Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: 300+ viruses. windows installer is missing.  (Read 5310 times)

0 Members and 1 Guest are viewing this topic.

BatchFileBasics

    Topic Starter


    Hopeful

    Thanked: 18
    300+ viruses. windows installer is missing.
    « on: July 13, 2009, 05:24:30 PM »
    so like the tittle says, this computer has more than 300worms, trojans , adware, and others i have 2 / 3 requested logs, cannot install super anti spyware because miexecis missing.

    Windows Xp Professional
    Version 2002.
    SP3
    512 mb of Physical ram.
    intel  Pentium III processor


    so heres the hijackthis:
    Code: [Select]
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:14:55 PM, on 7/13/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
    Boot mode: Normal

    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\Program Files\The Skins Factory\Hyperdesk\Common\HdThemeEnabler.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\windows\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\windows\System32\svchost.exe
    C:\WINDOWS\system32\UTSCSI.EXE
    C:\windows\system32\wscntfy.exe
    C:\windows\explorer.exe
    C:\windows\system32\wuauclt.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    C:\Program Files\McAfee\Common Framework\McTray.exe
    C:\windows\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.imesh.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60001
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60001
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {035EE524-3B69-4721-B8DE-7E5A2ABB7D48} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [RelevantKnowledge] C:\Program Files\RelevantKnowledge\rlvknlg.exe -boot
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKLM\..\Run: [gtsrp] C:\Program Files\gtsrp\gtsrp.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
    O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
    O4 - Startup: taksman.exe
    O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: Identities Editor - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
    O8 - Extra context menu item: RoboForm TaskBar Icon - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
    O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: TaskBar - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
    O9 - Extra 'Tools' menuitem: RoboForm TaskBar Icon - {320AF880-6646-11D3-ABEE-C5DBF3571F51} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComTaskBarIcon.html
    O9 - Extra button: Identities - {45DB34C3-955C-11D3-ABEF-444553540000} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
    O9 - Extra 'Tools' menuitem: Identities Editor - {45DB34C3-955C-11D3-ABEF-444553540000} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComEditIdent.html
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\windows\system32\shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Monopoly/Images/stg_drm.ocx
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {7417F730-7BAB-409E-8BB7-6936D361B869} (MLauncher Class) - http://csweb.netgame.com/yulgang/MLauncher.cab
    O16 - DPF: {7C564BC7-73BD-4750-A90A-8FF2D8C8C64B} (SysInfo Control) - https://secure.cabal.co.kr/cabalweb/Include/SysInfo.cab
    O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Risk/Images/armhelper.ocx
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://chill.comcast.net/Gameshell/GameHost/1.0/OberonGameHost.cab
    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
    O20 - AppInit_DLLs: C:\WINDOWS\System32\dfrgsnap32.dll
    O20 - Winlogon Notify: 9cd717d5619 - C:\WINDOWS\System32\dfrgsnap32.dll (file missing)
    O20 - Winlogon Notify: ssqQkKcy - ssqQkKcy.dll (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe
    O23 - Service: Hyperdesk Theme Enabler (HdThemeEnabler) - The Skins Factory, Inc. - C:\Program Files\The Skins Factory\Hyperdesk\Common\HdThemeEnabler.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: KeenfinderSrch Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\KeenfinderSrch\keenfinder136.exe (file missing)
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: Windows Installer (MSIServer) - Unknown owner - C:\WINDOWS\system32\msiexec.exe (file missing)
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\windows\System32\TuneUpDefragService.exe
    O23 - Service: CLCV0 (UTSCSI) - Unknown owner - C:\WINDOWS\system32\UTSCSI.EXE

    --
    End of file - 12214 bytes
    When the power of love overcomes the love of power the world will know peace - Jimi Hendrix.

