Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

Goto page : 1, 2  Next

View previous topic View next topic Go down  Message [Page 1 of 2]

1 sure i have a virus on Fri May 28, 2010 1:59 am

luke sutton


Member
Member
hello i just got givin a laptop by by girlfreinds sister as she got a new 1 and when i turned it on o noticed it was really slow and that she had no anti-virus or nothing like that so i was hopeing u cud help me check to see if there where any infections on the pc because i just dont know where to start thank you

2 Re: sure i have a virus on Fri May 28, 2010 2:32 am

DragonMaster Jay


Site Owner
Site Owner
Hello, and welcome to The Ultimate Geek TaskForce!

Please note the following information about the malware forum:
  • Only Moderators and Administrators are allowed to give advice on removing malware from your computer.
  • From this point on, please do not make any more changes to your computer; such as install/uninstall programs, use special fix tools, delete files, edit the registry, etc. - unless advised by the staff I noted above.
  • Please do not ask for help elsewhere (in this site or other sites). Doing so can result in system changes, which may not show up in the logs you post.
  • If you have already asked for help somewhere, please post the link to the topic you were helped.
  • We try our best to reply quickly, but for any reason we do not reply in two days, do this:

    Reply to this topic with the word BUMP.

  • Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal. Persist in this topic until its close, and your computer is declared clean.





Please visit this webpage for a tutorial on downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

See the area: Using ComboFix, and when done, post the log back here.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

3 Re: sure i have a virus on Fri May 28, 2010 6:20 am

luke sutton


Member
Member
ComboFix 10-05-27.03 - jade 28/05/2010 10:47:59.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.223.122 [GMT 1:00]
Running from: c:\documents and settings\jade\Desktop\ComboFix.exe
AV: Madesafe Antivirus ver. 5.80 *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Thumbs.db
c:\windows\system32\abvkhcpo.ini
c:\windows\system32\ahvpwjka.ini
c:\windows\system32\aofwdsnh.ini
c:\windows\system32\aowcwlxw.ini
c:\windows\system32\ariynton.ini
c:\windows\system32\arygueyp.ini
c:\windows\system32\asmcrqdk.ini
c:\windows\system32\bdadrxit.ini
c:\windows\system32\beatolrk.ini
c:\windows\system32\bioatklj.ini
c:\windows\system32\blttmqti.ini
c:\windows\system32\blydqmjs.ini
c:\windows\system32\boyygqsu.ini
c:\windows\system32\brnwjlxg.ini
c:\windows\system32\bsmtqqhf.ini
c:\windows\system32\btjxmidv.ini
c:\windows\system32\ccqkoydk.ini
c:\windows\system32\cdmpcdtk.ini
c:\windows\system32\cgqjtcee.ini
c:\windows\system32\cirkajmu.ini
c:\windows\system32\ckmvsjvd.ini
c:\windows\system32\coajonik.ini
c:\windows\system32\cqocdwvx.ini
c:\windows\system32\csytobov.ini
c:\windows\system32\daotprdg.ini
c:\windows\system32\dbdptuqw.ini
c:\windows\system32\dcjdhewh.ini
c:\windows\system32\ddlxafdb.ini
c:\windows\system32\dghhk.bak1
c:\windows\system32\dghhk.bak2
c:\windows\system32\dghhk.ini
c:\windows\system32\dghhk.ini2
c:\windows\system32\dghhk.tmp
c:\windows\system32\dglibtwf.ini
c:\windows\system32\dnwacdsk.ini
c:\windows\system32\dwqsymmx.ini
c:\windows\system32\dyxxexsh.ini
c:\windows\system32\efiostyf.ini
c:\windows\system32\efklqipt.ini
c:\windows\system32\efywovvr.ini
c:\windows\system32\eghhaeml.ini
c:\windows\system32\egyhtuqp.ini
c:\windows\system32\fftkveqm.ini
c:\windows\system32\fijkkiml.ini
c:\windows\system32\fpyrxtmy.ini
c:\windows\system32\fpyukkrj.ini
c:\windows\system32\gccatwfk.ini
c:\windows\system32\ggevfumo.ini
c:\windows\system32\ghahyxsx.ini
c:\windows\system32\gqoqilxr.ini
c:\windows\system32\grmmporh.ini
c:\windows\system32\gulgynap.ini
c:\windows\system32\gwrqdbtv.ini
c:\windows\system32\hjhoonnv.ini
c:\windows\system32\hkmpunvk.ini
c:\windows\system32\hkyxxwqj.ini
c:\windows\system32\hnlddggy.ini
c:\windows\system32\htqgesto.ini
c:\windows\system32\hwatluoi.ini
c:\windows\system32\hxdjxwid.ini
c:\windows\system32\indtxkcv.ini
c:\windows\system32\inruocmg.ini
c:\windows\system32\iuqkrkxr.ini
c:\windows\system32\ixnfjaxa.ini
c:\windows\system32\jdkvsnfr.ini
c:\windows\system32\jfwgmlpk.ini
c:\windows\system32\jguskapv.ini
c:\windows\system32\jgviaaat.ini
c:\windows\system32\jhjtnrmr.ini
c:\windows\system32\jiileouw.ini
c:\windows\system32\jjflqmnt.ini
c:\windows\system32\jqvlkhpu.ini
c:\windows\system32\kjfgmixh.ini
c:\windows\system32\kjtuylaw.ini
c:\windows\system32\kkwbxjjo.ini
c:\windows\system32\klpndncl.ini
c:\windows\system32\kvjnheqf.ini
c:\windows\system32\kxqokwef.ini
c:\windows\system32\kypofnrv.ini
c:\windows\system32\lcnpspjx.ini
c:\windows\system32\ldbeuvhu.ini
c:\windows\system32\ldisesbx.ini
c:\windows\system32\lhJInidm.dll
c:\windows\system32\ljjulsls.ini
c:\windows\system32\ljyqmqli.ini
c:\windows\system32\lndqkfph.ini
c:\windows\system32\mcmfrndk.ini
c:\windows\system32\mdhsehjp.ini
c:\windows\system32\meyeelgg.ini
c:\windows\system32\miyrmvfu.ini
c:\windows\system32\mnpyxpqv.ini
c:\windows\system32\mpjjthwc.ini
c:\windows\system32\nebgmapx.ini
c:\windows\system32\nhmbeyrq.ini
c:\windows\system32\npgemgot.ini
c:\windows\system32\nshqnvsq.ini
c:\windows\system32\ntefykdv.ini
c:\windows\system32\nwbnfrvv.ini
c:\windows\system32\odqixkmm.ini
c:\windows\system32\oqotcqrc.ini
c:\windows\system32\otjahpga.ini
c:\windows\system32\oxabmqmh.ini
c:\windows\system32\oxwyuogw.ini
c:\windows\system32\oylayfta.ini
c:\windows\system32\oyvuowbx.ini
c:\windows\system32\pctjpgrn.ini
c:\windows\system32\pknllcup.ini
c:\windows\system32\pljtxgtt.ini
c:\windows\system32\plmhjneo.ini
c:\windows\system32\plpufwja.ini
c:\windows\system32\ppiiqufh.ini
c:\windows\system32\prkwnern.ini
c:\windows\system32\ptgbxjkd.ini
c:\windows\system32\pxknotrp.ini
c:\windows\system32\pyqoekaj.ini
c:\windows\system32\qdfmueit.ini
c:\windows\system32\qiqqhnvq.ini
c:\windows\system32\qjycwxhd.ini
c:\windows\system32\qlkhcyoi.ini
c:\windows\system32\qukginqo.ini
c:\windows\system32\qxpswsti.ini
c:\windows\system32\rcxhkktd.ini
c:\windows\system32\rmhewwij.ini
c:\windows\system32\rowmljip.ini
c:\windows\system32\rsgfggpx.ini
c:\windows\system32\rsrvjxtm.ini
c:\windows\system32\rwyvlixo.ini
c:\windows\system32\ryhpxdsw.ini
c:\windows\system32\sfuvtoeo.ini
c:\windows\system32\skopgygy.ini
c:\windows\system32\sqbusiya.ini
c:\windows\system32\sqoqsekp.ini
c:\windows\system32\stgcagst.ini
c:\windows\system32\sybmtaym.ini
c:\windows\system32\syjdljfd.ini
c:\windows\system32\tchiuxrg.ini
c:\windows\system32\teshwtig.ini
c:\windows\system32\Thumbs.db
c:\windows\system32\tomhvjit.ini
c:\windows\system32\tqwrpkqi.ini
c:\windows\system32\trbucnbx.ini
c:\windows\system32\ufckihhk.ini
c:\windows\system32\ufhvuwbi.ini
c:\windows\system32\ufnwlmhv.ini
c:\windows\system32\uhqnfodb.ini
c:\windows\system32\uiuihxst.ini
c:\windows\system32\ukqkehta.ini
c:\windows\system32\uldwpgkl.ini
c:\windows\system32\unximrvv.ini
c:\windows\system32\upbbivjr.ini
c:\windows\system32\urgfgseq.ini
c:\windows\system32\uromjmcf.ini
c:\windows\system32\utwjbxcq.ini
c:\windows\system32\vgivknpx.ini
c:\windows\system32\vimgrklo.ini
c:\windows\system32\voldwuji.ini
c:\windows\system32\voorlocj.ini
c:\windows\system32\voxaktlj.ini
c:\windows\system32\vryuhvck.ini
c:\windows\system32\vxqbpmwu.ini
c:\windows\system32\vxxjsjka.ini
c:\windows\system32\wjhnlpgi.ini
c:\windows\system32\wjiybcix.ini
c:\windows\system32\wnfdofik.ini
c:\windows\system32\wrxycqxf.ini
c:\windows\system32\xbirfbix.ini
c:\windows\system32\xdvokabs.ini
c:\windows\system32\xelptceu.ini
c:\windows\system32\xiaycggh.ini
c:\windows\system32\xkyodacc.ini
c:\windows\system32\xlyulmeh.ini
c:\windows\system32\xootrocq.ini
c:\windows\system32\yfdvnjkk.ini
c:\windows\system32\ygxmwfrl.ini
c:\windows\system32\ymrbdxbf.ini
c:\windows\system32\yomnqawo.ini
c:\windows\system32\yqcuvuks.ini

