The BullGuard products and services are part of NortonLifeLock Inc., a global leader in consumer Cyber Safety with a portofolio of brands including Norton, Avira and more. Learn more at NortonLifeLock.com

WinBlue Soft

Posted 5/29/2009 4:32 AM
#73919
User avatar

Bird Man Member

Date Joined Nov 2016
Total Posts: 2
Hi,
I have a malware called winbluesoft on my pc. It has taken over. It won't let me run avast, the taskmanager, run or anything else. The desktop screen has turned black with my icons and says warning your computer has a virus. I tried to uninstall the winsoftblue program and it will not let me and pop ups from both sides of the screen want me to register for winbluesoft antivirus software removal but I haven't. I have been working on my computer all day and did not get a chance to back up my files before this happened and I really need them! I am not very computer savy so please !!!! down the step by step directions for removing this virus if you can help me!

Thank you.
Posted 5/29/2009 5:41 AM
#73924
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
Hello Bird Man :smile:




See if you can download and run combofix -




Please download combofix here -> https://download.bleepingcomputer.com/sUBs/ComboFix.exe



Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows.


Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.
Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall.
It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after
scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please post it.



NB. If you can´t run combofix from normal mode, do it from safe mode.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 5/30/2009 1:27 AM
#73952
User avatar

Bird Man Member

Date Joined Nov 2016
Total Posts: 2
I can't get online even in safe mode. Anything else I could try?

Thanks.
Posted 5/30/2009 1:52 AM
#73953
User avatar

Master Moss Member

Date Joined Nov 2016
Total Posts: 1
Hi there, I have the same problem and I've done everything up to posting it. Is there a specific part of the logfile you want posted, because there's a LOT of text in the logfile.
Posted 5/30/2009 4:26 AM
#73962
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
Bird Man -> Try this:






  1. Remove WiniBlueSoft Directories.
    To find WiniBlueSoft directories, go to Start > My Computer > Local Disk (C:) > Program Files > Show the contents of this folder.
    Search and delete the following WiniBlueSoft directories:
    C:\Program Files\WiniBlueSoft Software
    C:\Program Files\WiniBlueSoft Software\WiniBlueSoft
    C:\Documents and Settings\All Users\Start Menu\Programs\WiniBlueSoft

    Right-click on the WiniBlueSoft folder and select Delete.
    A message will appear saying ‘Are you sure you want to remove the folder WiniBlueSoft and move all its contents to the Recycle Bin?’, click Yes.
    Another message will appear saying ‘Renaming, moving or deleting WiniBlueSoft could make some programs not work. Are you sure you want to do this?’, click Yes.
    * To remove WiniBlueSoft icons on your Desktop, drag and drop them to the Recycle Bin.

Reboot.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/2/2009 11:54 AM
#74013
User avatar

gosiowo Member

Date Joined Nov 2016
Total Posts: 1
Hello :)
it does not help
I've deleted all winsoftblue files, downloaded combofix (renamed it) and it still can not be run
I don't know what to do :(
please help me with this :)
Posted 6/2/2009 4:09 PM
#74031
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
This topic are now for gosiowo
Click here: https://www.gmer.net/

and download the installer for Gmer to your desktop, then click that file to run Gmer.

(scroll down, and click on – Download Exe – Button)


If on it's opening scan Gmer locates items shown in red or indicates "hidden" or "rootkit", stop there, and click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please. We don't want any crashes just from taking an initial look at things.

If not, then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.






[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/23/2009 8:12 PM
#74654
User avatar

booklet Member

Date Joined Nov 2016
Total Posts: 3
Hey Touch,

I want to thanks God for you and posting advice to delete the winblue software. I made a foolish mistake to download this software. I unistalled the winblue software. And still bug me with the ads post. I end up purchase the winblue software with my credit card. That was a dumb move. I did not receive the email from them and plus I unistall the software. So I could not use it. I have no plan to download this software because I now don't trust it. I hope they don't mess with my credit card but I have no plan to ask for refund. I let them keep the money $49. I wonder how many people has been dupe by this method.

Any way I follow the advice here. I first start out with https://www.gmer.net/. I delete the things in red, that did not work. So I download the combofix. The combofix fix the problem. I don't know how that work. But now McAcfee scanner is working properly. Everytime I make McAcfee to scan, the computer restart for no reason. Now it no problem. I did not check other stuff on my computer but I believe it should be ok now.

God bless you, booklet
Posted 6/24/2009 4:48 AM
#74670
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
Hello booklet :smile:




I´ll suggest you post the combofix log, and I´ll look to it.

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/24/2009 5:38 AM
#74676
User avatar

booklet Member

Date Joined Nov 2016
Total Posts: 3
Sorry I did not save the log. Can I get it back?
Posted 6/24/2009 5:58 AM
#74677
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
No. Start from here ->



Please download Combofix:

Here

And save to the desktop.



Close all other browser windows.



Double-click on the combofix icon found on your desktop.



Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.



Combofix will create a logfile and display it after your computer has rebooted.

Usually located in c:\combofix.txt, please post it to your next reply.


[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 6/29/2009 6:36 AM
#74815
User avatar

booklet Member

Date Joined Nov 2016
Total Posts: 3
Ok I post the log at the bottom. Hope it ok. Thanks.

Booklet




ComboFix 09-06-28.02 - Owner 06/28/2009 20:24.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.895.328 [GMT -10:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active

.

((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.

