Well someone may recognize them, I know I don't though.
They look similar to these:
O4 - HKLM\..\Run: [JYXOH931.exe] C:\WINDOWS\system32\JYXOH931.exe
O4 - HKLM\..\Run: [Z2WDQLRP.exe] C:\WINDOWS\system32\Z2WDQLRP.exe
O4 - HKLM\..\Run: [FJMTSEYI.exe] C:\WINDOWS\system32\FJMTSEYI.exe
O4 - HKLM\..\Run: [VXSNC3EC.exe] C:\WINDOWS\system32\VXSNC3EC.exe
O4 - HKLM\..\Run: [SH11PD2S.exe] C:\WINDOWS\system32\SH11PD2S.exe
O4 - HKLM\..\Run: [I8OK6QNG.exe] C:\WINDOWS\system32\I8OK6QNG.exe
O4 - HKLM\..\Run: [X2B4KL19.exe] C:\WINDOWS\system32\X2B4KL19.exe
O4 - HKLM\..\Run: [6EOKRHLJ.exe] C:\WINDOWS\system32\6EOKRHLJ.exe
O4 - HKLM\..\Run: [C5A7ISZ9.exe] C:\WINDOWS\system32\C5A7ISZ9.exe
O4 - HKLM\..\Run: [B4MJFI4U.exe] C:\WINDOWS\system32\B4MJFI4U.exe
O4 - HKLM\..\Run: [ZAUO1HQB.exe] C:\WINDOWS\system32\ZAUO1HQB.exe
O4 - HKLM\..\Run: [15ZH8C38.exe] C:\WINDOWS\system32\15ZH8C38.exe
O4 - HKLM\..\Run: [SVJJETQ9.exe] C:\WINDOWS\system32\SVJJETQ9.exe
O4 - HKLM\..\Run: [BXFYRJVN.exe] C:\WINDOWS\system32\BXFYRJVN.exe
O4 - HKLM\..\Run: [NW922BYO.exe] C:\WINDOWS\system32\NW922BYO.exe
O4 - HKLM\..\Run: [S29LFOLX.exe] C:\WINDOWS\system32\S29LFOLX.exe
O4 - HKLM\..\Run: [DC5OMKDS.exe] C:\WINDOWS\system32\DC5OMKDS.exe
O4 - HKLM\..\Run: [F2653LPC.exe] C:\WINDOWS\system32\F2653LPC.exe
O4 - HKLM\..\Run: [4E8F1COZ.exe] C:\WINDOWS\system32\4E8F1COZ.exe
O4 - HKLM\..\Run: [228PV3S8.exe] C:\WINDOWS\system32\228PV3S8.exe
O4 - HKLM\..\Run: [CYJU3Q16.exe] C:\WINDOWS\system32\CYJU3Q16.exe
O4 - HKLM\..\Run: [6FLD6HPM.exe] C:\WINDOWS\system32\6FLD6HPM.exe
O4 - HKLM\..\Run: [UUYVEZPW.exe] C:\WINDOWS\system32\UUYVEZPW.exe
O4 - HKLM\..\Run: [JKOB3QZV.exe] C:\WINDOWS\system32\JKOB3QZV.exe
O4 - HKLM\..\Run: [824BNV5U.exe] C:\WINDOWS\system32\824BNV5U.exe
O4 - HKLM\..\Run: [NNVIIBKB.exe] C:\WINDOWS\system32\NNVIIBKB.exe
O4 - HKLM\..\Run: [JP54FCT9.exe] C:\WINDOWS\system32\JP54FCT9.exe
Check out the thread here:
http://www.geekstogo...t=0If it looks the same to you I think all these are headed by these:
O4 - HKLM\..\Run: [Windows NT Update Manager] WINL0G0N.exe
W32 Shoho @ MM
http://[email protected]-=jonnyrotten=-