here is everything . combofix appeared to work like it should.
ComboFix 09-08-31.03 - Owner 09/01/2009 3:55.1.1 - NTFSx86
Running from: c:\documents and settings\Owner\Desktop\al-g.exe
AV: BullGuard Antivirus *On-access scanning disabled* (Outdated) {7A9BB333-8EDF-4FDC-A2A5-1A30FA021913}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: BullGuard Firewall *disabled* {2AEF4CB6-61B5-4E60-AF22-D95E75B63FA1}
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
ADS - explorer.exe: deleted 88 bytes in 2 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Owner\Local Settings\Application Data\{C720B391-FD4E-4007-9961-68855EB744A5}
c:\documents and settings\Owner\Local Settings\Application Data\{C720B391-FD4E-4007-9961-68855EB744A5}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{C720B391-FD4E-4007-9961-68855EB744A5}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{C720B391-FD4E-4007-9961-68855EB744A5}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{C720B391-FD4E-4007-9961-68855EB744A5}\install.rdf
c:\recycler\S-1-5-21-4110985211-1758993271-3769943490-1003
c:\windows\AUTOLNCH.REG
c:\windows\Installer\1324b.msi
c:\windows\system32\AVR09.exe
c:\windows\system32\kbiwkmatmnpuvr.dat
c:\windows\system32\kbiwkmftkospxj.dll
c:\windows\system32\kbiwkmhagofovc.dat
c:\windows\system32\kbiwkmorabvfvn.dll
c:\windows\system32\kbiwkmpfonjkgp.dll
c:\windows\system32\kbiwkmpspwticq.dat
c:\windows\system32\kbiwkmsgywqgtr.dll
c:\windows\system32\kbiwkmyymdriww.dat
c:\windows\system32\tajf83ikdmf.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\winhelper.dll
F:\Autorun.inf
Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NEW_DRV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.
2009-08-30 00:45 . 2009-08-30 03:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-29 23:59 . 2009-08-29 23:59 -------- d-----w- c:\program files\ESET
2009-08-29 20:10 . 2009-09-01 07:40 -------- d-----w- c:\program files\Panda Security
2009-08-29 10:13 . 2009-08-29 10:13 31896 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-28 11:41 . 2009-08-28 11:41 -------- d-----w- C:\rsit
2009-08-28 11:40 . 2009-08-28 11:40 120 ----a-w- c:\windows\Ymaqa.dat
2009-08-28 10:01 . 2009-08-28 10:01 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2009-08-28 05:03 . 2009-08-05 23:29 3036024 ----a-w- c:\documents and settings\Owner\Application Data\Simply Super Software\Trojan Remover\bte8.exe
2009-08-28 04:09 . 2003-02-03 00:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2009-08-28 04:09 . 2009-08-28 04:09 -------- d-----w- c:\documents and settings\Owner\Application Data\Simply Super Software
2009-08-28 01:20 . 2009-08-28 01:20 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 04:22 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-21 04:16 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-08-21 04:16 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 07:55 . 2006-08-10 21:25 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SampleView
2009-09-01 07:45 . 2008-05-31 03:18 -------- d-----w- c:\program files\Coupons
2009-09-01 07:42 . 2009-08-30 07:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Doctor Web
2009-09-01 07:41 . 2006-08-12 04:45 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-01 07:41 . 2006-08-12 04:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-01 07:39 . 2009-08-30 07:37 -------- d-----w- c:\program files\DrWeb
2009-09-01 06:08 . 2009-09-01 06:08 874 ----a-w- C:\6.reg
2009-09-01 06:08 . 2009-09-01 06:08 1234 ----a-w- C:\8.reg
2009-09-01 06:08 . 2009-09-01 06:08 1108 ----a-w- C:\7.reg
2009-09-01 06:08 . 2009-09-01 06:08 1506 ----a-w- C:\avexport.bat
2009-08-30 09:02 . 2009-08-30 09:02 -------- d-----w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-29 19:18 . 2008-03-01 03:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-29 19:13 . 2006-08-10 20:30 1033728 ----a-w- c:\windows\explorer.exe
2009-08-28 03:31 . 2006-08-12 04:40 -------- d-----w- c:\program files\SpywareBlaster
2009-08-21 04:53 . 2008-08-02 14:49 -------- d-----w- c:\documents and settings\All Users\Application Data\RFA_Backups
2009-08-13 05:03 . 2009-03-02 14:33 -------- d-----w- c:\documents and settings\Owner\Application Data\Vidalia
2009-08-13 05:03 . 2009-03-02 14:34 -------- d-----w- c:\documents and settings\Owner\Application Data\tor
2009-08-05 09:01 . 2006-08-10 20:31 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2006-08-10 20:32 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2006-08-10 20:30 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2006-08-10 20:29 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2006-08-10 20:32 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-08 01:27 . 2009-07-08 01:26 -------- d-----w- c:\documents and settings\Owner\Application Data\Canon
2009-07-08 01:06 . 2009-07-08 00:58 -------- d-----w- c:\program files\Canon
2009-07-08 01:04 . 2009-07-08 01:04 -------- d-----w- c:\program files\Common Files\CANON
2009-07-08 01:01 . 2009-07-08 01:01 -------- d--h--w- c:\documents and settings\All Users\Application Data\CanonBJ
2009-07-08 00:59 . 2009-07-08 00:59 -------- d--h--w- c:\program files\CanonBJ
2009-07-03 17:09 . 2006-08-10 20:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2006-08-10 20:32 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2006-08-10 20:32 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2006-08-10 20:32 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2006-08-10 20:31 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2006-08-10 20:31 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2006-08-10 20:30 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2006-08-10 20:30 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-23 00:07 . 2009-06-23 00:07 1878984 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-06-12 12:31 . 2006-08-10 20:32 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2006-08-10 20:29 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2006-08-10 20:31 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2006-08-10 20:32 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-08 02:26 . 2006-09-13 15:56 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-08 02:20 . 2009-06-08 02:20 466944 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\MusicLoad.dll
2009-06-08 02:20 . 2009-06-08 02:20 197912 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\PlgSoundclick.dll
2009-06-08 02:20 . 2009-06-08 02:20 177432 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\PlgIJigg.dll
2009-06-08 02:20 . 2009-06-08 02:20 169240 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\PlgPandora.dll
2009-06-08 02:20 . 2009-06-08 02:20 136472 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\PlgLastfm.dll
2009-06-08 02:20 . 2009-06-08 02:20 197912 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\PlgImeem.dll
2009-06-08 02:20 . 2009-06-08 02:19 1258776 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\RadioRip.dll
2009-06-08 02:18 . 2009-06-08 02:18 409600 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\DailyMotion.dll
2009-06-08 02:18 . 2009-06-08 02:18 413696 ----a-w- c:\documents and settings\All Users\Application Data\RapidSolution\Tunebite\WebRipDLLs\YouTube.dll
2009-06-03 19:09 . 2006-08-10 20:32 1291264 ----a-w- c:\windows\system32\quartz.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Diagnostic Manager
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Resurections
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
R1 SASKUTIL;SASKUTIL; [x]
R2 asurscsi;asurscsi; [x]
R2 wfjutr;wfjutr;c:\windows\system32\drivers\skqhbjy.sys [x]
R2 xyxh;xyxh;c:\windows\system32\drivers\jifizq.sys [x]
R3 BGRaSvc;BGRaSvc;c:\program files\BullGuard Ltd\BullGuard\support\bgrasvc.exe [2009-05-30 79184]
R3 cwrwdm;SoundFusion(tm) WDM Driver;c:\windows\system32\DRIVERS\cwrwdm.sys [2004-08-04 48640]
R3 tbcspud;Santa Cruz Driver;c:\windows\system32\drivers\tbcspud.sys [x]
R3 tbcwdm;Santa Cruz WDM Driver;c:\windows\system32\drivers\tbcwdm.sys [x]
S2 BdFileSpy;BullGuard File Monitor Driver;c:\windows\system32\drivers\BdFileSpy.sys [2009-01-27 55504]
S2 BsFileScan;BullGuard File Scan Service;c:\windows\System32\svchost.exe [2008-04-14 14336]
S2 BsFire;BullGuard Firewall Service;c:\windows\System32\svchost.exe [2008-04-14 14336]
S2 BsMailProxy;BullGuard Email Monitoring Service;c:\windows\System32\svchost.exe [2008-04-14 14336]
S3 afw;Agnitum firewall driver;c:\windows\system32\DRIVERS\afw.sys [2009-04-07 31128]
S3 AfwCore;Agnitum Firewall Core Driver;c:\windows\system32\Drivers\AfwCore.sys [2009-04-07 257304]
S3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2009-04-23 16640]
S3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2009-04-23 16640]
S3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2009-04-23 16640]
S3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2009-04-23 16640]
S3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2009-04-23 16640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
BullGuard REG_MULTI_SZ BgMainSvc BsFileScan BsMailProxy BsFire
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\pchealth\helpctr\System\panels\blank.htm
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=EM&Loc=ENG_US&Sys=DTP&M=T3418
IE: E&xport to Microsoft Excel
LSP: c:\windows\system32\bglsp.dll
DPF: Microsoft XML Parser for Java
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/dsl_settings/include/vzTCPConfig.CAB
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ty8zdb5t.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-09-01 03:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2648)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\BullGuard Ltd\BullGuard\BackupShellHook.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\program files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\windows\system32\locator.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-01 4:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-01 08:02
Pre-Run: 118,585,364,480 bytes free
Post-Run: 118,604,058,624 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /noguiboot /usepmtimer
230
do you mean the avenger log from what I ran previously ? That is all I have it is below
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Tue Sep 01 02:07:33 2009
02:07:27: Warning: Skipping potentially dangerous line:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbiwkmuwwiyvnk\modules" (Registry key deletion mode)
02:07:33: Error: Execution aborted by user!
//////////////////////////////////////////
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Tue Sep 01 02:08:49 2009
02:08:34: Warning: Skipping potentially dangerous line:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbiwkmuwwiyvnk\main" (Registry key deletion mode)
//////////////////////////////////////////
Logfile of The Avenger Version 2.0, (c) by Swandog46
https://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: file "C:\WINDOWS\system32\drivers\kbiwkmepwaomsn.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\kbiwkmepwaomsn.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\WINDOWS\system32\kbiwkmsmivppfd.dll" deleted successfully.
File "C:\WINDOWS\system32\kbiwkmspipmbcr.dat" deleted successfully.
File "C:\WINDOWS\system32\kbiwkmjkhoyrtf.dll" deleted successfully.
Error: file "C:\WINDOWS\system32\kbiwkmqitnesmp.dat" not found!
Deletion of file "C:\WINDOWS\system32\kbiwkmqitnesmp.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\TDSSmaxt.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\TDSSmaxt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSriqp.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSriqp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSScfgb.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSScfgb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSnmxh.log" not found!
Deletion of file "C:\WINDOWS\system32\TDSSnmxh.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSsbhc.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSsbhc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSthym.dll" not found!
Deletion of file "C:\WINDOWS\system32\TDSSthym.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSStkdv.log" not found!
Deletion of file "C:\WINDOWS\system32\TDSStkdv.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\TDSSbubx.log" not found!
Deletion of file "C:\WINDOWS\system32\TDSSbubx.log" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\UACxjjqbhgmec.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\UACxjjqbhgmec.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINDOWS\system32\drivers\UACxjjqbhgmec.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\UACxjjqbhgmec.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\WINDOWS\system32\UACwkbabiysbt.dll" deleted successfully.
Error: file "C:\WINDOWS\system32\UACyugewtvccr.dll" not found!
Deletion of file "C:\WINDOWS\system32\UACyugewtvccr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
File "C:\WINDOWS\system32\UACppyobffwro.dat" deleted successfully.
File "C:\WINDOWS\system32\UACskxvnlrjkw.db" deleted successfully.
File "C:\WINDOWS\system32\UACqftpibmkdw.dll" deleted successfully.
Error: file "C:\WINDOWS\system32\UACyrbxpkospb.dll" not found!
Deletion of file "C:\WINDOWS\system32\UACyrbxpkospb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\UACxjjqbhgmec" not found!
Deletion of driver "UACxjjqbhgmec" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSserv" not found!
Deletion of driver "TDSSserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Driver "Kbiwkmuwwiyvnk" deleted successfully.
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSmaxt" not found!
Deletion of driver "TDSSmaxt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\kbiwkmepwaomsn" not found!
Deletion of driver "kbiwkmepwaomsn" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbiwkmuwwiyvnk\modules" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbiwkmuwwiyvnk\modules" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\kbiwkmuwwiyvnk\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\UACd.sys\modules" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\UACd.sys" deleted successfully.
Registry key "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.