2009-06-23 06:22 . 2009-06-23 06:22 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-22 20:57 . 2009-06-17 21:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-22 20:57 . 2009-06-22 22:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 20:57 . 2009-06-22 20:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-22 20:57 . 2009-06-17 21:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-22 15:23 . 2009-06-22 15:23 -------- d-----w- c:\program files\HDQuality
2009-06-14 22:53 . 2009-05-05 18:40 1137664 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\coolcore57.dll
2009-06-14 22:53 . 2008-06-04 11:07 811008 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\coolcore52.dll
2009-06-14 22:53 . 2008-06-04 11:05 249856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\xprt6.dll
2009-06-14 22:53 . 2007-11-09 20:09 786432 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\coolcore50.dll
2009-06-14 22:53 . 2007-03-20 02:48 249856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\xprt5.dll
2009-06-14 22:53 . 2009-05-19 05:23 757248 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\acccore.dll
2009-06-14 22:51 . 2009-05-19 11:35 69104 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\amos.exe
2009-06-14 22:51 . 2009-05-19 11:35 37888 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\amoinst.exe
2009-06-14 22:51 . 2009-05-19 11:35 1225352 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\msvc9rt.exe
2009-06-11 18:38 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 18:38 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-08 21:16 . 2009-06-08 21:16 -------- d-----w- c:\program files\iPod
2009-06-08 21:16 . 2009-06-08 21:17 -------- d-----w- c:\program files\iTunes
2009-06-02 11:25 . 2009-06-02 11:26 -------- d-----w- c:\program files\ICN Gaming Bar
2009-06-02 07:05 . 2009-06-02 07:05 -------- d-sh--w- c:\documents and settings\Owner\IECompatCache
2009-06-02 07:04 . 2009-06-02 07:04 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2009-06-01 19:12 . 2009-06-01 19:12 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-01 16:45 . 2009-06-01 16:45 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-06-01 16:42 . 2009-06-12 13:04 -------- d-----w- c:\windows\ie8updates
2009-06-01 16:42 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-01 16:41 . 2009-06-01 16:41 -------- dc-h--w- c:\windows\ie8
2009-05-30 22:50 . 2009-05-30 22:50 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-29 04:00 . 2007-11-10 04:10 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-29 04:00 . 2008-04-27 01:27 -------- d-----w- c:\program files\Norton Security Scan
2009-06-28 14:34 . 2008-08-18 10:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-28 02:39 . 2008-03-08 09:31 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-06-27 00:58 . 2007-11-10 04:28 -------- d-----w- c:\documents and settings\Owner\Application Data\Spare Backup
2009-06-24 03:10 . 2008-03-31 17:22 -------- d-----w- c:\program files\Safari
2009-06-14 22:56 . 2008-02-23 21:39 -------- d-----w- c:\program files\AIM6
2009-06-14 22:51 . 2008-02-23 23:45 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-06-12 13:05 . 2007-11-10 03:59 -------- d-----w- c:\program files\Microsoft Works
2009-06-12 13:05 . 2007-11-10 04:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-08 21:16 . 2008-02-19 18:57 -------- d-----w- c:\program files\Common Files\Apple
2009-06-08 21:14 . 2008-12-03 05:32 -------- d-----w- c:\program files\QuickTime
2009-06-05 21:59 . 2008-02-06 09:25 5888 ----a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-05-28 08:06 . 2009-02-19 05:43 -------- d-----w- c:\documents and settings\Owner\Application Data\U3
2009-05-24 07:05 . 2009-05-24 07:05 390664 ----a-w- c:\documents and settings\Owner\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-19 11:36 . 2009-06-14 22:52 97072 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\bsetutil.exe
2009-05-19 11:36 . 2009-06-14 22:52 2884832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\vwpt.exe
2009-05-19 11:36 . 2009-06-14 22:52 28 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\unregister.bat
2009-05-19 11:36 . 2009-06-14 22:52 25 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\register.bat
2009-05-19 11:36 . 2009-06-14 22:52 1484856 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\toolbar.exe
2009-05-19 11:36 . 2009-06-14 22:52 142040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\alsetup.exe
2009-05-19 11:36 . 2009-06-14 22:52 30512 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\Uninstaller.exe
2009-05-19 11:36 . 2009-06-14 22:52 111920 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\SUD4426\AOLSearch.dll
2009-05-19 07:04 . 2007-11-10 04:06 -------- d-----w- c:\program files\Java
2009-05-19 07:03 . 2009-05-19 07:03 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-14 08:33 . 2008-03-11 08:46 -------- d-----w- c:\program files\Comprehensive Review 3e
2009-05-14 08:31 . 2009-05-02 17:00 -------- d-----w- c:\program files\IrfanView
2009-05-13 05:15 . 2006-05-07 00:24 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-10 17:47 . 2009-05-10 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-07 15:32 . 2006-05-07 00:24 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-17 12:26 . 2006-05-07 00:24 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2006-05-07 00:24 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-06-23_06.18.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-27 00:56 . 2009-06-27 00:56 16384 c:\windows\Temp\Perflib_Perfdata_7a0.dat
+ 2009-06-23 06:22 . 2008-10-17 00:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-23 06:22 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-23 06:22 . 2008-04-14 00:12 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-23 06:22 . 2008-04-13 18:39 24576 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-23 06:22 . 2008-04-13 18:53 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-23 06:22 . 2008-04-14 00:12 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
- 2006-05-07 00:40 . 2009-06-23 03:09 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-05-07 00:40 . 2009-06-29 06:19 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-05-07 00:40 . 2009-06-23 03:09 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-05-07 00:40 . 2009-06-29 06:19 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-06-23 06:22 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-23 06:22 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-23 06:22 . 2008-04-14 00:12 578560 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-23 06:22 . 2008-04-14 00:12 295424 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-23 06:22 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-23 06:22 . 2009-02-06 11:11 110592 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-23 06:22 . 2008-04-13 19:20 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-23 06:22 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-23 06:22 . 2008-04-14 00:11 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2006-05-07 00:40 . 2009-06-29 06:19 196608 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-05-07 00:40 . 2009-06-23 03:09 196608 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-06-24 03:09 . 2009-06-24 03:09 307200 c:\windows\Installer\{C5C649A8-1D21-4C83-9B08-7B3752E580F4}\SafariIco.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-23 06:22 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-23 06:22 . 2009-02-08 05:02 2066048 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-23 06:22 . 2008-04-14 00:12 1033728 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8C7ADD44-D01F-4D04-B525-AE372B98AFD2}]
2009-06-02 11:26 1297920 ----a-w- c:\program files\ICN Gaming Bar\Toolbar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"EasyLinkAdvisor"="c:\program files\Linksys EasyLink Advisor\LinksysAgent.exe" [2007-03-16 454784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-18 39408]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-11-29 58928]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-11-10 1838592]
"BigFix"="c:\program files\Bigfix\bigfix.exe" [2006-11-17 2348584]
"Spare Backup"="c:\program files\Spare Backup\SpareBackup.exe" [2007-07-14 5252936]
"HostManager"="c:\program files\Common Files\AOL\1202217729\ee\AOLSoftware.exe" [2008-06-24 41824]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-09 54840]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-11 185896]
"NapsterShell"="c:\program files\Napster\napster.exe" [2009-02-03 323216]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-10-31 1622016]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-09-27 16844800]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-08-03 1826816]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-2-8 147456]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
OneNote Table Of Contents.onetoc2 [2008-7-2 3656]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2008-8-5 156784]
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2007-11-9 2348584]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1202217729\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0a\\waol.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 Stuffit Archive Name Service;Stuffit Archive Name Service;c:\program files\Smith Micro\StuffIt 12.0.1\ArcNameService.exe [5/23/2008 9:40 AM 157016]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/23/2008 1:44 PM 24652]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [6/30/2006 6:44 PM 69692]

--- Other Services/Drivers In Memory ---

*Deregistered* - eeCtrl

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 22:34]

2009-06-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-11-10 04:01]

2009-06-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-04-11 23:32]

2009-06-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-04-11 23:32]

2009-06-29 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 03:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AIM Toolbar Search - c:\documents and settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pqem3wc2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com?src=toolbar
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pqem3wc2.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}\platform\WINNT\components\FoxyTunes.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\pqem3wc2.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\components\WinampPlayer.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: browser.sessionstore.resume_from_crash - false
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-06-28 20:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1648)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-29 20:36
ComboFix-quarantined-files.txt 2009-06-29 06:35
ComboFix2.txt 2009-06-23 06:23

Pre-Run: 133,173,686,272 bytes free
Post-Run: 133,299,707,904 bytes free

278 --- E O F --- 2009-06-12 13:05
Posted 6/29/2009 6:56 AM
#74816
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
Next step ;-)



Viewpoint is considered foistware and is not needed on your computer.



Download and unzip ViewpointKiller to own folder on Desktop - [color=#0000ff>Here[/url]

Run ViewpointKiller.exe



Reboot.



Download: CCleaner here:
https://www.ccleaner.com/

Once installed, run CCleaner click the Windows tab
Select the following:
Internet Explorer:
Temp Internet
History
Recently Typed URLs
Delete Index.dat files


System:
Empty Recycle Bin
Temporary Files
Memory Dumps
Chkdsk File Fragments
Old Prefetch Data




Next: click Options click the Settings tab
Uncheck: "Only delete files older than 48 hrs.", click Ok


Then click Run Cleaner (bottom right) then Exit


Please download Malwarebytes' Anti-Malware:
https://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.



Once the program has loaded, select Perform full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.

When completed, a log will open in Notepad. Please save it to a convenient location.

NB[/color][/b]: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Click here: https://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe



to download HJTinstall.exe
Save HJTinstall.exe to your desktop.
Double click on the HJTinstall.exe icon on your desktop.
By default it will install to C:\Program Files\Trend Micro\Hijack This.
Click I accept
Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
Click Save to save the log file and then the log will open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.

DO NOT have Hijack This fix anything yet.
Most of what it finds will be harmless or even required.



Post hijackthis log along with Malwarebytes' Anti-Malware log, and tell how things are running ?

[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


Posted 7/8/2009 6:21 AM
#74957
User avatar

CherylS Member

Date Joined Nov 2016
Total Posts: 1
Thank you! Here is my log, I just pray the problem has been resolved! Let me know if there is anything else i need to do!