----- File Replicators -----

c:\windows\system32\akohwgpk.exe
c:\windows\system32\bwhugrsu.exe
c:\windows\system32\cacwvhuu.exe
c:\windows\system32\clnheoba.exe
c:\windows\system32\critksjw.exe
c:\windows\system32\ddrsyygs.exe
c:\windows\system32\dsrwcyce.exe
c:\windows\system32\dxsffenw.exe
c:\windows\system32\epradqed.exe
c:\windows\system32\fcuyhvdu.exe
c:\windows\system32\flybsvps.exe
c:\windows\system32\fsyuoyuh.exe
c:\windows\system32\gwkqtyys.exe
c:\windows\system32\iqhmfosg.exe
c:\windows\system32\itnldypo.exe
c:\windows\system32\jencjchu.exe
c:\windows\system32\jgbaeygk.exe
c:\windows\system32\jiocoyhc.exe
c:\windows\system32\juuthhcc.exe
c:\windows\system32\jvgtpmhm.exe
c:\windows\system32\jvvlktjx.exe
c:\windows\system32\kakaiyvu.exe
c:\windows\system32\klnmueaf.exe
c:\windows\system32\nbchfehs.exe
c:\windows\system32\ndpmwyxc.exe
c:\windows\system32\oeajyoop.exe
c:\windows\system32\phqiddap.exe
c:\windows\system32\pkryuxau.exe
c:\windows\system32\qeyflyxo.exe
c:\windows\system32\qouljial.exe
c:\windows\system32\raoujjva.exe
c:\windows\system32\rbqlricc.exe
c:\windows\system32\rpavpqdg.exe
c:\windows\system32\rsjutvjt.exe
c:\windows\system32\sbysdfdt.exe
c:\windows\system32\tukubtph.exe
c:\windows\system32\vatepopr.exe
c:\windows\system32\vjkmglya.exe
c:\windows\system32\wrrdmljm.exe
c:\windows\system32\xnymsqjo.exe
c:\windows\system32\xvgqblcd.exe
c:\windows\system32\ycrdkywk.exe
c:\windows\system32\yncjmqel.exe
c:\windows\system32\ytaxhbaj.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-28 )))))))))))))))))))))))))))))))
.

