afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > kone saastunut, apuja kaivataan!
Keskustelualueet
Keskustelualueet
Kone saastunut, apuja kaivataan!
Senior Member
4. joulukuuta 2009 @ 00:00
Linkki tähän viestiin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:38:05, on 3.12.2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\WinSnap\WinSnap.exe
C:\Program Files\RapidCheck\RapidCheck.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Secway\SimpPro 2.2\SimpPro.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\hjt\o.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW...&m=aspire_7730g
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW...&m=aspire_7730g
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW...&m=aspire_7730g
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O1 - Hosts: ::1 localhost
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll
O2 - BHO: Windows Live ID -kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: LitmusBHO - {C6867EB7-8350-4856-877F-93CF8AE3DC9C} - C:\Program Files\F-Secure Internet Security\NRS\iescript\baselitmus.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\hssie\HssIE.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Browsing Protection Toolbar - {265EEE8E-3228-44D3-AEA5-F7FDF5860049} - C:\Program Files\F-Secure Internet Security\NRS\iescript\baselitmus.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [WinSnap] "C:\Program Files\WinSnap\WinSnap.exe" /startup
O4 - HKCU\..\Run: [RapidCheck] C:\Program Files\RapidCheck\RapidCheck.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [Simp] C:\Program Files\Secway\SimpPro 2.2\SimpPro.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Paikallinen palvelu')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'Verkkopalvelu')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &L&ataa &BitCometilla - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &L&ataa jaujju videot BitCometilla - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &L&ataa kaikki BitCometilla - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 (file missing)
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Sol...wn.cab56986.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdat...b?1250197400069
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsof...b?1259588810078
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Mes...nt.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/sh...ash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{22205826-0CBB-437A-9404-7F7ADCEC96A8}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: BitComet AntiARP - Unknown owner - C:\Program Files\BitCometAntiARP\BitCometAntiARP.exe (file missing)
O23 - Service: BrlAPI - Unknown owner - C:\cygwin\bin\cygrunsrv.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter ) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\ORSP Client\fsorsp.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia . - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\Windows\System32\TUProgSt.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
--
End of file - 11255 bytes
Malwarebytes löysi aika paljon kaikkee..
Malwarebytes' Anti-Malware 1.41
Tietokantaversio: 3287
Windows 6.0.6002 Service Pack 2
3.12.2009 23:18:38
mbam-log-2009-12-03 (23-18-38).txt
Tarkistustyyppi: Täysi tarkistus (C:\|D:\|E:\|)
Tarkistetut kohteet: 491437
Kulunut aika: 2 hour(s), 10 minute(s), 55 second(s)
Saastuneita muistiprosesseja: 0
Saastuneita muistimoduuleja: 0
Saastuneita rekisteriavaimia: 0
Saastuneita rekisteriarvoja: 0
Saastuneita rekisterikohteita: 0
Saastuneita hakemistoja: 0
Saastuneita tiedostoja: 262
Saastuneita muistiprosesseja:
(Haitallisia kohteita ei löydetty)
Saastuneita muistimoduuleja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriavaimia:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisteriarvoja:
(Haitallisia kohteita ei löydetty)
Saastuneita rekisterikohteita:
(Haitallisia kohteita ei löydetty)
Saastuneita hakemistoja:
(Haitallisia kohteita ei löydetty)
Saastuneita tiedostoja:
C:\Program Files\Command and Conquer - The First Decade\COMMAND AND CONQUER\COMMAND AND CONQUER - RED ALERT\EDDOS.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Program Files\Command and Conquer - The First Decade\COMMAND AND CONQUER\COMMAND AND CONQUER - RED ALERT\RA.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} (Trojan.Downloader) -> Delete on reboot.
C:\WESTWOOD\REDALERT\EDDOS.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WESTWOOD\REDALERT\PATCH.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WESTWOOD\REDALERT\RA.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WESTWOOD\REDALERT\DICSSC 11\PATCH.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WESTWOOD\REDALERT\RED ALERT\PATCH.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WESTWOOD\REDALERT\RED ALERT\redalert\PATCH.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat (Trojan.Downloader) -> Delete on reboot.
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat (Trojan.Downloader) -> Delete on reboot.
C:\Windows\Fonts\8514oeme.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\8514oemg.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\8514oemr.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\8514oemt.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga40737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga40857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga40866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga40869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga80737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga80852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga80857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga80866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga80869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cga40852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\cvgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\dos737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\dos869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega40737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega40857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega40866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega40869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega80737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega80857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ega80869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\j8514fix.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\j8514oem.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\j8514sys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\jvgafix.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\jvgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ssee874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\ssef874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\svgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vga852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vga857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vga866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vga932.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vgas874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\Fonts\vgasys.fon (Trojan.Downloader) -> Delete on reboot.
C:\Windows\system\mouse.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\olecli.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\OLESVR.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\SHELL.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\system.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\vga.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\system\WFWNET.DRV (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\append.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\COMM.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\DRWATSON.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\edlin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\exe2bin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\fastopen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\GDI.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\krnl386.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\mouse.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\mscdexnt.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\nlsfunc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\olecli.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\OLESVR.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\setver.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\SHELL.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\sysedit.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\system.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\share.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\USER.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\vga.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WFWNET.DRV (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\win87em.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WINNLS.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WINOLDAP.MOD (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WINSPOOL.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WOWDEB.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\WOWEXEC.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-f..itmap-ms_sans_serif_31bf3856ad364e35_6.0.6000.16386_none_4e73ea6d973a7510_ssee874.fon_594d8854 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-f..itmap-ms_sans_serif_31bf3856ad364e35_6.0.6000.16386_none_4e73ea6d973a7510_ssef874.fon_594e8893 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-fixed_31bf3856ad364e35_6.0.6000.16386_none_7cd9205231b4785e_j8514fix.fon_cc283848 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-fixed_31bf3856ad364e35_6.0.6000.16386_none_7cd9205231b4785e_jvgafix.fon_f133926a (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_8514oeme.fon_dbdae0a9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_8514oemg.fon_dbdce127 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_8514oemr.fon_dbe7e3dc (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_8514oemt.fon_dbe9e45a (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_j8514oem.fon_cf1af1d6 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_vga852.fon_0a8e74dc (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_vga857.fon_0c23d887 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_vga866.fon_08f91131 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65_vga932.fon_1042dbe9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_cvgasys.fon_a23acca1 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_j8514sys.fon_cfb116c0 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_jvgasys.fon_d163c032 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_svgasys.fon_32986711 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_vgas874.fon_57846913 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989_vgasys.fon_5d8bebb4 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga40737.fon_2c4b9363 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga40852.fon_2c85a1a9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga40857.fon_2c8aa2e4 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga40866.fon_2c80a06e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga40869.fon_2c83a12b (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga80737.fon_2e43d167 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga80852.fon_2e7ddfad (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga80857.fon_2e82e0e8 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga80866.fon_2e78de72 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_cga80869.fon_2e7bdf2f (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_dos737.fon_8de20802 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_dos869.fon_85f815ea (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega40737.fon_5e5746b1 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega40857.fon_5e965632 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega40866.fon_5e8c53bc (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega40869.fon_5e8f5479 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega80737.fon_604f84b5 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega80857.fon_608e9436 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88_ega80869.fon_6087927d (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_append.exe_511080a0 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_comm.drv_058e064e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_debug.exe_bdafe3af (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_drwatson.exe_8001ab8e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_edlin.exe_420aa87c (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_exe2bin.exe_584b170f (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_fastopen.exe_34b8aa0e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_gdi.exe_f661b558 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_krnl386.exe_4fdf83ba (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_mem.exe_e5748c01 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_mouse.drv_27155db9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_mscdexnt.exe_8f9c39da (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_nlsfunc.exe_68d576d3 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_olecli.dll_1780cf38 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_olesvr.dll_fde98489 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_setver.exe_7abd3967 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_share.exe_bbb4488d (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_shell.dll_a7964274 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_sysedit.exe_9abddcf9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_system.drv_96e90a3f (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_user.exe_d3d0cbc9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_vga.drv_ccdb802e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_wfwnet.drv_0736bd8b (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_win87em.dll_15e1bccd (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_winnls.dll_6aeb9b19 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_winoldap.mod_b5cc0008 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_winspool.exe_af5728df (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_wowdeb.exe_6873642a (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8_wowexec.exe_2490d926 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_mouse.drv_27155db9 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_olecli.dll_1780cf38 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_olesvr.dll_fde98489 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_shell.dll_a7964274 (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_system.drv_96e90a3f (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_vga.drv_ccdb802e (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\Backup\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813_wfwnet.drv_0736bd8b (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-f..itmap-ms_sans_serif_31bf3856ad364e35_6.0.6000.16386_none_4e73ea6d973a7510\ssee874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-f..itmap-ms_sans_serif_31bf3856ad364e35_6.0.6000.16386_none_4e73ea6d973a7510\ssef874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-fixed_31bf3856ad364e35_6.0.6000.16386_none_7cd9205231b4785e\j8514fix.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-fixed_31bf3856ad364e35_6.0.6000.16386_none_7cd9205231b4785e\jvgafix.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\8514oeme.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\8514oemg.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\8514oemr.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\8514oemt.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\j8514oem.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\vga852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\vga857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\vga866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-oem_31bf3856ad364e35_6.0.6000.16386_none_fb2d5aefb17b8d65\vga932.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\cvgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\j8514sys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\jvgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\svgasys.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\vgas874.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-system_31bf3856ad364e35_6.0.6000.16386_none_81200aeaf9f41989\vgasys.fon (Trojan.Downloader) -> Delete on reboot.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga40737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga40852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga40857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga40866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga40869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga80737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga80852.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga80857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga80866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\cga80869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\dos737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\dos869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega40737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega40857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega40866.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega40869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega80737.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega80857.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-font-bitmap-terminal_31bf3856ad364e35_6.0.6000.16386_none_123896e8c4717b88\ega80869.fon (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\append.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\COMM.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\DRWATSON.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\edlin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\exe2bin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\fastopen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\GDI.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\krnl386.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\mouse.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\mscdexnt.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\nlsfunc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\olecli.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\OLESVR.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\setver.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\share.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\SHELL.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\sysedit.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\system.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\USER.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\vga.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WFWNET.DRV (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\win87em.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WINNLS.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WINOLDAP.MOD (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WINSPOOL.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WOWDEB.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6001.18000_none_fe0d791a728dd79c\WOWEXEC.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\append.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\COMM.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\debug.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\DRWATSON.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\edlin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\exe2bin.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\fastopen.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\GDI.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\krnl386.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\mouse.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\mscdexnt.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\nlsfunc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\olecli.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\OLESVR.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\setver.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\share.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\SHELL.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\sysedit.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\system.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\USER.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\vga.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WFWNET.DRV (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\win87em.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WINNLS.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WINOLDAP.MOD (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WINSPOOL.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WOWDEB.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system32_31bf3856ad364e35_6.0.6002.18005_none_fff8f2266fafa2e8\WOWEXEC.EXE (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\mouse.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\olecli.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\OLESVR.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\SHELL.DLL (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\system.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\vga.drv (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\winsxs\x86_microsoft-windows-ntvdm-system_31bf3856ad364e35_6.0.6000.16386_none_1e1753ed2313c813\WFWNET.DRV (Trojan.Downloader) -> Quarantined and deleted successfully.
Onko kone pahasti virusten valtaama vai? Kyllä se toimii ainakin ihan hyvin...
Hujo
Suspended permanently
4. joulukuuta 2009 @ 01:10
Linkki tähän viestiin
tyhjennä Malwarebytes' Anti-Malware karanteeni
Scannaa hjt:llä merkkaa paina Fix checked
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O13 - Gopher Prefix :
Voiko tietsikka koskaan toimia?
Senior Member
4. joulukuuta 2009 @ 15:08
Linkki tähän viestiin
Okkei. Mitä noi "fonttivirukset" oikeen oli? Ja eikö Ccleaneria kannata ajaa koneen käynnistyessä?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 4. joulukuuta 2009 @ 15:34
Hujo
Suspended permanently
4. joulukuuta 2009 @ 17:04
Linkki tähän viestiin
no jos katot mitä se ccleaner löytää niin kannataako sitä jokapäivä ajella
sun valinta se on mitä teet.
Voiko tietsikka koskaan toimia?
Viestiä on muokattu lähettämisen jälkeen. Viimeisin muokkaus 4. joulukuuta 2009 @ 17:05
Mainos
Senior Member
5. joulukuuta 2009 @ 13:45
Linkki tähän viestiin
Okei, no jätän sit ajamatta. Kiitti kun katoit lokin ;)
afterdawn.com > keskustelu > yleistä keskustelua tietokoneista > virukset ja haittaohjelmat - hijackthis -logit > kone saastunut, apuja kaivataan!