ComboFix 09-07-07.A2 - Amanda 07/07/2009 22:47.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.542 [GMT -7:00]
Running from: c:\documents and settings\Amanda\Desktop\123combofx.com.exe
AV: ZoneAlarm Security Suite Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-1417001333-1647877149-725345543-500
c:\recycler\S-1-5-21-3036349123-3059830484-2842643583-500
c:\recycler\S-1-5-21-791207165-234859006-1822604790-500
c:\windows\10139ddzar53086.ocx
c:\windows\1056zpambo5293.dll
c:\windows\10755zpy499.cpl
c:\windows\1075vir189z.bin
c:\windows\107z3hack5ool619.ocx
c:\windows\11121spaz5ot369.ocx
c:\windows\11502no9-a-virus53z.dll
c:\windows\11590vizus7f99.ocx
c:\windows\118z0spy3e59.ocx
c:\windows\120029iru526z.dll
c:\windows\1236znot-a-vi9us5a5.exe
c:\windows\12490vi9us25z.exe
c:\windows\1256z5ro9c5.bin
c:\windows\12799spambzt61f5.ocx
c:\windows\1292spy57z.dll
c:\windows\12z12tro93915.ocx
c:\windows\1332zhac9tool155.exe
c:\windows\14302hack5ool4z9.exe
c:\windows\14547spamb9tz25.ocx
c:\windows\1454spzrs519889.bin
c:\windows\147905zy391.dll
c:\windows\149035irus66z.bin
c:\windows\150bthr9az4895.bin
c:\windows\15173h9cztool1f3.bin
c:\windows\15330spambo951z.ocx
c:\windows\15472v9rzs5725.cpl
c:\windows\15570virzs7d89.bin
c:\windows\15z62troj95.cpl
c:\windows\16330zp95bot20c.bin
c:\windows\164139o5-a-vizus477.cpl
c:\windows\166495ot-a-virus9zb.dll
c:\windows\16959zdwa5e408.exe
c:\windows\171z9wo5m95.exe
c:\windows\17551spamb595z6.dll
c:\windows\17744hackto59z96.cpl
c:\windows\17a9down5oader2z94.cpl
c:\windows\17d5spywarz5999.dll
c:\windows\18489zorm598.ocx
c:\windows\18795hacktzol5359.exe
c:\windows\187z5tr9j747.ocx
c:\windows\187zthrea518923.dll
c:\windows\1887ztr9jc45.bin
c:\windows\189zpa59ot315.cpl
c:\windows\18zvi59681.exe
c:\windows\19003worz59d.bin
c:\windows\193589ot-z-virused.ocx
c:\windows\195fzir1099.cpl
c:\windows\1964thrzat554999.exe
c:\windows\19853tro5zd5.dll
c:\windows\1990zhac5tool1ab.exe
c:\windows\19953szambota9.exe
c:\windows\19954spyz05.exe
c:\windows\19981hack5oolze.ocx
c:\windows\19a6spyware5z80.bin
c:\windows\1a0adzwnloader3975.ocx
c:\windows\1b69addware1z15.exe
c:\windows\1d05addwzre1079.cpl
c:\windows\1e79back5oor1z.dll
c:\windows\1e9cs5ezl1206.ocx
c:\windows\1ez9thi5f1900.bin
c:\windows\1f48add5aze1392.exe
c:\windows\1f55zhief1989.cpl
c:\windows\1z06vir9965.exe
c:\windows\1z093spy59c.dll
c:\windows\1z84spam9o54d4.exe
c:\windows\1z926spy545.cpl
c:\windows\1z955t5oj915.dll
c:\windows\1zcfth5ef3913.bin
c:\windows\2005worm59cz.ocx
c:\windows\2038zha59tool2b.ocx
c:\windows\205z5hac5to9lc8.ocx
c:\windows\20979sp5mbot1za.exe
c:\windows\20zdba9kdo5r1205.bin
c:\windows\21f79hreat28z985.exe
c:\windows\2220backdo9r1z5.exe
c:\windows\22275s9y1z05.bin
c:\windows\225zi9us1a5.ocx
c:\windows\229z5vi5us25.cpl
c:\windows\23165hacktoolz39.bin
c:\windows\2392zspa9bot4005.ocx
c:\windows\23999s596b6z.bin
c:\windows\23b095iefz610.ocx
c:\windows\24155s9a5bzt35c.exe
c:\windows\242z5spy1529.ocx
c:\windows\251z3spambot7b9.cpl
c:\windows\253495irus2e2z.cpl
c:\windows\253esparsez962.cpl
c:\windows\2559vi9z356.cpl
c:\windows\25787tro55z9.dll
c:\windows\25892hacktooz193.bin
c:\windows\25bathre9t571z.ocx
c:\windows\25z16n5t-a-9irus57e.exe
c:\windows\25z96spy139.dll
c:\windows\25zb9ir2556.exe
c:\windows\26011ha5kzool6dd9.ocx
c:\windows\26155spamzo97295.dll
c:\windows\2623no5-a-virus29z.bin
c:\windows\263059acktooz7965.exe
c:\windows\266z79ackto5l4d1.dll
c:\windows\26781not-z-viru5596.dll
c:\windows\26806ha9ktooz7cb5.cpl
c:\windows\26934not-a-v9ruz554.dll
c:\windows\26950tzoj500.bin
c:\windows\273ha59zool327.dll
c:\windows\27500not-9zvirus730.exe
c:\windows\27955acktooz37e.exe
c:\windows\27997szy7fa5.dll
c:\windows\27z36hack9ool8b5.exe
c:\windows\27z69w5rm12.exe
c:\windows\28059tz9j519.cpl
c:\windows\28691zpambot529.ocx
c:\windows\288z9ddware29955.bin
c:\windows\28929zo5m3cb.bin
c:\windows\28d0st5al947z.dll
c:\windows\292245o9m18z.bin
c:\windows\29495virus55z.ocx
c:\windows\2974ztr5jb9.ocx
c:\windows\29861s59z91.cpl
c:\windows\29959troz5ac.bin
c:\windows\29z85viru51d0.cpl
c:\windows\2azdvir5795.cpl
c:\windows\2b91steal3z535.dll
c:\windows\2f2z9hreat24051.dll
c:\windows\2f8a9dwarez6775.cpl
c:\windows\2z13d9wnlo5der1355.bin
c:\windows\2z141viru52df9.cpl
c:\windows\2z58v9r360.bin
c:\windows\2z6295pambot9e.bin
c:\windows\2z78795y752.exe
c:\windows\2z869spambot335.bin
c:\windows\2z917n9t-a-vi5us7c6.exe
c:\windows\30051t9zj2ef.bin
c:\windows\301z9hac5too953.bin
c:\windows\3053zwo5m79.cpl
c:\windows\30576zpa5bo9324.cpl
c:\windows\30699vir5z789.ocx
c:\windows\30981v5ruz545.ocx
c:\windows\30spamb5t9fz.dll
c:\windows\31720t5zj90f.ocx
c:\windows\32037s5amboz9e4.exe
c:\windows\32235s59za2.dll
c:\windows\32419zacktoo537d.dll
c:\windows\3405no9-a-virusz5e.exe
c:\windows\34cdaddwa5e91z8.ocx
c:\windows\34e5threat2459z.cpl
c:\windows\352bd95nloader13z5.ocx
c:\windows\353zbac9door1854.cpl
c:\windows\35489wormzd.ocx
c:\windows\35599i5z289.exe
c:\windows\3579vir9257z.exe
c:\windows\3591zhief9112.cpl
c:\windows\3608th9efz785.exe
c:\windows\3629addza5e3071.ocx
c:\windows\365159arse198z.ocx
c:\windows\3704zhr9a518537.ocx
c:\windows\37379ackz5or658.bin
c:\windows\3867hacz5oo96c.bin
c:\windows\3889h5cktzol365.dll
c:\windows\397aspywa5z1693.exe
c:\windows\399bsteal58z.exe
c:\windows\3cf4ste9z5621.exe
c:\windows\3e5esparsz593.ocx
c:\windows\3e9bzownloade5255.bin
c:\windows\3ff6s5e9z2788.ocx
c:\windows\3fzspa5se9700.exe
c:\windows\3zc9sp5rse1586.dll
c:\windows\4027s9ambozd45.bin
c:\windows\4095zhreat2592.bin
c:\windows\4195azdwar91165.bin
c:\windows\425st5az9618.ocx
c:\windows\4301sp970z5.cpl
c:\windows\445as9azse1882.bin
c:\windows\44dcth59f39z.dll
c:\windows\4502downloaderz5849.exe
c:\windows\45319acktool630z.bin
c:\windows\4599worm1z5.exe
c:\windows\459fzir9120.ocx
c:\windows\45a9addwar91z22.dll
c:\windows\460zh9ef27615.bin
c:\windows\469es5eal2964z.bin
c:\windows\46addownloader519z.exe
c:\windows\46e9backzoor12995.cpl
c:\windows\485fspy9aze775.bin
c:\windows\4904add9aze29015.dll