2010-05-28 05:34 . 2010-05-28 10:08 -------- d-----w- c:\documents and settings\jade\Tracing
2010-05-27 22:16 . 2010-05-27 22:16 -------- d-----w- c:\program files\Microsoft
2010-05-27 22:11 . 2010-05-27 22:11 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-05-27 22:11 . 2010-05-28 10:08 684032 ----a-w- c:\documents and settings\All Users\Application Data\Amok Copy User Bib\MULTI GRID.exe
2010-05-27 22:11 . 2010-05-27 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Amok Copy User Bib
2010-05-27 22:10 . 2010-05-27 22:10 684032 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\osboictx.exe
2010-05-27 22:09 . 2010-05-27 22:09 -------- d-----w- c:\program files\AXIS SIGN
2010-05-27 22:07 . 2010-05-27 22:07 270336 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\scmlwmsd.exe
2010-05-27 22:03 . 2010-05-27 22:15 -------- d-----w- c:\program files\Windows Live
2010-05-27 21:57 . 2010-05-27 21:57 -------- d-----w- c:\program files\Common Files\Windows Live
2010-05-27 19:19 . 2010-05-27 19:19 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-05-27 19:16 . 2010-05-27 19:16 -------- d-----w- C:\temp
2010-05-27 19:16 . 2010-05-27 19:16 -------- d-----w- c:\documents and settings\jade\Application Data\InstallShield
2010-05-27 19:09 . 2010-05-27 19:09 -------- d-----w- C:\Siemens_WLAN108
2010-05-27 18:49 . 2010-05-27 22:34 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-05-27 18:37 . 2010-05-27 18:37 -------- d-----w- c:\documents and settings\jade\Application Data\Malwarebytes
2010-05-27 18:35 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-27 18:35 . 2010-05-27 18:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-27 18:35 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-27 18:35 . 2010-05-27 18:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 22:28 . 2007-04-07 12:12 -------- d-----w- c:\program files\MSN Messenger
2010-05-27 22:11 . 2007-04-30 13:14 -------- d-----w- c:\documents and settings\jade\Application Data\AXIS SIGN
2010-05-27 22:11 . 2007-05-21 17:33 311296 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\BibFast2.exe
2010-05-27 22:11 . 2007-05-21 17:33 270336 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\Base Roam Poke Dead.exe
2010-05-27 22:10 . 2007-05-21 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Playplanbuildlive
2010-05-27 22:10 . 2007-08-04 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Audio 4 part browse
2010-05-27 22:07 . 2007-04-30 13:14 544768 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\Waveglobal.exe
2010-05-27 19:18 . 2010-05-27 19:18 -------- d-----w- c:\program files\Siemens
2010-05-27 19:18 . 2006-11-10 18:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2007-05-08 14:36 . 2007-05-08 14:36 4904 --sh--w- c:\windows\system32\ienpkhqp.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Date Cast"="c:\docume~1\jade\APPLIC~1\AXISSI~1\Waveglobal.exe" [2010-05-27 544768]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2005-04-20 176128]
"S3hotkey"="S3hotkey.exe" [2003-05-27 159792]
"VTTimer"="VTTimer.exe" [2004-01-15 49152]
"Norman ZANDA"="c:\madesafe\bin\ZLH.EXE" [2005-03-07 135168]
"madeSafe ControlPad"="c:\program files\solarSoft\Madesafe\ControlPad.exe" [2005-03-07 679936]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-27 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-27 634880]
"user bib mp3 plan"="c:\documents and settings\All Users\Application Data\Amok Copy User Bib\MULTI GRID.exe" [2010-05-28 684032]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Gigaset WLAN Adapter Monitor.lnk - c:\program files\Siemens\Gigaset USB Adapter 108\GUI.exe [2010-5-27 811008]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^jade^Start Menu^Programs^Startup^TomTom HOME.lnk]
path=c:\documents and settings\jade\Start Menu\Programs\Startup\TomTom HOME.lnk
backup=c:\windows\pss\TomTom HOME.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Date Cast]
2010-05-27 22:07 544768 ----a-w- c:\docume~1\jade\APPLIC~1\AXISSI~1\Waveglobal.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPLv3]
2007-07-10 15:42 124436 ----a-w- c:\windows\system32\ibwuvhfu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hbdgwxlsr]
2007-07-06 17:57 278528 ----a-w- c:\windows\system32\hbdgwxlsr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j8231538]
2007-06-07 04:40 10752 ----a-w- c:\windows\system32\j8231538.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2003-10-10 13:25 118784 ----a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Part browse safe hold]
2009-08-17 19:27 3303936 ----a-w- c:\documents and settings\All Users\Application Data\Audio 4 part browse\mags dead.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2007-06-15 23:15 366400 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
2005-03-23 14:34 1630303 ------w- c:\program files\CyberLink\Power2Go\Power2GoExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
2005-02-17 14:18 110592 ------w- c:\program files\CyberLink\PowerStarter\PowerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 20:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-17 15:50 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{1290A33C-85F5-4164-A1BE-7DD299D4986A}]
2004-06-08 18:33 69721 ------w- c:\program files\CyberLink\PowerBackup\PBKScheduler.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 Ndiskio;Ndiskio;c:\madesafe\Nse\Bin\Ndiskio.sys [10/11/2006 19:33 18432]
R3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [27/05/2010 20:18 27072]
R3 NVCScheduler;Norman Virus Control Scheduler;c:\madesafe\Nvc\Bin\Nvcsched.exe [10/11/2006 19:33 126976]
S2 OMSCAN;OMSCAN;\SysO --> \SysO [?]
S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
S3 nvcfsr;nvcfsr;c:\madesafe\Nvc\Bin\Nvcfsr.sys [10/11/2006 19:33 3584]
S3 nvcoafl51;nvcoafl51;c:\madesafe\Nvc\Bin\Nvcoafl51.sys [10/11/2006 19:33 26496]
S3 nvcoaft51;nvcoaft51;c:\madesafe\Nvc\Bin\Nvcoaft51.sys [10/11/2006 19:33 96000]
S3 nvcoarc51;nvcoarc51;c:\madesafe\Nvc\Bin\Nvcoarc51.sys [10/11/2006 19:33 18944]
S3 nvcoas;Norman Virus Control on-access component;c:\madesafe\Nvc\Bin\Nvcoas.exe [10/11/2006 19:33 167936]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-05-28 c:\windows\Tasks\AAC6997E90811676.job
- c:\docume~1\jade\applic~1\axissi~1\BibFast2.exe [2007-05-21 22:11]

2007-10-20 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 12:00]
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Part browse safe hold - c:\documents and settings\All Users\Application Data\Audio 4 part browse\Save amen.exe
Notify-gebaaww - gebaaww.dll
Notify-urqoopn - urqoopn.dll
MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-28 11:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\jade\LOCALS~1\Temp\mc21.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(772)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
c:\windows\system32\athcfg11Res.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\madesafe\Bin\Zanda.exe
c:\madesafe\Nvc\BIN\nipsvc.exe
c:\madesafe\bin\NJEEVES.EXE
c:\windows\system32\pctspk.exe
c:\windows\system32\S3hotkey.exe
c:\windows\system32\VTTimer.exe
c:\madesafe\Nvc\BIN\NIP.EXE
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\acs.exe
.
**************************************************************************
.
Completion time: 2010-05-28 11:14:22 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-28 10:14

Pre-Run: 30,067,507,200 bytes free
Post-Run: 30,989,361,152 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - A6378F3ED73A4EADE787D2119ACA922A

4 Re: sure i have a virus on Fri May 28, 2010 4:09 pm

DragonMaster Jay


Site Owner
Site Owner
Re-running ComboFix to remove infections:

  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Open notepad and copy/paste the text in the box below into it:
    killall::

    rootkit::

    Reboot::
  • Save this as CFScript.txt, in the same location as ComboFix.exe



  • Referring to the picture above, drag CFScript into ComboFix.exe
  • When finished, it shall produce a log for you at C:\ComboFix.txt
  • Please post the contents of the log in your next reply.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

5 Re: sure i have a virus on Sat May 29, 2010 5:53 am

luke sutton


Member
Member
ComboFix 10-05-28.06 - jade 29/05/2010 10:27:21.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.44.1033.18.223.111 [GMT 1:00]
Running from: c:\documents and settings\jade\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\jade\Desktop\CFScript.txt
AV: Madesafe Antivirus ver. 5.80 *On-access scanning disabled* (Updated) {EB9EFB40-AE72-4C43-B204-0FCD0E92D5F1}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

----- File Replicators -----

c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630822.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630823.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630824.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630825.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630826.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630827.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630828.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630829.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630830.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630831.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630832.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630833.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630834.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630835.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630836.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630837.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630838.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630839.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630840.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630841.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630842.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630843.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630844.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630845.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630846.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630847.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630848.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630849.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630850.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630851.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630852.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630853.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630854.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630855.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630856.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630857.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630858.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630859.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630860.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630861.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630862.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630863.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630864.exe
c:\system volume information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630865.exe
.
.
((((((((((((((((((((((((( Files Created from 2010-04-28 to 2010-05-29 )))))))))))))))))))))))))))))))
.

2010-05-28 16:17 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-28 16:17 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-05-28 05:34 . 2010-05-29 09:41 -------- d-----w- c:\documents and settings\jade\Tracing
2010-05-27 22:16 . 2010-05-27 22:16 -------- d-----w- c:\program files\Microsoft
2010-05-27 22:11 . 2010-05-27 22:11 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-05-27 22:11 . 2010-05-29 09:40 684032 ----a-w- c:\documents and settings\All Users\Application Data\Amok Copy User Bib\MULTI GRID.exe
2010-05-27 22:11 . 2010-05-27 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Amok Copy User Bib
2010-05-27 22:10 . 2010-05-27 22:10 684032 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\osboictx.exe
2010-05-27 22:09 . 2010-05-27 22:09 -------- d-----w- c:\program files\AXIS SIGN
2010-05-27 22:07 . 2010-05-27 22:07 270336 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\scmlwmsd.exe
2010-05-27 22:03 . 2010-05-27 22:15 -------- d-----w- c:\program files\Windows Live
2010-05-27 21:57 . 2010-05-27 21:57 -------- d-----w- c:\program files\Common Files\Windows Live
2010-05-27 19:19 . 2010-05-27 19:19 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
2010-05-27 19:16 . 2010-05-27 19:16 -------- d-----w- C:\temp
2010-05-27 19:16 . 2010-05-27 19:16 -------- d-----w- c:\documents and settings\jade\Application Data\InstallShield
2010-05-27 19:09 . 2010-05-27 19:09 -------- d-----w- C:\Siemens_WLAN108
2010-05-27 18:49 . 2010-05-29 03:54 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-05-27 18:37 . 2010-05-27 18:37 -------- d-----w- c:\documents and settings\jade\Application Data\Malwarebytes
2010-05-27 18:35 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-27 18:35 . 2010-05-27 18:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-27 18:35 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-27 18:35 . 2010-05-27 18:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-27 22:28 . 2007-04-07 12:12 -------- d-----w- c:\program files\MSN Messenger
2010-05-27 22:11 . 2007-04-30 13:14 -------- d-----w- c:\documents and settings\jade\Application Data\AXIS SIGN
2010-05-27 22:11 . 2007-05-21 17:33 311296 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\BibFast2.exe
2010-05-27 22:11 . 2007-05-21 17:33 270336 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\Base Roam Poke Dead.exe
2010-05-27 22:10 . 2007-05-21 17:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Playplanbuildlive
2010-05-27 22:10 . 2007-08-04 15:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Audio 4 part browse
2010-05-27 22:07 . 2007-04-30 13:14 544768 ----a-w- c:\documents and settings\jade\Application Data\AXIS SIGN\Waveglobal.exe
2010-05-27 19:18 . 2010-05-27 19:18 -------- d-----w- c:\program files\Siemens
2010-05-27 19:18 . 2006-11-10 18:33 -------- d--h--w- c:\program files\InstallShield Installation Information
2007-05-08 14:36 . 2007-05-08 14:36 4904 --sh--w- c:\windows\system32\ienpkhqp.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Date Cast"="c:\docume~1\jade\APPLIC~1\AXISSI~1\Waveglobal.exe" [2010-05-27 544768]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCTVOICE"="pctspk.exe" [2005-04-20 176128]
"S3hotkey"="S3hotkey.exe" [2003-05-27 159792]
"VTTimer"="VTTimer.exe" [2004-01-15 49152]
"Norman ZANDA"="c:\madesafe\bin\ZLH.EXE" [2005-03-07 135168]
"madeSafe ControlPad"="c:\program files\solarSoft\Madesafe\ControlPad.exe" [2005-03-07 679936]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-27 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-27 634880]
"user bib mp3 plan"="c:\documents and settings\All Users\Application Data\Amok Copy User Bib\MULTI GRID.exe" [2010-05-29 684032]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Gigaset WLAN Adapter Monitor.lnk - c:\program files\Siemens\Gigaset USB Adapter 108\GUI.exe [2010-5-27 811008]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^jade^Start Menu^Programs^Startup^TomTom HOME.lnk]
path=c:\documents and settings\jade\Start Menu\Programs\Startup\TomTom HOME.lnk
backup=c:\windows\pss\TomTom HOME.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ScanRegistry]
C:\W [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-04 12:00 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Date Cast]
2010-05-27 22:07 544768 ----a-w- c:\docume~1\jade\APPLIC~1\AXISSI~1\Waveglobal.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GPLv3]
2007-07-10 15:42 124436 ----a-w- c:\windows\system32\ibwuvhfu.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hbdgwxlsr]
2007-07-06 17:57 278528 ----a-w- c:\windows\system32\hbdgwxlsr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j8231538]
2007-06-07 04:40 10752 ----a-w- c:\windows\system32\j8231538.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2003-10-10 13:25 118784 ----a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Part browse safe hold]
2009-08-17 19:27 3303936 ----a-w- c:\documents and settings\All Users\Application Data\Audio 4 part browse\mags dead.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
2007-06-15 23:15 366400 ----a-w- c:\program files\Picasa2\PicasaMediaDetector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
2005-03-23 14:34 1630303 ------w- c:\program files\CyberLink\Power2Go\Power2GoExpress.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PowerBar]
2005-02-17 14:18 110592 ------w- c:\program files\CyberLink\PowerStarter\PowerBar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-02 20:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-03-14 02:43 83608 ----a-w- c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-17 15:50 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{1290A33C-85F5-4164-A1BE-7DD299D4986A}]
2004-06-08 18:33 69721 ------w- c:\program files\CyberLink\PowerBackup\PBKScheduler.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R2 Ndiskio;Ndiskio;c:\madesafe\Nse\Bin\Ndiskio.sys [10/11/2006 19:33 18432]
R3 CBPSp50;CBPSp50 NDIS Protocol Driver;c:\windows\system32\drivers\CBPSp50.sys [27/05/2010 20:18 27072]
R3 NVCScheduler;Norman Virus Control Scheduler;c:\madesafe\Nvc\Bin\Nvcsched.exe [10/11/2006 19:33 126976]
S3 CBPMp50;CBPMp50 NDIS Protocol Driver;c:\windows\system32\Drivers\CBPMp50.sys --> c:\windows\system32\Drivers\CBPMp50.sys [?]
S3 nvcfsr;nvcfsr;c:\madesafe\Nvc\Bin\Nvcfsr.sys [10/11/2006 19:33 3584]
S3 nvcoafl51;nvcoafl51;c:\madesafe\Nvc\Bin\Nvcoafl51.sys [10/11/2006 19:33 26496]
S3 nvcoaft51;nvcoaft51;c:\madesafe\Nvc\Bin\Nvcoaft51.sys [10/11/2006 19:33 96000]
S3 nvcoarc51;nvcoarc51;c:\madesafe\Nvc\Bin\Nvcoarc51.sys [10/11/2006 19:33 18944]
S3 nvcoas;Norman Virus Control on-access component;c:\madesafe\Nvc\Bin\Nvcoas.exe [10/11/2006 19:33 167936]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2010-05-29 c:\windows\Tasks\AAC6997E90811676.job
- c:\docume~1\jade\applic~1\axissi~1\BibFast2.exe [2007-05-21 22:11]

