe
O4 - HKCU\..\Run: [wspjhco] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [jodyigt] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [kqubgny] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [dwihcic] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [watwobc] c:\windows\fmyrdoe.exe
O4 - HKCU\..\Run: [gblklqr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [apidcpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [cxyjvrr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [imfsohb] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [gcxscgh] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [yfyohsd] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wmmbhmb] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ouxuwtw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [jmewaqq] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [nadexwa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iegtxnv] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wuqpecm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [frftgls] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [dsxdjna] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ovouuyu] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iugrccm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [teneorg] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [wsesjpm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [feqjope] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bgbysxt] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [iyterka] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qwqgdad] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ygucxoy] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ngwbrou] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ljxdail] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ucoeenm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [agfxxeo] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ekynrpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ysayppx] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [jbboihi] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [lhymqjc] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [nlbwwyj] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [rahhenk] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [uxpbrqc] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [rwwfknu] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [axvynnr] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qnvqybp] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bakemql] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [awtolho] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ytrxbwf] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [urbrtqq] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [klxjbbm] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [uvseywh] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qhsrxwv] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [couirbk] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [kxfjspj] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [hcxachl] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ymovqmw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [hreyiqw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [xjkhwcs] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [obsstli] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [qbnbpkd] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [bstromw] c:\windows\brfmmaa.exe
O4 - HKCU\..\Run: [ailrtwu] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [ojfjhos] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [cpxjwxt] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [etonvpx] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [amnpvxv] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [tkaspke] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [mfmblip] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [iianaaw] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [wtpterm] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [tuidepa] c:\windows\dhfmleg.exe
O4 - HKCU\..\Run: [diqqhps] c:\windows\dhfmleg.exe
  • 0

#5
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
O4 - HKCU\..\Run: [cbmjhya] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [xxoakbv] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [hogiksn] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [sabvuuj] c:\windows\leawymq.exe
O4 - HKCU\..\Run: [mrgekca] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [dtmujby] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [yusjhxv] c:\windows\ufhslmx.exe
O4 - HKCU\..\Run: [yfcdsqg] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [bdtjrvc] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [xuinkvt] c:\windows\duacseq.exe
O4 - HKCU\..\Run: [pbpuugb] c:\windows\alfccqj.exe
O4 - HKCU\..\Run: [bvxvclb] c:\windows\pjecfhk.exe
O4 - HKCU\..\Run: [cuwurri] c:\windows\njepvgx.exe
O4 - HKCU\..\Run: [gnfyqcm] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [nymhnej] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [dnffmke] c:\windows\cwnqbof.exe
O4 - HKCU\..\Run: [ydlrppq] c:\windows\xlqqlxf.exe
O4 - HKCU\..\Run: [suqmgcn] c:\windows\xlqqlxf.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [ssxufcv] c:\windows\vpkjpyv.exe
O4 - HKCU\..\Run: [afcsclg] c:\windows\vpkjpyv.exe
O4 - HKCU\..\Run: [lcelbdh] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [bkobcuv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [pgkoatp] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [sxqwiop] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [gsnquxb] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [riuppiu] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [ihhkatw] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [orkceps] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [oukmoec] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [gdxcraa] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [hgqqbki] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [qsgwcmd] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [mfhxarq] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [efgtkqd] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [vballgj] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [lknktlx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [fhvddqv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [asvsgbk] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [lqdhimx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [cebcekx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [gpmtehf] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [livvxof] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [wewhmwb] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [ienwovg] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [gkuclrv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [grccovg] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [ykjdice] c:\windows\dmcdyrt.exe
O4 - HKCU\..\Run: [nogbajr] c:\windows\pdadlwm.exe
O4 - HKCU\..\Run: [yjwuoht] c:\windows\pdadlwm.exe
O4 - HKCU\..\Run: [jeigyko] c:\windows\pdadlwm.exe
O4 - HKCU\..\Run: [jhnrkgh] c:\windows\pdadlwm.exe
O4 - HKCU\..\Run: [cmyxvpc] c:\windows\pdadlwm.exe
O4 - HKCU\..\Run: [goldput] c:\windows\usigbro.exe
O4 - HKCU\..\Run: [ojibmou] c:\windows\usigbro.exe
O4 - HKCU\..\Run: [amntrfe] c:\windows\usigbro.exe
O4 - HKCU\..\Run: [ydadeks] c:\windows\usigbro.exe
O4 - HKCU\..\Run: [ocqgknp] c:\windows\usigbro.exe
O4 - HKCU\..\Run: [pymgmgf] c:\windows\vsiqcan.exe
O4 - HKCU\..\Run: [fltprbt] c:\windows\vsiqcan.exe
O4 - HKCU\..\Run: [emrvhos] c:\windows\fvqtlkv.exe
O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [lrujmdv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [ldtgceb] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [wbdiukj] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [fthxsym] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [rmijync] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [neinrqv] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [hqkpsuu] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [qlhlckn] c:\windows\ajvoeoj.exe
O4 - HKCU\..\RunServices: [qjjfdde] c:\windows\fquwaty.exe
O4 - HKCU\..\RunServices: [jdrfysd] c:\windows\fquwaty.exe
O4 - HKCU\..\RunServices: [axprjtm] c:\windows\fquwaty.exe
O4 - HKCU\..\RunServices: [lwxneko] c:\windows\fquwaty.exe
O4 - HKCU\..\RunServices: [vjtxthi] c:\windows\fquwaty.exe
O4 - HKCU\..\RunServices: [dbdpoxp] c:\windows\yxyrjwd.exe
O4 - HKCU\..\RunServices: [ilapdmt] c:\windows\pghfgcw.exe
O4 - HKCU\..\RunServices: [pwbahlu] c:\windows\pghfgcw.exe
O4 - HKCU\..\RunServices: [yviaeoe] c:\windows\pghfgcw.exe
O4 - HKCU\..\RunServices: [rvohtcc] c:\windows\pghfgcw.exe
O4 - HKCU\..\RunServices: [kphnsap] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [stagymd] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [vexncpb] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [cxmhqby] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [tqvaqct] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [nyeuupu] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [jolseyt] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [kqbmkpx] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [ufaortc] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [jwvwfcy] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [kfushsa] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [jlurqyj] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [jtipcjv] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [wuivlvx] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [vxtpkqi] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [gowpjto] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [xmcwnhm] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [yeaggsu] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [vvvqenc] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [ysxqqdr] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [anfmmcp] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [fgerctk] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [hpchioc] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [ehbmbyl] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [kcegsww] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [kwfkvgf] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [epdncks] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [cprvdci] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [xsxptfw] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [wcgyyci] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [bdbuolx] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [qaqbalg] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [nlxfhmg] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [cxgwcuj] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [nkjrixw] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [acdvlhu] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [byapndi] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [vuyokwm] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [qexkrdg] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [cwjasiw] c:\windows\wgqkacq.exe
O4 - HKCU\..\RunServices: [sdpalfs] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [knxtlhj] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [cvhwhlr] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [dcurbmx] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [fsbqtsa] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [nvugqwe] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [vhlprtm] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [sckehyo] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [clwtgbr] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [hhmgxvn] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [ctsaitc] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [tnfaboy] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [ejgvcij] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [rdghnel] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [qyvejxx] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [dqsolns] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [efytlub] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [qdrfycf] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [mirsqis] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [gtvmgli] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [chnnyyy] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [hsoenji] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [dygydxp] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [rkpkcjv] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [vxwxftt] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [rcxymhn] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [bdocnsw] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [locqufa] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [lmpexug] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [ynvctyn] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [gfpfmyd] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [nupvfqb] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [qsoptol] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [ylkbioc] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [nxfydjb] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [eoksfnt] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [erdopml] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [outillx] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [bqdcoei] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [nepslbj] c:\windows\ewaumdk.exe
O4 - HKCU\..\RunServices: [elhcpin] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [gsvajxe] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [qdybuao] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [motptvy] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [axffdpd] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [rmrhiux] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [ipugivp] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [uoaaous] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [kbmjism] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [jpsasqg] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [gfumndu] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [ugktvmj] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [jqkntmt] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [umtmeru] c:\windows\eemeiow.exe
O4 - HKCU\..\RunServices: [yvyhrdj] c:\windows\jfwegil.exe
O4 - HKCU\..\RunServices: [oqesmwv] c:\windows\jfwegil.exe
O4 - HKCU\..\RunServices: [offaxid] c:\windows\jfwegil.exe
O4 - HKCU\..\RunServices: [woskhgo] c:\windows\jfwegil.exe
O4 - HKCU\..\RunServices: [fahjayb] c:\windows\pybqgqe.exe
O4 - HKCU\..\RunServices: [lpvwqby] c:\windows\pybqgqe.exe
O4 - HKCU\..\RunServices: [necybof] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [xwmmuci] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [lxtwlwd] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [yhxjdul] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [falfjig] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [mpumhrf] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ifoaewh] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [mtliggu] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ndrimbh] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ydaupej] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [yetvcjj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [apiwmkm] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [dwcjkqs] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fvgngnn] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [evtgcdo] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [avtwooj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ykpmuhh] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [iwqxjcr] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [kexqbtk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [xsieyny] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [uoprbqa] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [gesbfxx] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [extmpbr] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [twngpvl] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [rncjaae] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [cpxnquk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ihrchvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [jpbwewn] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [gpkceme] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [pkvcnpj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [qqxegop] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [aypclgk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [frggihp] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [pbbldja] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fbstneo] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [saukcss] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [wgswvrb] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [msxuplj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [uhxrmll] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [tbfwqol] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [mpbcgma] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [oiuslvj] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [oafjhdk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [cpcritx] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [setxnay] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [mrupugs] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [advkkgl] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [uwnthdr] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [aokbpig] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [vutpfkt] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [yurlvbk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ltjnbmm] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ftpkuoy] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [jccdpbq] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [oreqwjx] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [qcypawe] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [tlbxiwy] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [piypdiw] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [yddngwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [kukjuup] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [jxgdpws] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fcyejwt] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [tjupqcm] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [qdcxwis] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [hrqwunk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ivfjwyu] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ftudgpy] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [lubkuij] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [tfmeero] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [heftpvb] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [xuaocjt] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [vfoyqof] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [ojtooxk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [rvvsgsw] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [gomqmwi] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [urikpcs] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [jpdewcl] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [feictey] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [mrkrlfn] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [cmfsjfg] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fcvbleo] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [rcytvcb] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [qnfmghn] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [keiylup] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [uutflpx] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [vgkphcf] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [sqdbrft] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [auyvsmk] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fafxnna] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [nngumpm] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [dqmaqfv] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [axjjyus] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [dcytxxh] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [iwfwsba] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [dpmsmam] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [yxwryhe] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [fxddetn] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [tqygwyv] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [hbfnovp] c:\windows\uikpxxl.exe
O4 - HKCU\..\RunServices: [lefurdo] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [hxkatpm] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [mswbfvo] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [sfddokl] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [yguurbe] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [lydvuui] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [bwdkvnv] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [ltmyrbc] c:\windows\mvdqves.exe
O4 - HKCU\..\RunServices: [krscxtc] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [ioqjime] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [xdofaks] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [vjbtefr] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [utsgpau] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [lcukxdw] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [faldqnk] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [kvcmagd] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [lqgkpwn] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [fthjudk] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [otaauik] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [asxvlrb] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [irmfuiq] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [kimyjik] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [cotxvqj] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [yhlvypp] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [obvngrp] c:\windows\atiyiac.exe
O4 - HKCU\..\RunServices: [tvrxibc] c:\windows\kgjafnw.exe
O4 - HKCU\..\RunServices: [vxtbpko] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [yyouxeu] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [twblros] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [erobjky] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [kwjyuul] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [mebqqqd] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [fjyoqmb] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [sxgfldm] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [fabrpvd] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [qlsmeio] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [tbgrxhl] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [jjssqlu] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [heukvyi] c:\windows\grtpciw.exe
O4 - HKCU\..\RunServices: [qhegvbh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [icsddfy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [hgawnsa] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [dmygjnu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [upigjlo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [qylvywv] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [aguwklh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [ienwpxh] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [wmocnoo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [ghuvewu] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [oagsarx] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [yuihass] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [uaupybw] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [fgtftij] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [ytvxcqc] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [umtnpdg] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [wnfjdcj] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [mejribo] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [rqpyuoy] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [wqfauuq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [xfjxkhq] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [qagxxhk] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [nqggthe] c:\windows\tuqvsyf.exe
O4 - HKCU\..\RunServices: [decmywt] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [pkfqnqb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [yhdyiur] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [igvsebb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [beglxlb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [vooriqo] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [lilooco] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [rwscbkm] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [ijwgbgu] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [eacnshb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [jrihqas] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [nyickje] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [gbfcbqt] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [xrnxgbg] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [nvgtevi] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [nnulsan] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [wkjtgtb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [brxpkub] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [lxrkucn] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [ngdqgqf] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [ahndulo] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [eewwmou] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [jrmsofb] c:\windows\duismvq.exe
O4 - HKCU\..\RunServices: [dvjoaxf] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [ectsgjd] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [yxhsmnr] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [hpmsgds] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [lsegxuw] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [drwffrc] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [mmactuv] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [gcyrdsd] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [hfolosw] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [pgkygym] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [uedtjld] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [fbrgbuq] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [untangb] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [evtmsjn] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [tainfce] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [lvauaov] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [vxsylqx] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [gqfnwvq] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [vgfmtkh] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [qhrjqtt] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [porrejr] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [gkhapou] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [ysbgaqx] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [wboxghi] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [cgrhivf] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [lgfngvd] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [prybmjc] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [qoyqqwp] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [luvprfq] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [xhjhvne] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [qklcycr] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [opxwfuo] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [kewjsww] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [nkrlwam] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [hbvosde] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [qbvosqf] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [atpouiy] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [svfggpa] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [bbsaebs] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [wlxhlud] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [mkfmbsl] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [ryhcdoj] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [qdiibny] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [nwlmvha] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [guvberx] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [bxhaclp] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [aucceae] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [rmjpqna] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [wkbspwn] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [agvnwai] c:\windows\msyityk.exe
O4 - HKCU\..\RunServices: [rpqrkii] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ovoykia] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fiheuhk] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ttfsxqx] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [gmidtfq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [beesngh] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [nfjjntb] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [hcngucj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [cwjagwh] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [niuknss] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [euiidcf] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ncjcaqt] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [pjyyavy] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [iodvmaj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ulvdpop] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [bdhgrlo] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [afepjqn] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [uqvqhom] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [tcuqsbv] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [djqbtmv] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [dglmywh] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lrykrue] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ecryvrp] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lstjwso] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lmgnmrn] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [srkwaus] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [rucmynj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fhrtmpc] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ctcwojy] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ajgcjyy] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mfacmgq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [afiwnpq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [qljkakd] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [otipmsv] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [irmjluo] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [rjaiqeu] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [beosmts] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mxrsncv] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fvwseee] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [nyybxht] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [uktllui] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [opwpgqi] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ruitiby] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [xgrnwex] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [pkeihym] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [hblosxb] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ljifvmi] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [jgmvmwg] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [knhmchm] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [tmldlgp] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lhyianx] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [pltaydu] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lfrmoil] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [qxugelu] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [winxacd] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fjocuaa] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [bnfucqd] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [dauovje] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [yptsjjn] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [vjyjrkj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [oxmppqc] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [thlorti] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [xmnkkug] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [cknmncn] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lxijnfe] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mhxtxym] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [cgctppo] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fntveab] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [asirsgc] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [pddvvjv] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ptndgne] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [kqmnngr] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lxaslrq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [pabwshb] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mdiiljs] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ogjqnpu] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [vhngdvl] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ebcotsq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [njrvdye] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [dcinvix] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [bjaypha] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [ccrjyul] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [iexgvqj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fvwtbrc] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [neamvom] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [gbrqera] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [bpdeyxg] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [kuspnuh] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [lwuswsw] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mbqyydd] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mqhpgip] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [upbaghx] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [mobbvcq] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [opohoff] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [bcbydae] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [vvctwxf] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [vueivbd] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [euywtbs] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [nywlljj] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [kulyris] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [gkqgxmu] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [spraylp] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [dnqclwn] c:\windows\pydrhlr.exe
O4 - HKCU\..\RunServices: [fibqnxw] c:\windows\fkynecs.exe
O4 - HKCU\..\RunServices: [lglereq] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [cdarnab] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [ryfwufd] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [gbxbmfh] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [fpobqym] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [mapfdpy] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [gllfrwi] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [xptjwjk] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [ismylyf] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [mcxmbdk] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [mswvaha] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [nwmrpeg] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [vhyetvy] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [jaqlabt] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [ipgjjug] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [winpbhf] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [wissrbv] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [amgyusr] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [scifmyq] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [swbftxa] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [oymvwoe] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [ofmvnai] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [txjdyaw] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [quxcjre] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [xxtbklc] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [mgrecxw] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [grlfhvf] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [abntmhi] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [yndisqy] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [mxfinly] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [yyydviq] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [vgxsscw] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [kbriopr] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [noajsbc] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [kldhsls] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [yennoxi] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [uqmnwak] c:\windows\rebardy.exe
O4 - HKCU\..\RunServices: [uhxxlrk] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [jheocjg] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [fjvhjdp] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [vgikxsk] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [ucnriao] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [dvyyjev] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [danjwui] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [ccwmhxm] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [wugxlvt] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [akjmryh] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [ufxkvfp] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [tegjjbp] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [nkaqnif] c:\windows\wpsedws.exe
O4 - HKCU\..\RunServices: [segsjcv] c:\windows\ahuohjr.exe
O4 - HKCU\..\RunServices: [jwjfrun] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [bxqdbva] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [eihjymo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [dgvqolw] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [jelwhjo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [ikyrvag] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [cchvnph] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [vlsywvo] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [xofcbry] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [apbgjnx] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [urmxhkm] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [vjudlsp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [clpknwp] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [mwycgrj] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [hcdsnyb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [rmcbylb] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [jaliqux] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [krbyldc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [qwmpigy] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [opmvnpf] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [jwsrprc] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [pfmglkd] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [lvfdmdt] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [jrjuoih] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [evhvtup] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [wcmhyrq] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [iwxonsa] c:\windows\mlgfnwk.exe
O4 - HKCU\..\RunServices: [assnudw] c:\windows\qfarcaj.exe
O4 - HKCU\..\RunServices: [gqvthyy] c:\windows\cyfodva.exe
O4 - HKCU\..\RunServices: [cdlgtnk] c:\windows\lxtwehg.exe
O4 - HKCU\..\RunServices: [eqvlihk] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [ndkjoux] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [afdkmes] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [akernqe] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [hrwriku] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [sfsysfb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [gsyhbel] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [swycdgb] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [rhqrelx] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [xrxvwsn] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [klrdrim] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [njbuusw] c:\windows\rsdgdpr.exe
O4 - HKCU\..\RunServices: [cqvchdc] c:\windows\yslnhau.exe
O4 - HKCU\..\RunServices: [lhyfoxu] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [vqjeuhs] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [pexhlxq] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [pfrfxye] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [waamrnh] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [fdjbfeb] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [gnajiyi] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [wfcyblh] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [sdssdvq] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [pgwhxxu] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [qwllyqw] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [qvjscwy] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [gogygvb] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [erxkoyo] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [eeudcdy] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [ufytutl] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [iordvja] c:\windows\snvsrer.exe
O4 - HKCU\..\RunServices: [ftutjfi] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [mwsslll] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [ahxdkfh] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [pbilvsk] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [qsxyegj] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [kpjjnvb] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [hbfvher] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [hfcevsc] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [hpjjjti] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [huvrbxp] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [tfpveot] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [jtlqlfk] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [vhxjxhh] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [jncntlx] c:\windows\sxtadqi.exe
O4 - HKCU\..\RunServices: [vrliyfh] c:\windows\okpkgpl.exe
O4 - HKCU\..\RunServices: [ykcaopp] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [itrpgel] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [iqpfilo] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [jxsvbyx] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [pcvgfus] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [gvrhxal] c:\windows\wefaudv.exe
O4 - HKCU\..\RunServices: [vtqxgjn] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [sjglldm] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [quasbas] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [knpiwjb] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [hlgvxia] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [nbertrn] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [avrdnnw] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [acdraig] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [lipjtok] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [rtsxbrf] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [wkrlccr] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [cohnksf] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [ujmlskr] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [yidrkjd] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [yuwqlud] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [feunuhf] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [lxubypd] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [jixcudp] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [studluo] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [umswxvr] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [sarykrn] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [llwovpu] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [cwomfku] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [swixlsl] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [kmijdyv] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [tramxdm] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [rnwwwnx] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [lmavxxi] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [kexnwwl] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [mkkytpc] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [khafwqf] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [tjigqfg] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [acqpjct] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [pngjayq] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [uyogkcb] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [cywawjg] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [iqqfwpn] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [nwtfjfn] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [nunvveb] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [wafwgif] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [vuseodi] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [kfcrinr] c:\windows\vqoukes.exe
O4 - HKCU\..\RunServices: [hbrfsks] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [vmhxjft] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [djwlvjs] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [eofvcun] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [oopsglx] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [tlmfoud] c:\windows\leaoqpj.exe
O4 - HKCU\..\RunServices: [taexkkb] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [tlmpdhw] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [hiwrojy] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [wisjfhn] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [lfewojd] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [jmstlku] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [mkddjws] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [pwjsciy] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [noamgwt] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [ifpxqmu] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [faexihe] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [pqayfjc] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [fdpcvme] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [vriiync] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [xaxnnqq] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [dnbdkri] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [ajddcvn] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [gpaucjh] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [jqruuve] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [aogmxlb] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [qulqxwe] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [vgsebmg] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [latepdr] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [sngugcv] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [axpfkeh] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [dwhdbqf] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [hatsewp] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [dscldiy] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [bpdgrse] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [kqptooh] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [atambfg] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [onoplqu] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [vyogart] c:\windows\hfbbynp.exe
O4 - HKCU\..\RunServices: [auagmnm] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [dcdllls] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [yixyctm] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [hfdsvik] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [nwiqevu] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [gshrjjh] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [mdblucu] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [lcdvebt] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [lfraurg] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [jwbjgyh] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [kjolyoq] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [yifdlyb] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [rqqwapb] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [apjatpv] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [viyayhr] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [ouulkye] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [tdndkrp] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [oyfjhle] c:\windows\hdmvptv.exe
O4 - HKCU\..\RunServices: [rylrogx] c:\windows\ojgphmu.exe
O4 - HKCU\..\RunServices: [wspjhco] c:\windows\fmyrdoe.exe
O4 - HKCU\..\RunServices: [jodyigt] c:\windows\fmyrdoe.exe
O4 - HKCU\..\RunServices: [kqubgny] c:\windows\fmyrdoe.exe
O4 - HKCU\..\RunServices: [dwihcic] c:\windows\fmyrdoe.exe
O4 - HKCU\..\RunServices: [watwobc] c:\windows\fmyrdoe.exe
O4 - HKCU\..\RunServices: [gblklqr] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [apidcpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [cxyjvrr] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [imfsohb] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [gcxscgh] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [yfyohsd] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [wmmbhmb] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ouxuwtw] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [jmewaqq] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [nadexwa] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [iegtxnv] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [wuqpecm] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [frftgls] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [dsxdjna] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ovouuyu] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [iugrccm] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [teneorg] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [wsesjpm] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [feqjope] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [bgbysxt] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [iyterka] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [qwqgdad] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ygucxoy] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ngwbrou] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ljxdail] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ucoeenm] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [agfxxeo] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ekynrpa] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [ysayppx] c:\windows\brfmmaa.exe
O4 - HKCU\..\RunServices: [jbboihi] c:\windows\br
  • 0