c:\windows\494cvir275z9.dll
c:\windows\49b5addware589z.bin
c:\windows\49c6downlo5derz536.cpl
c:\windows\49f2s9ea5517z.ocx
c:\windows\4b09ba5kdoor2z97.exe
c:\windows\4b37down5oade91509z.ocx
c:\windows\4b41add95re325z.dll
c:\windows\4d5cthre9t12z45.bin
c:\windows\4ecethzef12195.exe
c:\windows\4f81tz9ef5068.bin
c:\windows\4fz9s5eal1418.ocx
c:\windows\50149virus6bz.bin
c:\windows\50279zy95.exe
c:\windows\50db9ckdoor2z05.cpl
c:\windows\5148not-a5v9ruszda.dll
c:\windows\5150thiez2098.dll
c:\windows\5167zpa5se9260.bin
c:\windows\5170downloa5z91902.bin
c:\windows\5176ha5ktool63z9.bin
c:\windows\52412zr9j3e7.dll
c:\windows\5325doznload9r1461.bin
c:\windows\532zvir2991.exe
c:\windows\539cdown9oa5erz075.cpl
c:\windows\53bzthief2799.exe
c:\windows\53ebthr9zt25803.ocx
c:\windows\5472h9ckto5l1az.bin
c:\windows\54bf9hief287z.dll
c:\windows\5502d9wnlozder3027.bin
c:\windows\550athie5995z.dll
c:\windows\5518zspambo928f.cpl
c:\windows\551zha5ktool4e9.dll
c:\windows\553e9ddware1z34.dll
c:\windows\556zteal9394.ocx
c:\windows\55759not-a-viru94z6.bin
c:\windows\5596sparz59367.cpl
c:\windows\55z99acktool73c.bin
c:\windows\564bzteal597.ocx
c:\windows\56614zackt9ol152.exe
c:\windows\5715s9azse3247.dll
c:\windows\57971szy610.cpl
c:\windows\57z5downloader9255.dll
c:\windows\5809vizus3a.exe
c:\windows\5870s5yware3z09.bin
c:\windows\58dadzw9loader512.dll
c:\windows\5907t5oj1z39.cpl
c:\windows\591cspzrse130.cpl
c:\windows\5924wormz5f.cpl
c:\windows\5941backdoor19z15.cpl
c:\windows\5959ztea59678.bin
c:\windows\595ezteal2273.dll
c:\windows\59719zeal354.bin
c:\windows\597azteal9560.bin
c:\windows\5983hacktool13z5.exe
c:\windows\5993sparse1505z.dll
c:\windows\599czddware2715.dll
c:\windows\59cstza93005.ocx
c:\windows\59z2st5al2999.exe
c:\windows\59z39irus505.exe
c:\windows\5a56zir2898.bin
c:\windows\5a89dow5lzader19059.ocx
c:\windows\5b94stea5808z.cpl
c:\windows\5dzd9ir1355.exe
c:\windows\5e535hief936z.exe
c:\windows\5e8z9hreat56581.cpl
c:\windows\5ee4zhief17595.cpl
c:\windows\5f73zir9875.ocx
c:\windows\5fcdvirz6959.exe
c:\windows\5fz6sp5rse719.dll
c:\windows\5z49vir822.exe
c:\windows\5z59steal2336.ocx
c:\windows\5zb5sp5rse2966.dll
c:\windows\6052sparze22749.cpl
c:\windows\609aviz5052.cpl
c:\windows\610ds9arse54z5.cpl
c:\windows\6130szy5are1691.ocx
c:\windows\617z9acktool655.bin
c:\windows\6252addwaze30859.ocx
c:\windows\6291bac95oor2z67.exe
c:\windows\6319iz1586.ocx
c:\windows\6357spamboz596.bin
c:\windows\6399spywaz52118.dll
c:\windows\6399vir5z7ae.exe
c:\windows\63bzt5reat16697.exe
c:\windows\64bevi9159z.cpl
c:\windows\65f9zownloa9er2018.ocx
c:\windows\668dvir1z569.bin
c:\windows\672cstz5l2904.exe
c:\windows\6762spz5se27279.ocx
c:\windows\68ea9tzal1375.bin
c:\windows\696esze5l96.cpl
c:\windows\69z05ownloader751.bin
c:\windows\6c9as5yware1z31.exe
c:\windows\6d23ad9wa5e2z72.dll
c:\windows\6e1fa9dzare7985.bin
c:\windows\6e91vzr582.cpl
c:\windows\71529tez51953.cpl
c:\windows\71985hrea9116z8.ocx
c:\windows\7270w5rm695z.exe
c:\windows\72d9thr5az19882.exe
c:\windows\746download5r29z4.dll
c:\windows\74f5spaz9e2835.bin
c:\windows\751az95al1807.exe
c:\windows\75f2tzrea596504.dll
c:\windows\75zcth9ef2406.cpl
c:\windows\78ethief536z9.cpl
c:\windows\78zsp9wa5e622.ocx
c:\windows\792zwo5me9.dll
c:\windows\796fdownlo5de92564z.exe
c:\windows\79a1downl5zder3123.exe
c:\windows\7a0zvi9355.exe
c:\windows\7a995ir2196z.exe
c:\windows\7b54az9ware2378.bin
c:\windows\7c5zdo9nloader968.cpl
c:\windows\7cazthr5at282559.ocx
c:\windows\7dz1t9rea54282.exe
c:\windows\7e95sparsz2575.dll
c:\windows\80thi5f27z9.dll
c:\windows\8395s5y115z.ocx
c:\windows\88079roj485z.bin
c:\windows\89315izus6a5.cpl
c:\windows\8ccdownlza9er1365.exe
c:\windows\91515ir2150z.exe
c:\windows\9180s59mbzt1d1.cpl
c:\windows\91884worm15z5.bin
c:\windows\91z4steal2531.ocx
c:\windows\92709hzckto5l4e.dll
c:\windows\92z55spy3ff.cpl
c:\windows\9339ha5ztool377.cpl
c:\windows\9357wormz5e5.ocx
c:\windows\93698not-a-viruszea5.cpl
c:\windows\9396spz597.ocx
c:\windows\94z4hacktool4f5.bin
c:\windows\95151hacktzol25.exe
c:\windows\9519sp5zse2974.exe
c:\windows\95556zpy3ed.bin
c:\windows\97305parse31z8.dll
c:\windows\9871sp5z4.dll
c:\windows\987zthief2355.dll
c:\windows\98zbt5ief934.ocx
c:\windows\9905vi9uz638.cpl
c:\windows\99527zpy110.cpl
c:\windows\9a07szars5691.bin
c:\windows\9c905zckdoor430.dll
c:\windows\9cast9a52647z.exe
c:\windows\9cfbvirz578.ocx
c:\windows\9fz4vir5171.cpl
c:\windows\9fzthrea522280.bin
c:\windows\9zb1st5al339.cpl
c:\windows\9zf5spyware1716.exe
c:\windows\a4t5reat10z619.ocx
c:\windows\c6bz95eat11585.dll
c:\windows\cc35hi9fz499.dll
c:\windows\ed35hief295z.dll
c:\windows\f5d9pazse957.exe
c:\windows\Installer\10567152.msp
c:\windows\Installer\2e14a50.msp
c:\windows\Installer\316f4.msp
c:\windows\Installer\3cf57.msp
c:\windows\Installer\4aa88b8.msp
c:\windows\Installer\a4a036f.msp
c:\windows\Installer\WinRMSrv.msi
c:\windows\setup.exe
c:\windows\system32\100829i5us40z.dll
c:\windows\system32\1018az9war5269.dll
c:\windows\system32\101955ozm7d6.cpl
c:\windows\system32\10298zorm2f75.cpl
c:\windows\system32\107d5zeal393.ocx
c:\windows\system32\1089stza5835.exe
c:\windows\system32\10985spa5zot2c9.dll
c:\windows\system32\109stezl2552.exe
c:\windows\system32\109z6not-a-virus519.cpl
c:\windows\system32\1133sp95z9.cpl
c:\windows\system32\118z8worm519.exe
c:\windows\system32\11zdaddw5re99.dll
c:\windows\system32\12354vir9z7ef.ocx
c:\windows\system32\13063spamz9t595.cpl
c:\windows\system32\132s9yz4a5.bin
c:\windows\system32\13449zacktoo9657.exe
c:\windows\system32\1358t95ezt19141.ocx
c:\windows\system32\13595hacktool1ez.dll
c:\windows\system32\1395virus59z.dll
c:\windows\system32\13zcthief16975.dll
c:\windows\system32\14020spz952.ocx
c:\windows\system32\142z7tr9j45f.cpl
c:\windows\system32\14944zp551.exe
c:\windows\system32\153695roj5z1.exe
c:\windows\system32\15499spzm5ote9.dll
c:\windows\system32\1571threat79z4.bin
c:\windows\system32\1579759ambot4edz.dll
c:\windows\system32\15839py6bdz.dll
c:\windows\system32\15844v59us37az.dll
