Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #11  
Old 04-15-2005, 09:40 PM
sula sula is offline
Junior Member
 
Join Date: Apr 2005
Posts: 8
Ok here you go :

File C:\WINDOWS\System32\mocih.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~1.EXE infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2F.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~2.EXE infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp39.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~3.EXE infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp32.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\slbaaaaa.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\Loader.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File c:\windows\system\BHOmod.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\Loader.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File c:\windows\system\BHOmod.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File C:\windows\system32\eliteett32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate03430305[1].exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate07872521[1].exe infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate52561670[1].exe infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mocih.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File System Found infected by "lq Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "WebSiteViewer Spyware/Adware" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1711.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1712.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1742.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3025.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3044.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3545.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3822.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3840.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys458.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys53.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aaeftaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aamicaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aeadlmem.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aeejaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aelghqji.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aenaecys.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aesqaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aidruaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\amkswaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\cmdtel.exe infected by "Email-Worm.Win32.Bagz.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\cmdteld.exe infected by "Email-Worm.Win32.Bagz.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\djklaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnjduyay.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnttrypt.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnvmohwj.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\draaaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\gltyqeum.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\gplaaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\init32m.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jghrrlau.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jkaaaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jkmfraaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jktwwaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mocihd.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mtiddaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mtvfaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mxgknaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mxwpcnfy.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\pajaaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\peryeaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\piswaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\pmaareri.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\q17i9a4j.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\rnai.exe infected by "not-a-virus:AdWare.PurityScan.w" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\sdjdgxye.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\sdrbaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\slbaaaaa.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\syprccft.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\syqdnprl.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vqmyvaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vqojalki.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vu****to.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vuldrsim.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vunhtfnl.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vutrkaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2C.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2D.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2F.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp3.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp32.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp39.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp41.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp44.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp45.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp6.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp7.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp8.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp9.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmpB.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmpD.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\a775a87a[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\free****hotel[1].htm infected by "Trojan-Clicker.JS.Linker.j" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\rdgCA1882[1].exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ CHIZ8H6V\124365[1].exe infected by "not-a-virus:****-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ CHIZ8H6V\count5[1].htm infected by "Trojan-Downloader.VBS.Psyme.ap" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ WX2J49MV\MediaTicketsInstaller[1].cab infected by "not-a-virus:AdWare.MediaTickets.f" Virus. Action Taken: No Action Taken.
File C:\124365.exe infected by "not-a-virus:****-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy3.zi p infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.
Reply With Quote
  #12  
Old 04-15-2005, 09:47 PM
sula sula is offline
Junior Member
 
Join Date: Apr 2005
Posts: 8
Wait.. more are coming... so forget my last post... here's the real one...