#6
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
O4 - HKCU\..\RunServices: [yusjhxv] c:\windows\ufhslmx.exe
O4 - HKCU\..\RunServices: [yfcdsqg] c:\windows\duacseq.exe
O4 - HKCU\..\RunServices: [bdtjrvc] c:\windows\duacseq.exe
O4 - HKCU\..\RunServices: [xuinkvt] c:\windows\duacseq.exe
O4 - HKCU\..\RunServices: [pbpuugb] c:\windows\alfccqj.exe
O4 - HKCU\..\RunServices: [bvxvclb] c:\windows\pjecfhk.exe
O4 - HKCU\..\RunServices: [cuwurri] c:\windows\njepvgx.exe
O4 - HKCU\..\RunServices: [gnfyqcm] c:\windows\cwnqbof.exe
O4 - HKCU\..\RunServices: [nymhnej] c:\windows\cwnqbof.exe
O4 - HKCU\..\RunServices: [dnffmke] c:\windows\cwnqbof.exe
O4 - HKCU\..\RunServices: [ydlrppq] c:\windows\xlqqlxf.exe
O4 - HKCU\..\RunServices: [suqmgcn] c:\windows\xlqqlxf.exe
O4 - HKCU\..\RunServices: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\RunServices: [ssxufcv] c:\windows\vpkjpyv.exe
O4 - HKCU\..\RunServices: [afcsclg] c:\windows\vpkjpyv.exe
O4 - HKCU\..\RunServices: [lcelbdh] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [bkobcuv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [pgkoatp] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [sxqwiop] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [gsnquxb] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [riuppiu] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [ihhkatw] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [orkceps] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [oukmoec] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [gdxcraa] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [hgqqbki] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [qsgwcmd] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [mfhxarq] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [efgtkqd] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [vballgj] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [lknktlx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [fhvddqv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [asvsgbk] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [lqdhimx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [cebcekx] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [gpmtehf] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [livvxof] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [wewhmwb] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [ienwovg] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [gkuclrv] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [grccovg] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [ykjdice] c:\windows\dmcdyrt.exe
O4 - HKCU\..\RunServices: [nogbajr] c:\windows\pdadlwm.exe
O4 - HKCU\..\RunServices: [yjwuoht] c:\windows\pdadlwm.exe
O4 - HKCU\..\RunServices: [jeigyko] c:\windows\pdadlwm.exe
O4 - HKCU\..\RunServices: [jhnrkgh] c:\windows\pdadlwm.exe
O4 - HKCU\..\RunServices: [cmyxvpc] c:\windows\pdadlwm.exe
O4 - HKCU\..\RunServices: [goldput] c:\windows\usigbro.exe
O4 - HKCU\..\RunServices: [ojibmou] c:\windows\usigbro.exe
O4 - HKCU\..\RunServices: [amntrfe] c:\windows\usigbro.exe
O4 - HKCU\..\RunServices: [ydadeks] c:\windows\usigbro.exe
O4 - HKCU\..\RunServices: [ocqgknp] c:\windows\usigbro.exe
O4 - HKCU\..\RunServices: [pymgmgf] c:\windows\vsiqcan.exe
O4 - HKCU\..\RunServices: [fltprbt] c:\windows\vsiqcan.exe
O4 - HKCU\..\RunServices: [emrvhos] c:\windows\fvqtlkv.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Bridge - http://download.game...nts/y/bt1_x.cab
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://kelvin.viewne...m/bl_camera.cab
O16 - DPF: {A2979615-DC81-4AE4-A153-912E3C227058} (Yahoo! 相簿輕鬆上載工具 Class) - http://us.dl1.yimg.c...ropper1_6hk.cab
  • 0