c:\windows\system32\15935pyware150z.exe
c:\windows\system32\15993viruz505.dll
c:\windows\system32\15z1sp5rse1299.dll
c:\windows\system32\16474s9yz65.dll
c:\windows\system32\166779p5mbot1az.exe
c:\windows\system32\17378spam5zt34a9.bin
c:\windows\system32\179925ot-a-viru9z81.dll
c:\windows\system32\179z6spambot549.ocx
c:\windows\system32\18135spazb95608.ocx
c:\windows\system32\181595ot-a-viruz6cc.exe
c:\windows\system32\18185ozm3239.exe
c:\windows\system32\1839bazkd59r862.bin
c:\windows\system32\1858szy297.exe
c:\windows\system32\18598notza-virus62c.dll
c:\windows\system32\18zdthrea516989.cpl
c:\windows\system32\1902not-azv5ru9476.ocx
c:\windows\system32\190z0hacktoo51c9.bin
c:\windows\system32\192765irus2z8.exe
c:\windows\system32\1935tr9jz59.ocx
c:\windows\system32\19457spazb9tb9.ocx
c:\windows\system32\194cstz9l5362.ocx
c:\windows\system32\19623vzrus1f59.bin
c:\windows\system32\19699hacktoo555z.cpl
c:\windows\system32\1976addware456z.exe
c:\windows\system32\1995wor5z1f.dll
c:\windows\system32\1999zworm5a8.exe
c:\windows\system32\19z959acktool693.bin
c:\windows\system32\1a40sz9al456.dll
c:\windows\system32\1azd5teal914.bin
c:\windows\system32\1b51vir1z019.ocx
c:\windows\system32\1c59thzef2535.dll
c:\windows\system32\1c79zpy9are1335.bin
c:\windows\system32\1f87downloa5er1497z.bin
c:\windows\system32\1f9b5te9l1z47.dll
c:\windows\system32\1z33spyware2159.bin
c:\windows\system32\2039down5oader1028z.bin
c:\windows\system32\20498v9rus15z.dll
c:\windows\system32\212965pambz9c7.exe
c:\windows\system32\21315hackz9ol385.bin
c:\windows\system32\213e5teal92z9.ocx
c:\windows\system32\21495ownloazer1133.cpl
c:\windows\system32\21553t9ojzc5.dll
c:\windows\system32\21558spazbot69.exe
c:\windows\system32\21913spzmbota5.ocx
c:\windows\system32\21f9b5ckdoorz54.ocx
c:\windows\system32\2215zhacktoo91b5.bin
c:\windows\system32\2219backdoo5z443.ocx
c:\windows\system32\22599zpy531.ocx
c:\windows\system32\225z2v9rusea.bin
c:\windows\system32\22959sp9mbzt5a35.cpl
c:\windows\system32\23549t9ojzd1.bin
c:\windows\system32\23599no9-a-v5rus6z8.bin
c:\windows\system32\23928virzs9365.cpl
c:\windows\system32\23989irus5z5.bin
c:\windows\system32\241369py530z.cpl
c:\windows\system32\24275hacz9ool4325.cpl
c:\windows\system32\24505vir9z2ae.cpl
c:\windows\system32\25061spamz9t727.exe
c:\windows\system32\252z9spambot379.dll
c:\windows\system32\2530spywa9ez748.bin
c:\windows\system32\25353nzt-a-viru9687.dll
c:\windows\system32\253z5worm539.ocx
c:\windows\system32\2545zworm4915.cpl
c:\windows\system32\254z5viru9481.bin
c:\windows\system32\254z7wor59ed.dll
c:\windows\system32\25586no9za-virus70f.cpl
c:\windows\system32\2586thr5at9593z.bin
c:\windows\system32\25961virus615z.bin
c:\windows\system32\25e7threz9421.bin
c:\windows\system32\25z94s5y6ea.ocx
c:\windows\system32\26506not-a-vzr5s591.cpl
c:\windows\system32\265d5a9kzoor1696.exe
c:\windows\system32\26995vizus169.cpl
c:\windows\system32\26fe5dzware912.bin
c:\windows\system32\27249spzmbota5.bin
c:\windows\system32\272z25irus399.bin
c:\windows\system32\276895py1f6z.cpl
c:\windows\system32\27859troj595z.ocx
c:\windows\system32\2797z9acktool560.dll
c:\windows\system32\28205s9ambot5z1.cpl
c:\windows\system32\28340not-a9viru55c6z.ocx
c:\windows\system32\28654spy9z5.bin
c:\windows\system32\28946haczto95679.exe
c:\windows\system32\289979a5ktozl50f.cpl
c:\windows\system32\289z35irus358.dll
c:\windows\system32\2908z5ief2902.exe
c:\windows\system32\29255te9lz73.exe
c:\windows\system32\29261troj598z.dll
c:\windows\system32\29305s5yz3a.dll
c:\windows\system32\29642no5za-viru92be.bin
c:\windows\system32\296f95r9z.bin
c:\windows\system32\2994zspa5bot33.exe
c:\windows\system32\29950spambot9z9.bin
c:\windows\system32\29z17not-5-virus5fe9.cpl
c:\windows\system32\2b07doz9l5ader1112.cpl
c:\windows\system32\2b99addwz5e129.cpl
c:\windows\system32\2c409parsez855.exe
c:\windows\system32\2cb7ad5wa9e31z4.ocx
c:\windows\system32\2d075ir9z32.exe
c:\windows\system32\2d75v9r1920z.cpl
c:\windows\system32\2z3199a5ktool4c0.exe
c:\windows\system32\30376s59z20.bin
c:\windows\system32\30858vir5z29d.cpl
c:\windows\system32\30964t9oj583z.bin
c:\windows\system32\3139viruz2975.bin
c:\windows\system32\31605notza9vir5s6c5.bin
c:\windows\system32\31647spzmbot9db5.dll
c:\windows\system32\31919not-a-5izus449.ocx
c:\windows\system32\31d9stzal5745.cpl
c:\windows\system32\32z30n5t-a-virus389.cpl
c:\windows\system32\3309spyw5rez742.exe
c:\windows\system32\352z9pywar52861.ocx
c:\windows\system32\3535add9aze3076.bin
c:\windows\system32\3569d9wn5oader1556z.cpl
c:\windows\system32\361a9ddwarez2665.bin
c:\windows\system32\36315ozm6e19.ocx
c:\windows\system32\365bzhief6559.exe
c:\windows\system32\3676downz5ader9945.bin
c:\windows\system32\3769downloader1925z.dll
c:\windows\system32\38z0ba59door1759.ocx
c:\windows\system32\3954viz2449.dll
c:\windows\system32\39b0s5yware76z.dll
c:\windows\system32\3aacstea5879z.bin
c:\windows\system32\3b0zs9ea52033.exe
c:\windows\system32\3cf0spars92252z.dll
c:\windows\system32\3d3s5eal5z9.cpl
c:\windows\system32\3z535spa5bot98.cpl
c:\windows\system32\3z954troj1dc.dll
c:\windows\system32\3z965tr5j520.bin
c:\windows\system32\4051v9r515z.exe
c:\windows\system32\4056s95az1640.ocx
c:\windows\system32\41d5thiez9891.bin
c:\windows\system32\4279not-9-viruz564.cpl
c:\windows\system32\449ct5ief9134z.cpl
c:\windows\system32\45a6bac9door3156z.ocx
c:\windows\system32\467ds5ars9z496.ocx
c:\windows\system32\46a99ackdo5r29z8.dll
c:\windows\system32\47fcszywar51998.cpl
c:\windows\system32\47z8backdo9r1495.exe
c:\windows\system32\4803tzoj95b.dll
c:\windows\system32\4808th5eat5509z.bin
c:\windows\system32\4905viz1847.exe
c:\windows\system32\4917downlo5der1z21.bin
c:\windows\system32\4919t5izf665.exe
c:\windows\system32\498az5yware1388.ocx
c:\windows\system32\49995yzfc.dll
c:\windows\system32\4b2zp9r5e2908.bin
c:\windows\system32\4c5cdownzoader9848.exe
c:\windows\system32\4c86t5izf692.ocx
c:\windows\system32\4cf69ackzoor2265.exe