File C:\WINDOWS\System32\mocih.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~1.EXE infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2F.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~2.EXE infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp39.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~3.EXE infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp32.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\slbaaaaa.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\Loader.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File c:\windows\system\BHOmod.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\SYSTEM\Loader.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File c:\windows\system\BHOmod.dll infected by "Trojan-Downloader.Win32.Agent.li" Virus. Action Taken: No Action Taken.
File C:\windows\system32\eliteett32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate03430305[1].exe infected by "Trojan-Dropper.Win32.Small.ue" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate07872521[1].exe infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate52561670[1].exe infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mocih.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File System Found infected by "lq Spyware/Adware" Virus. Action Taken: No Action Taken.
File System Found infected by "WebSiteViewer Spyware/Adware" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1711.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1712.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys1742.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3025.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3044.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3545.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3822.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys3840.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys458.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\sys53.exe infected by "Trojan-Proxy.Win32.Lager.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\ucmoreiex.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore.a" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aaeftaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aamicaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aeadlmem.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aeejaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aelghqji.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aenaecys.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aesqaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\aidruaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\amkswaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\cmdtel.exe infected by "Email-Worm.Win32.Bagz.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\cmdteld.exe infected by "Email-Worm.Win32.Bagz.i" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\djklaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnjduyay.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnttrypt.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\dnvmohwj.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\draaaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\gltyqeum.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\gplaaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\init32m.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jghrrlau.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jkaaaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jkmfraaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\jktwwaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mocihd.exe infected by "Email-Worm.Win32.Bagz.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mtiddaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mtvfaaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mxgknaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mxwpcnfy.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\pajaaaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\peryeaaa.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\piswaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\pmaareri.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\q17i9a4j.exe infected by "not-a-virus:AdWare.Sahat.o" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\rnai.exe infected by "not-a-virus:AdWare.PurityScan.w" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\sdjdgxye.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\sdrbaaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\slbaaaaa.exe infected by "Trojan-Downloader.Win32.Agent.ho" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\syprccft.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\syqdnprl.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vqmyvaaa.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vqojalki.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vu****to.exe infected by "Trojan-Dropper.Win32.Small.uz" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vuldrsim.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vunhtfnl.exe infected by "Trojan-Dropper.Win32.Small.wv" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\vutrkaaa.exe infected by "Trojan-Dropper.Win32.Agent.ii" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2C.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2D.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2F.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp3.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp32.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp39.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp41.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp44.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp45.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp6.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp7.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp8.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp9.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmpB.tmp infected by "Trojan-Downloader.Win32.Small.aql" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmpD.tmp infected by "Trojan-Downloader.Win32.Murlo.s" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\a775a87a[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\free****hotel[1].htm infected by "Trojan-Clicker.JS.Linker.j" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ 45YNCL2R\rdgCA1882[1].exe infected by "Trojan.Win32.Dialer.ht" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ CHIZ8H6V\124365[1].exe infected by "not-a-virus:****-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ CHIZ8H6V\count5[1].htm infected by "Trojan-Downloader.VBS.Psyme.ap" Virus. Action Taken: No Action Taken.
File C:\DOCUME~1\Olivier\LOCALS~1\TEMPOR~1\Content.IE5\ WX2J49MV\MediaTicketsInstaller[1].cab infected by "not-a-virus:AdWare.MediaTickets.f" Virus. Action Taken: No Action Taken.
File C:\124365.exe infected by "not-a-virus:****-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy3.zi p infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Bureau\backups\backup-20050413-063938-670.dll infected by "not-a-virus:AdWare.PurityScan.ak" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Bureau\backups\backup-20050414-215801-112.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.af" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Bureau\backups\backup-20050414-215801-848.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Bureau\backups\backup-20050414-222602-431.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.af" Virus. Action Taken: No Action Taken.
File C:\Documents and Settings\Olivier\Bureau\backups\backup-20050414-222602-568.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
Reply With Quote
  #13  
Old 04-15-2005, 09:53 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Ill have a reply in about 30 minutes so chqack back then please..
Reply With Quote
  #14  
Old 04-15-2005, 10:18 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Now download killbox.exe from here http://www.spyware911.net/downloads/KillBox.exe

Open and in the space provided paste this line:
C:\WINDOWS\System32\mocih.exe
Then tick "Delete on reboot"
Then tick the red x.
Do not reboot when asked, we must save that till the end. do the above process for each of these files first:

C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~1.EXE

C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp2F.tmp

C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~2.EXE

C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp39.tmp

C:\DOCUME~1\Olivier\MENUDM~1\PROGRA~1\DMARRA~1\WIN UPD~3.EXE

C:\DOCUME~1\Olivier\LOCALS~1\Temp\tmp32.tmp

C:\WINDOWS\System32\slbaaaaa.exe

C:\WINDOWS\SYSTEM\Loader.dll

c:\windows\system\BHOmod.dll

C:\WINDOWS\SYSTEM\Loader.dll

c:\windows\system\BHOmod.dll

C:\windows\system32\eliteett32.exe

C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate03430305[1].exe

C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate07872521[1].exe

C:\Documents and Settings\Olivier\Menu Démarrer\Programmes\Démarrage\winupdate52561670[1].exe