#7
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
The 3.txt file (split into 2 parts)

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe"
"ScanRegistry"="C:\\WINDOWS\\scanregw.exe /autorun"
"TaskMonitor"="C:\\WINDOWS\\taskmon.exe"
"PCHealth"="C:\\WINDOWS\\PCHealth\\Support\\PCHSchd.exe -s"
"SystemTray"="SysTray.Exe"
"LoadPowerProfile"="Rundll32.exe powrprof.dll,LoadCurrentPwrScheme"
"smapp"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMTray.exe"
"SiSAudio"="C:\\WINDOWS\\SYSTEM\\MP_S3.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\SYSTEM\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"URLLSTCK.exe"="C:\\Program Files\\Norton Internet Security\\UrlLstCk.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMON.EXE /Consumer"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"LoadQM"="loadqm.exe"
"DataLayer"="C:\\Program Files\\Common Files\\PCSuite\\DataLayer\\DataLayer.exe"
@=""
"Nokia Tray Application"="C:\\Program Files\\Common Files\\Nokia\\Tools\\NclTray.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"lrujmdv"="c:\\windows\\ajvoeoj.exe"
"ldtgceb"="c:\\windows\\ajvoeoj.exe"
"wbdiukj"="c:\\windows\\ajvoeoj.exe"
"fthxsym"="c:\\windows\\ajvoeoj.exe"
"rmijync"="c:\\windows\\ajvoeoj.exe"
"neinrqv"="c:\\windows\\ajvoeoj.exe"
"hqkpsuu"="c:\\windows\\ajvoeoj.exe"
"qlhlckn"="c:\\windows\\ajvoeoj.exe"
"qjjfdde"="c:\\windows\\fquwaty.exe"
"jdrfysd"="c:\\windows\\fquwaty.exe"
"axprjtm"="c:\\windows\\fquwaty.exe"
"lwxneko"="c:\\windows\\fquwaty.exe"
"vjtxthi"="c:\\windows\\fquwaty.exe"
"dbdpoxp"="c:\\windows\\yxyrjwd.exe"
"ilapdmt"="c:\\windows\\pghfgcw.exe"
"pwbahlu"="c:\\windows\\pghfgcw.exe"
"yviaeoe"="c:\\windows\\pghfgcw.exe"
"rvohtcc"="c:\\windows\\pghfgcw.exe"
"kphnsap"="c:\\windows\\wgqkacq.exe"
"stagymd"="c:\\windows\\wgqkacq.exe"
"vexncpb"="c:\\windows\\wgqkacq.exe"
"cxmhqby"="c:\\windows\\wgqkacq.exe"
"tqvaqct"="c:\\windows\\wgqkacq.exe"
"nyeuupu"="c:\\windows\\wgqkacq.exe"
"jolseyt"="c:\\windows\\wgqkacq.exe"
"kqbmkpx"="c:\\windows\\wgqkacq.exe"
"ufaortc"="c:\\windows\\wgqkacq.exe"
"jwvwfcy"="c:\\windows\\wgqkacq.exe"
"kfushsa"="c:\\windows\\wgqkacq.exe"
"jlurqyj"="c:\\windows\\wgqkacq.exe"
"jtipcjv"="c:\\windows\\wgqkacq.exe"
"wuivlvx"="c:\\windows\\wgqkacq.exe"
"vxtpkqi"="c:\\windows\\wgqkacq.exe"
"gowpjto"="c:\\windows\\wgqkacq.exe"
"xmcwnhm"="c:\\windows\\wgqkacq.exe"
"yeaggsu"="c:\\windows\\wgqkacq.exe"
"vvvqenc"="c:\\windows\\wgqkacq.exe"
"ysxqqdr"="c:\\windows\\wgqkacq.exe"
"anfmmcp"="c:\\windows\\wgqkacq.exe"
"fgerctk"="c:\\windows\\wgqkacq.exe"
"hpchioc"="c:\\windows\\wgqkacq.exe"
"ehbmbyl"="c:\\windows\\wgqkacq.exe"
"kcegsww"="c:\\windows\\wgqkacq.exe"
"kwfkvgf"="c:\\windows\\wgqkacq.exe"
"epdncks"="c:\\windows\\wgqkacq.exe"
"cprvdci"="c:\\windows\\wgqkacq.exe"
"xsxptfw"="c:\\windows\\wgqkacq.exe"
"wcgyyci"="c:\\windows\\wgqkacq.exe"
"bdbuolx"="c:\\windows\\wgqkacq.exe"
"qaqbalg"="c:\\windows\\wgqkacq.exe"
"nlxfhmg"="c:\\windows\\wgqkacq.exe"
"cxgwcuj"="c:\\windows\\wgqkacq.exe"
"nkjrixw"="c:\\windows\\wgqkacq.exe"
"acdvlhu"="c:\\windows\\wgqkacq.exe"
"byapndi"="c:\\windows\\wgqkacq.exe"
"vuyokwm"="c:\\windows\\wgqkacq.exe"
"qexkrdg"="c:\\windows\\wgqkacq.exe"
"cwjasiw"="c:\\windows\\wgqkacq.exe"
"sdpalfs"="c:\\windows\\ewaumdk.exe"
"knxtlhj"="c:\\windows\\ewaumdk.exe"
"cvhwhlr"="c:\\windows\\ewaumdk.exe"
"dcurbmx"="c:\\windows\\ewaumdk.exe"
"fsbqtsa"="c:\\windows\\ewaumdk.exe"
"nvugqwe"="c:\\windows\\ewaumdk.exe"
"vhlprtm"="c:\\windows\\ewaumdk.exe"
"sckehyo"="c:\\windows\\ewaumdk.exe"
"clwtgbr"="c:\\windows\\ewaumdk.exe"
"hhmgxvn"="c:\\windows\\ewaumdk.exe"
"ctsaitc"="c:\\windows\\ewaumdk.exe"
"tnfaboy"="c:\\windows\\ewaumdk.exe"
"ejgvcij"="c:\\windows\\ewaumdk.exe"
"rdghnel"="c:\\windows\\ewaumdk.exe"
"qyvejxx"="c:\\windows\\ewaumdk.exe"
"dqsolns"="c:\\windows\\ewaumdk.exe"
"efytlub"="c:\\windows\\ewaumdk.exe"
"qdrfycf"="c:\\windows\\ewaumdk.exe"
"mirsqis"="c:\\windows\\ewaumdk.exe"
"gtvmgli"="c:\\windows\\ewaumdk.exe"
"chnnyyy"="c:\\windows\\ewaumdk.exe"
"hsoenji"="c:\\windows\\ewaumdk.exe"
"dygydxp"="c:\\windows\\ewaumdk.exe"
"rkpkcjv"="c:\\windows\\ewaumdk.exe"
"vxwxftt"="c:\\windows\\ewaumdk.exe"
"rcxymhn"="c:\\windows\\ewaumdk.exe"
"bdocnsw"="c:\\windows\\ewaumdk.exe"
"locqufa"="c:\\windows\\ewaumdk.exe"
"lmpexug"="c:\\windows\\ewaumdk.exe"
"ynvctyn"="c:\\windows\\ewaumdk.exe"
"gfpfmyd"="c:\\windows\\ewaumdk.exe"
"nupvfqb"="c:\\windows\\ewaumdk.exe"
"qsoptol"="c:\\windows\\ewaumdk.exe"
"ylkbioc"="c:\\windows\\ewaumdk.exe"
"nxfydjb"="c:\\windows\\ewaumdk.exe"
"eoksfnt"="c:\\windows\\ewaumdk.exe"
"erdopml"="c:\\windows\\ewaumdk.exe"
"outillx"="c:\\windows\\ewaumdk.exe"
"bqdcoei"="c:\\windows\\ewaumdk.exe"
"nepslbj"="c:\\windows\\ewaumdk.exe"
"elhcpin"="c:\\windows\\eemeiow.exe"
"gsvajxe"="c:\\windows\\eemeiow.exe"
"qdybuao"="c:\\windows\\eemeiow.exe"
"motptvy"="c:\\windows\\eemeiow.exe"
"axffdpd"="c:\\windows\\eemeiow.exe"
"rmrhiux"="c:\\windows\\eemeiow.exe"
"ipugivp"="c:\\windows\\eemeiow.exe"
"uoaaous"="c:\\windows\\eemeiow.exe"
"kbmjism"="c:\\windows\\eemeiow.exe"
"jpsasqg"="c:\\windows\\eemeiow.exe"
"gfumndu"="c:\\windows\\eemeiow.exe"
"ugktvmj"="c:\\windows\\eemeiow.exe"
"jqkntmt"="c:\\windows\\eemeiow.exe"
"umtmeru"="c:\\windows\\eemeiow.exe"
"yvyhrdj"="c:\\windows\\jfwegil.exe"
"oqesmwv"="c:\\windows\\jfwegil.exe"
"offaxid"="c:\\windows\\jfwegil.exe"
"woskhgo"="c:\\windows\\jfwegil.exe"
"fahjayb"="c:\\windows\\pybqgqe.exe"
"lpvwqby"="c:\\windows\\pybqgqe.exe"
"necybof"="c:\\windows\\uikpxxl.exe"
"xwmmuci"="c:\\windows\\uikpxxl.exe"
"lxtwlwd"="c:\\windows\\uikpxxl.exe"
"yhxjdul"="c:\\windows\\uikpxxl.exe"
"falfjig"="c:\\windows\\uikpxxl.exe"
"mpumhrf"="c:\\windows\\uikpxxl.exe"
"ifoaewh"="c:\\windows\\uikpxxl.exe"
"mtliggu"="c:\\windows\\uikpxxl.exe"
"ndrimbh"="c:\\windows\\uikpxxl.exe"
"ydaupej"="c:\\windows\\uikpxxl.exe"
"yetvcjj"="c:\\windows\\uikpxxl.exe"
"apiwmkm"="c:\\windows\\uikpxxl.exe"
"dwcjkqs"="c:\\windows\\uikpxxl.exe"
"fvgngnn"="c:\\windows\\uikpxxl.exe"
"evtgcdo"="c:\\windows\\uikpxxl.exe"
"avtwooj"="c:\\windows\\uikpxxl.exe"
"ykpmuhh"="c:\\windows\\uikpxxl.exe"
"iwqxjcr"="c:\\windows\\uikpxxl.exe"
"kexqbtk"="c:\\windows\\uikpxxl.exe"
"xsieyny"="c:\\windows\\uikpxxl.exe"
"uoprbqa"="c:\\windows\\uikpxxl.exe"
"gesbfxx"="c:\\windows\\uikpxxl.exe"
"extmpbr"="c:\\windows\\uikpxxl.exe"
"twngpvl"="c:\\windows\\uikpxxl.exe"
"rncjaae"="c:\\windows\\uikpxxl.exe"
"cpxnquk"="c:\\windows\\uikpxxl.exe"
"ihrchvj"="c:\\windows\\uikpxxl.exe"
"jpbwewn"="c:\\windows\\uikpxxl.exe"
"gpkceme"="c:\\windows\\uikpxxl.exe"
"pkvcnpj"="c:\\windows\\uikpxxl.exe"
"qqxegop"="c:\\windows\\uikpxxl.exe"
"aypclgk"="c:\\windows\\uikpxxl.exe"
"frggihp"="c:\\windows\\uikpxxl.exe"
"pbbldja"="c:\\windows\\uikpxxl.exe"
"fbstneo"="c:\\windows\\uikpxxl.exe"
"saukcss"="c:\\windows\\uikpxxl.exe"
"wgswvrb"="c:\\windows\\uikpxxl.exe"
"msxuplj"="c:\\windows\\uikpxxl.exe"
"uhxrmll"="c:\\windows\\uikpxxl.exe"
"tbfwqol"="c:\\windows\\uikpxxl.exe"
"mpbcgma"="c:\\windows\\uikpxxl.exe"
"oiuslvj"="c:\\windows\\uikpxxl.exe"
"oafjhdk"="c:\\windows\\uikpxxl.exe"
"cpcritx"="c:\\windows\\uikpxxl.exe"
"setxnay"="c:\\windows\\uikpxxl.exe"
"mrupugs"="c:\\windows\\uikpxxl.exe"
"advkkgl"="c:\\windows\\uikpxxl.exe"
"uwnthdr"="c:\\windows\\uikpxxl.exe"
"aokbpig"="c:\\windows\\uikpxxl.exe"
"vutpfkt"="c:\\windows\\uikpxxl.exe"
"yurlvbk"="c:\\windows\\uikpxxl.exe"
"ltjnbmm"="c:\\windows\\uikpxxl.exe"
"ftpkuoy"="c:\\windows\\uikpxxl.exe"
"jccdpbq"="c:\\windows\\uikpxxl.exe"
"oreqwjx"="c:\\windows\\uikpxxl.exe"
"qcypawe"="c:\\windows\\uikpxxl.exe"
"tlbxiwy"="c:\\windows\\uikpxxl.exe"
"piypdiw"="c:\\windows\\uikpxxl.exe"
"yddngwi"="c:\\windows\\uikpxxl.exe"
"kukjuup"="c:\\windows\\uikpxxl.exe"
"jxgdpws"="c:\\windows\\uikpxxl.exe"
"fcyejwt"="c:\\windows\\uikpxxl.exe"
"tjupqcm"="c:\\windows\\uikpxxl.exe"
"qdcxwis"="c:\\windows\\uikpxxl.exe"
"hrqwunk"="c:\\windows\\uikpxxl.exe"
"ivfjwyu"="c:\\windows\\uikpxxl.exe"
"ftudgpy"="c:\\windows\\uikpxxl.exe"
"lubkuij"="c:\\windows\\uikpxxl.exe"
"tfmeero"="c:\\windows\\uikpxxl.exe"
"heftpvb"="c:\\windows\\uikpxxl.exe"
"xuaocjt"="c:\\windows\\uikpxxl.exe"
"vfoyqof"="c:\\windows\\uikpxxl.exe"
"ojtooxk"="c:\\windows\\uikpxxl.exe"
"rvvsgsw"="c:\\windows\\uikpxxl.exe"
"gomqmwi"="c:\\windows\\uikpxxl.exe"
"urikpcs"="c:\\windows\\uikpxxl.exe"
"jpdewcl"="c:\\windows\\uikpxxl.exe"
"feictey"="c:\\windows\\uikpxxl.exe"
"mrkrlfn"="c:\\windows\\uikpxxl.exe"
"cmfsjfg"="c:\\windows\\uikpxxl.exe"
"fcvbleo"="c:\\windows\\uikpxxl.exe"
"rcytvcb"="c:\\windows\\uikpxxl.exe"
"qnfmghn"="c:\\windows\\uikpxxl.exe"
"keiylup"="c:\\windows\\uikpxxl.exe"
"uutflpx"="c:\\windows\\uikpxxl.exe"
"vgkphcf"="c:\\windows\\uikpxxl.exe"
"sqdbrft"="c:\\windows\\uikpxxl.exe"
"auyvsmk"="c:\\windows\\uikpxxl.exe"
"fafxnna"="c:\\windows\\uikpxxl.exe"
"nngumpm"="c:\\windows\\uikpxxl.exe"
"dqmaqfv"="c:\\windows\\uikpxxl.exe"
"axjjyus"="c:\\windows\\uikpxxl.exe"
"dcytxxh"="c:\\windows\\uikpxxl.exe"
"iwfwsba"="c:\\windows\\uikpxxl.exe"
"dpmsmam"="c:\\windows\\uikpxxl.exe"
"yxwryhe"="c:\\windows\\uikpxxl.exe"
"fxddetn"="c:\\windows\\uikpxxl.exe"
"tqygwyv"="c:\\windows\\uikpxxl.exe"
"hbfnovp"="c:\\windows\\uikpxxl.exe"
"lefurdo"="c:\\windows\\mvdqves.exe"
"hxkatpm"="c:\\windows\\mvdqves.exe"
"mswbfvo"="c:\\windows\\mvdqves.exe"
"sfddokl"="c:\\windows\\mvdqves.exe"
"yguurbe"="c:\\windows\\mvdqves.exe"
"lydvuui"="c:\\windows\\mvdqves.exe"
"bwdkvnv"="c:\\windows\\mvdqves.exe"
"ltmyrbc"="c:\\windows\\mvdqves.exe"
"krscxtc"="c:\\windows\\atiyiac.exe"
"ioqjime"="c:\\windows\\atiyiac.exe"
"xdofaks"="c:\\windows\\atiyiac.exe"
"vjbtefr"="c:\\windows\\atiyiac.exe"