2007-10-20 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 12:00]
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-29 10:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\jade\LOCALS~1\Temp\mc21.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\OMSCAN]
"ImagePath"="\Sys"
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\madesafe\Bin\Zanda.exe
c:\madesafe\bin\NJEEVES.EXE
c:\madesafe\Nvc\BIN\nipsvc.exe
c:\windows\system32\pctspk.exe
c:\windows\system32\S3hotkey.exe
c:\windows\system32\VTTimer.exe
c:\madesafe\Nvc\BIN\NIP.EXE
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\acs.exe
.
**************************************************************************
.
Completion time: 2010-05-29 10:48:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-29 09:48
ComboFix2.txt 2010-05-28 10:14

Pre-Run: 31,013,216,256 bytes free
Post-Run: 31,018,053,632 bytes free

- - End Of File - - 097A78AE8120FDC3502AFED596CFA98B

6 Re: sure i have a virus on Sat May 29, 2010 10:50 pm

DragonMaster Jay


Site Owner
Site Owner
Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

7 Re: sure i have a virus on Mon May 31, 2010 1:43 pm

luke sutton


Member
Member
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e202f84aaeaf3042b02a8ea1ff1dbea6
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-05-31 02:17:15
# local_time=2010-05-31 03:17:15 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=5378 16777214 100 74 112119665 222477391 0 0
# compatibility_mode=8192 67108863 100 0 445 445 0 0
# scanned=45744
# found=482
# cleaned=482
# scan_time=12173
C:\Documents and Settings\All Users\Application Data\Amok Copy User Bib\MULTI GRID.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\Audio 4 part browse\mags dead.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\All Users\Application Data\Playplanbuildlive\BuildLicense.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\aeunrucj.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\afdlyako.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\amsjaryx.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\bdnbzwyx.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\BibDumbRoam.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\dovsciwf.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\eljtmhlh.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\hgeplkys.exe a variant of Win32/Obfuscated.EN trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\jmwjcbbw.exe a variant of Win32/TrojanDownloader.Swizzor.NAW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\jpnwjwpb.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\osboictx.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\pxzxnfug.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Application Data\AXIS SIGN\xubivvdd.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\jade\Local Settings\temp\0.9710907572422475.exe Win32/Spy.Zbot.YW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\found.003\file0000.chk Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\Adverts\uninst.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\solarSoft\Madesafe\SMSH1.EXE probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\abvkhcpo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ahvpwjka.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\aofwdsnh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\aowcwlxw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ariynton.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\arygueyp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\asmcrqdk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\bdadrxit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\beatolrk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\bioatklj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\blttmqti.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\blydqmjs.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\boyygqsu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\brnwjlxg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\bsmtqqhf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\btjxmidv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ccqkoydk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\cdmpcdtk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\cgqjtcee.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\cirkajmu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ckmvsjvd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\coajonik.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\cqocdwvx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\csytobov.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\daotprdg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dbdptuqw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dcjdhewh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ddlxafdb.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dghhk.bak1.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dghhk.bak2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dghhk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dghhk.ini2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dglibtwf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dnwacdsk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dwqsymmx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\dyxxexsh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\efiostyf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\efklqipt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\efywovvr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\eghhaeml.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\egyhtuqp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\fftkveqm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\fijkkiml.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\fpyrxtmy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\fpyukkrj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\gccatwfk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ggevfumo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ghahyxsx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\gqoqilxr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\grmmporh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\gulgynap.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\gwrqdbtv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hjhoonnv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hkmpunvk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hkyxxwqj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hnlddggy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\htqgesto.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hwatluoi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\hxdjxwid.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\indtxkcv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\inruocmg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\iuqkrkxr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ixnfjaxa.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jdkvsnfr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jfwgmlpk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jguskapv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jgviaaat.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jhjtnrmr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jiileouw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jjflqmnt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\jqvlkhpu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kjfgmixh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kjtuylaw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kkwbxjjo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\klpndncl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kvjnheqf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kxqokwef.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\kypofnrv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\lcnpspjx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ldbeuvhu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ldisesbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\lhjinidm.dll.vir Win32/BHO.G trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ljjulsls.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ljyqmqli.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\lndqkfph.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mcmfrndk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mdhsehjp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\meyeelgg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\miyrmvfu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mnpyxpqv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\mpjjthwc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\nebgmapx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\nhmbeyrq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\npgemgot.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\nshqnvsq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ntefykdv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\nwbnfrvv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\odqixkmm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\oqotcqrc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\otjahpga.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\oxabmqmh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\oxwyuogw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\oylayfta.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\oyvuowbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\pctjpgrn.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\pknllcup.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\pljtxgtt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\plmhjneo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\plpufwja.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ppiiqufh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\prkwnern.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ptgbxjkd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\pxknotrp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\pyqoekaj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qdfmueit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qiqqhnvq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qjycwxhd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qlkhcyoi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qukginqo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\qxpswsti.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rcxhkktd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rmhewwij.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rowmljip.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rsgfggpx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rsrvjxtm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\rwyvlixo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ryhpxdsw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\sfuvtoeo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\skopgygy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\sqbusiya.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\sqoqsekp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\stgcagst.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\sybmtaym.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\syjdljfd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\tchiuxrg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\teshwtig.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\tomhvjit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\tqwrpkqi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\trbucnbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ufckihhk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ufhvuwbi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ufnwlmhv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\uhqnfodb.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\uiuihxst.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ukqkehta.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\uldwpgkl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\unximrvv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\upbbivjr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\urgfgseq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\uromjmcf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\utwjbxcq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\vgivknpx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\vimgrklo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\voldwuji.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\voorlocj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\voxaktlj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\vryuhvck.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\vxqbpmwu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\vxxjsjka.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\wjhnlpgi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\wjiybcix.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\wnfdofik.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\wrxycqxf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xbirfbix.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xdvokabs.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xelptceu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xiaycggh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xkyodacc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xlyulmeh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\xootrocq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\yfdvnjkk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ygxmwfrl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\ymrbdxbf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\yomnqawo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\C\WINDOWS\system32\yqcuvuks.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Qoobox\Quarantine\Replicators\0E732BA265543BCD90E458D862D8C6F8 Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630573.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630610.exe a variant of Win32/TrojanDownloader.Swizzor.NCR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630611.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630612.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630613.exe a variant of Win32/TrojanDownloader.Swizzor.NCR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630723.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630731.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630866.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630867.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630868.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630869.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630870.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630871.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630872.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630873.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630874.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630875.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630876.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630877.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630878.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630879.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630880.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630881.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630882.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630883.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630884.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630885.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630886.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630887.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630888.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630889.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630890.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