    BatchFileBasics

      Topic Starter


      Hopeful

      Thanked: 18
      Re: 300+ viruses. windows installer is missing.
      « Reply #1 on: July 13, 2009, 05:24:50 PM »
      And here is mbam
      Code: [Select]
      Malwarebytes' Anti-Malware 1.39
      Database version: 2421
      Windows 5.1.2600 Service Pack 3

      7/13/2009 3:31:58 PM
      mbam-log-2009-07-13 (15-31-58).txt
      A
      Scan type: Quick Scan
      Objects scanned: 92895
      Time elapsed: 18 minute(s), 8 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 9
      Registry Keys Infected: 38
      Registry Values Infected: 13
      Registry Data Items Infected: 5
      Folders Infected: 28
      Files Infected: 279

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      C:\WINDOWS\Temp\uia6.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\fiaA.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\tha6.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\hia7.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\lia9.tmp (Worm.Parite) -> Delete on reboot.
      C:\Documents and Settings\LocalService\Local Settings\Temp\djaB.tmp (Worm.Parite) -> Delete on reboot.
      C:\Program Files\RelevantKnowledge\rlls.dll (Spyware.Marketscore) -> Delete on reboot.
      C:\WINDOWS\system32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot.
      C:\WINDOWS\system32\__c0034C40.dat (Trojan.Agent) -> Delete on reboot.

      Registry Keys Infected:
      HKEY_CLASSES_ROOT\bndshell3.bho (Adware.AdBand) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\bndshell3.bho.1 (Adware.AdBand) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\imeshmediabar.stockbar (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\TypeLib\{6c380604-92b2-4633-becb-bde03fa45980} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{4481c34a-10df-4c96-92a6-0ef31b6b95d6} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{f9c23cd1-6da9-4e0b-8367-c6f9f1f78baf} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\imeshmediabar.stockbar.1 (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\imon.tieadvbho (Trojan.BHO) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\AppID\{8d71eeb8-a1a7-4733-8fa2-1cac015c967d} (Adware.BHO) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d032570a-5f63-4812-a094-87d007c23012} (Trojan.BHO) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227d9c-0efe-4f8a-aa55-30386a3f5686} (Adware.ISTBar) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{875a1348-7674-42aa-adac-b4f36a004a2d} (Adware.AdBand) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\relevantknowledge (Spyware.Marketscore) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0034c40 (Trojan.Vundo) -> Delete on reboot.
      HKEY_CLASSES_ROOT\AppID\Sidebar.dll (Adware.BHO) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\superiorads (Adware.BHO) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\QdrDrive (Adware.ISM) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831} (Adware.RelevantKnowledge) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Adware.BHO) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{8e015787-b1e3-404a-95de-3e71e1fa0305} (Adware.BHO) -> Quarantined and deleted successfully.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{41c29b07-6f91-4966-91be-2e2841643c83} (Adware.Adssite) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{94bc3d1d-22e9-4744-8ed1-3e08a3b74078} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Salestart (Rogue.Multiple) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cp-kr (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cp-kr (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spa_start (Adware.BHO) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f46d9732.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f10891a37.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\a00f19f0ae.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SystemManger (Trojan.Downloader) -> Quarantined and deleted successfully.

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Data: c:\windows\system32\mpk\mpk.exe -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Data: system32\mpk\mpk.exe -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Trojan.Agent) -> Data: c:\windows\config\csrss.exe -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe C:\WINDOWS\Config\csrss.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Bad: (c:\windows\system32\userinit.exe,C:\WINDOWS\system32\MPK\MPK.exe) Good: (Userinit.exe) -> Quarantined and deleted successfully.