"utsgpau"="c:\\windows\\atiyiac.exe"
"lcukxdw"="c:\\windows\\atiyiac.exe"
"faldqnk"="c:\\windows\\atiyiac.exe"
"kvcmagd"="c:\\windows\\atiyiac.exe"
"lqgkpwn"="c:\\windows\\atiyiac.exe"
"fthjudk"="c:\\windows\\atiyiac.exe"
"otaauik"="c:\\windows\\atiyiac.exe"
"asxvlrb"="c:\\windows\\atiyiac.exe"
"irmfuiq"="c:\\windows\\atiyiac.exe"
"kimyjik"="c:\\windows\\atiyiac.exe"
"cotxvqj"="c:\\windows\\atiyiac.exe"
"yhlvypp"="c:\\windows\\atiyiac.exe"
"obvngrp"="c:\\windows\\atiyiac.exe"
"tvrxibc"="c:\\windows\\kgjafnw.exe"
"vxtbpko"="c:\\windows\\grtpciw.exe"
"yyouxeu"="c:\\windows\\grtpciw.exe"
"twblros"="c:\\windows\\grtpciw.exe"
"erobjky"="c:\\windows\\grtpciw.exe"
"kwjyuul"="c:\\windows\\grtpciw.exe"
"mebqqqd"="c:\\windows\\grtpciw.exe"
"fjyoqmb"="c:\\windows\\grtpciw.exe"
"sxgfldm"="c:\\windows\\grtpciw.exe"
"fabrpvd"="c:\\windows\\grtpciw.exe"
"qlsmeio"="c:\\windows\\grtpciw.exe"
"tbgrxhl"="c:\\windows\\grtpciw.exe"
"jjssqlu"="c:\\windows\\grtpciw.exe"
"heukvyi"="c:\\windows\\grtpciw.exe"
"qhegvbh"="c:\\windows\\tuqvsyf.exe"
"icsddfy"="c:\\windows\\tuqvsyf.exe"
"hgawnsa"="c:\\windows\\tuqvsyf.exe"
"dmygjnu"="c:\\windows\\tuqvsyf.exe"
"upigjlo"="c:\\windows\\tuqvsyf.exe"
"qylvywv"="c:\\windows\\tuqvsyf.exe"
"aguwklh"="c:\\windows\\tuqvsyf.exe"
"ienwpxh"="c:\\windows\\tuqvsyf.exe"
"wmocnoo"="c:\\windows\\tuqvsyf.exe"
"ghuvewu"="c:\\windows\\tuqvsyf.exe"
"oagsarx"="c:\\windows\\tuqvsyf.exe"
"yuihass"="c:\\windows\\tuqvsyf.exe"
"uaupybw"="c:\\windows\\tuqvsyf.exe"
"fgtftij"="c:\\windows\\tuqvsyf.exe"
"ytvxcqc"="c:\\windows\\tuqvsyf.exe"
"umtnpdg"="c:\\windows\\tuqvsyf.exe"
"wnfjdcj"="c:\\windows\\tuqvsyf.exe"
"mejribo"="c:\\windows\\tuqvsyf.exe"
"rqpyuoy"="c:\\windows\\tuqvsyf.exe"
"wqfauuq"="c:\\windows\\tuqvsyf.exe"
"xfjxkhq"="c:\\windows\\tuqvsyf.exe"
"qagxxhk"="c:\\windows\\tuqvsyf.exe"
"nqggthe"="c:\\windows\\tuqvsyf.exe"
"decmywt"="c:\\windows\\duismvq.exe"
"pkfqnqb"="c:\\windows\\duismvq.exe"
"yhdyiur"="c:\\windows\\duismvq.exe"
"igvsebb"="c:\\windows\\duismvq.exe"
"beglxlb"="c:\\windows\\duismvq.exe"
"vooriqo"="c:\\windows\\duismvq.exe"
"lilooco"="c:\\windows\\duismvq.exe"
"rwscbkm"="c:\\windows\\duismvq.exe"
"ijwgbgu"="c:\\windows\\duismvq.exe"
"eacnshb"="c:\\windows\\duismvq.exe"
"jrihqas"="c:\\windows\\duismvq.exe"
"nyickje"="c:\\windows\\duismvq.exe"
"gbfcbqt"="c:\\windows\\duismvq.exe"
"xrnxgbg"="c:\\windows\\duismvq.exe"
"nvgtevi"="c:\\windows\\duismvq.exe"
"nnulsan"="c:\\windows\\duismvq.exe"
"wkjtgtb"="c:\\windows\\duismvq.exe"
"brxpkub"="c:\\windows\\duismvq.exe"
"lxrkucn"="c:\\windows\\duismvq.exe"
"ngdqgqf"="c:\\windows\\duismvq.exe"
"ahndulo"="c:\\windows\\duismvq.exe"
"eewwmou"="c:\\windows\\duismvq.exe"
"jrmsofb"="c:\\windows\\duismvq.exe"
"dvjoaxf"="c:\\windows\\msyityk.exe"
"ectsgjd"="c:\\windows\\msyityk.exe"
"yxhsmnr"="c:\\windows\\msyityk.exe"
"hpmsgds"="c:\\windows\\msyityk.exe"
"lsegxuw"="c:\\windows\\msyityk.exe"
"drwffrc"="c:\\windows\\msyityk.exe"
"mmactuv"="c:\\windows\\msyityk.exe"
"gcyrdsd"="c:\\windows\\msyityk.exe"
"hfolosw"="c:\\windows\\msyityk.exe"
"pgkygym"="c:\\windows\\msyityk.exe"
"uedtjld"="c:\\windows\\msyityk.exe"
"fbrgbuq"="c:\\windows\\msyityk.exe"
"untangb"="c:\\windows\\msyityk.exe"
"evtmsjn"="c:\\windows\\msyityk.exe"
"tainfce"="c:\\windows\\msyityk.exe"
"lvauaov"="c:\\windows\\msyityk.exe"
"vxsylqx"="c:\\windows\\msyityk.exe"
"gqfnwvq"="c:\\windows\\msyityk.exe"
"vgfmtkh"="c:\\windows\\msyityk.exe"
"qhrjqtt"="c:\\windows\\msyityk.exe"
"porrejr"="c:\\windows\\msyityk.exe"
"gkhapou"="c:\\windows\\msyityk.exe"
"ysbgaqx"="c:\\windows\\msyityk.exe"
"wboxghi"="c:\\windows\\msyityk.exe"
"cgrhivf"="c:\\windows\\msyityk.exe"
"lgfngvd"="c:\\windows\\msyityk.exe"
"prybmjc"="c:\\windows\\msyityk.exe"
"qoyqqwp"="c:\\windows\\msyityk.exe"
"luvprfq"="c:\\windows\\msyityk.exe"
"xhjhvne"="c:\\windows\\msyityk.exe"
"qklcycr"="c:\\windows\\msyityk.exe"
"opxwfuo"="c:\\windows\\msyityk.exe"
"kewjsww"="c:\\windows\\msyityk.exe"
"nkrlwam"="c:\\windows\\msyityk.exe"
"hbvosde"="c:\\windows\\msyityk.exe"
"qbvosqf"="c:\\windows\\msyityk.exe"
"atpouiy"="c:\\windows\\msyityk.exe"
"svfggpa"="c:\\windows\\msyityk.exe"
"bbsaebs"="c:\\windows\\msyityk.exe"
"wlxhlud"="c:\\windows\\msyityk.exe"
"mkfmbsl"="c:\\windows\\msyityk.exe"
"ryhcdoj"="c:\\windows\\msyityk.exe"
"qdiibny"="c:\\windows\\msyityk.exe"
"nwlmvha"="c:\\windows\\msyityk.exe"
"guvberx"="c:\\windows\\msyityk.exe"
"bxhaclp"="c:\\windows\\msyityk.exe"
"aucceae"="c:\\windows\\msyityk.exe"
"rmjpqna"="c:\\windows\\msyityk.exe"
"wkbspwn"="c:\\windows\\msyityk.exe"
"agvnwai"="c:\\windows\\msyityk.exe"
"rpqrkii"="c:\\windows\\pydrhlr.exe"
"ovoykia"="c:\\windows\\pydrhlr.exe"
"fiheuhk"="c:\\windows\\pydrhlr.exe"
"ttfsxqx"="c:\\windows\\pydrhlr.exe"
"gmidtfq"="c:\\windows\\pydrhlr.exe"
"beesngh"="c:\\windows\\pydrhlr.exe"
"nfjjntb"="c:\\windows\\pydrhlr.exe"
"hcngucj"="c:\\windows\\pydrhlr.exe"
"cwjagwh"="c:\\windows\\pydrhlr.exe"
"niuknss"="c:\\windows\\pydrhlr.exe"
"euiidcf"="c:\\windows\\pydrhlr.exe"
"ncjcaqt"="c:\\windows\\pydrhlr.exe"
"pjyyavy"="c:\\windows\\pydrhlr.exe"
"iodvmaj"="c:\\windows\\pydrhlr.exe"
"ulvdpop"="c:\\windows\\pydrhlr.exe"
"bdhgrlo"="c:\\windows\\pydrhlr.exe"
"afepjqn"="c:\\windows\\pydrhlr.exe"
"uqvqhom"="c:\\windows\\pydrhlr.exe"
"tcuqsbv"="c:\\windows\\pydrhlr.exe"
"djqbtmv"="c:\\windows\\pydrhlr.exe"
"dglmywh"="c:\\windows\\pydrhlr.exe"
"lrykrue"="c:\\windows\\pydrhlr.exe"
"ecryvrp"="c:\\windows\\pydrhlr.exe"
"lstjwso"="c:\\windows\\pydrhlr.exe"
"lmgnmrn"="c:\\windows\\pydrhlr.exe"
"srkwaus"="c:\\windows\\pydrhlr.exe"
"rucmynj"="c:\\windows\\pydrhlr.exe"
"fhrtmpc"="c:\\windows\\pydrhlr.exe"
"ctcwojy"="c:\\windows\\pydrhlr.exe"
"ajgcjyy"="c:\\windows\\pydrhlr.exe"
"mfacmgq"="c:\\windows\\pydrhlr.exe"
"afiwnpq"="c:\\windows\\pydrhlr.exe"
"qljkakd"="c:\\windows\\pydrhlr.exe"
"otipmsv"="c:\\windows\\pydrhlr.exe"
"irmjluo"="c:\\windows\\pydrhlr.exe"
"rjaiqeu"="c:\\windows\\pydrhlr.exe"
"beosmts"="c:\\windows\\pydrhlr.exe"
"mxrsncv"="c:\\windows\\pydrhlr.exe"
"fvwseee"="c:\\windows\\pydrhlr.exe"
"nyybxht"="c:\\windows\\pydrhlr.exe"
"uktllui"="c:\\windows\\pydrhlr.exe"
"opwpgqi"="c:\\windows\\pydrhlr.exe"
"ruitiby"="c:\\windows\\pydrhlr.exe"
"xgrnwex"="c:\\windows\\pydrhlr.exe"
"pkeihym"="c:\\windows\\pydrhlr.exe"
"hblosxb"="c:\\windows\\pydrhlr.exe"
"ljifvmi"="c:\\windows\\pydrhlr.exe"
"jgmvmwg"="c:\\windows\\pydrhlr.exe"
"knhmchm"="c:\\windows\\pydrhlr.exe"
"tmldlgp"="c:\\windows\\pydrhlr.exe"
"lhyianx"="c:\\windows\\pydrhlr.exe"
"pltaydu"="c:\\windows\\pydrhlr.exe"
"lfrmoil"="c:\\windows\\pydrhlr.exe"
"qxugelu"="c:\\windows\\pydrhlr.exe"
"winxacd"="c:\\windows\\pydrhlr.exe"
"fjocuaa"="c:\\windows\\pydrhlr.exe"
"bnfucqd"="c:\\windows\\pydrhlr.exe"
"dauovje"="c:\\windows\\pydrhlr.exe"
"yptsjjn"="c:\\windows\\pydrhlr.exe"
"vjyjrkj"="c:\\windows\\pydrhlr.exe"
"oxmppqc"="c:\\windows\\pydrhlr.exe"
"thlorti"="c:\\windows\\pydrhlr.exe"
"xmnkkug"="c:\\windows\\pydrhlr.exe"
"cknmncn"="c:\\windows\\pydrhlr.exe"
"lxijnfe"="c:\\windows\\pydrhlr.exe"
"mhxtxym"="c:\\windows\\pydrhlr.exe"
"cgctppo"="c:\\windows\\pydrhlr.exe"
"fntveab"="c:\\windows\\pydrhlr.exe"
"asirsgc"="c:\\windows\\pydrhlr.exe"
"pddvvjv"="c:\\windows\\pydrhlr.exe"
"ptndgne"="c:\\windows\\pydrhlr.exe"
"kqmnngr"="c:\\windows\\pydrhlr.exe"
"lxaslrq"="c:\\windows\\pydrhlr.exe"
"pabwshb"="c:\\windows\\pydrhlr.exe"
"mdiiljs"="c:\\windows\\pydrhlr.exe"
"ogjqnpu"="c:\\windows\\pydrhlr.exe"
"vhngdvl"="c:\\windows\\pydrhlr.exe"
"ebcotsq"="c:\\windows\\pydrhlr.exe"
"njrvdye"="c:\\windows\\pydrhlr.exe"
"dcinvix"="c:\\windows\\pydrhlr.exe"
"bjaypha"="c:\\windows\\pydrhlr.exe"
"ccrjyul"="c:\\windows\\pydrhlr.exe"
"iexgvqj"="c:\\windows\\pydrhlr.exe"
"fvwtbrc"="c:\\windows\\pydrhlr.exe"
"neamvom"="c:\\windows\\pydrhlr.exe"
"gbrqera"="c:\\windows\\pydrhlr.exe"
"bpdeyxg"="c:\\windows\\pydrhlr.exe"
"kuspnuh"="c:\\windows\\pydrhlr.exe"
"lwuswsw"="c:\\windows\\pydrhlr.exe"
"mbqyydd"="c:\\windows\\pydrhlr.exe"
"mqhpgip"="c:\\windows\\pydrhlr.exe"
"upbaghx"="c:\\windows\\pydrhlr.exe"
"mobbvcq"="c:\\windows\\pydrhlr.exe"
"opohoff"="c:\\windows\\pydrhlr.exe"
"bcbydae"="c:\\windows\\pydrhlr.exe"
"vvctwxf"="c:\\windows\\pydrhlr.exe"
"vueivbd"="c:\\windows\\pydrhlr.exe"
"euywtbs"="c:\\windows\\pydrhlr.exe"
"nywlljj"="c:\\windows\\pydrhlr.exe"
"kulyris"="c:\\windows\\pydrhlr.exe"
"gkqgxmu"="c:\\windows\\pydrhlr.exe"
"spraylp"="c:\\windows\\pydrhlr.exe"
"dnqclwn"="c:\\windows\\pydrhlr.exe"
"fibqnxw"="c:\\windows\\fkynecs.exe"
"lglereq"="c:\\windows\\rebardy.exe"
"cdarnab"="c:\\windows\\rebardy.exe"
"ryfwufd"="c:\\windows\\rebardy.exe"
"gbxbmfh"="c:\\windows\\rebardy.exe"
"fpobqym"="c:\\windows\\rebardy.exe"
"mapfdpy"="c:\\windows\\rebardy.exe"
"gllfrwi"="c:\\windows\\rebardy.exe"
"xptjwjk"="c:\\windows\\rebardy.exe"
"ismylyf"="c:\\windows\\rebardy.exe"
"mcxmbdk"="c:\\windows\\rebardy.exe"
"mswvaha"="c:\\windows\\rebardy.exe"
"nwmrpeg"="c:\\windows\\rebardy.exe"
"vhyetvy"="c:\\windows\\rebardy.exe"
"jaqlabt"="c:\\windows\\rebardy.exe"
"ipgjjug"="c:\\windows\\rebardy.exe"
"winpbhf"="c:\\windows\\rebardy.exe"
"wissrbv"="c:\\windows\\rebardy.exe"
"amgyusr"="c:\\windows\\rebardy.exe"
"scifmyq"="c:\\windows\\rebardy.exe"
"swbftxa"="c:\\windows\\rebardy.exe"
"oymvwoe"="c:\\windows\\rebardy.exe"
"ofmvnai"="c:\\windows\\rebardy.exe"
"txjdyaw"="c:\\windows\\rebardy.exe"
"quxcjre"="c:\\windows\\rebardy.exe"
"xxtbklc"="c:\\windows\\rebardy.exe"
"mgrecxw"="c:\\windows\\rebardy.exe"
"grlfhvf"="c:\\windows\\rebardy.exe"
"abntmhi"="c:\\windows\\rebardy.exe"
"yndisqy"="c:\\windows\\rebardy.exe"
"mxfinly"="c:\\windows\\rebardy.exe"
"yyydviq"="c:\\windows\\rebardy.exe"