8 Re: sure i have a virus on Mon May 31, 2010 1:44 pm

luke sutton


Member
Member
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630891.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630892.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630893.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630894.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630895.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630896.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630897.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630898.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630899.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630900.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630901.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630902.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630903.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630904.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630905.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630906.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630907.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630908.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630909.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630910.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630911.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630912.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630913.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630914.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630915.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630916.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630917.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630918.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630919.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630920.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630921.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630922.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630923.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630924.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630925.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630926.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630927.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630928.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630929.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630930.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630931.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630932.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630933.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630934.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630935.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630936.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630937.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630938.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630939.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630940.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630941.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630942.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630943.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630944.dll Win32/BHO.G trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630945.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630946.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630947.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630948.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630949.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630950.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630951.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630952.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630953.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630954.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630955.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630956.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630957.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630958.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630959.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630960.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630961.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630962.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630963.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630964.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630965.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630966.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630967.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630968.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630969.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630970.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630971.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630972.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630973.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630974.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630975.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630976.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630977.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630978.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630979.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630980.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630981.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630982.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630983.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630984.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630985.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630986.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630987.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630988.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630989.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630990.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630991.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630992.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630993.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630994.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630995.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630996.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630997.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630998.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0630999.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631000.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631001.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631002.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631003.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631004.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631005.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631006.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631007.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631008.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631009.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631010.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631011.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631012.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631013.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631014.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631015.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631016.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631017.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631018.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631019.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631020.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631021.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631022.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631023.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631024.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631025.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631026.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631027.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631028.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631029.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631030.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631031.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631032.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631033.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631034.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631035.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631036.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631037.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631051.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631123.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP62\A0631136.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP63\A0631227.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP63\A0631343.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP64\A0632010.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP65\A0632040.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP65\A0632052.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632066.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632067.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632068.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632069.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632070.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632071.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632072.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632073.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632074.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632075.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632076.exe a variant of Win32/TrojanDownloader.Swizzor.NEM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632077.exe a variant of Win32/TrojanDownloader.Swizzor.NAW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632078.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632079.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632080.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632081.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632082.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}\RP66\A0632083.EXE probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\acmsbaur.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\agwpxsmf.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ajwfuplp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\akjsjxxv.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\bfeqwyma.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\bnombqdp.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\cdordvxg.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ckjehgdm.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ckqyfabi.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\dkjxbgtp.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\dtkkhxcr.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\dvjsvmkc.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\dxrnapfb.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\eectjqgc.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\eisrosgk.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\fbxdbrmy.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\fcmjmoru.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\fthufhnc.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\fytsoife.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\gdrptoad.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\gmcourni.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hbdgwxlsr.exe a variant of Win32/Adware.NaviPromo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hdwmolpr.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hfxgukww.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hmqmbaxo.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hsxexxyd.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\hximgfjk.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ibwuvhfu.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ienpkhqp.tmp Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ilqmqyjl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\itqmttlb.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\j8231538.dll Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\jakeoqyp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\jaqrytqf.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\jcolroov.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\jsqkphjg.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\jsrjqkbm.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\kinojaoc.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\kplmgwfj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\kpmsjtdd.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\lcndnplk.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\lkmltele.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\mdmnngmg.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\meosumoa.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\mieloclk.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\oenjhmlp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\oexfindh.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ofswtnkv.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ooggjves.exe probably a variant of Win32/TrojanDownloader.Small trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\panyglug.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\pmnkigf.exe probably a variant of Win32/TrojanDownloader.Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\pybfauil.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\qcortoox.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\qcsjqksg.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\qesgfgru.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\rfnsvkdj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\rjvibbpu.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\rwwiurlj.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\sbakovdx.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\sfomomog.exe Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\sjmqdylb.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\slslujjl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\tfhymhak.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\tnmqlfjj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\tsgacgts.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ttgxtjlp.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\txhawygx.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\uectplex.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ugipvlme.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\uhpgavkj.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\uhvuebdl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\umeejtnt.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\vhmlwnfu.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\vkndcwge.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\vqpxypnm.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\vrnfopyk.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\vvrfnbwn.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\wktxeuox.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\yggddlnh.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ykbnurli.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\ytfxywwx.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

9 Re: sure i have a virus on Mon May 31, 2010 7:39 pm

DragonMaster Jay


Site Owner
Site Owner
Please download Malwarebytes Anti-Malware from Malwarebytes.org.
Alternate link: BleepingComputer.com.
(Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

Double Click mbam-setup.exe to install the application.

(Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Copy and paste the entire report in your next reply.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

10 Re: sure i have a virus on Wed Jun 02, 2010 11:02 am

luke sutton


Member
Member
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4161

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

01/06/2010 15:28:34
mbam-log-2010-06-01 (15-28-34).txt

Scan type: Full scan (C:\|)
Objects scanned: 156725
Time elapsed: 1 hour(s), 20 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{4776c4dc-e894-7c06-2148-5d73cef5f905} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Zbot) -> Data: system32\sdra64.exe -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\WINDOWS\system32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
C:\Documents and Settings\jade\Local Settings\temp\0.5668422897515436.exe (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sdra64.exe (Trojan.Zbot) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\WINDOWS\system32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.