      Folders Infected:
      C:\Program Files\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Start Menu\Programs\RelevantKnowledge (Spyware.Marketscore) -> Quarantined and deleted successfully.
      C:\Program Files\RelevantKnowledge (Spyware.Marketscore) -> Delete on reboot.
      C:\Program Files\QdrDrive (Adware.AdBand) -> Quarantined and deleted successfully.
      C:\Program Files\QdrModule (Adware.ISM) -> Quarantined and deleted successfully.
      C:\Program Files\Advantage (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{A89AED22-9133-424c-88E7-C8235C5FF302} (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components (Adware.Advantage) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Mark Cook\Application Data\ErrorSmart (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
      c:\documents and settings\mark cook\application data\errorsmart\Log (Rogue.ErrorSmart) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\MPK (Refog.Keylogger) -> Delete on reboot.
      c:\WINDOWS\system32\MPK\Help (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images (Refog.Keylogger) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Application Data\MPK (Refog.Keylogger) -> Delete on reboot.
      c:\documents and settings\all users\application data\MPK\1 (Refog.Keylogger) -> Delete on reboot.
      c:\documents and settings\all users\application data\MPK\1 (Refog.Keylogger) -> Files: 3666 -> Delete on reboot.
      c:\documents and settings\all users\application data\MPK\2 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\3 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\4 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\CPDA (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\CPDM (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\REFOG Personal Monitor (Refog.Keylogger) -> Quarantined and deleted successfully.