"vgxsscw"="c:\\windows\\rebardy.exe"
"kbriopr"="c:\\windows\\rebardy.exe"
"noajsbc"="c:\\windows\\rebardy.exe"
"kldhsls"="c:\\windows\\rebardy.exe"
"yennoxi"="c:\\windows\\rebardy.exe"
"uqmnwak"="c:\\windows\\rebardy.exe"
"uhxxlrk"="c:\\windows\\wpsedws.exe"
"jheocjg"="c:\\windows\\wpsedws.exe"
"fjvhjdp"="c:\\windows\\wpsedws.exe"
"vgikxsk"="c:\\windows\\wpsedws.exe"
"ucnriao"="c:\\windows\\wpsedws.exe"
"dvyyjev"="c:\\windows\\wpsedws.exe"
"danjwui"="c:\\windows\\wpsedws.exe"
"ccwmhxm"="c:\\windows\\wpsedws.exe"
"wugxlvt"="c:\\windows\\wpsedws.exe"
"akjmryh"="c:\\windows\\wpsedws.exe"
"ufxkvfp"="c:\\windows\\wpsedws.exe"
"tegjjbp"="c:\\windows\\wpsedws.exe"
"nkaqnif"="c:\\windows\\wpsedws.exe"
"segsjcv"="c:\\windows\\ahuohjr.exe"
"jwjfrun"="c:\\windows\\mlgfnwk.exe"
"bxqdbva"="c:\\windows\\mlgfnwk.exe"
"eihjymo"="c:\\windows\\mlgfnwk.exe"
"dgvqolw"="c:\\windows\\mlgfnwk.exe"
"jelwhjo"="c:\\windows\\mlgfnwk.exe"
"ikyrvag"="c:\\windows\\mlgfnwk.exe"
"cchvnph"="c:\\windows\\mlgfnwk.exe"
"vlsywvo"="c:\\windows\\mlgfnwk.exe"
"xofcbry"="c:\\windows\\mlgfnwk.exe"
"apbgjnx"="c:\\windows\\mlgfnwk.exe"
"urmxhkm"="c:\\windows\\mlgfnwk.exe"
"vjudlsp"="c:\\windows\\mlgfnwk.exe"
"clpknwp"="c:\\windows\\mlgfnwk.exe"
"mwycgrj"="c:\\windows\\mlgfnwk.exe"
"hcdsnyb"="c:\\windows\\mlgfnwk.exe"
"rmcbylb"="c:\\windows\\mlgfnwk.exe"
"jaliqux"="c:\\windows\\mlgfnwk.exe"
"krbyldc"="c:\\windows\\mlgfnwk.exe"
"qwmpigy"="c:\\windows\\mlgfnwk.exe"
"opmvnpf"="c:\\windows\\mlgfnwk.exe"
"jwsrprc"="c:\\windows\\mlgfnwk.exe"
"pfmglkd"="c:\\windows\\mlgfnwk.exe"
"lvfdmdt"="c:\\windows\\mlgfnwk.exe"
"jrjuoih"="c:\\windows\\mlgfnwk.exe"
"evhvtup"="c:\\windows\\mlgfnwk.exe"
"wcmhyrq"="c:\\windows\\mlgfnwk.exe"
"iwxonsa"="c:\\windows\\mlgfnwk.exe"
"assnudw"="c:\\windows\\qfarcaj.exe"
"gqvthyy"="c:\\windows\\cyfodva.exe"
"cdlgtnk"="c:\\windows\\lxtwehg.exe"
"eqvlihk"="c:\\windows\\rsdgdpr.exe"
"ndkjoux"="c:\\windows\\rsdgdpr.exe"
"afdkmes"="c:\\windows\\rsdgdpr.exe"
"akernqe"="c:\\windows\\rsdgdpr.exe"
"hrwriku"="c:\\windows\\rsdgdpr.exe"
"sfsysfb"="c:\\windows\\rsdgdpr.exe"
"gsyhbel"="c:\\windows\\rsdgdpr.exe"
"swycdgb"="c:\\windows\\rsdgdpr.exe"
"rhqrelx"="c:\\windows\\rsdgdpr.exe"
"xrxvwsn"="c:\\windows\\rsdgdpr.exe"
"klrdrim"="c:\\windows\\rsdgdpr.exe"
"njbuusw"="c:\\windows\\rsdgdpr.exe"
"cqvchdc"="c:\\windows\\yslnhau.exe"
"lhyfoxu"="c:\\windows\\snvsrer.exe"
"vqjeuhs"="c:\\windows\\snvsrer.exe"
"pexhlxq"="c:\\windows\\snvsrer.exe"
"pfrfxye"="c:\\windows\\snvsrer.exe"
"waamrnh"="c:\\windows\\snvsrer.exe"
"fdjbfeb"="c:\\windows\\snvsrer.exe"
"gnajiyi"="c:\\windows\\snvsrer.exe"
"wfcyblh"="c:\\windows\\snvsrer.exe"
"sdssdvq"="c:\\windows\\snvsrer.exe"
"pgwhxxu"="c:\\windows\\snvsrer.exe"
"qwllyqw"="c:\\windows\\snvsrer.exe"
"qvjscwy"="c:\\windows\\snvsrer.exe"
"gogygvb"="c:\\windows\\snvsrer.exe"
"erxkoyo"="c:\\windows\\snvsrer.exe"
"eeudcdy"="c:\\windows\\snvsrer.exe"
"ufytutl"="c:\\windows\\snvsrer.exe"
"iordvja"="c:\\windows\\snvsrer.exe"
"ftutjfi"="c:\\windows\\sxtadqi.exe"
"mwsslll"="c:\\windows\\sxtadqi.exe"
"ahxdkfh"="c:\\windows\\sxtadqi.exe"
"pbilvsk"="c:\\windows\\sxtadqi.exe"
"qsxyegj"="c:\\windows\\sxtadqi.exe"
"kpjjnvb"="c:\\windows\\sxtadqi.exe"
"hbfvher"="c:\\windows\\sxtadqi.exe"
"hfcevsc"="c:\\windows\\sxtadqi.exe"
"hpjjjti"="c:\\windows\\sxtadqi.exe"
"huvrbxp"="c:\\windows\\sxtadqi.exe"
"tfpveot"="c:\\windows\\sxtadqi.exe"
"jtlqlfk"="c:\\windows\\sxtadqi.exe"
"vhxjxhh"="c:\\windows\\sxtadqi.exe"
"jncntlx"="c:\\windows\\sxtadqi.exe"
"vrliyfh"="c:\\windows\\okpkgpl.exe"
"ykcaopp"="c:\\windows\\wefaudv.exe"
"itrpgel"="c:\\windows\\wefaudv.exe"
"iqpfilo"="c:\\windows\\wefaudv.exe"
"jxsvbyx"="c:\\windows\\wefaudv.exe"
"pcvgfus"="c:\\windows\\wefaudv.exe"
"gvrhxal"="c:\\windows\\wefaudv.exe"
"vtqxgjn"="c:\\windows\\vqoukes.exe"
"sjglldm"="c:\\windows\\vqoukes.exe"
"quasbas"="c:\\windows\\vqoukes.exe"
"knpiwjb"="c:\\windows\\vqoukes.exe"
"hlgvxia"="c:\\windows\\vqoukes.exe"
"nbertrn"="c:\\windows\\vqoukes.exe"
"avrdnnw"="c:\\windows\\vqoukes.exe"
"acdraig"="c:\\windows\\vqoukes.exe"
"lipjtok"="c:\\windows\\vqoukes.exe"
"rtsxbrf"="c:\\windows\\vqoukes.exe"
"wkrlccr"="c:\\windows\\vqoukes.exe"
"cohnksf"="c:\\windows\\vqoukes.exe"
"ujmlskr"="c:\\windows\\vqoukes.exe"
"yidrkjd"="c:\\windows\\vqoukes.exe"
"yuwqlud"="c:\\windows\\vqoukes.exe"
"feunuhf"="c:\\windows\\vqoukes.exe"
"lxubypd"="c:\\windows\\vqoukes.exe"
"jixcudp"="c:\\windows\\vqoukes.exe"
"studluo"="c:\\windows\\vqoukes.exe"
"umswxvr"="c:\\windows\\vqoukes.exe"
"sarykrn"="c:\\windows\\vqoukes.exe"
"llwovpu"="c:\\windows\\vqoukes.exe"
"cwomfku"="c:\\windows\\vqoukes.exe"
"swixlsl"="c:\\windows\\vqoukes.exe"
"kmijdyv"="c:\\windows\\vqoukes.exe"
"tramxdm"="c:\\windows\\vqoukes.exe"
"rnwwwnx"="c:\\windows\\vqoukes.exe"
"lmavxxi"="c:\\windows\\vqoukes.exe"
"kexnwwl"="c:\\windows\\vqoukes.exe"
"mkkytpc"="c:\\windows\\vqoukes.exe"
"khafwqf"="c:\\windows\\vqoukes.exe"
"tjigqfg"="c:\\windows\\vqoukes.exe"
"acqpjct"="c:\\windows\\vqoukes.exe"
"pngjayq"="c:\\windows\\vqoukes.exe"
"uyogkcb"="c:\\windows\\vqoukes.exe"
"cywawjg"="c:\\windows\\vqoukes.exe"
"iqqfwpn"="c:\\windows\\vqoukes.exe"
"nwtfjfn"="c:\\windows\\vqoukes.exe"
"nunvveb"="c:\\windows\\vqoukes.exe"
"wafwgif"="c:\\windows\\vqoukes.exe"
"vuseodi"="c:\\windows\\vqoukes.exe"
"kfcrinr"="c:\\windows\\vqoukes.exe"
"hbrfsks"="c:\\windows\\leaoqpj.exe"
"vmhxjft"="c:\\windows\\leaoqpj.exe"
"djwlvjs"="c:\\windows\\leaoqpj.exe"
"eofvcun"="c:\\windows\\leaoqpj.exe"
"oopsglx"="c:\\windows\\leaoqpj.exe"
"tlmfoud"="c:\\windows\\leaoqpj.exe"
"taexkkb"="c:\\windows\\hfbbynp.exe"
"tlmpdhw"="c:\\windows\\hfbbynp.exe"
"hiwrojy"="c:\\windows\\hfbbynp.exe"
"wisjfhn"="c:\\windows\\hfbbynp.exe"
"lfewojd"="c:\\windows\\hfbbynp.exe"
"jmstlku"="c:\\windows\\hfbbynp.exe"
"mkddjws"="c:\\windows\\hfbbynp.exe"
"pwjsciy"="c:\\windows\\hfbbynp.exe"
"noamgwt"="c:\\windows\\hfbbynp.exe"
"ifpxqmu"="c:\\windows\\hfbbynp.exe"
"faexihe"="c:\\windows\\hfbbynp.exe"
"pqayfjc"="c:\\windows\\hfbbynp.exe"
"fdpcvme"="c:\\windows\\hfbbynp.exe"
"vriiync"="c:\\windows\\hfbbynp.exe"
"xaxnnqq"="c:\\windows\\hfbbynp.exe"
"dnbdkri"="c:\\windows\\hfbbynp.exe"
"ajddcvn"="c:\\windows\\hfbbynp.exe"
"gpaucjh"="c:\\windows\\hfbbynp.exe"
"jqruuve"="c:\\windows\\hfbbynp.exe"
"aogmxlb"="c:\\windows\\hfbbynp.exe"
"qulqxwe"="c:\\windows\\hfbbynp.exe"
"vgsebmg"="c:\\windows\\hfbbynp.exe"
"latepdr"="c:\\windows\\hfbbynp.exe"
"sngugcv"="c:\\windows\\hfbbynp.exe"
"axpfkeh"="c:\\windows\\hfbbynp.exe"
"dwhdbqf"="c:\\windows\\hfbbynp.exe"
"hatsewp"="c:\\windows\\hfbbynp.exe"
"dscldiy"="c:\\windows\\hfbbynp.exe"
"bpdgrse"="c:\\windows\\hfbbynp.exe"
"kqptooh"="c:\\windows\\hfbbynp.exe"
"atambfg"="c:\\windows\\hfbbynp.exe"
"onoplqu"="c:\\windows\\hfbbynp.exe"
"vyogart"="c:\\windows\\hfbbynp.exe"
"auagmnm"="c:\\windows\\hdmvptv.exe"
"dcdllls"="c:\\windows\\hdmvptv.exe"
"yixyctm"="c:\\windows\\hdmvptv.exe"
"hfdsvik"="c:\\windows\\hdmvptv.exe"
"nwiqevu"="c:\\windows\\hdmvptv.exe"
"gshrjjh"="c:\\windows\\hdmvptv.exe"
"mdblucu"="c:\\windows\\hdmvptv.exe"
"lcdvebt"="c:\\windows\\hdmvptv.exe"
"lfraurg"="c:\\windows\\hdmvptv.exe"
"jwbjgyh"="c:\\windows\\hdmvptv.exe"
"kjolyoq"="c:\\windows\\hdmvptv.exe"
"yifdlyb"="c:\\windows\\hdmvptv.exe"
"rqqwapb"="c:\\windows\\hdmvptv.exe"
"apjatpv"="c:\\windows\\hdmvptv.exe"
"viyayhr"="c:\\windows\\hdmvptv.exe"
"ouulkye"="c:\\windows\\hdmvptv.exe"
"tdndkrp"="c:\\windows\\hdmvptv.exe"
"oyfjhle"="c:\\windows\\hdmvptv.exe"
"rylrogx"="c:\\windows\\ojgphmu.exe"
"wspjhco"="c:\\windows\\fmyrdoe.exe"
"jodyigt"="c:\\windows\\fmyrdoe.exe"
"kqubgny"="c:\\windows\\fmyrdoe.exe"
"dwihcic"="c:\\windows\\fmyrdoe.exe"
"watwobc"="c:\\windows\\fmyrdoe.exe"
"gblklqr"="c:\\windows\\brfmmaa.exe"
"apidcpa"="c:\\windows\\brfmmaa.exe"
"cxyjvrr"="c:\\windows\\brfmmaa.exe"
"imfsohb"="c:\\windows\\brfmmaa.exe"
"gcxscgh"="c:\\windows\\brfmmaa.exe"
"yfyohsd"="c:\\windows\\brfmmaa.exe"
"wmmbhmb"="c:\\windows\\brfmmaa.exe"
"ouxuwtw"="c:\\windows\\brfmmaa.exe"
"jmewaqq"="c:\\windows\\brfmmaa.exe"
"nadexwa"="c:\\windows\\brfmmaa.exe"
"iegtxnv"="c:\\windows\\brfmmaa.exe"
"wuqpecm"="c:\\windows\\brfmmaa.exe"
"frftgls"="c:\\windows\\brfmmaa.exe"
"dsxdjna"="c:\\windows\\brfmmaa.exe"
"ovouuyu"="c:\\windows\\brfmmaa.exe"
"iugrccm"="c:\\windows\\brfmmaa.exe"
"teneorg"="c:\\windows\\brfmmaa.exe"
"wsesjpm"="c:\\windows\\brfmmaa.exe"
"feqjope"="c:\\windows\\brfmmaa.exe"
"bgbysxt"="c:\\windows\\brfmmaa.exe"
"iyterka"="c:\\windows\\brfmmaa.exe"
"qwqgdad"="c:\\windows\\brfmmaa.exe"
"ygucxoy"="c:\\windows\\brfmmaa.exe"
"ngwbrou"="c:\\windows\\brfmmaa.exe"
"ljxdail"="c:\\windows\\brfmmaa.exe"
"ucoeenm"="c:\\windows\\brfmmaa.exe"
"agfxxeo"="c:\\windows\\brfmmaa.exe"
"ekynrpa"="c:\\windows\\brfmmaa.exe"
"ysayppx"="c:\\windows\\brfmmaa.exe"
"jbboihi"="c:\\windows\\brfmmaa.exe"
"lhymqjc"="c:\\windows\\brfmmaa.exe"
"nlbwwyj"="c:\\windows\\brfmmaa.exe"
"rahhenk"="c:\\windows\\brfmmaa.exe"
"uxpbrqc"="c:\\windows\\brfmmaa.exe"
"rwwfknu"="c:\\windows\\brfmmaa.exe"
"axvynnr"="c:\\windows\\brfmmaa.exe"
"qnvqybp"="c:\\windows\\brfmmaa.exe"
"bakemql"="c:\\windows\\brfmmaa.exe"
"awtolho"="c:\\windows\\brfmmaa.exe"
"ytrxbwf"="c:\\windows\\brfmmaa.exe"
"urbrtqq"="c:\\windows\\brfmmaa.exe"
"klxjbbm"="c:\\windows\\brfmmaa.exe"
"uvseywh"="c:\\windows\\brfmmaa.exe"
"qhsrxwv"="c:\\windows\\brfmmaa.exe"
"couirbk"="c:\\windows\\brfmmaa.exe"
"kxfjspj"="c:\\windows\\brfmmaa.exe"
"hcxachl"="c:\\windows\\brfmmaa.exe"
"ymovqmw"="c:\\windows\\brfmmaa.exe"
"hreyiqw"="c:\\windows\\brfmmaa.exe"
"xjkhwcs"="c:\\windows\\brfmmaa.exe"
"obsstli"="c:\\windows\\brfmmaa.exe"
  • 0