c:\windows\system32\4e1bz9ckdoor558.dll
c:\windows\system32\4f03spar5z1809.bin
c:\windows\system32\4f39hzeat47515.cpl
c:\windows\system32\4fd9spywaze485.bin
c:\windows\system32\4zb9v5r107.exe
c:\windows\system32\4zc2t9reat2185.cpl
c:\windows\system32\5084stzal30619.bin
c:\windows\system32\5097zddwar5542.cpl
c:\windows\system32\5113sparse99z8.ocx
c:\windows\system32\5141zvirus219.bin
c:\windows\system32\5150dow5z9ader2507.ocx
c:\windows\system32\516fdow5lza9er1030.exe
c:\windows\system32\5195addwarz411.bin
c:\windows\system32\5199thrzat59578.exe
c:\windows\system32\51a9viz57.dll
c:\windows\system32\51z5troj4389.exe
c:\windows\system32\51zc9ir2846.bin
c:\windows\system32\52799troz3aa.exe
c:\windows\system32\528d9ackdoorz886.bin
c:\windows\system32\52902spambot79az.cpl
c:\windows\system32\529at5reatz6940.cpl
c:\windows\system32\529z7virus789.dll
c:\windows\system32\5304not-a5virus69z.bin
c:\windows\system32\5348wor9z065.ocx
c:\windows\system32\535wz5950f.ocx
c:\windows\system32\539czackd5or1883.bin
c:\windows\system32\54252wormze9.cpl
c:\windows\system32\5448s9az5e2111.bin
c:\windows\system32\553b9zeal1663.cpl
c:\windows\system32\556backdo9rz153.bin
c:\windows\system32\55795zpy590.ocx
c:\windows\system32\5599ownloaderz65.bin
c:\windows\system32\56f6s5zrse3099.ocx
c:\windows\system32\5702z9wnloader9555.dll
c:\windows\system32\57059hackto9z171.exe
c:\windows\system32\57341not-9zvirus203.bin
c:\windows\system32\57499ot-a-virus3z3.ocx
c:\windows\system32\57895spy49z.dll
c:\windows\system32\57fzst9al511.ocx
c:\windows\system32\581dthreatz9333.cpl
c:\windows\system32\589spyzf3.dll
c:\windows\system32\58c9thizf2019.exe
c:\windows\system32\58d9vir99z75.ocx
c:\windows\system32\5919spyware139z.dll
c:\windows\system32\596559arze2320.exe
c:\windows\system32\596ad9w5re11z6.dll
c:\windows\system32\5997threat177z9.ocx
c:\windows\system32\59z16h9cktool2ee.cpl
c:\windows\system32\5a55downl9adzr2865.exe
c:\windows\system32\5a66threat285z59.dll
c:\windows\system32\5b2addwzre9051.ocx
c:\windows\system32\5be9spz5are13079.bin
c:\windows\system32\5c49steal456z.dll
c:\windows\system32\5c845ir10z59.ocx
c:\windows\system32\5c9z5ddware916.ocx
c:\windows\system32\5c9zspyware755.dll
c:\windows\system32\5d69bzckd5or929.exe
c:\windows\system32\5ddzth5e9212.exe
c:\windows\system32\5deztea9977.exe
c:\windows\system32\5f5down9oadzr2534.exe
c:\windows\system32\5fdspa9se533z.exe
c:\windows\system32\5z40vir14795.cpl
c:\windows\system32\5z53t9ief86.ocx
c:\windows\system32\5z99troj5aa.dll
c:\windows\system32\5zf1a5dware498.dll
c:\windows\system32\615es9zal621.dll
c:\windows\system32\622bsp9wa5e29z3.ocx
c:\windows\system32\6382s9a5bot44z.bin
c:\windows\system32\649dzir1553.exe
c:\windows\system32\64fbz59al1930.cpl
c:\windows\system32\6556vir953z.bin
c:\windows\system32\655d9hrzat17879.dll
c:\windows\system32\6581backdzor28579.dll
c:\windows\system32\65d5v5r101z9.exe
c:\windows\system32\65z2vir4859.cpl
c:\windows\system32\664dspyware5z629.cpl
c:\windows\system32\6656thze95539.bin
c:\windows\system32\66z5backdoo92334.dll
c:\windows\system32\674zspamb9t558.exe
c:\windows\system32\678ezac5door1992.dll
c:\windows\system32\67a8zir5490.cpl
c:\windows\system32\6896zor5166.dll
c:\windows\system32\6979spywa9e25z7.exe
c:\windows\system32\699cdoznload5r15859.dll
c:\windows\system32\69b5addwarez183.dll
c:\windows\system32\69dow5loader25z.dll
c:\windows\system32\6a58za9kdoor1220.exe
c:\windows\system32\6ce5thr9zt6819.bin
c:\windows\system32\6d2fzh9eat62665.bin
c:\windows\system32\6z53vi9500.exe
c:\windows\system32\7127bazk9oor28535.exe
c:\windows\system32\7155addw9re2158z.ocx
c:\windows\system32\72z99ir1455.exe
c:\windows\system32\730zs5ambot59e.exe
c:\windows\system32\73a3sparse1z945.exe
c:\windows\system32\74599zeal390.bin
c:\windows\system32\7478not-a-5izus669.ocx
c:\windows\system32\752f9parsz3208.cpl
c:\windows\system32\7560spa9sz2951.dll
c:\windows\system32\75b9spywarz608.bin
c:\windows\system32\768759ief2753z.cpl
c:\windows\system32\76a1bzckd5o91440.ocx
c:\windows\system32\77295acktool3z89.cpl
c:\windows\system32\7834noz-a-v59us73a.dll
c:\windows\system32\7958steal13z4.exe
c:\windows\system32\797bszy5are2094.exe
c:\windows\system32\7a57addware3159z.cpl
c:\windows\system32\7bzaddwa5e2095.dll
c:\windows\system32\7cczth95at10516.ocx
c:\windows\system32\7d8bdownloadzr15349.dll
c:\windows\system32\7dz9hief6045.ocx
c:\windows\system32\7f695ownloade9315z.cpl
c:\windows\system32\7z47bac5door3944.cpl
c:\windows\system32\85cd5wnl9aderz052.cpl
c:\windows\system32\8786zorm9b5.cpl
c:\windows\system32\88zs95198.exe
c:\windows\system32\89dth5ef11z.bin
c:\windows\system32\89z2virus3f95.exe
c:\windows\system32\8z3th5e9223.cpl
c:\windows\system32\906baczd5or365.ocx
c:\windows\system32\90z3w9rm5a1.bin
c:\windows\system32\917threaz174495.bin
c:\windows\system32\9255tzoj976.exe
c:\windows\system32\9325not-a-5zrus675.dll
c:\windows\system32\9385z9cktool675.dll
c:\windows\system32\9536downlzade52390.cpl
c:\windows\system32\953ethzeat54721.exe
c:\windows\system32\95465spambot4az.exe
c:\windows\system32\95c6addware52z.exe
c:\windows\system32\95cbszarse2311.cpl
c:\windows\system32\95e1thief322z.dll
c:\windows\system32\9605virus97z5.exe
c:\windows\system32\9606not-5-virus193z.ocx
c:\windows\system32\9631spy15fz.bin
c:\windows\system32\969z9acktoo5121.bin
c:\windows\system32\96thzef14655.ocx
c:\windows\system32\96z7spyware5921.ocx
c:\windows\system32\9739wor5z79.dll
c:\windows\system32\97642viruz5ba.cpl
c:\windows\system32\980cdow5loader2z98.dll
c:\windows\system32\98525iruz5ef.ocx
c:\windows\system32\98ezthief29095.dll
c:\windows\system32\99c6backdoor515z.ocx
c:\windows\system32\99casteaz5064.bin
c:\windows\system32\9a14vzr5596.bin
c:\windows\system32\9b24thiez2579.dll
c:\windows\system32\9b44dzwnloader5734.bin
c:\windows\system32\9c92addwzre12455.ocx
c:\windows\system32\9f59steaz2425.dll
c:\windows\system32\9z19addware335.exe
c:\windows\system32\9z260tro51b2.exe
c:\windows\system32\9z51steal1588.cpl
c:\windows\system32\9z665irus7ea9.cpl