11 Re: sure i have a virus on Thu Jun 03, 2010 3:39 pm

DragonMaster Jay


Site Owner
Site Owner
You have a severe infection on the system.

If the Computer has been used for any important data, you are strongly advised to do the following, immediately:

  • Back up all important data on the machine.
  • If you have ever used this computer for shopping, banking, or any transactions relating to your financial well being:

    Call all of your banks, credit card companies, and financial institutions, informing them that you may be a victim of identity theft, and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change ALL your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
  • DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new password and transaction information.
  • Take any other steps you think appropriate for potential identity theft caused by the infections.


=================

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, you may close the window
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

12 Re: sure i have a virus on Mon Jun 07, 2010 6:22 am

luke sutton


Member
Member
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e202f84aaeaf3042b02a8ea1ff1dbea6
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-05-31 02:17:15
# local_time=2010-05-31 03:17:15 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=5378 16777214 100 74 112119665 222477391 0 0
# compatibility_mode=8192 67108863 100 0 445 445 0 0
# scanned=45744
# found=482
# cleaned=482
# scan_time=12173
C:Documents and SettingsAll UsersApplication DataAmok Copy User BibMULTI GRID.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting (after the next restart) - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsAll UsersApplication DataAudio 4 part browsemags dead.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsAll UsersApplication DataPlayplanbuildliveBuildLicense.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNaeunrucj.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNafdlyako.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNamsjaryx.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNbdnbzwyx.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNBibDumbRoam.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNdovsciwf.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNeljtmhlh.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNhgeplkys.exe a variant of Win32/Obfuscated.EN trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNjmwjcbbw.exe a variant of Win32/TrojanDownloader.Swizzor.NAW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNjpnwjwpb.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNosboictx.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNpxzxnfug.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeApplication DataAXIS SIGNxubivvdd.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Documents and SettingsjadeLocal Settingstemp.9710907572422475.exe Win32/Spy.Zbot.YW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:found.003file0000.chk Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Program FilesAdvertsuninst.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:Program FilessolarSoftMadesafeSMSH1.EXE probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32abvkhcpo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ahvpwjka.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32aofwdsnh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32aowcwlxw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ariynton.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32arygueyp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32asmcrqdk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32bdadrxit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32beatolrk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32bioatklj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32blttmqti.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32blydqmjs.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32boyygqsu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32brnwjlxg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32bsmtqqhf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32btjxmidv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ccqkoydk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32cdmpcdtk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32cgqjtcee.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32cirkajmu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ckmvsjvd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32coajonik.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32cqocdwvx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32csytobov.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32daotprdg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dbdptuqw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dcjdhewh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ddlxafdb.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dghhk.bak1.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dghhk.bak2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dghhk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dghhk.ini2.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dglibtwf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dnwacdsk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dwqsymmx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32dyxxexsh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32efiostyf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32efklqipt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32efywovvr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32eghhaeml.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32egyhtuqp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32fftkveqm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32fijkkiml.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32fpyrxtmy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32fpyukkrj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32gccatwfk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ggevfumo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ghahyxsx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32gqoqilxr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32grmmporh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32gulgynap.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32gwrqdbtv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hjhoonnv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hkmpunvk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hkyxxwqj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hnlddggy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32htqgesto.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hwatluoi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32hxdjxwid.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32indtxkcv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32inruocmg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32iuqkrkxr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ixnfjaxa.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jdkvsnfr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jfwgmlpk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jguskapv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jgviaaat.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jhjtnrmr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jiileouw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jjflqmnt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32jqvlkhpu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kjfgmixh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kjtuylaw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kkwbxjjo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32klpndncl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kvjnheqf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kxqokwef.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32kypofnrv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32lcnpspjx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ldbeuvhu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ldisesbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32lhjinidm.dll.vir Win32/BHO.G trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ljjulsls.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ljyqmqli.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32lndqkfph.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32mcmfrndk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32mdhsehjp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32meyeelgg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32miyrmvfu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32mnpyxpqv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32mpjjthwc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32nebgmapx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32nhmbeyrq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32npgemgot.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32nshqnvsq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ntefykdv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32nwbnfrvv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32odqixkmm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32oqotcqrc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32otjahpga.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32oxabmqmh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32oxwyuogw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32oylayfta.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32oyvuowbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32pctjpgrn.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32pknllcup.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32pljtxgtt.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32plmhjneo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32plpufwja.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ppiiqufh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32prkwnern.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ptgbxjkd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32pxknotrp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32pyqoekaj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qdfmueit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qiqqhnvq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qjycwxhd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qlkhcyoi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qukginqo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32qxpswsti.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rcxhkktd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rmhewwij.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rowmljip.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rsgfggpx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rsrvjxtm.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32rwyvlixo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ryhpxdsw.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32sfuvtoeo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32skopgygy.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32sqbusiya.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32sqoqsekp.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32stgcagst.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32sybmtaym.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32syjdljfd.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32tchiuxrg.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32teshwtig.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32tomhvjit.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32tqwrpkqi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32trbucnbx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ufckihhk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ufhvuwbi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ufnwlmhv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32uhqnfodb.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32uiuihxst.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ukqkehta.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32uldwpgkl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32unximrvv.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32upbbivjr.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32urgfgseq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32uromjmcf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32utwjbxcq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32vgivknpx.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32vimgrklo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32voldwuji.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32voorlocj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32voxaktlj.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32vryuhvck.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32vxqbpmwu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32vxxjsjka.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32wjhnlpgi.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32wjiybcix.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32wnfdofik.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32wrxycqxf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xbirfbix.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xdvokabs.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xelptceu.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xiaycggh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xkyodacc.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xlyulmeh.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32xootrocq.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32yfdvnjkk.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ygxmwfrl.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32ymrbdxbf.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32yomnqawo.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineCWINDOWSsystem32yqcuvuks.ini.vir Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:QooboxQuarantineReplicatorsE732BA265543BCD90E458D862D8C6F8 Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630573.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630610.exe a variant of Win32/TrojanDownloader.Swizzor.NCR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630611.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630612.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630613.exe a variant of Win32/TrojanDownloader.Swizzor.NCR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630723.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630731.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630866.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630867.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630868.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630869.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630870.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630871.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630872.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630873.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630874.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630875.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630876.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630877.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630878.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630879.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630880.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630881.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630882.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630883.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630884.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630885.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630886.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630887.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630888.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630889.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630890.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630891.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630892.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630893.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630894.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630895.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630896.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630897.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630898.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630899.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630900.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630901.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630902.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630903.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630904.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630905.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630906.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630907.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630908.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630909.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630910.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630911.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630912.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630913.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630914.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