#8
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
"qbnbpkd"="c:\\windows\\brfmmaa.exe"
"bstromw"="c:\\windows\\brfmmaa.exe"
"ailrtwu"="c:\\windows\\dhfmleg.exe"
"ojfjhos"="c:\\windows\\dhfmleg.exe"
"cpxjwxt"="c:\\windows\\dhfmleg.exe"
"etonvpx"="c:\\windows\\dhfmleg.exe"
"amnpvxv"="c:\\windows\\dhfmleg.exe"
"tkaspke"="c:\\windows\\dhfmleg.exe"
"mfmblip"="c:\\windows\\dhfmleg.exe"
"iianaaw"="c:\\windows\\dhfmleg.exe"
"wtpterm"="c:\\windows\\dhfmleg.exe"
"tuidepa"="c:\\windows\\dhfmleg.exe"
"diqqhps"="c:\\windows\\dhfmleg.exe"
"cbmjhya"="c:\\windows\\leawymq.exe"
"xxoakbv"="c:\\windows\\leawymq.exe"
"hogiksn"="c:\\windows\\leawymq.exe"
"sabvuuj"="c:\\windows\\leawymq.exe"
"mrgekca"="c:\\windows\\ufhslmx.exe"
"dtmujby"="c:\\windows\\ufhslmx.exe"
"yusjhxv"="c:\\windows\\ufhslmx.exe"
"yfcdsqg"="c:\\windows\\duacseq.exe"
"bdtjrvc"="c:\\windows\\duacseq.exe"
"xuinkvt"="c:\\windows\\duacseq.exe"
"pbpuugb"="c:\\windows\\alfccqj.exe"
"bvxvclb"="c:\\windows\\pjecfhk.exe"
"cuwurri"="c:\\windows\\njepvgx.exe"
"gnfyqcm"="c:\\windows\\cwnqbof.exe"
"nymhnej"="c:\\windows\\cwnqbof.exe"
"dnffmke"="c:\\windows\\cwnqbof.exe"
"ydlrppq"="c:\\windows\\xlqqlxf.exe"
"suqmgcn"="c:\\windows\\xlqqlxf.exe"
"Spyware Doctor"="\"C:\\PROGRAM FILES\\SPYWARE DOCTOR\\SWDOCTOR.EXE\" /Q"
"ssxufcv"="c:\\windows\\vpkjpyv.exe"
"afcsclg"="c:\\windows\\vpkjpyv.exe"
"lcelbdh"="c:\\windows\\dmcdyrt.exe"
"bkobcuv"="c:\\windows\\dmcdyrt.exe"
"pgkoatp"="c:\\windows\\dmcdyrt.exe"
"sxqwiop"="c:\\windows\\dmcdyrt.exe"
"gsnquxb"="c:\\windows\\dmcdyrt.exe"
"riuppiu"="c:\\windows\\dmcdyrt.exe"
"ihhkatw"="c:\\windows\\dmcdyrt.exe"
"orkceps"="c:\\windows\\dmcdyrt.exe"
"oukmoec"="c:\\windows\\dmcdyrt.exe"
"gdxcraa"="c:\\windows\\dmcdyrt.exe"
"hgqqbki"="c:\\windows\\dmcdyrt.exe"
"qsgwcmd"="c:\\windows\\dmcdyrt.exe"
"mfhxarq"="c:\\windows\\dmcdyrt.exe"
"efgtkqd"="c:\\windows\\dmcdyrt.exe"
"vballgj"="c:\\windows\\dmcdyrt.exe"
"lknktlx"="c:\\windows\\dmcdyrt.exe"
"fhvddqv"="c:\\windows\\dmcdyrt.exe"
"asvsgbk"="c:\\windows\\dmcdyrt.exe"
"lqdhimx"="c:\\windows\\dmcdyrt.exe"
"cebcekx"="c:\\windows\\dmcdyrt.exe"
"gpmtehf"="c:\\windows\\dmcdyrt.exe"
"livvxof"="c:\\windows\\dmcdyrt.exe"
"wewhmwb"="c:\\windows\\dmcdyrt.exe"
"ienwovg"="c:\\windows\\dmcdyrt.exe"
"gkuclrv"="c:\\windows\\dmcdyrt.exe"
"grccovg"="c:\\windows\\dmcdyrt.exe"
"ykjdice"="c:\\windows\\dmcdyrt.exe"
"nogbajr"="c:\\windows\\pdadlwm.exe"
"yjwuoht"="c:\\windows\\pdadlwm.exe"
"jeigyko"="c:\\windows\\pdadlwm.exe"
"jhnrkgh"="c:\\windows\\pdadlwm.exe"
"cmyxvpc"="c:\\windows\\pdadlwm.exe"
"goldput"="c:\\windows\\usigbro.exe"
"ojibmou"="c:\\windows\\usigbro.exe"
"amntrfe"="c:\\windows\\usigbro.exe"
"ydadeks"="c:\\windows\\usigbro.exe"
"ocqgknp"="c:\\windows\\usigbro.exe"
"pymgmgf"="c:\\windows\\vsiqcan.exe"
"fltprbt"="c:\\windows\\vsiqcan.exe"
"emrvhos"="c:\\windows\\fvqtlkv.exe"
  • 0