c:\windows\system32\9z768virus156.dll
c:\windows\system32\a459parsz794.cpl
c:\windows\system32\a4fsp9zare2545.cpl
c:\windows\system32\af1dow5l9adzr2124.cpl
c:\windows\system32\azat5ief2390.exe
c:\windows\system32\c9cspa5sez099.exe
c:\windows\system32\cc3szyware5994.ocx
c:\windows\system32\cz5ba9kdoor757.cpl
c:\windows\system32\drivers\MSIVXufpelbljabsruayqeeaanoyhdtkioncn.sys
c:\windows\system32\dzas95ware956.bin
c:\windows\system32\e6a9pa5sz44.cpl
c:\windows\system32\ea85hreat90477z.exe
c:\windows\system32\f78download5r91z.bin
c:\windows\system32\MSIVXcbwdqcnuoytouniodtkxroleaycdrdlf.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXqqsnqdmudjnqlanypmvwfarvhmsvlgxj.dll
c:\windows\system32\setup2.exe
c:\windows\system32\z1087wor955d.exe
c:\windows\system32\z1249spamb9ta5.cpl
c:\windows\system32\z1556spy59.ocx
c:\windows\system32\z22bac5door976.ocx
c:\windows\system32\z3095troj30d.bin
c:\windows\system32\z3846hacktool5d9.ocx
c:\windows\system32\z470spar5e994.ocx
c:\windows\system32\z591worm85.ocx
c:\windows\system32\z5dcspa9se20685.exe
c:\windows\system32\z6359py765.exe
c:\windows\system32\z7fcspars92858.dll
c:\windows\system32\z895vir2958.exe
c:\windows\system32\z9b0vir2957.ocx
c:\windows\system32\za29ir1685.exe
c:\windows\system32\zaadownloa95r3149.bin
c:\windows\system32\zc00back5oor1934.bin
c:\windows\system32\zc56s9arse12.ocx
c:\windows\system32\zc59thi9f1951.dll
c:\windows\system32\zc85steal897.ocx
c:\windows\system32\zd119parse1589.exe
c:\windows\system32\zeacthreat95499.exe
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
c:\windows\z0694n9t-a-virus5b3.exe
c:\windows\z1554worm93b.cpl
c:\windows\z17ea5dw9re1294.cpl
c:\windows\z1951worm56.exe
c:\windows\z1e6b5ckdoor9127.dll
c:\windows\z2187wo9m5c1.ocx
c:\windows\z23905roj398.bin
c:\windows\z35aspyware15259.dll
c:\windows\z4051spambot459.dll
c:\windows\z445vi91552.cpl
c:\windows\z4728viru5991.ocx
c:\windows\z48105p9e2.ocx
c:\windows\z485addwa9e2085.cpl
c:\windows\z51sp5mbot4599.dll
c:\windows\z5690worm143.bin
c:\windows\z599threat7660.dll
c:\windows\z59cste9l28.dll
c:\windows\z679wor9725.ocx
c:\windows\z71bstea919835.cpl
c:\windows\z790spy495.dll
c:\windows\z8159eal2286.cpl
c:\windows\z81895yware1304.bin
c:\windows\z861159y427.exe
c:\windows\z87aa9dwar52805.ocx
c:\windows\z9467spambot3c55.exe
c:\windows\z99cdo5nloader1599.bin
c:\windows\z9a5dwar9343.bin
c:\windows\zc55s9eal2217.cpl
c:\windows\zc79spywa5e488.bin
c:\windows\zc87sp9rs51387.cpl
c:\windows\zddc5hr9at5412.bin
c:\windows\zf4fspy9are2165.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-07-07 20:14 . 2009-07-07 20:14 11595 ----a-w- c:\windows\system32\z271559yb.dll
2009-07-05 05:04 . 2009-07-05 05:04 -------- d-----w- C:\VundoFix Backups
2009-07-04 19:14 . 2009-07-04 19:14 -------- d-----w- c:\program files\iPod
2009-07-04 19:05 . 2009-07-04 19:05 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe
2009-06-30 15:33 . 2009-03-09 19:06 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-30 14:53 . 2009-03-09 19:06 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-30 14:53 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-30 14:53 . 2009-06-30 14:53 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-30 14:53 . 2009-06-30 14:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-30 14:53 . 2009-06-30 14:53 -------- d-----w- c:\program files\Lavasoft
2009-06-28 01:30 . 2009-06-28 01:30 -------- d-----w- c:\program files\Microsoft Silverlight
2009-06-26 02:00 . 2009-06-26 02:00 -------- d-----w- c:\program files\QuickTiming
2009-06-19 02:01 . 2009-06-19 02:01 390664 ----a-w- c:\documents and settings\Amanda\Application Data\Real\RealPlayer\Update\realplayer11gold.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-08 05:46 . 2008-01-10 03:22 4212 ---h--w- c:\windows\system32\zllictbl.dat
2009-07-04 19:58 . 2008-01-19 23:29 -------- d-----w- c:\documents and settings\Amanda\Application Data\Apple Computer
2009-07-04 19:22 . 2009-03-24 01:13 -------- d-----w- c:\program files\Safari
2009-07-04 19:15 . 2008-01-19 23:28 -------- d-----w- c:\program files\iTunes
2009-07-04 19:14 . 2008-01-19 23:26 -------- d-----w- c:\program files\Common Files\Apple
2009-07-04 19:13 . 2008-01-19 23:27 -------- d-----w- c:\program files\QuickTime
2009-06-26 02:00 . 2008-01-10 03:30 65010208 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-26 01:58 . 2009-04-26 21:52 -------- d-----w- c:\documents and settings\Amanda\Application Data\U3
2009-06-22 20:12 . 2008-04-11 21:51 -------- d-----w- c:\documents and settings\Amanda\Application Data\LimeWire
2009-06-15 14:15 . 2007-10-04 20:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-12 18:48 . 2008-01-10 03:30 855908 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-11 06:18 . 2008-09-15 22:35 1915520 ----a-w- c:\documents and settings\Amanda\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-05 22:37 . 2009-06-05 10:46 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-05 18:42 . 2009-03-24 01:17 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-06-05 18:42 . 2009-01-14 00:06 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-06-01 21:20 . 2009-06-01 21:14 -------- d-----w- c:\program files\Rhapsody
2009-05-22 01:40 . 2009-05-22 01:40 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-07 15:32 . 2007-04-17 20:24 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-29 04:56 . 2007-04-17 20:24 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2007-04-17 20:24 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2007-04-17 20:24 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2007-04-17 20:24 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-01-30 22:18 . 2008-01-27 03:05 88 --sh--r- c:\windows\system32\A5B1C70534.sys
2009-01-30 22:18 . 2008-01-08 07:23 4026 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2006-10-23 06:24 . 2006-10-23 06:24 620152 c:\program files\Adobe\Acrobat 8.0\Acrobat\bak\Acrotray.exe