C:\WINDOWS\System32\mocih.exe

C:\WINDOWS\sys1711.exe

C:\WINDOWS\sys1712.exe

C:\WINDOWS\sys1742.exe

C:\WINDOWS\sys3025.exe

C:\WINDOWS\sys3044.exe

C:\WINDOWS\sys3545.exe

C:\WINDOWS\sys3822.exe

C:\WINDOWS\sys3840.exe

C:\WINDOWS\sys458.exe

C:\WINDOWS\sys53.exe

C:\WINDOWS\ucmoreiex.exe

C:\WINDOWS\System32\aaeftaaa.exe

C:\WINDOWS\System32\aamicaaa.exe

C:\WINDOWS\System32\aeadlmem.exe

C:\WINDOWS\System32\aeejaaaa.exe

C:\WINDOWS\System32\aelghqji.exe

C:\WINDOWS\System32\aenaecys.exe

C:\WINDOWS\System32\aesqaaaa.exe

C:\WINDOWS\System32\aidruaaa.exe

C:\WINDOWS\System32\amkswaaa.exe

C:\WINDOWS\System32\cmdtel.exe

C:\WINDOWS\System32\cmdteld.exe

C:\WINDOWS\System32\djklaaaa.exe

C:\WINDOWS\System32\dnjduyay.exe

C:\WINDOWS\System32\dnttrypt.exe

C:\WINDOWS\System32\dnvmohwj.exe

C:\WINDOWS\System32\draaaaaa.exe

C:\WINDOWS\System32\gltyqeum.exe

C:\WINDOWS\System32\gplaaaaa.exe

C:\WINDOWS\System32\init32m.exe

C:\WINDOWS\System32\jghrrlau.exe

C:\WINDOWS\System32\jkaaaaaa.exe

C:\WINDOWS\System32\jkmfraaa.exe

C:\WINDOWS\System32\jktwwaaa.exe

C:\WINDOWS\System32\mocihd.exe

C:\WINDOWS\System32\mtiddaaa.exe

C:\WINDOWS\System32\mtvfaaaa.exe

C:\WINDOWS\System32\mxgknaaa.exe

C:\WINDOWS\System32\mxwpcnfy.exe

C:\WINDOWS\System32\pajaaaaa.exe

C:\WINDOWS\System32\peryeaaa.exe

C:\WINDOWS\System32\piswaaaa.exe

C:\WINDOWS\System32\pmaareri.exe

C:\WINDOWS\System32\q17i9a4j.exe

C:\WINDOWS\System32\rnai.exe

C:\WINDOWS\System32\sdjdgxye.exe

C:\WINDOWS\System32\sdrbaaaa.exe

C:\WINDOWS\System32\slbaaaaa.exe

C:\WINDOWS\System32\syprccft.exe

C:\WINDOWS\System32\syqdnprl.exe

C:\WINDOWS\System32\vqmyvaaa.exe

C:\WINDOWS\System32\vqojalki.exe

C:\WINDOWS\System32\vu****to.exe

C:\WINDOWS\System32\vuldrsim.exe

C:\WINDOWS\System32\vunhtfnl.exe

C:\WINDOWS\System32\vutrkaaa.exe


C:\124365.exe

Then do this following:
Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin


Then this:

Go to Start>Run and type msconfig Press enter.

When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.

Check the box labeled Turn off System restore on all Drives.


Reboot. Go back in and Turn System Restore Back on. A new Restore Point will be created.


Now reboot

Rescan with hijackthis again and post a fresh log for me please.
Reply With Quote
  #15  
Old 04-15-2005, 11:13 PM
sula sula is offline
Junior Member
 
Join Date: Apr 2005
Posts: 8
Here a fresh log :

Logfile of HijackThis v1.99.1
Scan saved at 23:11:23, on 2005-04-15
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPMon32.exe
C:\windows\system32\taskmg.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Documents and Settings\Olivier\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://w-find.com/index.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w-find.com/index.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://w-find.com/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://w-find.com/index.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll (file missing)
O2 - BHO: BHOmodObj Class - {7F6828CA-9E42-462C-BC60-418C8144012C} - c:\windows\system\BHOmod.dll (file missing)
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPMon32.exe"
O4 - HKLM\..\Run: [ASDPLUGIN] C:\WINDOWS\System32\canada.exe -N
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmg.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [labjyji] c:\windows\xmdwvgd.exe
O4 - HKCU\..\Run: [eydqnxw] c:\windows\xmdwvgd.exe
O4 - HKCU\..\Run: [rbcqgpr] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [qidkenp] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [lxqqhkt] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [qyiygej] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [viggfwp] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [yircvyf] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [umloyqw] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [jdrjtks] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [grmfvmh] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [kxmrqrt] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [fdxhwqw] c:\windows\ayqswnt.exe
O4 - HKCU\..\Run: [ekfiwra] c:\windows\peqygva.exe
O4 - HKCU\..\Run: [ybscoyt] c:\windows\vejuouo.exe
O4 - HKCU\..\Run: [tqghire] c:\windows\vejuouo.exe
O4 - HKCU\..\Run: [fhpoumf] c:\windows\vejuouo.exe
O4 - HKCU\..\Run: [lrqrcyj] c:\windows\vejuouo.exe
O4 - HKCU\..\Run: [dgrklwd] c:\windows\vejuouo.exe
O4 - HKCU\..\Run: [slrsose] c:\windows\ifbvpbj.exe
O4 - HKCU\..\Run: [xmvxemx] c:\windows\ifbvpbj.exe
O4 - HKCU\..\Run: [faotflo] c:\windows\ifbvpbj.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [xjsyidf] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [vkuwbky] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [evfvtje] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [psryxgk] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [kyenkvm] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ebgabuq] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [qqqihrc] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ylcdcks] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [uyudqxs] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [uqauvss] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [hiqobhb] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [adraxyc] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [gwjqpgp] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [tnkqwvv] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [vqxdlej] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [dupnwqg] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [fxuetmm] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [duwbgmn] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [fsgytui] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [arjlspk] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [amwkmhy] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ijlfwlm] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [neguiwv] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [sfoutje] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [rjeykyv] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [lsqfyvq] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [krwrtlj] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ycnmxav] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [kqhbjrl] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [edbrsgr] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [bjjfbsh] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [iybmyuo] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [oobrwhr] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [cfadblq] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ojphxdr] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [goxjuip] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ymvjdfk] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [afkijos] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [cbefudf] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [npytmih] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [cwkgdkj] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [wvewysc] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [wrrkfep] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [grhuosp] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [dgosejq] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [hbdpdhf] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [rqsrvti] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [cfhpdmv] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [hxuwqbp] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [hfqwkpw] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [sdmssfk] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [mjfneol] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [agdxnsj] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [yvhgqbt] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [dhjnntc] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [udwuoxl] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [binnkxq] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [ismsktd] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [wxtvpjl] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [oaiwmjl] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [raxiuoh] c:\windows\qvkdeqq.exe
O4 - HKCU\..\Run: [vuogjhs] c:\windows\jgyupmi.exe
O4 - HKCU\..\Run: [osgkcib] c:\windows\iyoayom.exe
O4 - HKCU\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O4 - Global Startup: Assistant Internet.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Universite Laval Client VPN ULaval.lnk = C:\Program Files\UnivLaval\vpngui.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {7A237B81-9A42-404D-89E5-76AA84F49C01} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {7A237B81-9A42-404D-89E5-76AA84F49C01} - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\flsmngr.dll
O16 - DPF: {08BF6530-81D5-32FF-D4A6-33AC59A50AA4} - http://69.50.182.94/1/rdgCA1882.exe
O16 - DPF: {1D324B44-616A-17F1-ECFC-5F147C414204} - http://69.50.182.94/1/rdgCA1882.exe
O16 - DPF: {1E8DC3CA-AB1C-277A-3B70-33577A024A19} - http://69.50.182.94/1/rdgCA1882.exe
O16 - DPF: {3D2594C1-55AF-1EFE-82E9-60BD24982DA5} - http://69.50.182.94/1/rdgCA1882.exe
O16 - DPF: {4961D849-5BA7-35EE-D97C-1BEA1F8B03FF} - http://69.50.182.94/1/rdgCA1882.exe
O23 - Service: Trace network connections (ACCRA) - Unknown owner - C:\WINDOWS\System32\mocih.exe (file missing)
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
Reply With Quote
  #16  
Old 04-15-2005, 11:15 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
OK and another mwav scan as well.
Reply With Quote
  #17  
Old 04-16-2005, 12:16 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Lets now have you follow along with this http://www.spyware911.net/forum/inde...page&pg=Bube.d
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    2 Problems Need Help theamcguy Windows 2000 | Windows xp | Vista 3 08-27-2005 08:29 PM
    got some virus problems scott86 Spyware / Virus Removal 3 04-05-2005 02:20 PM
    Norton Firewall 2005 install problems aazatgrabya Antivirus | firewall 1 01-28-2005 05:59 PM
    Win XP Installation Problems kadu1669 Windows 2000 | Windows xp | Vista 2 01-18-2005 01:13 PM
    Adaware update problems.... Pancake Software Update Alerts 0 11-04-2004 10:26 PM



    All times are GMT -5. The time now is 05:49 PM.


    Firefox 2