#9
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Go to Start->Run and type in regedit and hit OK. Go to File->Export and save the registry somewhere as a backup. Close the Registry Editor now. Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

REGEDIT4
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"Spyware Doctor"="\"C:\\PROGRAM FILES\\SPYWARE DOCTOR\\SWDOCTOR.EXE\" /Q"


Save the file as "delete.reg". Make sure to save it with the quotes. Double click on it and choose Yes to merge it. You may delete the file afterwards.

Download KillBox http://www.greyknigh...spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. Copy the below files and go back to KillBox. Go to File->Paste from Clipboard and then hit the button with a red circle and white X. Confirm to delete and when asked if you want to reboot, say Yes:

c:\windows\ajvoeoj.exe
c:\windows\fquwaty.exe
c:\windows\yxyrjwd.exe
c:\windows\pghfgcw.exe
c:\windows\wgqkacq.exe
c:\windows\ewaumdk.exe
c:\windows\eemeiow.exe
c:\windows\jfwegil.exe
c:\windows\pybqgqe.exe
c:\windows\uikpxxl.exe
c:\windows\uikpxxl.exe
c:\windows\mvdqves.exe
c:\windows\atiyiac.exe
c:\windows\kgjafnw.exe
c:\windows\grtpciw.exe
c:\windows\tuqvsyf.exe
c:\windows\duismvq.exe
c:\windows\msyityk.exe
c:\windows\pydrhlr.exe


If you get a PendingOperations message, just close it and restart your computer manually.

After the restart, run a new HijackThis scan and post that new log here.
  • 0

#10
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
Here is the new log........ but I found that the "abcsearch4u" still in the registry.

Logfile of HijackThis v1.99.1
Scan saved at PM 07:22:00, on 2005/10/3
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINPENJR\WIN32\PPHIDPAD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\TOOLS\NCLTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\RunServices: [yksmqjw] c:\windows\oeldlyp.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Bridge - http://download.game...nts/y/bt1_x.cab
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://kelvin.viewne...m/bl_camera.cab
O16 - DPF: {A2979615-DC81-4AE4-A153-912E3C227058} (Yahoo! 相簿輕鬆上載工具 Class) - http://us.dl1.yimg.c...ropper1_6hk.cab
  • 0

Advertisements


#11
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
Much better :tazz:

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Go to My Computer->Tools (or View)->Folder Options->View tab:
* Under the Hidden files and folders heading, select Show hidden files and folders (it's Show all files for Windows 98).
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm and then click OK.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Make sure to close any open browsers. Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O4 - HKCU\..\Run: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\RunServices: [yksmqjw] c:\windows\oeldlyp.exe


Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

c:\windows\oeldlyp.exe

Restart and run BOTH of these scans:

Run an online virus scan at TrendMicro http://uk.trendmicro...call_launch.php. Just follow the instructions on the site to run the free online scan. If any viruses/trojans are detected, try to delete or clean them in that site. If any are not cleanable, copy and paste the infected files here. You may also use Panda ActiveScan at http://www.pandasoft...ucts/activescan. Post the log from the Panda scan here.

Restart and run a new HijackThis scan. Save the log file and post it here along with the Panda log.
  • 0

#12
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
i try to follow your instruction and HijackThis under Safe Mode, however i the log shows below, i found that

c:\windows\grfdqyq.exe
c:\windows\jvbxkcp.exe

being added again...... also at the bottom of the log found that the update.exe file is added, everytime i open IE my norton internet security will pop up and said that "update.exe" try to connect to DNS server.....

i didn't follow the steps and let you take a look first. after i reboot the computer and run the HijackThis the log become bigger and i will post on the next post.

Logfile of HijackThis v1.99.1
Scan saved at AM 12:20:56, on 2005/10/5
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\Run: [chbdfyy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfoaqqi] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bqvacwh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [irjtdgo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ucgpptw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eajvsfv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtfbscc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ywsgobh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rpdxkii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtilffo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uousict] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [etqoslk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ukclbpm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xtdvnjp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [oiaoopy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rkdqnsc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pqjfwll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [inhlwii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gtdtppu] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ssqnnbp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [drgxjlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [upgmyll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mpxmyel] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pxlouga] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tvqirka] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yigywnr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ciuvowm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yhdpveo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [daojwhw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xklcgke] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyqiovj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pvcemtc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [flkgssy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mojhypt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ppuridv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [hctpymj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dgmsrrc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [blpkggq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [newnjri] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xphktdt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dinjvim] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mayymlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [sccdisn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ksufmkn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qwxouni] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bmakkhr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yamturq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jlacxvf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ydlvsqc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [kwpapgk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [amqylub] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ltktadd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jcjadgy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [nuelvcg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jqcrstl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xraunew] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ceehypl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qyfrxif] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [quoiaop] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xrmqims] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dvtqlqp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dbtgkgd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ahociwo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [doubcbx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fldxblp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [liwnuhe] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ncveodg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uyqyjyj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [utovlbd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fixtlth] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tmruevr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfrblcw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bshnjav] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xpcmgun] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [csnpfps] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyhpgvs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [odtjrfs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ehwjysp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gvgshmf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eusxlrx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ojfmfnq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gpxrbia] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [amhtcbo] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ijsdemy] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ntavugn] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [gtalbrv] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [dkwcrsh] c:\windows\jvbxkcp.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Bridge - http://download.game...nts/y/bt1_x.cab
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://kelvin.viewne...m/bl_camera.cab
O16 - DPF: {A2979615-DC81-4AE4-A153-912E3C227058} (Yahoo! 相簿輕鬆上載工具 Class) - http://us.dl1.yimg.c...ropper1_6hk.cab
O16 - DPF: {D8A8A7F1-53EF-41F2-B44D-F3E2E595DC27} - ms-its:mhtml:file://C:\MAIN.MHT!http://69.50.172.106...hm::/update.exe
  • 0

#13
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
i reboot the computer from safe mode and run the HijackThis again and get this log.......

i found that beside c:\windows\grfdqyq.exe and c:\windows\jvbxkcp.exe

c:\windows\sntngje.exe

is being added........

Logfile of HijackThis v1.99.1
Scan saved at AM 12:24:05, on 2005/10/5
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINPENJR\WIN32\PPHIDPAD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\TOOLS\NCLTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
C:\WINDOWS\OELDLYP.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\Run: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\Run: [chbdfyy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfoaqqi] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bqvacwh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [irjtdgo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ucgpptw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eajvsfv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtfbscc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ywsgobh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rpdxkii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtilffo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uousict] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [etqoslk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ukclbpm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xtdvnjp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [oiaoopy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rkdqnsc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pqjfwll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [inhlwii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gtdtppu] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ssqnnbp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [drgxjlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [upgmyll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mpxmyel] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pxlouga] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tvqirka] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yigywnr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ciuvowm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yhdpveo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [daojwhw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xklcgke] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyqiovj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pvcemtc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [flkgssy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mojhypt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ppuridv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [hctpymj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dgmsrrc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [blpkggq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [newnjri] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xphktdt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dinjvim] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mayymlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [sccdisn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ksufmkn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qwxouni] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bmakkhr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yamturq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jlacxvf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ydlvsqc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [kwpapgk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [amqylub] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ltktadd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jcjadgy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [nuelvcg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jqcrstl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xraunew] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ceehypl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qyfrxif] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [quoiaop] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xrmqims] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dvtqlqp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dbtgkgd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ahociwo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [doubcbx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fldxblp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [liwnuhe] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ncveodg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uyqyjyj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [utovlbd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fixtlth] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tmruevr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfrblcw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bshnjav] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xpcmgun] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [csnpfps] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyhpgvs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [odtjrfs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ehwjysp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gvgshmf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eusxlrx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ojfmfnq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gpxrbia] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [amhtcbo] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ijsdemy] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ntavugn] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [gtalbrv] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [dkwcrsh] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [rpahxct] c:\windows\sntngje.exe
O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\RunServices: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\RunServices: [chbdfyy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tfoaqqi] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bqvacwh] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [irjtdgo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ucgpptw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [eajvsfv] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [vtfbscc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ywsgobh] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [rpdxkii] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [vtilffo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [uousict] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [etqoslk] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ukclbpm] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xtdvnjp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [oiaoopy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [rkdqnsc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pqjfwll] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [inhlwii] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gtdtppu] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ssqnnbp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [drgxjlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [upgmyll] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mpxmyel] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pxlouga] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tvqirka] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yigywnr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ciuvowm] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yhdpveo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [daojwhw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xklcgke] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [iyqiovj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pvcemtc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [flkgssy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mojhypt] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ppuridv] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [hctpymj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dgmsrrc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [blpkggq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [newnjri] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xphktdt] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dinjvim] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mayymlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [sccdisn] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ksufmkn] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [qwxouni] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bmakkhr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yamturq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jlacxvf] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ydlvsqc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [kwpapgk] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [amqylub] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ltktadd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jcjadgy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [nuelvcg] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jqcrstl] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xraunew] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ceehypl] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [qyfrxif] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [quoiaop] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xrmqims] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dvtqlqp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dbtgkgd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ahociwo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [doubcbx] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [fldxblp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [liwnuhe] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ncveodg] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [uyqyjyj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [utovlbd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [fixtlth] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tmruevr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tfrblcw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bshnjav] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xpcmgun] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [csnpfps] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [iyhpgvs] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [odtjrfs] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ehwjysp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gvgshmf] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [eusxlrx] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ojfmfnq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gpxrbia] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [amhtcbo] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [ijsdemy] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [ntavugn] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [gtalbrv] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [dkwcrsh] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [rpahxct] c:\windows\sntngje.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Bridge - http://download.game...nts/y/bt1_x.cab
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://kelvin.viewne...m/bl_camera.cab
O16 - DPF: {A2979615-DC81-4AE4-A153-912E3C227058} (Yahoo! 相簿輕鬆上載工具 Class) - http://us.dl1.yimg.c...ropper1_6hk.cab
O16 - DPF: {D8A8A7F1-53EF-41F2-B44D-F3E2E595DC27} - ms-its:mhtml:file://C:\MAIN.MHT!http://69.50.172.106...hm::/update.exe
  • 0

#14
greyknight17

greyknight17

    Malware Expert

  • Visiting Consultant
  • 16,560 posts
OK, we'll have to do it the hard way then.