2007-04-17 20:24 . 2007-03-09 17:52 172032 c:\program files\Apoint2K\bak\Apoint.exe

2006-09-27 21:32 . 2008-01-19 21:45 2321600 c:\program files\Common Files\Adobe\Updater5\bak\AdobeUpdater.exe

2007-02-21 18:17 . 2007-02-21 18:17 970752 c:\program files\Intel\Wireless\Bin\bak\ifrmewrk.exe

2007-02-21 18:19 . 2007-02-21 18:19 819200 c:\program files\Intel\Wireless\Bin\bak\ZCfgSvc.exe

2007-01-31 04:59 . 2007-01-31 04:59 371712 c:\program files\Intuit\SimpleStartEntice\bak\entice.exe

2008-01-15 11:22 . 2008-01-15 11:22 267048 c:\program files\iTunes\bak\iTunesHelper.exe
2009-06-05 20:39 . 2009-06-05 20:39 292136 c:\program files\iTunes\iTunesHelper.exe

2007-04-17 23:28 . 2006-05-03 09:56 36975 c:\program files\Java\jre1.5.0_07\bin\bak\jusched.exe

2006-02-23 01:10 . 2006-02-23 01:10 1354240 c:\program files\Protector Suite QL\bak\menusw.exe

2008-01-10 23:27 . 2008-01-10 23:27 385024 c:\program files\QuickTime\bak\qttask.exe
2009-05-27 00:18 . 2009-05-27 00:18 413696 c:\program files\QuickTime\QTTask.exe

2007-04-17 23:16 . 2004-02-20 21:12 32768 c:\program files\Sony\ISB Utility\bak\ISBMgr.exe

2007-04-17 23:43 . 2007-03-26 23:17 217088 c:\program files\Sony\VAIO Power Management\bak\SPMgr.exe

2007-04-18 17:39 . 2007-04-17 00:00 2322432 c:\program files\Sony\VAIO Security Center\bak\VSC.exe

2007-04-18 16:51 . 2007-02-05 18:22 546936 c:\program files\Sony\VAIO Update 3\bak\VAIOUpdt.exe

2007-10-04 20:13 . 2007-01-24 04:46 176128 c:\program files\Sony\Wireless Switch Setting Utility\bak\Switcher.exe

2007-04-17 23:28 . 2003-04-20 04:08 28672 c:\windows\SONYSYS\VAIO Recovery\bak\PartSeal.exe

2007-04-17 20:24 . 2006-02-28 11:00 15360 c:\windows\system32\bak\ctfmon.exe
2007-04-17 20:24 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe

2007-04-17 20:24 . 2007-04-05 20:03 162584 c:\windows\system32\bak\hkcmd.exe

2007-04-17 20:24 . 2007-04-05 20:03 138008 c:\windows\system32\bak\igfxpers.exe

2007-04-17 20:24 . 2007-04-05 20:04 138008 c:\windows\system32\bak\igfxtray.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Amanda\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-06 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [N/A]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [N/A]
"Persistence"="c:\windows\system32\igfxpers.exe" [N/A]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [N/A]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [N/A]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [N/A]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [N/A]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [N/A]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [N/A]
"VAIOSecurity"="c:\program files\Sony\VAIO Security Center\VSC.exe" [N/A]
"Biomenu"="c:\program files\Protector Suite QL\menusw.exe" [N/A]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [N/A]
"QuickBooks Simple Start"="c:\program files\Intuit\SimpleStartEntice\entice.exe" [N/A]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [N/A]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-11-15 919016]
"FixCamera"="c:\windows\FixCamera.exe" [2007-02-10 20480]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-13 198160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"WinBlueSoft"="c:\program files\WinBlueSoft Software\WinBlueSoft\WinBlueSoft.exe" [N/A]

c:\documents and settings\Amanda\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-2-2 2756608]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2006-11-29 968224]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-02-23 01:11 39936 ----a-w- c:\windows\system32\fusstub.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-12-28 23:54 73728 ----a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli fusstub

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/30/2009 7:53 AM 64160]
R0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\drivers\shpf.sys [4/17/2007 1:25 PM 14720]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [1/11/2008 5:50 PM 30312]
R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [2/22/2006 6:13 PM 13440]
R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [2/22/2006 6:13 PM 33024]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [4/17/2007 1:24 PM 36352]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [4/17/2007 1:24 PM 808448]
S2 gupdate1c996349d4f067c;Google Update Service (gupdate1c996349d4f067c);c:\program files\Google\Update\GoogleUpdate.exe [2/23/2009 9:01 PM 133104]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 951632]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [4/17/2007 1:25 PM 31104]
.
Contents of the 'Scheduled Tasks' folder

2009-06-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]

2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:34]

2009-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 04:01]

2009-07-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 04:01]

2009-07-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1624432084-341411213-1424645306-1008.job
- c:\documents and settings\Amanda\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-06 01:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &Search - https://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm553YYUS
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Amanda\Application Data\Mozilla\Firefox\Profiles\jcszaftf.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-07-07 23:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1252)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
c:\windows\system32\biologon.dll
c:\program files\Protector Suite QL\homepass.dll
c:\program files\Protector Suite QL\passport.dll
c:\program files\Protector Suite QL\BhTcAll.dll
c:\program files\Protector Suite QL\BhDevTfm.dll
c:\program files\Protector Suite QL\AlgVer.dll
c:\program files\Protector Suite QL\TCBioLib.dll
c:\program files\Protector Suite QL\remote.dll
c:\windows\system32\VESWinlogon.dll
c:\program files\Protector Suite QL\config.dll

- - - - - - - > 'lsass.exe'(1308)
c:\windows\system32\fusstub.dll
c:\program files\Protector Suite QL\infra.dll
c:\program files\Protector Suite QL\homefus.dll
.
Completion time: 2009-07-08 23:08
ComboFix-quarantined-files.txt 2009-07-08 06:08

Pre-Run: 34,877,349,888 bytes free
Post-Run: 34,831,179,776 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

983 --- E O F --- 2009-06-15 14:15
Posted 7/8/2009 10:59 AM
#74961
User avatar

Touch Advanced member

Date Joined Nov 2016
Total Posts: 12974
Hello CherylS




Download this program: https://www.ctrlaltdel.dk/Fix_download.exe

and save it on the desktop. Then double click on it (Fix_download.exe).

You may have to allow the program to download files from the web!

The program download the necessary cleaning programs. Once the program
is downloaded, there will be a folder on your desktop named
Fix. – if the instructions not automatically opens, so
double-click "FIX_manual.htm" in Fix folder.

Please follow the instructions and copy the logs, in your own new Topic.


Note : Fix_download.exe is detected by some antivirus programs as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


[color=black face="Courier New" sab="311">[2]Click here: Before-posting-a-log[/2][/url]

<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" />[/color]
Do not PM me with logfiles. They will be deleted.


  • Unread posts or replies
  • No unread posts or replies
  • Unread Posts (Read Only Forum)
  • No Unread Posts (Read Only Forum)

Forum Information

Currently it is Saturday, July 2, 2022, 12:24 PM (GMT +2)
There are a total of 61,974 posts in 13,697 threads.
In the last 3 days there were 0 new threads and 0 reply posts.

Who's online

This forum has 38,684 registered members. Please welcome our newest member, james44.
49 Guest(s), 0 Registered Member(s) are currently online.