13 Re: sure i have a virus on Mon Jun 07, 2010 6:23 am

luke sutton


Member
Member
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630915.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630916.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630917.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630918.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630919.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630920.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630921.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630922.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630923.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630924.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630925.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630926.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630927.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630928.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630929.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630930.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630931.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630932.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630933.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630934.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630935.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630936.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630937.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630938.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630939.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630940.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630941.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630942.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630943.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630944.dll Win32/BHO.G trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630945.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630946.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630947.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630948.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630949.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630950.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630951.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630952.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630953.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630954.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630955.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630956.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630957.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630958.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630959.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630960.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630961.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630962.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630963.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630964.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630965.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630966.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630967.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630968.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630969.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630970.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630971.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630972.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630973.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630974.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630975.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630976.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630977.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630978.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630979.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630980.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630981.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630982.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630983.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630984.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630985.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630986.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630987.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630988.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630989.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630990.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630991.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630992.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630993.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630994.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630995.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630996.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630997.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630998.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0630999.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631000.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631001.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631002.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631003.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631004.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631005.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631006.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631007.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631008.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631009.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631010.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631011.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631012.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631013.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631014.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631015.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631016.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631017.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631018.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631019.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631020.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631021.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631022.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631023.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631024.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631025.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631026.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631027.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631028.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631029.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631030.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631031.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631032.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631033.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631034.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631035.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631036.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631037.ini Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631051.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631123.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP62A0631136.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP63A0631227.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP63A0631343.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP64A0632010.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP65A0632040.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP65A0632052.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632066.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632067.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632068.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632069.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632070.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632071.exe a variant of Win32/TrojanDownloader.Swizzor.NDI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632072.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632073.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632074.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632075.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632076.exe a variant of Win32/TrojanDownloader.Swizzor.NEM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632077.exe a variant of Win32/TrojanDownloader.Swizzor.NAW trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632078.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632079.exe a variant of Win32/TrojanDownloader.Swizzor.NEH trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632080.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632081.exe a variant of Win32/TrojanDownloader.Swizzor.NCV trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632082.exe Win32/Obfuscated.A1 trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632083.EXE probably unknown NewHeur_PE virus (deleted - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32acmsbaur.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32agwpxsmf.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ajwfuplp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32akjsjxxv.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32bfeqwyma.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32bnombqdp.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32cdordvxg.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ckjehgdm.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ckqyfabi.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32dkjxbgtp.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32dtkkhxcr.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32dvjsvmkc.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32dxrnapfb.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32eectjqgc.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32eisrosgk.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32fbxdbrmy.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32fcmjmoru.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32fthufhnc.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32fytsoife.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32gdrptoad.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32gmcourni.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hbdgwxlsr.exe a variant of Win32/Adware.NaviPromo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hdwmolpr.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hfxgukww.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hmqmbaxo.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hsxexxyd.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32hximgfjk.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ibwuvhfu.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ienpkhqp.tmp Win32/Adware.Virtumonde.NEO application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ilqmqyjl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32itqmttlb.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32j8231538.dll Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32jakeoqyp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32jaqrytqf.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32jcolroov.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32jsqkphjg.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32jsrjqkbm.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32kinojaoc.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32kplmgwfj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32kpmsjtdd.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32lcndnplk.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32lkmltele.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32mdmnngmg.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32meosumoa.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32mieloclk.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32oenjhmlp.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32oexfindh.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ofswtnkv.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ooggjves.exe probably a variant of Win32/TrojanDownloader.Small trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32panyglug.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32pmnkigf.exe probably a variant of Win32/TrojanDownloader.Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32pybfauil.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32qcortoox.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32qcsjqksg.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32qesgfgru.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32rfnsvkdj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32rjvibbpu.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32rwwiurlj.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32sbakovdx.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32sfomomog.exe Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32sjmqdylb.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32slslujjl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32tfhymhak.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32tnmqlfjj.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32tsgacgts.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ttgxtjlp.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32txhawygx.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32uectplex.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ugipvlme.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32uhpgavkj.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32uhvuebdl.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32umeejtnt.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32vhmlwnfu.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32vkndcwge.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32vqpxypnm.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32vrnfopyk.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32vvrfnbwn.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32wktxeuox.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32yggddlnh.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ykbnurli.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:WINDOWSsystem32ytfxywwx.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e202f84aaeaf3042b02a8ea1ff1dbea6
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-06-06 05:31:08
# local_time=2010-06-06 06:31:08 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=5378 16777214 100 74 112648359 223006085 0 0
# compatibility_mode=8192 67108863 100 0 529139 529139 0 0
# scanned=54002
# found=80
# cleaned=80
# scan_time=13500
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632084.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632085.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632086.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632087.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632088.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632089.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632090.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632091.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632092.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632093.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632094.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632095.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632096.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632097.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632098.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632099.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632100.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632101.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632102.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632103.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632104.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632105.exe a variant of Win32/Adware.NaviPromo application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632106.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632107.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632108.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632109.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632110.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632111.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632112.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632113.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632114.dll Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632115.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632116.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632117.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632118.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632119.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632120.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632121.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632122.dll Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632123.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632124.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632125.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632126.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632127.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632128.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632129.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632130.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632131.exe probably a variant of Win32/TrojanDownloader.Small trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632132.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632133.exe probably a variant of Win32/TrojanDownloader.Agent trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632134.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632135.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632136.exe Win32/Adware.Ezula application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632137.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632138.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632139.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632140.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632141.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632142.exe Win32/TrojanClicker.Agent.NBZ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632143.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632144.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632145.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632146.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632147.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632148.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632149.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632150.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632151.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632152.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632153.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632154.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632155.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632156.exe Win32/Agent.ANR trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632157.dll Win32/Adware.Virtumonde.KI application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632158.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632159.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632160.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632161.dll Win32/Adware.Virtumonde application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632162.dll a variant of Win32/Adware.BHO.V application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:System Volume Information_restore{A691D9AC-3FB6-44D4-9362-7DF89913D98E}RP66A0632163.dll Win32/Spy.VBStat.J trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

14 Re: sure i have a virus on Mon Jun 07, 2010 11:23 am

DragonMaster Jay


Site Owner
Site Owner
Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

15 Re: sure i have a virus on Tue Jun 08, 2010 1:03 pm

luke sutton


Member
Member
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4177

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

08/06/2010 08:13:36
mbam-log-2010-06-08 (08-13-36).txt

Scan type: Quick scan
Objects scanned: 116127
Time elapsed: 13 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ad Bot


View previous topic View next topic Back to top  Message [Page 1 of 2]

Goto page : 1, 2  Next

Permissions in this forum:
You cannot reply to topics in this forum