Download and Save spywad9xremove to your computer from this link: http://www.thespykil...wad9xremove.exe

Double click on the spywad9xremove.exe file and it will automatically extract to c:\spywad9x where it needs to be to run.

It will automatically open the 98 remove spywad.vbs script for you ready to paste in the line mentioned below

If it doesn't open then go to c:\spywad9x and double click on the 98 remove spywad.vbs Do not run any other file from there please unless asked to.

If you have script blocking enabled you will get a warning about a malicious script wanting to run. Please allow this script to run. It is not malicious.

It will open an Input box. Paste this line into the box

c:\windows\oeldlyp.exe

The script will kill that process, backup and then delete any matching files in Windows System and your Windows Directory. It will create a log of all files deleted. This log file will be named Spywad.txt and be located inside the C:\Spywad9x Folder. The backups will also be located in two subfolders there. One named Systems and the other named Window.

The script will search the Windows Directory and delete desktop.html and popup.html if they exist. It will add entries to the log if these files are found and deleted.

It will then kill Explorer. You will lose your taskbar and desktop. It will repair the registry entries returning your normal desktop and context menu functions.

It will restart Explorer.


** Script Does not remove the orphaned run entries.

Finally, it will Run hijackthis so that you can remove the orphaned run entries and anything else as instructed by your Advisor on the forums.

If hijackthis doesn't start, run it manually.

Run a HijackThis scan. Check and fix these entries:

O4 - HKCU\..\Run: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\Run: [chbdfyy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfoaqqi] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bqvacwh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [irjtdgo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ucgpptw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eajvsfv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtfbscc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ywsgobh] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rpdxkii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [vtilffo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uousict] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [etqoslk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ukclbpm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xtdvnjp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [oiaoopy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [rkdqnsc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pqjfwll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [inhlwii] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gtdtppu] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ssqnnbp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [drgxjlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [upgmyll] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mpxmyel] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pxlouga] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tvqirka] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yigywnr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ciuvowm] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yhdpveo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [daojwhw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xklcgke] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyqiovj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [pvcemtc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [flkgssy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mojhypt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ppuridv] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [hctpymj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dgmsrrc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [blpkggq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [newnjri] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xphktdt] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dinjvim] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [mayymlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [sccdisn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ksufmkn] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qwxouni] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bmakkhr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [yamturq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jlacxvf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ydlvsqc] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [kwpapgk] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [amqylub] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ltktadd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jcjadgy] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [nuelvcg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [jqcrstl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xraunew] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ceehypl] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [qyfrxif] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [quoiaop] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xrmqims] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dvtqlqp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [dbtgkgd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ahociwo] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [doubcbx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fldxblp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [liwnuhe] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ncveodg] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [uyqyjyj] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [utovlbd] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [fixtlth] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tmruevr] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [tfrblcw] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [bshnjav] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [xpcmgun] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [csnpfps] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [iyhpgvs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [odtjrfs] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ehwjysp] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gvgshmf] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [eusxlrx] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [ojfmfnq] c:\windows\grfdqyq.exe
O4 - HKCU\..\Run: [gpxrbia] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [amhtcbo] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ijsdemy] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [ntavugn] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [gtalbrv] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [dkwcrsh] c:\windows\jvbxkcp.exe
O4 - HKCU\..\Run: [rpahxct] c:\windows\sntngje.exe
O4 - HKCU\..\RunServices: [yksmqjw] c:\windows\oeldlyp.exe
O4 - HKCU\..\RunServices: [chbdfyy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tfoaqqi] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bqvacwh] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [irjtdgo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ucgpptw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [eajvsfv] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [vtfbscc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ywsgobh] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [rpdxkii] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [vtilffo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [uousict] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [etqoslk] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ukclbpm] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xtdvnjp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [oiaoopy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [rkdqnsc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pqjfwll] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [inhlwii] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gtdtppu] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ssqnnbp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [drgxjlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [upgmyll] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mpxmyel] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pxlouga] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tvqirka] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yigywnr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ciuvowm] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yhdpveo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [daojwhw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xklcgke] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [iyqiovj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [pvcemtc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [flkgssy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mojhypt] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ppuridv] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [hctpymj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dgmsrrc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [blpkggq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [newnjri] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xphktdt] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dinjvim] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [mayymlp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [sccdisn] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ksufmkn] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [qwxouni] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bmakkhr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [yamturq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jlacxvf] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ydlvsqc] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [kwpapgk] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [amqylub] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ltktadd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jcjadgy] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [nuelvcg] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [jqcrstl] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xraunew] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ceehypl] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [qyfrxif] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [quoiaop] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xrmqims] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dvtqlqp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [dbtgkgd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ahociwo] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [doubcbx] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [fldxblp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [liwnuhe] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ncveodg] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [uyqyjyj] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [utovlbd] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [fixtlth] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tmruevr] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [tfrblcw] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [bshnjav] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [xpcmgun] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [csnpfps] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [iyhpgvs] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [odtjrfs] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ehwjysp] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gvgshmf] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [eusxlrx] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [ojfmfnq] c:\windows\grfdqyq.exe
O4 - HKCU\..\RunServices: [gpxrbia] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [amhtcbo] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [ijsdemy] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [ntavugn] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [gtalbrv] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [dkwcrsh] c:\windows\jvbxkcp.exe
O4 - HKCU\..\RunServices: [rpahxct] c:\windows\sntngje.exe
O16 - DPF: {D8A8A7F1-53EF-41F2-B44D-F3E2E595DC27} - ms-its:mhtml:file://C:\MAIN.MHT!http://69.50.172.106...hm::/update.exe


Download KillBox http://www.greyknigh...spy/KillBox.exe. Run KillBox and check the box that says 'End Explorer Shell While Killing File'. Next click on 'Delete on Reboot'. Copy the below files and go back to KillBox. Go to File->Paste from Clipboard and then hit the button with a red circle and white X. Confirm to delete and when asked if you want to reboot, say Yes:

c:\windows\grfdqyq.exe
c:\windows\jvbxkcp.exe
c:\windows\oeldlyp.exe
c:\windows\sntngje.exe


If you get a PendingOperations message, just close it and restart your computer manually.


When finished, post the contents of Spywad.txt and a new Hijackthis log.

If the files deleted are all found to be part of the infection and nothing important has been deleted, you will be instructed to delete the entire Spywad Folder after you have cleaned up all other User Profiles on that system.

Once you have performed the big cleanup, each of the other Users on the System needs to be signed in to clean up their desktop and regain the right click.

I have included another vbs to do this. It is named 98 registry only.vbs

Have each User sign in and run 98 registry only.vbs
Open C:\ (Go to Start>Run and type C: Press enter) and Open the C:\Spywad9x folder. Double click on 98 registry only.vbs

Explorer will be ended and that user's active desktop registry entries will be repaired. Explorer will be restarted.

Run HijackThis again and fix the below (read below for more information):

Check and fix the same entries I listed for you previously (if they are still found).

To restore the desktop to whatever picture you normally have right click on a blank part of desktop & select properties/desktop & select your prefered picture press apply & then ok to exit and then Click on the desktop. Press F5 once or twice to refresh.

You will need to do this step for every user account.
  • 0

#15
kelvindou

kelvindou

    Member

  • Topic Starter
  • Member
  • PipPip
  • 41 posts
thanks again for helping me out.......

when i run the spywad it didn't "kill the Explorer" is it normal?
also when i run the killbox when i choose Go to File->Paste from Clipboard nothing come out and i only input those file with the path in the box and click the red "X" botton, is it ok?

this machine only got one user and i think no other user login because there is no login from the beginning of the window start up

the following is the HijackThis log and the Spywad.txt

Logfile of HijackThis v1.99.1
Scan saved at AM 02:14:49, on 2005/10/5
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINPENJR\WIN32\PPHIDPAD.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPROXY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ANALOG DEVICES\SOUNDMAX\SMTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\DATALAYER\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\TOOLS\NCLTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE
C:\PROGRAM FILES\COMMON FILES\PCSUITE\SERVICES\SERVICELAYER.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
D:\MY DOCUMENTS\KELVIN\HIJACKTHIS.EXE

O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDSG.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1028,收音機[&R] - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSAudio] C:\WINDOWS\SYSTEM\MP_S3.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\Tools\NclTray.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [PPHIDPAD] C:\WINPENJR\Win32\pphidpad.exe
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [ccProxy] C:\PROGRA~1\COMMON~1\SYMANT~1\CCPROXY.EXE
O4 - HKLM\..\RunServices: [SndSrvc] C:\PROGRA~1\COMMON~1\SYMANT~1\SNDSRVC.EXE
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - HKCU\..\RunServices: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\RunServices: [Spyware Doctor] "C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\TOOLS\IESDPB.DLL
O16 - DPF: Yahoo! Pyramids - http://download.game...ts/y/pyt1_x.cab
O16 - DPF: Yahoo! Bridge - http://download.game...nts/y/bt1_x.cab
O16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://kelvin.viewne...m/bl_camera.cab
O16 - DPF: {A2979615-DC81-4AE4-A153-912E3C227058} (Yahoo! 相簿輕鬆上載工具 Class) - http://us.dl1.yimg.c...ropper1_6hk.cab

Spywad.txt
2005/10/5 AM 01:58:22
C:\WINDOWS\SYSTEM\mldqbheh.exe
C:\WINDOWS\sntngje.exe
C:\WINDOWS\grfdqyq.exe
C:\WINDOWS\jvbxkcp.exe
C:\WINDOWS\fkynecs.exe
C:\WINDOWS\rebardy.exe
C:\WINDOWS\wpsedws.exe
C:\WINDOWS\ahuohjr.exe
C:\WINDOWS\mlgfnwk.exe
C:\WINDOWS\qfarcaj.exe
C:\WINDOWS\cyfodva.exe
C:\WINDOWS\lxtwehg.exe
C:\WINDOWS\rsdgdpr.exe
C:\WINDOWS\yslnhau.exe
C:\WINDOWS\snvsrer.exe
C:\WINDOWS\sxtadqi.exe
C:\WINDOWS\okpkgpl.exe
C:\WINDOWS\wefaudv.exe
C:\WINDOWS\vqoukes.exe
C:\WINDOWS\leaoqpj.exe
C:\WINDOWS\hfbbynp.exe
C:\WINDOWS\hdmvptv.exe
C:\WINDOWS\ojgphmu.exe
C:\WINDOWS\fmyrdoe.exe
C:\WINDOWS\brfmmaa.exe
C:\WINDOWS\dhfmleg.exe
C:\WINDOWS\leawymq.exe
C:\WINDOWS\ufhslmx.exe
C:\WINDOWS\duacseq.exe
C:\WINDOWS\alfccqj.exe
C:\WINDOWS\pjecfhk.exe
C:\WINDOWS\njepvgx.exe
C:\WINDOWS\cwnqbof.exe
C:\WINDOWS\xlqqlxf.exe
C:\WINDOWS\vpkjpyv.exe
C:\WINDOWS\dmcdyrt.exe
C:\WINDOWS\pdadlwm.exe
C:\WINDOWS\usigbro.exe
C:\WINDOWS\vsiqcan.exe
C:\WINDOWS\unsatti.exe
C:\WINDOWS\fvqtlkv.exe
C:\WINDOWS\mrtnoge.exe
C:\WINDOWS\eskngyv.exe
C:\WINDOWS\oeldlyp.exe
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP