# Solved: I am having trouble with my PC...here is my HJT log



## mcarpio (Nov 14, 2003)

You guys have helped me in the past, that is why I have turned to you now. I have something in my computer that I can't get rid of. 

For starters here is my HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:30:47 PM, on 7/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\appwh32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscript.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\iwmln.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {E570DCA4-C521-2B7F-EB9D-E2F8DD25DF6B} - C:\WINDOWS\winnr32.dll
O2 - BHO: Class - {FB375D03-ADFB-A764-80E7-7750FF44A796} - C:\WINDOWS\d3oz32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [appwh32.exe] C:\WINDOWS\appwh32.exe
O4 - HKLM\..\RunOnce: [mfcfv32.exe] C:\WINDOWS\mfcfv32.exe
O4 - HKLM\..\RunOnce: [ielb.exe] C:\WINDOWS\ielb.exe
O4 - HKLM\..\RunOnce: [apppd.exe] C:\WINDOWS\apppd.exe
O4 - HKLM\..\RunOnce: [ntyf.exe] C:\WINDOWS\system32\ntyf.exe
O4 - HKLM\..\RunOnce: [appvt.exe] C:\WINDOWS\appvt.exe
O4 - HKLM\..\RunOnce: [addyb.exe] C:\WINDOWS\system32\addyb.exe
O4 - HKLM\..\RunOnce: [netll.exe] C:\WINDOWS\system32\netll.exe
O4 - HKLM\..\RunOnce: [javawk.exe] C:\WINDOWS\system32\javawk.exe
O4 - HKLM\..\RunOnce: [msph32.exe] C:\WINDOWS\system32\msph32.exe
O4 - HKLM\..\RunOnce: [appoc.exe] C:\WINDOWS\system32\appoc.exe
O4 - HKLM\..\RunOnce: [netse.exe] C:\WINDOWS\system32\netse.exe
O4 - HKLM\..\RunOnce: [apibc.exe] C:\WINDOWS\apibc.exe
O4 - HKLM\..\RunOnce: [neteb32.exe] C:\WINDOWS\system32\neteb32.exe
O4 - HKLM\..\RunOnce: [mfchl32.exe] C:\WINDOWS\mfchl32.exe
O4 - HKLM\..\RunOnce: [msiz.exe] C:\WINDOWS\msiz.exe
O4 - HKLM\..\RunOnce: [atlvh.exe] C:\WINDOWS\system32\atlvh.exe
O4 - HKLM\..\RunOnce: [mfcjr32.exe] C:\WINDOWS\system32\mfcjr32.exe
O4 - HKLM\..\RunOnce: [d3sv32.exe] C:\WINDOWS\system32\d3sv32.exe
O4 - HKLM\..\RunOnce: [ipff32.exe] C:\WINDOWS\system32\ipff32.exe
O4 - HKLM\..\RunOnce: [iejp32.exe] C:\WINDOWS\iejp32.exe
O4 - HKLM\..\RunOnce: [d3fr32.exe] C:\WINDOWS\system32\d3fr32.exe
O4 - HKLM\..\RunOnce: [mfccr32.exe] C:\WINDOWS\system32\mfccr32.exe
O4 - HKLM\..\RunOnce: [atlub.exe] C:\WINDOWS\atlub.exe
O4 - HKLM\..\RunOnce: [nttx32.exe] C:\WINDOWS\system32\nttx32.exe
O4 - HKLM\..\RunOnce: [appmq.exe] C:\WINDOWS\system32\appmq.exe
O4 - HKLM\..\RunOnce: [sysat32.exe] C:\WINDOWS\system32\sysat32.exe
O4 - HKLM\..\RunOnce: [crhx32.exe] C:\WINDOWS\system32\crhx32.exe
O4 - HKLM\..\RunOnce: [ipdv32.exe] C:\WINDOWS\ipdv32.exe
O4 - HKLM\..\RunOnce: [addnl.exe] C:\WINDOWS\system32\addnl.exe
O4 - HKLM\..\RunOnce: [ipce.exe] C:\WINDOWS\ipce.exe
O4 - HKLM\..\RunOnce: [netkp.exe] C:\WINDOWS\system32\netkp.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [appup.exe] C:\WINDOWS\appup.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v7.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

Thanks


----------



## mcarpio (Nov 14, 2003)

Can somebody please help me? I know you are all busy, but I see many posts with replies and mine doesn't even have a sorry we can't help you. This is my second try, Wednesday night I posted a thread and that one still hasn't had a response either. The last time I had a problem you guys were really helpful. I am sorry if I sound impatient, I am just frustrated that I can't figure out how to fix my problem.


----------



## BLADE4356 (Feb 25, 2004)

hey mcarpio , sometimes it does seem like you're getting passed over but thats not the case . If your thread starts getting pushed back , just "bump" it up and it will get attention. This site is very busy...


----------



## flavallee (May 12, 2002)

You've got some major problems that need to be dealt with, but it's beyond my expertise, so some of the "heavy hitters" in this forum are going to need to help you. The *R0*, *R1*, and *O4* entries appear to be the biggest problem.

----------------------------------------------------------------

Have you downloaded, installed, updated, and run the following?

*Ad-Aware SE Personal 1.06

Spybot - Search & Destroy 1.4

CWShredder 2.15

Aboutbuster 5.0*

If not, go to the spyware tools section at www.majorgeeks.com and get them. They're all free.

----------------------------------------------------------------


----------



## iaavagent (Jan 11, 2004)

I think also that you will be asked to download "ewido utility". Whomever will give you the link etc if so. 
Hang in there,somebody may be going over your log as we post. It's gona take a little time as yours is "heavy".
Good Luck. 
Remember,be patient as patience is a virtue! What's a virtue? I have no idea! But I'm told that all the time!


----------



## mcarpio (Nov 14, 2003)

I have downloaded and run: 

Ad-Aware SE Personal 1.06

Spybot - Search & Destroy 1.4

CWShredder 2.15

Aboutbuster 5.0

None have helped with the problem. The only reason I am able to use the computer much now is because I have IE shields up from Spy Sweeper. Thanks for the responses...it makes me feel better just to hear something


----------



## flavallee (May 12, 2002)

You're telling me that Ad-Aware and Spybot didn't find any spyware-related entries and other "nasties" to get rid of? I find that hard to believe.

----------------------------------------------------------------

These entries, among others, look very suspicious:

*O4 - HKLM\..\Run: [appwh32.exe] C:\WINDOWS\appwh32.exe
O4 - HKLM\..\RunOnce: [mfcfv32.exe] C:\WINDOWS\mfcfv32.exe
O4 - HKLM\..\RunOnce: [ielb.exe] C:\WINDOWS\ielb.exe
O4 - HKLM\..\RunOnce: [apppd.exe] C:\WINDOWS\apppd.exe
O4 - HKLM\..\RunOnce: [ntyf.exe] C:\WINDOWS\system32\ntyf.exe
O4 - HKLM\..\RunOnce: [appvt.exe] C:\WINDOWS\appvt.exe
O4 - HKLM\..\RunOnce: [addyb.exe] C:\WINDOWS\system32\addyb.exe
O4 - HKLM\..\RunOnce: [netll.exe] C:\WINDOWS\system32\netll.exe
O4 - HKLM\..\RunOnce: [javawk.exe] C:\WINDOWS\system32\javawk.exe
O4 - HKLM\..\RunOnce: [msph32.exe] C:\WINDOWS\system32\msph32.exe
O4 - HKLM\..\RunOnce: [appoc.exe] C:\WINDOWS\system32\appoc.exe
O4 - HKLM\..\RunOnce: [netse.exe] C:\WINDOWS\system32\netse.exe
O4 - HKLM\..\RunOnce: [apibc.exe] C:\WINDOWS\apibc.exe
O4 - HKLM\..\RunOnce: [neteb32.exe] C:\WINDOWS\system32\neteb32.exe
O4 - HKLM\..\RunOnce: [mfchl32.exe] C:\WINDOWS\mfchl32.exe
O4 - HKLM\..\RunOnce: [msiz.exe] C:\WINDOWS\msiz.exe
O4 - HKLM\..\RunOnce: [atlvh.exe] C:\WINDOWS\system32\atlvh.exe
O4 - HKLM\..\RunOnce: [mfcjr32.exe] C:\WINDOWS\system32\mfcjr32.exe
O4 - HKLM\..\RunOnce: [d3sv32.exe] C:\WINDOWS\system32\d3sv32.exe
O4 - HKLM\..\RunOnce: [ipff32.exe] C:\WINDOWS\system32\ipff32.exe
O4 - HKLM\..\RunOnce: [iejp32.exe] C:\WINDOWS\iejp32.exe
O4 - HKLM\..\RunOnce: [d3fr32.exe] C:\WINDOWS\system32\d3fr32.exe
O4 - HKLM\..\RunOnce: [mfccr32.exe] C:\WINDOWS\system32\mfccr32.exe
O4 - HKLM\..\RunOnce: [atlub.exe] C:\WINDOWS\atlub.exe
O4 - HKLM\..\RunOnce: [nttx32.exe] C:\WINDOWS\system32\nttx32.exe
O4 - HKLM\..\RunOnce: [appmq.exe] C:\WINDOWS\system32\appmq.exe
O4 - HKLM\..\RunOnce: [sysat32.exe] C:\WINDOWS\system32\sysat32.exe
O4 - HKLM\..\RunOnce: [crhx32.exe] C:\WINDOWS\system32\crhx32.exe
O4 - HKLM\..\RunOnce: [ipdv32.exe] C:\WINDOWS\ipdv32.exe
O4 - HKLM\..\RunOnce: [addnl.exe] C:\WINDOWS\system32\addnl.exe
O4 - HKLM\..\RunOnce: [ipce.exe] C:\WINDOWS\ipce.exe
O4 - HKLM\..\RunOnce: [netkp.exe] C:\WINDOWS\system32\netkp.exe
O4 - HKLM\..\RunOnce: [appup.exe] C:\WINDOWS\appup.exe*

Let's see what the "heavy hitters" on this forum have to say about them.

----------------------------------------------------------------

You need to post a new log here so we can look at it and get some of the entries fixed.

----------------------------------------------------------------


----------



## mcarpio (Nov 14, 2003)

Actually they find problems, they just can't fix them. Spybot brings up av gold and blue trek error nuker (pretty close?) then says it couldn't fix because it is active in memory (or something to that effect) can it run again at start up, but it always has the same result. Ad-aware found a bunch of stuff that was quarentined--still no change. I think when I did About Buster (Thursday afternoon) it found stuff and said it couldn't fix any of it. For this HJT I will disable my IE shield, as soon as I do that my homepage and searchpage change. I think the run once stuff may be all the nasty links that keep getting added to my Favorites folder. This thing is also making links to their stuff out of words in regular text, I have never seen that before. P.S. I am also using Spy Blaster.


----------



## mcarpio (Nov 14, 2003)

Logfile of HijackThis v1.99.1
Scan saved at 11:20:14 AM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\javawh32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC07.EXE
C:\Documents and Settings\Owner\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\jmqzn.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {F3A0E4F7-5A26-16D7-F285-82AF755C81E0} - C:\WINDOWS\system32\nethz32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe
O4 - HKLM\..\RunOnce: [iezr32.exe] C:\WINDOWS\system32\iezr32.exe
O4 - HKLM\..\RunOnce: [sdkhg32.exe] C:\WINDOWS\system32\sdkhg32.exe
O4 - HKLM\..\RunOnce: [ippt.exe] C:\WINDOWS\system32\ippt.exe
O4 - HKLM\..\RunOnce: [wintp.exe] C:\WINDOWS\system32\wintp.exe
O4 - HKLM\..\RunOnce: [javabp32.exe] C:\WINDOWS\javabp32.exe
O4 - HKLM\..\RunOnce: [apihr.exe] C:\WINDOWS\apihr.exe
O4 - HKLM\..\RunOnce: [winai32.exe] C:\WINDOWS\system32\winai32.exe
O4 - HKLM\..\RunOnce: [appau32.exe] C:\WINDOWS\appau32.exe
O4 - HKLM\..\RunOnce: [apizz.exe] C:\WINDOWS\system32\apizz.exe
O4 - HKLM\..\RunOnce: [addao.exe] C:\WINDOWS\system32\addao.exe
O4 - HKLM\..\RunOnce: [mszb.exe] C:\WINDOWS\mszb.exe
O4 - HKLM\..\RunOnce: [sdkub32.exe] C:\WINDOWS\system32\sdkub32.exe
O4 - HKLM\..\RunOnce: [adduh.exe] C:\WINDOWS\adduh.exe
O4 - HKLM\..\RunOnce: [mfczw.exe] C:\WINDOWS\mfczw.exe
O4 - HKLM\..\RunOnce: [atlun.exe] C:\WINDOWS\system32\atlun.exe
O4 - HKLM\..\RunOnce: [javadw.exe] C:\WINDOWS\javadw.exe
O4 - HKLM\..\RunOnce: [ippc32.exe] C:\WINDOWS\ippc32.exe
O4 - HKLM\..\RunOnce: [sdklq32.exe] C:\WINDOWS\sdklq32.exe
O4 - HKLM\..\RunOnce: [syscb.exe] C:\WINDOWS\system32\syscb.exe
O4 - HKLM\..\RunOnce: [winhi32.exe] C:\WINDOWS\winhi32.exe
O4 - HKLM\..\RunOnce: [d3ua32.exe] C:\WINDOWS\d3ua32.exe
O4 - HKLM\..\RunOnce: [cryp32.exe] C:\WINDOWS\cryp32.exe
O4 - HKLM\..\RunOnce: [netes.exe] C:\WINDOWS\system32\netes.exe
O4 - HKLM\..\RunOnce: [addps32.exe] C:\WINDOWS\addps32.exe
O4 - HKLM\..\RunOnce: [sysku.exe] C:\WINDOWS\system32\sysku.exe
O4 - HKLM\..\RunOnce: [atloy32.exe] C:\WINDOWS\system32\atloy32.exe
O4 - HKLM\..\RunOnce: [msua.exe] C:\WINDOWS\msua.exe
O4 - HKLM\..\RunOnce: [javajk.exe] C:\WINDOWS\system32\javajk.exe
O4 - HKLM\..\RunOnce: [mszt.exe] C:\WINDOWS\system32\mszt.exe
O4 - HKLM\..\RunOnce: [ntyj32.exe] C:\WINDOWS\system32\ntyj32.exe
O4 - HKLM\..\RunOnce: [d3xu.exe] C:\WINDOWS\system32\d3xu.exe
O4 - HKLM\..\RunOnce: [netrt32.exe] C:\WINDOWS\system32\netrt32.exe
O4 - HKLM\..\RunOnce: [addli32.exe] C:\WINDOWS\addli32.exe
O4 - HKLM\..\RunOnce: [appev.exe] C:\WINDOWS\system32\appev.exe
O4 - HKLM\..\RunOnce: [wincw32.exe] C:\WINDOWS\system32\wincw32.exe
O4 - HKLM\..\RunOnce: [iekb.exe] C:\WINDOWS\iekb.exe
O4 - HKLM\..\RunOnce: [crtw32.exe] C:\WINDOWS\system32\crtw32.exe
O4 - HKLM\..\RunOnce: [nteu.exe] C:\WINDOWS\system32\nteu.exe
O4 - HKLM\..\RunOnce: [nethc32.exe] C:\WINDOWS\system32\nethc32.exe
O4 - HKLM\..\RunOnce: [crjx.exe] C:\WINDOWS\crjx.exe
O4 - HKLM\..\RunOnce: [d3pd.exe] C:\WINDOWS\system32\d3pd.exe
O4 - HKLM\..\RunOnce: [netux32.exe] C:\WINDOWS\netux32.exe
O4 - HKLM\..\RunOnce: [nttn32.exe] C:\WINDOWS\system32\nttn32.exe
O4 - HKLM\..\RunOnce: [winrw.exe] C:\WINDOWS\system32\winrw.exe
O4 - HKLM\..\RunOnce: [ntre32.exe] C:\WINDOWS\ntre32.exe
O4 - HKLM\..\RunOnce: [sysgb.exe] C:\WINDOWS\sysgb.exe
O4 - HKLM\..\RunOnce: [winqz.exe] C:\WINDOWS\system32\winqz.exe
O4 - HKLM\..\RunOnce: [d3ey32.exe] C:\WINDOWS\system32\d3ey32.exe
O4 - HKLM\..\RunOnce: [ntco32.exe] C:\WINDOWS\ntco32.exe
O4 - HKLM\..\RunOnce: [atlhq32.exe] C:\WINDOWS\atlhq32.exe
O4 - HKLM\..\RunOnce: [sysgf32.exe] C:\WINDOWS\system32\sysgf32.exe
O4 - HKLM\..\RunOnce: [apiey32.exe] C:\WINDOWS\apiey32.exe
O4 - HKLM\..\RunOnce: [winjt.exe] C:\WINDOWS\winjt.exe
O4 - HKLM\..\RunOnce: [appcu32.exe] C:\WINDOWS\system32\appcu32.exe
O4 - HKLM\..\RunOnce: [ipnq.exe] C:\WINDOWS\ipnq.exe
O4 - HKLM\..\RunOnce: [mfcza32.exe] C:\WINDOWS\system32\mfcza32.exe
O4 - HKLM\..\RunOnce: [apppv32.exe] C:\WINDOWS\system32\apppv32.exe
O4 - HKLM\..\RunOnce: [netnc.exe] C:\WINDOWS\system32\netnc.exe
O4 - HKLM\..\RunOnce: [javajg.exe] C:\WINDOWS\system32\javajg.exe
O4 - HKLM\..\RunOnce: [netra.exe] C:\WINDOWS\system32\netra.exe
O4 - HKLM\..\RunOnce: [sysqi32.exe] C:\WINDOWS\system32\sysqi32.exe
O4 - HKLM\..\RunOnce: [netxx.exe] C:\WINDOWS\system32\netxx.exe
O4 - HKLM\..\RunOnce: [addkr32.exe] C:\WINDOWS\addkr32.exe
O4 - HKLM\..\RunOnce: [ieiw.exe] C:\WINDOWS\system32\ieiw.exe
O4 - HKLM\..\RunOnce: [applx.exe] C:\WINDOWS\applx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v7.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\wintp.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


----------



## flavallee (May 12, 2002)

Restart your computer in safe mode, then run all those utilities from there. Hopefully, they'll run better and do their job properly.

After you've done that, restart your computer in normal Windows mode, run another scan, then post a new log here.

----------------------------------------------------------------


----------



## iaavagent (Jan 11, 2004)

Go to MS and download their antispyware beta tool and run it per their instructions. Based on tests against others theirs did a better job=100%

While there download their Malicious software tool KB something? and run it also per their instructions just to be safe.It's updated every second tuesday of the month.
Lets see if the tests were correct. 
Then post another HJT log.Then lets go from there.

Just a suggestion base on your results with other ad/spyware tools.
Good luck.


----------



## flavallee (May 12, 2002)

Personally, I wouldn't use *Microsoft AntiSpyware* because it's still in beta testing and not a finished product.


----------



## mcarpio (Nov 14, 2003)

Logfile of HijackThis v1.99.1
Scan saved at 8:52:23 PM, on 7/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\javawh32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ccbwz.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {8E7F30A6-13D2-011A-7035-94F744F9CFE8} - C:\WINDOWS\netdr32.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {EC241FF0-652E-A2FA-E684-F15E5A9719CD} - C:\WINDOWS\javacq.dll
O2 - BHO: Class - {F3A0E4F7-5A26-16D7-F285-82AF755C81E0} - C:\WINDOWS\system32\nethz32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe
O4 - HKLM\..\RunOnce: [ntgj32.exe] C:\WINDOWS\system32\ntgj32.exe
O4 - HKLM\..\RunOnce: [wintp.exe] C:\WINDOWS\system32\wintp.exe
O4 - HKLM\..\RunOnce: [atlld.exe] C:\WINDOWS\system32\atlld.exe
O4 - HKLM\..\RunOnce: [d3xw.exe] C:\WINDOWS\d3xw.exe
O4 - HKLM\..\RunOnce: [netdr32.exe] C:\WINDOWS\netdr32.exe
O4 - HKLM\..\RunOnce: [syscz.exe] C:\WINDOWS\system32\syscz.exe
O4 - HKLM\..\RunOnce: [sdkqb.exe] C:\WINDOWS\system32\sdkqb.exe
O4 - HKLM\..\RunOnce: [msbh.exe] C:\WINDOWS\msbh.exe
O4 - HKLM\..\RunOnce: [wintt32.exe] C:\WINDOWS\system32\wintt32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v7.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

This is my log after running everything in safe mode. As you can see it didn't make much difference.


----------



## iaavagent (Jan 11, 2004)

Here's the link for ewido download trial.= http://www.ewido.net/en/download/ 
Many of the experts on TSG site have been suggesting that it be used. You can review what it does at the site and then download it if you want. I wouldn't use it until an expert instructs you on what to do.
I see a lot of "fixes" from your log and you may have a virus/trojan?, not sure as you have protection and assume it's updated.

I know there are pros and cons on MS antispyware but many have used it since MS has updated and repaired most bugs? This is not to say it's now ok, but the test results I've read have been pretty good.Will it fix yours? it will find them,fixing is another matter in view of your difficulty with the other products.

With all that said, and I know it hasn't helped you, I wish you luck and know one the experts on this site will know what you should do.
Take care.


----------



## mcarpio (Nov 14, 2003)

I read these instuctions in another post...I have got everything ready to follow them but I won't do anything until I hear from an expert. I think the problem is pretty much the same, however I know there could be key differences. I am only putting this here just in case it saves someone from alot of typing, lol.

Now go ahead and set your computer to show hidden files like so:

Because XP will not always show you hidden files and folders by default, 
Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden 
files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View 
tab and make sure that "Show hidden files and folders" is checked. Also 
uncheck "Hide protected operating system files" and "Hide extensions for 
known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

______________________________________________________________________

Sign off the Internet and remain offline until this procedure is complete. 
Unplug your modem or disconnect the cable or phone line. Copy these 
instructions to notepad and save them on your desktop for easy access. You 
must follow these directions exactly and you cannot skip any part of it.
______________________________________________________________________

Click Start > Run > and type in:

services.msc

Click OK.

In the services window find Network Security Service 
Right click and choose "Properties". On the "General" tab under "Service 
Status" click the "Stop" button to stop the service. Beside "Startup Type" 
in the dropdown menu select "Disabled". Click Apply then OK. Exit the 
Services utility.

Note: You may get an error here when trying to access the properties of the 
service. If you do get an error, just select the service and look there in 
the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.

______________________________________________________________________

Restart to safe mode.

http://service1.symantec.com/SUPPOR...001052409420406

Perform the following steps in safe mode:
____________________________________________________________________

Double click on the cwsserviceemove.reg file you downloaded at the beginning to enter into the registry. Answer yes when asked to have its contents added to the registry.
____________________________________________________________________

* Restart your computer into safe mode now. Perform the following steps in 
safe mode:

* Run Ewido:

* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

Go to Start > Run and type Hijackthis. Press enter to start HijackThis. 
DO NOT OPEN ANYTHING ELSE!

Put a check by these entries in Hijack This and click the "Fix Checked" 
button:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar /> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page /> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL /> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar /> R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page /> R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant /> R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant /> R3 - Default URLSearchHook is missing
O2 - BHO: GDS module - {A084A565-B09B-4e4c-A497-7CC50AEAB2A7} - C:\WINDOWS\gds5.dll
O2 - BHO: Class - {E29E716E-89A9-0782-CB51-5A1AF0B309FC} - C:\WINDOWS\system32\crzg32.dll
O2 - BHO: Class - {FF534564-71EA-B589-BFE1-B3735E7B4CF5} - C:\WINDOWS\system32\sdkmq32.dll
O4 - HKLM\..\Run: [apixr.exe] C:\WINDOWS\apixr.exe
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\javauy32.exe" /s (file missing)

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. 
In the Full Path of File to Delete box, copy and paste each of the following 
lines one at a time then click on the button that has the red circle with the
X in the middle after you enter each file. It will ask for confirmation to 
delete the file. Click Yes. Continue with that same procedure until you have 
copied and pasted all of these in the Paste Full Path of File to Delete box.

Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you 
don't miss any.

C:\WINDOWS\gds5.dll
C:\WINDOWS\system32\crzg32.dll
C:\WINDOWS\system32\sdkmq32.dll
O4 - HKLM\..\Run: [apixr.exe] C:\WINDOWS\apixr.exe

___________________________________________________________________

Next run aboutbuster. Double click aboutbuster.exe, click OK, click Start, 
then click OK. This will scan your computer for the bad files and delete them.
_______________________________________________________________________

Finally, run CWShredder. Just click on the cwshredder.exe then click "Fix" 
(Not "Scan only") and let it do its thing.

_______________________________________________________________________

In safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and
go to Edit > Select All then Edit > Delete to delete the entire contents of
the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open.
Click Edit > Select All then Edit > Delete to delete the entire contents of 
the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under 
"Temporary Internet Files" Click "Delete Files". Put a check by "Delete 
Offline Content" and click OK. Click on the Programs tab then click the 
"Reset Web Settings" button. Click Apply then OK.
_______________________________________________________________________

Boot back into Windows now.

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.

Go to: http://housecall.trendmicro.com/ and do an online virus scan.

Be sure and put a check in the box by "Auto Clean" before you do the scan. 
If it finds anything that it cannot clean have it delete it or make a note 
of the file location so you can delete it yourself. Housecall will detect 
the leftover files from this hijacker.

This hijacker is known to alter or delete certain files so check this out 
please:

Download the Hoster from: 
http://www.funkytoad.com/download/hoster.zip UnZip 
the file and press "Restore Original Hosts" and press "OK". Exit Program.

If you have Spybot S&D installed you will also need to replace one file. Go 
to: http://www.spywareinfo.com/~merijn/winfiles.html and download 
SDHelper.dll. Copy the file to the folder containing your Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)

Check in the C:\Windows\system32 folder to be sure you have a file named 
Shell.dll. If you do not have one, go to the C:\Windows\system32\dllcache 
folder.

Find shell.dll and right click on it. Choose Copy from the menu.
Open the System32 folder and right click on an empty space in the window. 
Choose Paste from the menu. Otherwise, you can download following the 
instructions here: http://www.bleepingcomputer.com/files/shellxp.php

control.exe may have been deleted.
See if control.exe is present in C:\windows\system32

If control.exe isn't there, go to: 
http://www.richardthelionhearted.co...es.html#control, and download 
control.exe per the instructions at the site.

IMPORTANT!: Please check your ActiveX security settings. They may have been 
changed by this CWS variant to allow ALL ActiveX!! Reset your ActiveX security settings like so... Go to Internet Options > Security > Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options (Download signed and 
unsigned ActiveX
controls) to 'prompt', and 'Initialize and Script ActiveX controls not 
marked as safe" to 'disable'.

Now run ccleaner

Reboot and post another Hijack This log please and the ewido log.
__________________
khazars

--------------------------------------------------------------------------------


----------



## flavallee (May 12, 2002)

Mcarpio:

Those utilities must've done their job properly in safe mode. Most of those O18 C:\WINDOWS are no longer in your log. Let's see if we can get rid of the rest of them.

Run another scan, then select and fix the following:

*R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ccbwz.dll/sp.html#37049

R3 - Default URLSearchHook is missing

O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe

O4 - HKLM\..\RunOnce: [ntgj32.exe] C:\WINDOWS\system32\ntgj32.exe

O4 - HKLM\..\RunOnce: [wintp.exe] C:\WINDOWS\system32\wintp.exe

O4 - HKLM\..\RunOnce: [atlld.exe] C:\WINDOWS\system32\atlld.exe

O4 - HKLM\..\RunOnce: [d3xw.exe] C:\WINDOWS\d3xw.exe

O4 - HKLM\..\RunOnce: [netdr32.exe] C:\WINDOWS\netdr32.exe

O4 - HKLM\..\RunOnce: [syscz.exe] C:\WINDOWS\system32\syscz.exe

O4 - HKLM\..\RunOnce: [sdkqb.exe] C:\WINDOWS\system32\sdkqb.exe

O4 - HKLM\..\RunOnce: [msbh.exe] C:\WINDOWS\msbh.exe

O4 - HKLM\..\RunOnce: [wintt32.exe] C:\WINDOWS\system32\wintt32.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)*

Reboot afterwards, then post a new log here.

----------------------------------------------------------------


----------



## mcarpio (Nov 14, 2003)

I did what you said and I ran the HJT again (I was in safe mode), I removed the items you listed then ran the cleaners again. First was spybot, it came up with the same garbage that keeps coming back, so I am writing here what it came up with.

here goes:

1. startpage-EH
bookmark [internet explorer: owner]
internet explorer [owner] = only s*x website (http://www.onlys*x.ws/)

2. av-gold
class ID
HKEY_Classes_Root\CLSID\{9CB478A2-CA39-0CFD-EFAC- 
DB89710601D3}

3. Coolwwwsearch.Aff.Winshow
link
C:\documents and settings\owner\favorites\----38 different endings to this

4. Klez
Executable
C:\windows\system32\winkr.exe

Executable
C:\windows\system32\winkd.exe

5. Trek Blue Error Nuker
settings
hkey_local_machine\system\currentcontrolset\services\11FB followed weird symbols.

settings
hkey_local_machine\sytem\controlset001\services\11FB weird symbols.

Three of these will only list one, then the endings:
uninstall settings
hkey_local_machine\software\microsoft\windows\currentversion\
uninstall\sw
uninstall\se
uninstall\hsa

After 'fixing' the problems AV-Gold and Trek Blue Error Nuker - settings
hkey_local_machine\sytem\controlset001\services\11FB weird symbols
remained.


----------



## mcarpio (Nov 14, 2003)

Okay...then I ran AD AWARE 37 objects from coll web search and 2 tracking cookies. I had it do its thing then I did About Buster (I am not sure what it did or found so I think I may need to redownload it). CWShredder didn't find anything. I did spybot again and only AV-Gold was there(still couldn't be removed)
Then I ran spy sweeper and it found 6 items from cool web search, cws_ns3 (more than 20 items associated with that), 11 items from cws_tiny0, and this Trojan_downloader_tibser (2 items)


----------



## mcarpio (Nov 14, 2003)

That being said, I restarted the computer in normal mode and ran HJT and here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 10:33:43 PM, on 7/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\javawh32.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ubnim.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {5952B661-A49F-07C2-2FD6-A5C20926F8DF} - C:\WINDOWS\iehi32.dll
O2 - BHO: Class - {73C994D2-169A-3A21-18CA-289B70E63DA3} - C:\WINDOWS\sdklb32.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {F3A0E4F7-5A26-16D7-F285-82AF755C81E0} - C:\WINDOWS\system32\nethz32.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe
O4 - HKLM\..\RunOnce: [mfcbe32.exe] C:\WINDOWS\system32\mfcbe32.exe
O4 - HKLM\..\RunOnce: [crgs32.exe] C:\WINDOWS\crgs32.exe
O4 - HKLM\..\RunOnce: [syswt32.exe] C:\WINDOWS\system32\syswt32.exe
O4 - HKLM\..\RunOnce: [netgx32.exe] C:\WINDOWS\system32\netgx32.exe
O4 - HKLM\..\RunOnce: [msum.exe] C:\WINDOWS\system32\msum.exe
O4 - HKLM\..\RunOnce: [ipof.exe] C:\WINDOWS\system32\ipof.exe
O4 - HKLM\..\RunOnce: [netpf.exe] C:\WINDOWS\system32\netpf.exe
O4 - HKLM\..\RunOnce: [ntyu.exe] C:\WINDOWS\system32\ntyu.exe
O4 - HKLM\..\RunOnce: [apppe32.exe] C:\WINDOWS\system32\apppe32.exe
O4 - HKLM\..\RunOnce: [winxr.exe] C:\WINDOWS\system32\winxr.exe
O4 - HKLM\..\RunOnce: [netpn.exe] C:\WINDOWS\netpn.exe
O4 - HKLM\..\RunOnce: [sysel32.exe] C:\WINDOWS\system32\sysel32.exe
O4 - HKLM\..\RunOnce: [appoy.exe] C:\WINDOWS\system32\appoy.exe
O4 - HKLM\..\RunOnce: [netvj.exe] C:\WINDOWS\netvj.exe
O4 - HKLM\..\RunOnce: [winwt32.exe] C:\WINDOWS\system32\winwt32.exe
O4 - HKLM\..\RunOnce: [mfcyg.exe] C:\WINDOWS\system32\mfcyg.exe
O4 - HKLM\..\RunOnce: [javana32.exe] C:\WINDOWS\system32\javana32.exe
O4 - HKLM\..\RunOnce: [sdkhg32.exe] C:\WINDOWS\system32\sdkhg32.exe
O4 - HKLM\..\RunOnce: [javarn.exe] C:\WINDOWS\system32\javarn.exe
O4 - HKLM\..\RunOnce: [sdkzq32.exe] C:\WINDOWS\sdkzq32.exe
O4 - HKLM\..\RunOnce: [wingf.exe] C:\WINDOWS\wingf.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v7.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcbe32.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

I hope that this info can help solve this puzzle. I really appreciate all the help, even if it seems like we are chipping away at a brick wall, lol. Really, thank you


----------



## flavallee (May 12, 2002)

Some of the "heavy hitters" on this forum are going to need to help you because you still have too many problems in your log that need fixing.

----------------------------------------------------------------

Click Start - Run, type in MSCONFIG and then click OK - Startup(tab). Write down everything in the leftmost column that still have a checkmark next to them, then post the list here in a vertical column.

----------------------------------------------------------------


----------



## flavallee (May 12, 2002)

Just to make sure I'm clear as to what I said earlier, I just need you to write down what's listed in the leftmost column next to the little square boxes. I don't need the command lines or file paths. Just write down the ones that still have a checkmark next to them.

---------------------------------------------------------------

You need to run a scan with HijackThis in normal Windows mode. If you run it in safe mode, it won't display everything.

---------------------------------------------------------------


----------



## iaavagent (Jan 11, 2004)

I know there is a special remover for AV GOLD and some "fix" items you have to also find the file and manually delete them. I'm no expert either but have seen this on other threads. As flavallee said, some of the heavy hitters need to wrap this up for ya. Hang tight.


----------



## iaavagent (Jan 11, 2004)

mcarpio, here is a link http://forums.techguy.org/showthread.php?t=376692&page=1 to just "read" on TSG which will shed some light on the matter. Also read this, link in TSG= http://forums.techguy.org/showthread.php?t=376692&page=1 as you have a 020 entry that is simillar.
Hang in there.


----------



## iaavagent (Jan 11, 2004)

PS, according to the above 2nd link, a Moderator needs to handle your log.
One should get to you soon. If not in a day or so, just type "BUMP" in this thread
to get ones attention. Good luck.


----------



## mcarpio (Nov 14, 2003)

Thanks alot. I didn't know that HJT didn't show everything in safe mode, but I did have a feeling that if I ran it in normal mode after going on the internet just one time, all the bad stuff would be back (and I was right). Also, just in case it wasn't clear, if I were to run spybot s&d right now, all of those problems would be back. Even the ones that I supposedly fixed. Also, this thing keeps changing my security settings to enable active x, I have changed it back 4 times now.


----------



## mcarpio (Nov 14, 2003)

Well I'm off now to do the msconfig thing. BRB


----------



## mcarpio (Nov 14, 2003)

igfxtray
hkcmd
RECGUARD
NeroCheck
PDVDServ
shwiconem
<-- this is checked AND blank!
portAOL
SNDMon
jusched
SpySweeper
dumprep 0 -k
javawh32
msmsgs
ypager
BigFix
hp psc 1000 series
hpoddt01.exe


----------



## flavallee (May 12, 2002)

Mcarpio:

Thanks for posting the startup list. I was almost ready to give up on you.

The startup list that you posted all still have a checkmark next to them, right?

----------------------------------------------------------------

You can remove the checkmark from the ones that I have highlighted in bold print.

*igfxtray* Read here
*hkcmd* Read here
RECGUARD
NeroCheck
*PDVDServ* Read here
shwiconem
*<-- this is checked AND blank!*
portAOL
SNDMon
*jusched* Read here
SpySweeper
*dumprep 0 -k* Read here
*javawh32* (I'm fairly sure this one is virus-related)
*msmsgs* Read here
*ypager* Read here
*BigFix* Read here
hp psc 1000 series
hpoddt01.exe

Once you're done, click Apply - OK, then reboot. When the SCU window appears during reboot, ignore the message. Just place a checkmark in it, then click OK.

*msmsgs* and *ypager* are associated with chat programs. You don't need to have them load automatically during startup. You can always start them manually when you're ready to use them. You might also go into their options/preferences section and disable any commands there that allow them to load during startup.

*PDVDServ* isn't needed, unless you use a remote control with your DVD drive.

----------------------------------------------------------------


----------



## mcarpio (Nov 14, 2003)

Thank you again. I will go uncheck those items now.


----------



## flavallee (May 12, 2002)

Re-read my reply, as I've updated it.


----------



## mcarpio (Nov 14, 2003)

I don't use AOL anymore as I have a cable modem now. Should I uncheck the AOL item?


----------



## flavallee (May 12, 2002)

By all means, uncheck *portAOL*

You might also want to check and make sure that all the AOL crap is out of your computer.

Getting rid of AOL was a good move. 

---------------------------------------------------------------

Once that startup list is trimmed down, you should notice an overall performance improvement. :up:

---------------------------------------------------------------


----------



## mcarpio (Nov 14, 2003)

Thank you again!


----------



## flavallee (May 12, 2002)

You're welcome. Glad to have helped.


----------



## mcarpio (Nov 14, 2003)

When I ran cwshredder it made my computer restart. I wasn't sure what was going on, so I removed it and went to dl another copy of it. While I was there I read this:


CWShredder or HijackThis closes immediately after opening? 
There is a variant of the Coolwebsearch trojan spreading that closes several anti-spyware apps when you try to open them. 
If this is happening to you, download PepiMK's CoolWWWSearch.SmartKiller removal tool first and run it. After it does its job, CWShredder and HijackThis will run properly (as well Spybot S&D, Ad-aware and several anti-spyware forums). 


Should I dl the smartkiller removal tool? Or should I just hold on until one of the moderators can respond to my thread?


----------



## khazars (Feb 15, 2004)

hi there, post a new hijack this log as it will have changed and I'll check it for you. 


Do you have all the tools downloaded already, ewdido, cwsservice reg cwshredder and aboutbuster, kilbox?


----------



## mcarpio (Nov 14, 2003)

I have those tools downloaded. I will be right back with the new log!


----------



## mcarpio (Nov 14, 2003)

Logfile of HijackThis v1.99.1
Scan saved at 5:24:24 PM, on 7/18/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\javawh32.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {AE33961D-B5C6-86A4-3C72-DBA3BBD317B9} - C:\WINDOWS\appqw32.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Class - {CA536228-5961-D1A0-FEFF-CF26224A6BFA} - C:\WINDOWS\appzs.dll
O2 - BHO: Class - {FD28144A-BE74-ABB6-5C2B-E60BF82588B7} - C:\WINDOWS\addpr.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe
O4 - HKLM\..\RunOnce: [sdkuu.exe] C:\WINDOWS\system32\sdkuu.exe
O4 - HKLM\..\RunOnce: [winly.exe] C:\WINDOWS\system32\winly.exe
O4 - HKLM\..\RunOnce: [ipql32.exe] C:\WINDOWS\system32\ipql32.exe
O4 - HKLM\..\RunOnce: [ntrh.exe] C:\WINDOWS\system32\ntrh.exe
O4 - HKLM\..\RunOnce: [d3cv32.exe] C:\WINDOWS\system32\d3cv32.exe
O4 - HKLM\..\RunOnce: [winqt.exe] C:\WINDOWS\system32\winqt.exe
O4 - HKLM\..\RunOnce: [crtw.exe] C:\WINDOWS\crtw.exe
O4 - HKLM\..\RunOnce: [appfu32.exe] C:\WINDOWS\system32\appfu32.exe
O4 - HKLM\..\RunOnce: [ieeh32.exe] C:\WINDOWS\ieeh32.exe
O4 - HKLM\..\RunOnce: [javacu32.exe] C:\WINDOWS\system32\javacu32.exe
O4 - HKLM\..\RunOnce: [d3of.exe] C:\WINDOWS\d3of.exe
O4 - HKLM\..\RunOnce: [ntmt32.exe] C:\WINDOWS\system32\ntmt32.exe
O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\Program Files\Yahoo!\YPSR\ppclean.exe" "clean" "smartfinder" "2"
O4 - HKLM\..\RunOnce: [addcj32.exe] C:\WINDOWS\addcj32.exe
O4 - HKLM\..\RunOnce: [d3hf32.exe] C:\WINDOWS\d3hf32.exe
O4 - HKLM\..\RunOnce: [mfcbe32.exe] C:\WINDOWS\system32\mfcbe32.exe
O4 - HKLM\..\RunOnce: [appcr32.exe] C:\WINDOWS\appcr32.exe
O4 - HKLM\..\RunOnce: [ipno.exe] C:\WINDOWS\system32\ipno.exe
O4 - HKLM\..\RunOnce: [netxx32.exe] C:\WINDOWS\netxx32.exe
O4 - HKLM\..\RunOnce: [ievw32.exe] C:\WINDOWS\ievw32.exe
O4 - HKLM\..\RunOnce: [sdkby32.exe] C:\WINDOWS\system32\sdkby32.exe
O4 - HKLM\..\RunOnce: [iekr32.exe] C:\WINDOWS\iekr32.exe
O4 - HKLM\..\RunOnce: [ntyt.exe] C:\WINDOWS\ntyt.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_games/gamehouse/frenzy/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://aolsvc.aol.com/onlinegames/bejeweled2/popcaploader_v7.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcbe32.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


----------



## mcarpio (Nov 14, 2003)

I still am wondering if it is normal for the computer to restart auto. while running cwshredder?


----------



## khazars (Feb 15, 2004)

I think that might be the psyware. Make syre to boot into safe mode to run these tools and follow all my instructions precisely! ewido will take care of most of those 04s!

* Download the trial version of Ewido Security Suite here

http://www.ewido.net/en/

* Install ewido.
* During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
* Launch ewido
* It will prompt you to update click the OK button and it will go to the main screen
* On the left side of the main screen click update
* Click on Start and let it update.
* DO NOT run a scan yet. You will do that later in safe mode.

You will need to download the following tools and have them ready to run. 
Do not run any of them until instructed to do so:

Click: http://castlecops.com/zx/flrman1/cwsserviceremove.zip to download 
cwsserviceremove.zip and unzip it to your desktop.

Go here: http://www.filehippo.com/download_ccleaner.html to download and 
install CCleaner.

Download Killbox here: http://www.thespykiller.co.uk/files/killbox.exe and 
save it to your desktop.

Click here: http://cwshredder.net/bin/CWSInstall.exe to download 
CWSinstall.exe to the desktop.

Click: http://www.downloads.subratam.org/AboutBuster.zip to download 
AboutBuster created by Rubber Ducky.

Unzip AboutBuster to the Desktop then click the "Update Button" then click 
"Check for Update" and download the updates and then click "Exit" because I 
don't want you to run it yet. Just get the updates so it is ready to run 
later in safe mode.

Now go ahead and set your computer to show hidden files like so:

Because XP will not always show you hidden files and folders by default,
Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden
files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View
tab and make sure that "Show hidden files and folders" is checked. Also
uncheck "Hide protected operating system files" and "Hide extensions for
known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

______________________________________________________________________

Sign off the Internet and remain offline until this procedure is complete.
Unplug your modem or disconnect the cable or phone line. Copy these
instructions to notepad and save them on your desktop for easy access. You
must follow these directions exactly and you cannot skip any part of it.
______________________________________________________________________

Click Start > Run > and type in:

services.msc

Click OK.

In the services window find Workstation NetLogon Service
Right click and choose "Properties". On the "General" tab under "Service
Status" click the "Stop" button to stop the service. Beside "Startup Type"
in the dropdown menu select "Disabled". Click Apply then OK. Exit the
Services utility.

Note: You may get an error here when trying to access the properties of the
service. If you do get an error, just select the service and look there in
the top left of the main service window and click "Stop" to stop the service. If that gives an error or it is already stopped, just skip this step and proceed with the rest.

______________________________________________________________________

Restart to safe mode.

http://service1.symantec.com/SUPPOR...001052409420406

Perform the following steps in safe mode:
____________________________________________________________________

Double click on the cwsserviceemove.reg file you downloaded at the beginning to enter into the registry. Answer yes when asked to have its contents added to the registry.
____________________________________________________________________

* Run Ewido:

* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

Go to Start > Run and type Hijackthis. Press enter to start HijackThis.
DO NOT OPEN ANYTHING ELSE!

Put a check by these entries in Hijack This and click the "Fix Checked"
button:

Note, some of these files will have been deleted by ewido so just carry on with what's left.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\dodzn.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {AE33961D-B5C6-86A4-3C72-DBA3BBD317B9} - C:\WINDOWS\appqw32.dll
O2 - BHO: Class - {CA536228-5961-D1A0-FEFF-CF26224A6BFA} - C:\WINDOWS\appzs.dll
O2 - BHO: Class - {FD28144A-BE74-ABB6-5C2B-E60BF82588B7} - C:\WINDOWS\addpr.dll
O4 - HKLM\..\Run: [javawh32.exe] C:\WINDOWS\javawh32.exe
O23 - Service: Workstation NetLogon Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\mfcbe32.exe" /s (file missing)

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill.
In the Full Path of File to Delete box, copy and paste each of the following
lines one at a time then click on the button that has the red circle with the
X in the middle after you enter each file. It will ask for confirmation to
delete the file. Click Yes. Continue with that same procedure until you have
copied and pasted all of these in the Paste Full Path of File to Delete box.

Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you
don't miss any.

C:\WINDOWS\dodzn.dll
C:\WINDOWS\appqw32.dll
C:\WINDOWS\appzs.dll
C:\WINDOWS\addpr.dll
C:\WINDOWS\javawh32.exe

___________________________________________________________________

Next run aboutbuster. Double click aboutbuster.exe, click OK, click Start,
then click OK. This will scan your computer for the bad files and delete them.
_______________________________________________________________________

Finally, run CWShredder. Just click on the cwshredder.exe then click "Fix"
(Not "Scan only") and let it do its thing.

_______________________________________________________________________

In safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and
go to Edit > Select All then Edit > Delete to delete the entire contents of
the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open.
Click Edit > Select All then Edit > Delete to delete the entire contents of
the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under
"Temporary Internet Files" Click "Delete Files". Put a check by "Delete
Offline Content" and click OK. Click on the Programs tab then click the
"Reset Web Settings" button. Click Apply then OK.
_______________________________________________________________________

Boot back into Windows now.

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.

Go to: http://housecall.trendmicro.com/ and do an online virus scan.

Be sure and put a check in the box by "Auto Clean" before you do the scan.
If it finds anything that it cannot clean have it delete it or make a note
of the file location so you can delete it yourself. Housecall will detect
the leftover files from this hijacker.

This hijacker is known to alter or delete certain files so check this out
please:

Download the Hoster from:
http://www.funkytoad.com/download/hoster.zip UnZip
the file and press "Restore Original Hosts" and press "OK". Exit Program.

If you have Spybot S&D installed you will also need to replace one file. Go
to: http://www.spywareinfo.com/~merijn/winfiles.html and download
SDHelper.dll. Copy the file to the folder containing your Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)

Check in the C:\Windows\system32 folder to be sure you have a file named
Shell.dll. If you do not have one, go to the C:\Windows\system32\dllcache
folder.

Find shell.dll and right click on it. Choose Copy from the menu.
Open the System32 folder and right click on an empty space in the window.
Choose Paste from the menu. Otherwise, you can download following the
instructions here: http://www.bleepingcomputer.com/files/shellxp.php

control.exe may have been deleted.
See if control.exe is present in C:\windows\system32

If control.exe isn't there, go to:
http://www.richardthelionhearted.co...es.html#control, and download
control.exe per the instructions at the site.

IMPORTANT!: Please check your ActiveX security settings. They may have been
changed by this CWS variant to allow ALL ActiveX!! Reset your ActiveX security settings like so... Go to Internet Options > Security > Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options (Download signed and
unsigned ActiveX
controls) to 'prompt', and 'Initialize and Script ActiveX controls not
marked as safe" to 'disable'.

Now run ccleaner

Reboot and post another Hijack This log please and the ewido log.


----------



## mcarpio (Nov 14, 2003)

Thank you.


----------



## khazars (Feb 15, 2004)

ok, post back with the logs when your finished!


----------



## flavallee (May 12, 2002)

Mcarpio:

It is NOT normal for a computer to reboot after CWShredder runs. I am pretty confident that the "nasties" in your computer is the problem.


----------



## mcarpio (Nov 14, 2003)

Logfile of HijackThis v1.99.1
Scan saved at 8:51:33 AM, on 7/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search.yahoo.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {06E85FA0-EB81-EDBC-FD4B-8803432FFA71} - C:\WINDOWS\system32\javatn32.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


----------



## khazars (Feb 15, 2004)

how's your computer runing now, any better?

It looks clean apart form a minor entry

You never posted the log for ewido?

have hijack this fix this one.

O2 - BHO: Class - {06E85FA0-EB81-EDBC-FD4B-8803432FFA71} - C:\WINDOWS\system32\javatn32.dll (file missing)

if your happy and clean do this!?

you should now turn off system restore to flush out the bad restore points and
then re-enable it and make a new clean restore point.

How to turn off system restore

http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

http://support.microsoft.com/default.aspx?scid=kb;[LN];310405

here's some free tools to keep you from getting infected in the future.

to stop reinfection get these two tools, spywareguard and spywareblaster 
from

www.javacoolsoftware.com

get the hosts file from here.

put it into :

Windows XP = C:\WINDOWS\SYSTEM32\DRIVERS\ETC
Windows 2K = C:\WINNT\SYSTEM32\DRIVERS\ETC
Win 98\ME = C:\WINDOWS

http://www.mvps.org/winhelp2002/hosts.htm

ie-spyad.Puts over 5000 sites in your restricted zone so you'll be protected

when you visit innocent-looking sites that aren't actually innocent at all.

https://netfiles.uiuc.edu/ehowes/www/resource.htm

prevX: it stops spyware

http://www.prevx.com/prevxhome.asp

Use spybot's immunize button and use spywareblaster' enable 
protection once you update it. you can put spybot's hosts file into 
your own and lock it.

I would also suggest switching to Mozilla's firefox browser, it's safer, has a built in pop up blocker, blocks cookies and adds.

http://www.mozilla.org/

Read here to see how to tighten your security:

http://forums.techguy.org/t208517.html

A good overall guide for firewalls, anti-virus, and anti-trojans as well as 
regular spyware cleaners.

http://www.firewallguide.com/anti-trojan.htm

you can mark your own thread solved through thread tools at the top of 
the page.


----------



## mcarpio (Nov 14, 2003)

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 5:36:36 AM, 7/19/2005
+ Report-Checksum: 7D313ECF

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{0338CADD-858F-3942-A1BF-3990BAAC16E0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{033935E4-A208-AB9E-DD2A-6A9B7E426D04} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{04256906-BECE-83AC-2058-27ABA38B11A3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{08A3BAAE-CEB8-766F-9585-A831A8E94068} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0AD1A770-F33D-516E-A6BD-A3AEB8568EAC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0ADD4D53-B7DD-20F8-2AC9-AB9CB538A46F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0C016F66-0147-FD26-5123-5C470E6791DD} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0FBFA147-FFB4-19A8-49F8-D1A17B80E32D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{12130DCB-3DF4-96EC-27B9-61E0D766F680} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1F6A3B74-3D40-4D48-4D55-E3A0A8029CC2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{1F846F72-8833-7B85-FBF7-B2D81D30AB82} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{208BD4D8-3DA2-3736-A8E6-F3AF3479FA31} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{24E10FF7-10AA-6198-95AE-258D49D9ABCA} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{252B02AB-6C7E-32B3-827D-F05DA151232D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{29CDA41A-A8EB-6A68-BBF5-2877418D55C7} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2CAB7717-202B-8A26-BFD7-FA41EC47A745} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{30C5202D-2CDD-8C6D-6CD3-86CBAC73988B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{32FB9A97-C47A-795A-3B47-9A97C1448DFC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{47DA2122-90A1-597C-94D7-20963F392761} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{491288EB-D314-5571-9C18-B1EAC89ADE09} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4B3176F0-E32F-B010-C0D8-65FC118C3716} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{4FCD2C21-6232-FD0F-36AA-4EFFC9284B2A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5345A51F-E5D0-5A0D-1418-A1C95C417E3C} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{551764CC-ABCF-335C-76F6-62283B478A0F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5B9A8BE3-69A5-661B-3BB5-FA99E29D5453} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{5F574346-A206-D78A-7149-4C709D5204A4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{64770A00-0C3B-BCEC-D32D-83EE61896228} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{714C2287-DB2D-3514-4785-8EC21BA5C5F1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{72071605-48F5-CC68-B374-2CDDF451F27F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7359F8C5-7626-32C9-DA3E-ECDBA6CDF831} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8324D4AA-9FD0-5334-D040-C3B82F9A8957} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{88261A8F-96F3-66D7-0279-B1C677B30B41} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8A0FEDBB-3762-AEB7-E85E-6BCC16F76759} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8CD1D4D3-8260-44A7-67DD-A71E995AB77F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8D01C3C9-547A-12EE-5401-4B29F8F98176} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9B9D4A7D-1232-E364-432D-B58ECFAE5AF4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9CC4194D-70AD-AC3B-8852-00B56740427F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A5B3B4A7-6BD2-E7CE-E654-7A1D658D1BB3} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B1169ABC-E367-2937-9F96-3B9CB54E0F31} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B2E28203-4884-D849-F129-5F1A3C2A59D2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B36D5282-D413-F545-CF79-A6CE970CFEBB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BCE50D6B-B3E6-30B9-72AB-14B60D86EB35} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BD757058-7180-2CE5-E5B6-8C70AEF236CC} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C2E5E32B-0FD0-16A5-10FE-EDA2D4478683} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CD0FD544-5710-E7D8-7CDF-35F3B6A22A9A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D377FF80-B093-7377-D7F1-2D8792CCF322} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{D3E61C7F-BD83-EA01-13F4-464C2595C096} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DC690906-09E2-710F-7C3B-F2F819B49B2A} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{ED765395-C8D8-4E11-153C-4CF57031518D} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F29410C9-B2AD-CEAB-4F52-9AADB08954D1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F317424C-8ECC-86C7-5E5B-7AA1BD81D1C4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FC5F30D8-4A16-B1C4-CFF8-EE955DFA16A2} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FF1518B7-D821-1BF0-0368-AD32CBCF17E0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-2380827780-1083669934-3986856803-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{90C61707-C8F8-43DB-A25C-C1F4B18EE41E} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-2380827780-1083669934-3986856803-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0338CADD-858F-3942-A1BF-3990BAAC16E0} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2380827780-1083669934-3986856803-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{24773BD8-E594-EB59-AE83-FF78546EDE07} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2380827780-1083669934-3986856803-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD0FD544-5710-E7D8-7CDF-35F3B6A22A9A} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2380827780-1083669934-3986856803-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F29410C9-B2AD-CEAB-4F52-9AADB08954D1} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050718025627.zip/WINDOWS/system32/ipst32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050718025627.zip/WINDOWS/system32/winga.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050718025627.zip/WINDOWS/apivt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050718025627.zip/WINDOWS/system32/msph32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20050718025627.zip/WINDOWS/system32/sdkhb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addad.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addan.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addbm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addbn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addca32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addct32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addcx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adddx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addet.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addfh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addfz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgd32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addgd32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## khazars (Feb 15, 2004)

ok, check my post and instructions for post 45.


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\addgg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addgt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addhy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addis32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addjh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addjp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addkg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addkr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addli32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addlq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addlw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addma.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addme.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addml32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addns32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addnz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addoe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addor32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addow32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addpb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addph32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addpi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addpr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addps32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addpy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addqw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\addrm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addrq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addsh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addsk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addsx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addsz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addtk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addts32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addtx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addub.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adduh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adduy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addxm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addya.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addys32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addyz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addzo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addzt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\adjhr.txt:lxxhr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adjhr.txt:stdgj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\adjhr.txt:uethl -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adjhr.txt:vqdhb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\adyau.txt:cmamu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adyau.txt:cmdtx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adyau.txt:exhmu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adyau.txt:gfoiv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\adyau.txt:movoo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\adyau.txtvsqg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\adyau.txt:snqeb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\aobzc.txt:igubn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\aobzc.txt:laivch -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\aobzc.txt:rrvcg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\aobzc.txt:rtxpn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\aobzc.txt:slybw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apibc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apibl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apibx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apici.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apicq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apict32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apidd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apidg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apidh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apidt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apidy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apieb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiex.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiey32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apife32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apife32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apifk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apifv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiga32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apige32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apign32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apign32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apigw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiha.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apihi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiht.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiib.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiic.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiis32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiit.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiix.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apija.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apijs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apikg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiko32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apikp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apikp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apikt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiku.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apila.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apilz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apima.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apima32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apimy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apinf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apinf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apinh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apinn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiod32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apioe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiop.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apios32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apipv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiqx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apira32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apire.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apirk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apirm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apise32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apisy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apith.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiuf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiuh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiuo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiux32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apive.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apivp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiwl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiwv.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apiww.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apixy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apizq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appau32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appbw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appcb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appce32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appcg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appcr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appde.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\appdh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appdw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appen32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appex32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appfm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appgy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apphw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apphx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appii.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appja.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appjl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appkb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appkf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appkh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appkx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\applk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\applt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\applx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appmh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appmk.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appmk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appmr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appmv.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appmy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appnh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appni32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appoe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appox32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appoy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apppc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apppd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apppf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appph.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apppn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appql.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appqw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\appqw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apprf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apprg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appri32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apprl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appro32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appru.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appsg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appsi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appsl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appsm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appss32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appti.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appto.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appty32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apptz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appuc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appuh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\appum.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appup.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appup32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appus32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apput.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appuz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appvv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appwa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appwu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appxc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appxq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appxt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appxx.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\appxx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appyp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appyt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appzc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appzk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appzn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appzr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appzs.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atlaj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlak.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlak32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlba.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlbt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlbu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlbw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlbw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlby.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlch32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlcu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atldc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atldf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atleb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlec.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlej.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlem.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atleo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlew32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlff.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlfx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlfz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlgw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlhg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlhi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlhq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlht32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlhu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlic.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlic32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlin.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atliz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlja.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atljf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlkc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlkr32.exe -> Trojan.Agent.bi : Cleaned with ba


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\atllh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlli.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atllm32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atlmj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlmm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlmq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlmw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlmx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlnd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlnq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atloe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlom.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atloy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlph32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlpt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlpx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlqi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlqy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlrt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlrv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlrx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlsw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlsx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atlte.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atltl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlty.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlub.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atluh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atluh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\atlur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atluv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atluy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlvc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlvf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlvi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlvv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlwy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlwz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlxs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlye.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlyz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlzg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlzk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlzn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atlzz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\aunbf.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\bdomq.txt:enocs -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\bnfmt.txt:ailqt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bnfmt.txt:fnoet -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bnfmt.txt:wyiso -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bpxap.txt:mnmer -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\bpxap.txt:urklf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:auurm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:jmdxy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control.ini:qqjgj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:ssiso -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\control.ini:svysa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\control.ini:ufeoh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crak.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crak32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cral32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crap32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crav32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crbj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crbn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crbv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crcd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crcg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crcr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crcx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crdd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crdt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cref.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\creg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crej.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crel.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cren.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crfk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crfl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crgc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crgg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crgl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crgs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crgv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crgx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crgy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crhb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crhn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crhq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crhz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crim.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crin.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crio.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crir32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\criu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crja.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crjx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crkc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crkj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crkk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crks32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crku32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crkyj.txt:hpksi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crkyj.txt:swyan -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crli.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crlo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crlq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crlt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crlv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crly.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crly32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crmi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crms.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crmu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crmz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crnb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crnd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crnm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crnm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crns32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crnz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crod32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\croe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crok32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\croz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crpl32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crpm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crpv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crrj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crro.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crrs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crrv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crsc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crsi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crsm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crso32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crsz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crtf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crth32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crtp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crtq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crts32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crtw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crtz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crum32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cruv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cruw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\crvp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crws32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crwt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crwv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crxi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crxo32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\crxv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\cryz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crzy.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\d3ae.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ai.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3at.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ba32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3bp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ch32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ck32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3cy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3de32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3dj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3dn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3dv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3eb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ee32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ek.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3eo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ft32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3fw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3gx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3hf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3hj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ho.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3hq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ig32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ih32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3iu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3iy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3je32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3jg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ji32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3jk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3jl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3js.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3kl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ky32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3ky32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ld.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ml.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3mr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3mx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3mz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3nf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3nk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3nl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3nu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3of.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3oq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ps32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3pz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3qd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3qd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3qj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3rf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3rg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3rm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ss.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ss32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3tn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3tn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ua32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ue.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ue32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3uf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3uf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3uw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\d3ux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3ve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3vl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3vm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3vo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3vp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3wa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3wh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3wm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3wr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3xc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3xn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3xw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3yl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3yo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3yq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3yv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3zd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3zn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3zo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3zr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3zw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ddjjx.txt:dlqja -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ddjjx.txt:xmbyei -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ddjjx.txt:yhqbq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ddjjx.txt:zavpf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\desktop.ini:cpmnjw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:gldwc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:ijtld -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\desktop.ini:kperbx -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\desktop.ini:zmpoe -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\dodzn.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\dsmki.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\exzve.txt:curfw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exzve.txt:dbfpl -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\exzve.txt:gfgva -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exzve.txt:hihxm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exzve.txtwmdu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\exzve.txt:yadnb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:agiuw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\faeuv.txt:glnzo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\faeuv.txt:ibsyi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:jmywa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\faeuv.txt:lcivd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txtwsbc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:qocue -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:rqpzd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:sqztf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\faeuv.txt:ybywg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\fqybg.txt:biwlt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fqybg.txt:bkvoq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\fqybg.txt:edbif -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fqybg.txt:jypsp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fqybg.txthblk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\fqybg.txt:qlffi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\hipot.txt:dtgbd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\hpqEmlsz.INI:uknxf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\hpqEmlsz.INI:wlvuq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\idkxi.txt:gtkyd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\idkxi.txt:qjvre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\idkxi.txt:rybhh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\idkxi.txt:stulz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\idkxi.txt:ueewj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\idkxi.txt:xfqmg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\IE4 Error Log.txt:hvbru -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\IE4 Error Log.txt:lgbrd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iebx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieby32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieci32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iecj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieco32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iecp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iect32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iecw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iedu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iedx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iedx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieeh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieep32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iefa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iefb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iefq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iegl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iegm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iegn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iegq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iegv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehi32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iehi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iehw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieim32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iejd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iejg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iejp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iejy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iekv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ielb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iels32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ielx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iely.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieml.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iemz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ienc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iend32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ienh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ienq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ienu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieoi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieol32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iepy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieql.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieqt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ierc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ierr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ierv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ierw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iesk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ietd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ietd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ietg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ietn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ietq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iett.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iety.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieud.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieuj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieun32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieup32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieuq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieva.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ievx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iewr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iexh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iexj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iexz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ieya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieyz.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iezf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iezn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iezp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iezs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iezu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iezw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iezy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iezz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iltwain.ini:bpzwu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iltwain.ini:gbouk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iltwain.ini:mwblm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iltwain.ini:skmbsc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iltwain.ini:yssmg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipaw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipbz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipcb.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipcb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipce.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipcp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipcs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipct32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipdb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipdn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipdv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipdz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iped.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipej.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipeq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipff32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipfjw.txt:eumcv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipfjw.txt:fghpf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipfjw.txt:kwdld -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipfjw.txtkwjg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipfk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipfv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipfw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipgg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipgx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphe.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iphe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iphw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipig.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipig32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipin32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipiq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipir32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipiw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipix32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipiz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipjy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipki.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipkr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iplb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iplq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iplr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipmt32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ipnd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipng.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipnq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipok32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipom.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipon.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippm.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ippm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipps32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ippv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipqa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipqr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipqu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipqv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipqv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iprh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\iprh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iprp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iprs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipst.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipsz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipte32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iptl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iptt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipup.exe -> Trojan.Agent.bi : Cleaned


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\ipus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iput.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\iput32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipuz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipve.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ipve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipvf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipvj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipvo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipwa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipwd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipws32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipxa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipxg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipxs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipyc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipyo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipys32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipyu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipzz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaac32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javaac32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javaah32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javaah32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaba32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javabz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javace.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaci32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javack.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacm.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javacq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javacu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javacx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javadc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javadm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javadn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javadw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javadx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaea.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaek32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaeq.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javaez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaff.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javafh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javafx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javagm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javagn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javagz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javahd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javahl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaig32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\javaig32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javail.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javail32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaix.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javajz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javakb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javakh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaku32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javakv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaky32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javakz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javalp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javamb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javami.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javams32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javamw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javamz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javanb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javani32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javanv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javany32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaoq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaox32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javapr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaqr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javara32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javarb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javarc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javarh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javari.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javarl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaro.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javasa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javasq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javasv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javata.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javatl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javatt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javatw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javauk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javauq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javauv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javauv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javavm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javawa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javawc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javawh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javawk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javawq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javayi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javays32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javayz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javazu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\joasq.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\lfgpd.txt:bqozl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\lfgpd.txt:iekxb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\lfgpd.txtmcyj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\lfgpd.txt:qcecl -> TrojanDownloader.Agent.bc : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\mfcac.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcak32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcal.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcam.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcbq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcbu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfccb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfccf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfccn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcco32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcdf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcdo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcdu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfceb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcek32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfceo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcev.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mfcev.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcgy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcha32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfchg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfchj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfchl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfchr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfchx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcig.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcih32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcir32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfciz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcjk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcjt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcju.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcjw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfckc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfckj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfclb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfclf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfclg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcll.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfclx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcly.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcme32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcmq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcnc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcny.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mfcny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcoa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcoc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcom.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcos.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcpq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcqv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcrv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcrx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcry32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcsd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcso32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcsp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfctf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfctg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcto.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcue32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcuo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcvp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcwf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcxz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcyf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcyg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcyn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcze.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfczh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfczi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfczw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:aqjin -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:cmmkuh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:ixmvf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:ncrek -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:nkjhb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:nqyfg -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:rswtv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ModemLog_SoftV92 Data Fax Modem with SmartCP.txt:xlfvo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mpgzr.txt:zkhpj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msak32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msaw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msax32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msaz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msbk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mscv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mscv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mscx32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mscy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:atbun -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdfmap.ini:fyzjb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdfmap.ini:sdgqx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msdfmap.ini:taezdo -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdfmap.ini:veexv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdfmap.ini:wbwbl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msdq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msds32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msdw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msdy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msea.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msek32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msen32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msff32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msfz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msgz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msha.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mshf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mshs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mshx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mshy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msic.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msin32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msiz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mskb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mskh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msks.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mslf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mslj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mslp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mslt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msmo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msnd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msns32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msnt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msnw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msoa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msom32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msop32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msoq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msow.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mspx32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msqf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msqg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msql.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msqp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msqq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msqt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msqw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msrl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msrz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mssb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mssd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mstb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mstg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msti.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mstm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mstp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msua.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msui32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msut.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msuy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msvw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswa.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\mswa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mswr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msyo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\msyr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mszx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\muxdo.txt:adkxo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\muxdo.txt:srcnh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\muxdo.txt:uenfx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mxhcu.txt:gqbexl -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mxhcu.txt:lawegy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\naoft.txt:quyou -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\naoft.txt:rjari -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\naoft.txt:sulzh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\naoft.txt:zvrnsf -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:bjsub -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:dyzye -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:elpcv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:gelcw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:lkntk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NeroDigital.inifkcnx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\NeroDigital.ini:qgiep -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netae32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netah.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netas32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netat32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netax32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netba32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netbo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netbu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netbx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netbx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netck.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcu.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netcw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netcy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netdr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netdr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netdr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netdu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netdv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netec32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netef.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netef32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\neteh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\neteh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netes32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netew32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netex32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netfs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netgc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netgc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netgg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netgi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nethy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netid32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netie.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netin32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netiy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netje.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netjh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netji32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\netjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netjv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkf.exe -> TrojanDownloader.Agent.bq


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\netkg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netko.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netkw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netky32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netlc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netlm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netlt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netmg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netna32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netne32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netnp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netnx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netod.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\neton32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netop32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netou.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netou32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netpy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netql.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netrc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netrf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netsy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nette.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netth.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netti32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nettk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nettn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nettu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nettv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netui.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netul.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netut.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netuw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netux32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netuz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netvd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netvj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netvo.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netvp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netvu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netws32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netxg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netxk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\netxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netxx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netym32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netzg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netzy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netzz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntao.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntaz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntbi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntbk32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntbl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntcb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntcj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntco32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntct32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntcy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntdo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntdt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntdu32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntdu32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nten.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nteo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntev32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntfb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntfg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntfq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntfx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntgm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntgm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntgq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntgv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nthd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\nthj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntih32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntiq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntja.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntjg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntjh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntjm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntjs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntkk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntla.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntld.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntld32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntli.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntms.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntmu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntmz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntnb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntnf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntod.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntoe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntoi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntok.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntor32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntpa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntpl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntpt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntqf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntqr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntrc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntrl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntro.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntrr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntsq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntss.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntst.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nttl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nttm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nttq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntuh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntuw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntvb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntvq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntvs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntwe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntwe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntwm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntwq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxe32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntxe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntxx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntyx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntzb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntzf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntzp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntzs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntzy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:cdhuk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:djvos -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:uklje -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:wievfb -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ojzzt.txt:ghipe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ojzzt.txtiwaae -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ojzzt.txt:rcwen -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ojzzt.txt:riqob -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ojzzt.txt:vemeay -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ojzzt.txt:zciml -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\otzcf.txt:klswo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\otzcf.txt:nffrua -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\otzcf.txt:nhdtv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\otzcf.txt:vkftm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\piovg.txt:hujop -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qbhnr.txt:djqtn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qbhnr.txt:gdqei -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qbhnr.txt:juxzi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qbhnr.txt:nbgya -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qbhnr.txt:qusra -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qbhnr.txt:wrlfd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\qlctx.txt:dmcnf -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qlctx.txt:yybjj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qncjj.txt:ktcaj -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qomht.txt:atico -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\qorqd.txt:shuss -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\scahq.txt:ftkgjj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\scahq.txt:mbdhu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txtmzurf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:ttray -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:xdzxgq -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\screen.html:tajxk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\screen.html:twmag -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\screen.html:whjhzr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkat.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkat32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkav.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkaz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkbf.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkbg.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\sdkbo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkbu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkby32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkck.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkde.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkdz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkeb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkej32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkeq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkeu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkex.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkfw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkgc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkge.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkgs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkgu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkhv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkia32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkie.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkih.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkij32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkiq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkiv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkka.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sdkkh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkko.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdklg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdklh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdklq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdklz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkme.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkmg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkms.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkmw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdknu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkoy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkpx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqp.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkqu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkqx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkrb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkrj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkrs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkrv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdksk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdktc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdktz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkus.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkux32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sdkuz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkvw32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkwb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkwp32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkwx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkwx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkwy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkyz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkzq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\setuplog.txt:sebue -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.iniildr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.ini:qxsgu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\smscfg.ini:vwwuw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ssain.txt:myhue -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sysab32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysak32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sysao.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysbi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysbr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysce.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syscv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysdz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysec.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysey.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysft.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysfy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syshc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysho32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syshq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syshx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syshy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysiu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysiu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysiv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysja32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syska32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syskf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syskk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysle32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syslg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysll32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syslq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysmg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysmk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysmm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysmx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysng32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysni.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysnx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysod.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysoq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysot32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysox.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysoz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syspc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\syspe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syspv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysqo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysra32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysrk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysrq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysrq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syssk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syssl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysso.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syssr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\systa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system.ini:eaalz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32:ndaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup
C:\WINDOWS\system32\addao.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addat32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addce.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addch32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addcj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addcr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addct.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\adddl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\adddp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\adddt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addee.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addee32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addem.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addew.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addez.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addfr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addfz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addgi.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\addgi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addgr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addgr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addhx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addif.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addim32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addjh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addjr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addjx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addkq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addkx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addkz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addle32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addlx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addmi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addmp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addnc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addnl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addnm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addnx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addod.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addoj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addos.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addoz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addpa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addpi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addpj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addpo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addqs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addrh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addrr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addsa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addsp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addss.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addst32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addsx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addtg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addth32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addti32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addtj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addtw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addty32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\addug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\adduo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addur32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addvc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addvn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addwo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addxs32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\addya.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addze32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addzg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addzj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\addzv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiaf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apian32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apibt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apibv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apibz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apicl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apicz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apidu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiek.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiem32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiep32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiew32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apifj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apigl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apign.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apigp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apigr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apigv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiha.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apihg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apiho32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiih.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiii32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiio32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiiq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiiq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiiu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiiz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apija.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiji.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apijy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apikb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\apiki.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apikt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apikw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiky.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiky32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apilg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apilv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apimg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apimj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apimu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apinb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apinv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apioi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiok.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apioq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apips32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apipx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiqr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apire32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apirg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apirk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apirn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apisc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apish32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apism32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apitg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\apith32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apitn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apitn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apitp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiuc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiue.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiuj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiuk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apivc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apivk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiwy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apixc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apixd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apixu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apixy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiys.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apiyu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apize32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizt.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apizu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apizz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appae.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appaz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appbf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appbg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appbl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\appbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appcb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appcp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appcq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appcs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appcu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appds.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\appds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appdy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appec32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appem32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appep32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appev.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appfy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appgu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appgv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appgw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appgz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appgz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apphr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appht32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appim32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appit32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appiv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\appjg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appju.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appjw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appkc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appkk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appko32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appkp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appla.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appla32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\applj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\applo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\applv32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\applw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apply32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appmy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appnt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appoc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appoo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appoy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppc.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\apppe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apppw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appqu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appra.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appss32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appsx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appte.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\apptt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appue.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appuo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appux.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\appux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appvx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appwq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appwt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appwz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appwz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appxw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appym.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\appym32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appzf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appzv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\appzy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlaf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlas32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlbx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlcc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlck.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlcx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlde32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atldi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atldo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlee.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlej.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atles.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlfa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlfb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlfj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlfk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlga.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlge32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlgf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlgx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\atlhf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlhy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlic32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlid32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlin.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlio.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\atlio.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atliv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlji32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atljz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlkf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlkj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlkk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlkw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlld.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlln.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atllx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atllz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlml32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlmw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlna.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlnq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlnq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlny.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlok32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlom32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\atlop.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atloy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlpw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlqp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlqs32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\atlrk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlrn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlrp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlru32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlso.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlsy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlte.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\atlte.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atltg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atltw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atluh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlva32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlvh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlvn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlvt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlwt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\atlwy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlxb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlxq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlxv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlxx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlxz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlyc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlye32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlyr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlyt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlyu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlzb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlzn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\atlzu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crar32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crau32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crbx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crby.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crcc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crce.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crcf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crcs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crcw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crdd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crdu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crea32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\cred.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cred32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cref.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crem32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\creo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\creq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cres32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\cret.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crfc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crfk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crga.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crge32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crgw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crhx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crip32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\criy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\criz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crjr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crjz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crkh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crlc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crlm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crln32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crlv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crlz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crmg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crmh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crmp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crmr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crnf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crnr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crns32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crnt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crnv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crod32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crof.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crog32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\croh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crop32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crow.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\croz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crpc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crpf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crpq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crpz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crqa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crqf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crqg.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crqg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crqh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crqy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crrs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crsc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crse.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crse32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crsg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crso32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crsv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crtf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crtj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crtn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crto32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crtt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crtw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crub32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\crub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crui32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crum32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crur32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\crvd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crvo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crvp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crwm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crwq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crxe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crxo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crxo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crxu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crys32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\crzz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ab.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3af.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3an32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3as32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3at32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3au.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3aw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3aw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ba32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3bc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3be32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3bs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ca.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ce32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ci.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ck.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3cu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3cv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3cz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3dd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3dj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3dz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ec.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3en.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ev.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ey32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3fr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3fs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3fv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3gb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3gf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3gq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3hs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ip.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3iv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3jd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3je.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3jq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3js32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3jx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ke32.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3kk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ks32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3kt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3kx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ld32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ln32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3mz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3nf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3nh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3nm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3no.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3nx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3oa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3of.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3ol32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ot.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3pv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3qc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3qw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3qy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ra32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3rq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3rr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3rr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3se.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3sh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3si.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3so.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3su.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3su32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3sv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3tm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3tn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3tq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3tx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ug32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3ur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3uv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3vj.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## khazars (Feb 15, 2004)

well, your computer surely must be running a bit better after getting rid of all that ? lol  

anymore logs to come?


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\d3vy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\d3wc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3wd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3wh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3wq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3wy.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3xa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xh32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\d3xk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3xu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3yd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3yo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3yx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3zn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3zv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\d3zw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieaj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieaq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieat.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iebb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iebl32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iebo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieca32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iecb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iecb32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ieck.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\iecq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iecz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iede.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\iede.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iedg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iedm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iedw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieea.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieef32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieep.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieev32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iefz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iega32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iego32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iegx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iehs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieib.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieic32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieih.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieik32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieio32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieiw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieiz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iejb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iejq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iejy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iekr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieli32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iell32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ielm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ielp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ielr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iels32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iema.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iemh32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iemw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iene32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieni32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ienj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ienl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ienv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieok.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ieoo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iepa.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\iepb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieqa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieqr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ieqr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ierm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iese.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iese32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iesh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iesj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iesr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iesw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ietf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieti.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ietj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieuk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieuo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieuz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ievy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iewr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieww32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iexg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iexi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iexs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieyc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieyo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ieza.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iezw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipac.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipai32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipap.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipaz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipbo32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ipby32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipbz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipcf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipcs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipcz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipde.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipdn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipdv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipec.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipef.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipeq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipeu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipff32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipfw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipgb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iphi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipht.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iphu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iphw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\iphw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iphx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipig.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipii32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipil32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ipji32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipjr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipke.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipkg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipkt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipky.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iplc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iplh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iplj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iplm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iplr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipme.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ipme.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipmp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipmq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipmu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipmy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipnb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipnm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipno.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipnq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipnw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipny32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipob.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipoi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipoi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipom32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipoo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipox.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipph32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippj32.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ippm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ippt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipqk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipql32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## khazars (Feb 15, 2004)

is that the end of the ewido log?

see my post 45 for instructions!


----------



## mcarpio (Nov 14, 2003)

no, I had to take a break


----------



## khazars (Feb 15, 2004)

ok, post the rest and then carry out my instructions, post a hijack this log and then I'll get back to you!


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\ipqx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipra.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\iprq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipry32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ipsn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipsy.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\iptr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipts.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipua.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ipud.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipui32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipul32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipum.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipur32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipux32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipuy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipvi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipvl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipvr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipvs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipwb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipwe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipxv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipyl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipzc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipzj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ipzx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaae32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaah.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaar32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaas.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javabj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javabo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javabq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaci32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javacm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javacr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javacu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javadd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javadj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javadr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javadz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javafj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javafn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javagn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javagw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javagz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaho32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javahx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaid.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaig.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaip.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javait.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javajz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javakd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javakx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javakz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javali.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javali32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javalu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javama.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javame32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\javamk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaml.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javamn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javana.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javana32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javanj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javanp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javanz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaog.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaoi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaoq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaoq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javapc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javapg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javapl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javapn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaqg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaqp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaqq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javarf32.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\javarn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javarp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javarz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javasd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javasf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javasn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javasz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatn32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\javatn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javato.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javatv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javauc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javauj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaum.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaux.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javava32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javavx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaww.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javawz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\javaya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javaye.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayh.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\javayh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javayz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javazt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javazw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\javazx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcai.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcal.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcaq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcaq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcaz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfccd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfccg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfccj32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mfccq.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mfccr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcdq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfceq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcer32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcfc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcff32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcfz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcgc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcgk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcgl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcgz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfchl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfchn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfchq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcin.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcip.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfciq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcjr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcka.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfckg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfckh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcld32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfclk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcll.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfclu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfclu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcmu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcnk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcob32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcod.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mfcoh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcok32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcoo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcpm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcpu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcpw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcre.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcrg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcrk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcrq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcrw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mfcrw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcrx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcsa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcsa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcsy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfctc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfctd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfctg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfctu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfctu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcty32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcua.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcuh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcut.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcuv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcvj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcvr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcvz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcwd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcwm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcxw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfcyv32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mfcza32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mfczv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msaf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msam.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msao.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msay.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msbo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msbz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msci.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mscl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mscp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msct32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mscy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mscy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msdw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msee.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mseu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msfq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msft.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msfy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msgd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msgo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msgz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mshj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mshj32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mshk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mshs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mshz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mshz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msib32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msie.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msjg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msjn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msjz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mskg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msko.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mskp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mskt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mskv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msky32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mslf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mslj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msln32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mslr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mslu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msmo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msnc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msnl.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\msnl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msns.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msob32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msov.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msow32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\mspc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mspq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msqz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msrd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msrk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msrl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msrq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msrs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mssi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mssk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mssl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mssp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mstg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msts32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mstu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msue32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msum.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msup.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msuu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msuv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msvg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msvv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mswf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mswl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mswq32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\mswq32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\msxc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msxu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msyh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msyo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msyr.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\msyu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\msyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mszm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mszt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\mszz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netad32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netaf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netag.exe -> TrojanDownloader.Agent.bq : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\netax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netbr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netbx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netca32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netcd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netco32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netcx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netcy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netde.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netdz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\neteb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\neted32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netef32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\neteh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netes.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netew.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netex32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netez32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netfm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netfm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netfp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netfq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netfs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netge.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netgh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netgk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netgr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netgx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\nethp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nethz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netib.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netib32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netif.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netji32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netjp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netju32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netkb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netkf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netkm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netko.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netkp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netlc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netli32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netll.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netln.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netls.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netly32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netmf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netmh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netmi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netmu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netnc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netnr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netnu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netom32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netop32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netov32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netpf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netpm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netpn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netps.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netqm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netqu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netqv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netra.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\netrf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netrx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netse.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netsw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netth.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netti32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nettr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nettt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nettx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nettx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netue.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netuj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netvh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netvu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\netvu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netwa32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netwk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netwz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netxm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netxp.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\netxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netxx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netyb32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\netyb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netyd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netyi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netyj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netys.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\netyx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netza.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netzj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netzp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netzs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\netzv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntah32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntaj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntap32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntaz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntba32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntbd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntbq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntbt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntcc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntci32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntcv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntdb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntds.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntdy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nteh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nteu.exe -> Trojan.Agent.bi : Cleaned with backup
 C:\WINDOWS\system32\ntfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntfh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntfq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntfy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgn.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ntgp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntgv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nths.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\nthw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nthz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntik.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntik32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntit.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ntit.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntit32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntjn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntjy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntkj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntkm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntkn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntkp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntky.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntlc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntle32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntlg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntli.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntln32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntlv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntmd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntme32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntmj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntnf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntnw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntoe.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntok32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntoq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntph32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ntpw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntpw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntql.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\ntqm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntqv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntrf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntrg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntrh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntrn32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntrq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntsa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntst.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntsu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\nttx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntug32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntuj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntun.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntuq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntur.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntva32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntvc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntvk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntvt.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntwa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\ntxr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntxs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntyy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntzh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntzn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntzr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\ntzu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkag32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sdkag32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkar32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkat.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkbx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkby32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkbz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkcy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkda32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkdg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkdn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkdn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkdp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkdt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkee.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkes.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkew32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkfe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkfm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkfs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkfv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkgy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkhg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkhl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkhz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkid32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkig.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sdkiq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkiy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkjo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkjz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkka32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkkw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkla.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdklc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkll.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkly.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkmd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkmk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkmx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkns.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdknu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkoa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkon.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkor.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkos32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkoy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkpc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkpo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkpt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sdkqx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkqy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkrc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkrc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkrr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkrx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdksx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdktb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkte.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdktm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdktv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdktv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdktw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkub32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkuc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkui.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkuu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkuw32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\sdkvb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkve.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkvt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkwc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkwd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkwr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkxc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkxo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkxs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\sdkya32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkyy32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sdkzo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkzo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sdkzz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysab32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysal.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysat32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysax32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysbi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysbq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysbs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syscb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syscd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syscw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syscz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysdz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysee32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysek.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysek32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysfy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysgf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysgg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysgm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syshn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syshn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syshv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysif32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysis32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysiy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysiz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysjs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syska32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syskf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syskj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysko.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysku.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syslf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syslj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysls.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysls32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syslt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysmd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysmm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysmr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysna32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysng.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysni32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysnk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysnm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysnq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysnu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysnv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysoe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysoh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysoi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysoj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syson.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysow.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syspa32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syspp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syspq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syspv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syspw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysqv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysrf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysru.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysrx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syssf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syssg32.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\syssh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysso32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syssp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syssw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\systw.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysul.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysuy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysuz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysvz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syswz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysxz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysyh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\sysyv.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\sysyy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syszf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syszn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\syszt32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\system32\tllvv.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\system32\winab.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winae32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winai32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\winai32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winaj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winat.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\winbb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winbw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wincc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winch.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wincl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wincr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wincw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\windz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winei.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winek32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\wineo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winep.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wines32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winev.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winfh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winfx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wingk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wingm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wingp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wingx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winht.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winhz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winik32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winiv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winiw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winja.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winjy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winkk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winkn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winld.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winle.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winlg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winlk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winlt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winlu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winlx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winly.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winmy32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winnb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winnd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winni.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\system32\winni.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winnl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winnn.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\system32\winnr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winob.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winpa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winpj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winpn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winpt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winqh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winqn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winqs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winqt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winqz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winrw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winrz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winsa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winsh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winsn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winsr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winsz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\wintx32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winue32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winuh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winuo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winvc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winvk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winvs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winvu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winvw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winwi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winwj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winwo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winwp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winws32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winwt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winyz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winzn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winzo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\system32\winzu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\systi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysur32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysuu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysuv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysvg.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sysvh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysvm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysvo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysvt32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswe32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswg32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\syswi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syswq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysws.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysxx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysyi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\syszw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tpomp.txt:jrqyx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\urbxw.txtlcfu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\urbxw.txt:wcmjd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vb.ini:apejou -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vb.ini:dslnjp -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vb.ini:edvua -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vb.ini:fiwoz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vb.ini:fwawwu -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vb.ini:gnbho -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vb.ini:jltrc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vb.ini:ltqln -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vb.ini:mvspk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vb.ini:twyvz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vb.ini:yirpp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vbaddin.ini:tvrnz -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vlxmp.txt:gsudc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vlxmp.txt:msiqh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vlxmp.txtuxov -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vojpj.txt:wteses -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\vwbel.txt:jigtp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vwbel.txt:lqdsc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vwbel.txtlqdq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\vwbel.txt:xqhni -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\vwbel.txt:ypdly -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winaa.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winaf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winai32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winar32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winat.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winax.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winch32.exe -> Trojan.Agent.bi : Cleaned with backup


----------



## mcarpio (Nov 14, 2003)

C:\WINDOWS\wincr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\wincw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winea32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winec32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winen.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wineo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wineo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wineq.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wines.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winev.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winft32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wingf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wingt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wingv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winhi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winhm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winhr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winhr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winht32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winia32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winie32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winim.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winim32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winis.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winiu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjw.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winjw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winkr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winlb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winlg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winlh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winln32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winlq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winlz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winmr.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winmu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winne32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winno32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnr32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winnt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winnz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winoh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winoj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winok32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winoo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winpc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winpf32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winpl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winpq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winpr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winps32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winqj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winqk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winqs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winqu.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winqu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winqz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winrd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winrh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winrk.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winrz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winsb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winsl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winsz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wintg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wintu32.dll -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\winuc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winug.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winus32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winuz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvf.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winvf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvh32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winws.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winww32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winxe.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winxk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winxu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winye.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winyi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winyn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winze.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzp.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzs.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winzu.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\yzxck.txt:elhfm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\yzxck.txt:enyjx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\yzxck.txt:ivpmy -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\yzxck.txt:rabnp -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\zfrmp.txt:ccrfl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zfrmp.txt:yibxe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\zsack.dll -> Spyware.SearchPage : Cleaned with backup


::Report End


----------



## khazars (Feb 15, 2004)

did you check post 45?


----------



## mcarpio (Nov 14, 2003)

I just read post 45. I missed a few of your posts while I was posting the report.


----------



## khazars (Feb 15, 2004)

ok, you should be ok now?


----------



## mcarpio (Nov 14, 2003)

Okay, I just finished downloading all the protections. I dl'd spyware guard and spyware blaster while I was infected. Will they be fine or should I remove them and dl fresh ones? I already had the system restore turned off per your instructions, so now should I turn it on and restart? I know that you are probably sleeping now, so I will just do it and hope that it is the right thing


----------



## mcarpio (Nov 14, 2003)

flavallee thank you so much for responding to my thread. Even though you didn't know how to fix it, you made me feel so much more relaxed while I had to wait. And khazars, thank you so much. You really know how to get rid of that garbage. I saw your posts in other threads and I knew that you could help me, and what do you know, everything is back to good on the first try. This site is really a great place. Okay enough mushy time Here is my latest HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 5:29:38 PM, on 7/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.search.yahoo.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [PrevxPro] "C:\Program Files\Prevx Pro\SAGUI.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Pro\PXAgent.exe" -f (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


----------



## mcarpio (Nov 14, 2003)

Bye guys 

Michelle


----------



## flavallee (May 12, 2002)

Mcarpio:

You're welcome.


----------



## mcarpio (Nov 14, 2003)

Okay, one more thing. I just ran spybot s&d and it is still showing AV-Gold and CoolWebSearch. In add and remove programs the weird stuff is gone and HJT doesn't have any new entries; any suggestions? Spy sweeper is showing trojan downloaders and adware, so it's not just spybot.


----------



## flavallee (May 12, 2002)

You are selecting and fixing everything in red that Spybot is finding, right?


----------



## khazars (Feb 15, 2004)

if you have Avgold as well run these tools to clean it out?

you already have ewido so just download the other two.

You will need to disable prevX and spysweeper as it can interfere with the fix. Go to start/run/type msconfig/click ok/click startup/unchecck the boxes for spysweeper and prevx/click ok. Remember to re-enable them when finished and re-enable system restore and make a new restore point!

* Click here to download smitRem.zip.

http://noahdfear.geekstogo.com/click counter/click.php?id=1

* Save the file to your desktop.
* Unzip smitRem.zip to extract the two files it contains.
* Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.

* Go here to download CCleaner.

http://www.ccleaner.com/

* Install CCleaner
* Launch CCleaner and look in the upper right corner and click on the "Options" button.
* Click "Advanced" and remove the check by "Only delete files in Windows temp folders older than 48 hours".
* Click OK
* Do not run CCleaner yet. You will run it later in safe mode.

* Download the trial version of Ewido Security Suite.

http://www.ewido.net/en/

* Install ewido.
* During the installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
* Launch ewido
* It will prompt you to update click the OK button and it will go to the main screen
* On the left side of the main screen click update
* Click on Start and let it update.
* DO NOT run a scan yet. You will do that later in safe mode.

* Click here for info on how to boot to safe mode if you don't already know how.

http://service1.symantec.com/SUPPOR...2001052409420406?OpenDocument&src=sec_doc_nam

* Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

* Restart your computer into safe mode now. Perform the following steps in safe mode:

* Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

* Run Ewido:

* Click on scanner
* Click Complete System Scan and the scan will begin.
* During the scan it will prompt you to clean files, click OK
* When the scan is finished, look at the bottom of the screen and click the Save report button.
* Save the report to your desktop

* Start Ccleaner and click Run Cleaner

* Go to Control Panel > Internet Options. Click on the Programs tab then 
click the "Reset Web Settings" button. Click Apply then OK.

* Next go to Control Panel > Display. Click on the "Desktop" tab then click 
the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" you
should see an entry checked called something like "Security info" or similar.
If it is there, select that entry and click the "Delete" button. Click OK 
then Apply and OK.

* Restart back into Windows normally now.

* Run ActiveScan online virus scan here

http://www.pandasoftware.com/activescan/

When the scan is finished, anything that it cannot clean have it delete it. Make a note of the file location of anything that cannot be deleted so you can delete it yourself.
- Save the results from the scan!

post another hijack this log, the ewido and active scan logs


----------



## iaavagent (Jan 11, 2004)

khazars said:


> if you have Avgold as well run these tools to clean it out?
> 
> * Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.
> 
> ...


----------



## khazars (Feb 15, 2004)

there's obviously nothing to fix with hijack this!


----------



## mcarpio (Nov 14, 2003)

Okay I've just now got on to read your instructions. I will do them now and post again soon. Thanks


----------



## mcarpio (Nov 14, 2003)

Flavallee, I have tried to remove AV-Gold with spybot and it always says that it can't remove it.


----------



## flavallee (May 12, 2002)

Read here and see if it'll help you get rid of AV-Gold.


----------



## khazars (Feb 15, 2004)

read my instructions for post 76 that will get rid of it, you might just have some programme reporting you have a few leftovers? 

Tell me where it says you have Avgold and what programme is reporting this?


----------



## mcarpio (Nov 14, 2003)

Sorry for my delay. Spybot S&D is the one that finds AV-Gold,

av-gold
class ID
HKEY_Classes_Root\CLSID\{9CB478A2-CA39-0CFD-EFAC- 
DB89710601D3}

Spy Sweeper found a trojan down loader, but it hasn't identified any new programs or files on the computer.

That AV-Gold thing keeps saying it can't be removed, that it is active in the memory.

Anyway I will do the instructions posted in #76?, I'm not sure the number but I do know which one it is.


----------



## khazars (Feb 15, 2004)

ok, it might be just a leftover , but run the fix for it as it will clean up your registry for all the bad entries, pray proceed!

and post new logs


----------



## mcarpio (Nov 14, 2003)

ewido found no infected files


----------



## mcarpio (Nov 14, 2003)

Logfile of HijackThis v1.99.1
Scan saved at 10:10:31 PM, on 7/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Prevx Pro\PXAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Prevx Pro\SAGUI.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [PrevxPro] "C:\Program Files\Prevx Pro\SAGUI.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1121325533218
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Prevx Agent (PrevxAgent) - Unknown owner - C:\Program Files\Prevx Pro\PXAgent.exe" -f (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe


----------



## mcarpio (Nov 14, 2003)

Panda active scan

Incident Status Location 

Adware:adware/mywebsearch No disinfected HKEY_CLASSES_ROOT\CLSID\{147A976E-EEE1-4377-8EA7-4716E4CDD239}  
Adware:adware/cws.yexe No disinfected HKEY_CLASSES_ROOT\CLSID\{9CB478A2-CA39-0CFD-EFAC-DB80710601D3} 
Adware:Adware/PopCapLoader No disinfected C:\Program Files\backups\backup-20050719-054714-938.inf 
Adware:Adware/Comet No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3C.tmp 
Adware:Adware/SearchAid No disinfected C:\WINDOWS\n_dokmvr.dat 
Adware:Adware/SearchAid No disinfected C:\WINDOWS\system32\netsh.exe.tmp


----------



## khazars (Feb 15, 2004)

have hijack this fix this.

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. 
In the Full Path of File to Delete box, copy and paste each of the following 
lines one at a time then click on the button that has the red circle with the
X in the middle after you enter each file. It will ask for confirmation to 
delete the file. Click Yes. Continue with that same procedure until you have 
copied and pasted all of these in the Paste Full Path of File to Delete box.

Note: It is possible that Killbox will tell you that one or more files do not
exist. If that happens, just continue on with all the files. Be sure you 
don't miss any.

C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3C.tmp
C:\WINDOWS\n_dokmvr.dat
C:\WINDOWS\system32\netsh.exe.tmp


----------



## mcarpio (Nov 14, 2003)

I just did all of that. Do you want me to post anything ? I am going to try spybot now and see what it says.


----------



## mcarpio (Nov 14, 2003)

The AV-Gold showed up again with spybot. I will go do Panda again to see how that turns out.


----------



## khazars (Feb 15, 2004)

what is the name of the file spybot is finding, and what is it's location, doesn't spybot remove it?


----------