      Files Infected:
      C:\WINDOWS\Temp\uia6.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\fiaA.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\tha6.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\hia7.tmp (Worm.Parite) -> Delete on reboot.
      C:\WINDOWS\Temp\lia9.tmp (Worm.Parite) -> Delete on reboot.
      C:\Documents and Settings\LocalService\Local Settings\Temp\djaB.tmp (Worm.Parite) -> Delete on reboot.
      C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (Adware.SoftMate) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\155.tmp (Worm.P2P) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> Quarantined and deleted successfully.
      c:\documents and settings\localservice\local settings\Temp\cpaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\documents and settings\localservice\local settings\Temp\fpaE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\documents and settings\localservice\local settings\Temp\wiaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\documents and settings\localservice\local settings\Temp\woaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\pbe7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ppj498.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\pwa6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\pyk3CD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\qbu22.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\qep1BA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\qsu17A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\qxx2C1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rdi5EA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rit1C9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\eav231.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\edi68.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\enn3F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\eoj497.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\fbaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\fcg105.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\fna4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\fwd118.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\gia6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ana9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\arp10F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bcl9F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bdd1A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bha5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bqa3.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bwaE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\bwu133.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vru2F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\wkj496.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\wys262.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\wzs263.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xcg107.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xma2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xms1F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xqcE4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xtaC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xup517.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\xyi5E9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ybe8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yck79.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ydi66.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yfu24.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yla5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ylu132.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yma9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yna2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yth2E5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\yvaD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\zdt1C7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\zmy37.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\zna8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\znaB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\zpt1C6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\lia6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\lku71C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\lqa7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\lqcE6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mdp1B8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mma3.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mou719.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mqa6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mtaB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mxl137.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\mya7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\nhaD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\njc25.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\nxn41.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\oba9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\odk3CF.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ofv233.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ohu135.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\oka1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\otaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ots261.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rov726.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rrf4F.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rsu17B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ryu21.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\sad119.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ssa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\sua5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tfi5EB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tha5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tns20.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tun40.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tvp519.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\tzg1EF.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\uew733.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\uhp1BD.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\uqf4D.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\usl135.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\uta4.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\uwl136.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vah2E7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vfw34.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vgv234.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\hgu31.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\hla7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\hzw732.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ibl9E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ibn383.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ico10B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\idi67.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\iep51A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ifn385.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ifw734.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ila1.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ioa9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ipu71B.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\iuaC.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\iyg1ED.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\jclA0.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\jfn384.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\jma8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\jsv727.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\jua6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\kht1C8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\kia5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\kou179.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\kpa2.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\kxe6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\laa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\lbw32.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cea7.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cep51C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cfa8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cgc24.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\abd11A.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\aco10C.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\afu23.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\aia8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\clu71E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cna8.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cta9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ctv728.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cyo109.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\czh2E6.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dev232.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dgn266.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dhp1BB.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dhy35.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dis1E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dma5.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dxaA.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ammB9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\byn267.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\cgr33.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\dyu134.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\grf4E.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\ldk3CE.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\pas264.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\rkc26.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\WINDOWS\Temp\vha9.tmp (Worm.Parite) -> Quarantined and deleted successfully.
      c:\program files\contexttool\ContextHelper.dat (Adware.PlayaZ) -> Quarantined and deleted successfully.
      c:\program files\contexttool\pcre3.dll (Adware.PlayaZ) -> Quarantined and deleted successfully.
      c:\program files\contexttool\uninstall.exe (Adware.PlayaZ) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\start menu\Programs\relevantknowledge\About RelevantKnowledge.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\start menu\Programs\relevantknowledge\Privacy Policy and User License Agreement.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\start menu\Programs\relevantknowledge\Support.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\start menu\Programs\relevantknowledge\Uninstall Instructions.lnk (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\program files\relevantknowledge\rlls.dll (Spyware.Marketscore) -> Delete on reboot.
      c:\program files\relevantknowledge\rloci.bin (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\program files\relevantknowledge\rlph.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\program files\relevantknowledge\rlservice.exe (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\program files\relevantknowledge\rlxf.dll (Spyware.Marketscore) -> Quarantined and deleted successfully.
      c:\program files\QdrDrive\qdrloader.exe (Adware.AdBand) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\advantage.png (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\contents.rdf (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.js (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\overlay.xul (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\content\vssver2.scc (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\overlay.dtd (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\chrome\locale\en-US\vssver2.scc (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\program files\advantage\{a89aed22-9133-424c-88e7-c8235c5ff302}\components\MeMedia_FF.dll (Adware.Advantage) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\French.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\icon_1.ico (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\key.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\libeay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\logstart.vbs (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\loguninstall.vbs (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot.
      c:\WINDOWS\system32\MPK\MPK.exe (Refog.Keylogger) -> Delete on reboot.
      c:\WINDOWS\system32\MPK\Mpk64.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\MpkNetInstall.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\MPKView.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Romanian.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Spanish.lng (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\sqlite3.dll (Refog.Keylogger) -> Delete on reboot.
      c:\WINDOWS\system32\MPK\ssleay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\temp1.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\trial_pro.ini (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\unins000.dat (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\unins000.exe (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\zlib1.dll (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images\english.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images\german.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images\russian.gif (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\key.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\M0000 (Refog.Keylogger) -> Delete on reboot.
      c:\documents and settings\all users\application data\MPK\REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\2\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\2\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\3\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\3\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\4\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\4\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\CPDM\cpfm.bin (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\refog personal monitor\Order now!.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\refog personal monitor\REFOG Personal Monitor on the Web.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\refog personal monitor\REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
      c:\documents and settings\all users\application data\MPK\refog personal monitor\Uninstall REFOG Personal Monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully.
      C:\Program Files\Common Files\ErrorProtector Free\startmon.exe (Rogue.Multiple) -> Delete on reboot.
      c:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
      C:\WINDOWS\Config\csrss.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\__c0034C40.dat (Trojan.Vundo) -> Delete on reboot.
      C:\WINDOWS\system32\superiorads-uninst.exe (Adware.BHO) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\__c0020A9D.dat (Trojan.Agent) -> QuarantineAd and deleted successfully.
      c:\WINDOWS\system32\__c002515C.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\__c00328F9.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\__c00728BE.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\__c008D819.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\WINDOWS\system32\__c00B3F50.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Program Files\Internet Explorer\msn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Program Files\Internet Explorer\ods.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Program Files\Internet Explorer\stm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Program Files\Internet Explorer\iexplorer.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      When the power of love overcomes the love of power the world will know peace - Jimi Hendrix.

      harry 48



        Egghead

      • lay back , relax and chill out
      • Thanked: 129
        • Yes
        • Yes
        • Yes
        • Dribbling Pensioner
      • Certifications: List
      • Experience: Familiar
      • OS: Windows 7
      Re: 300+ viruses. windows installer is missing.
      « Reply #2 on: July 14, 2009, 02:16:03 PM »
      re-run mbam to see if its clean and post the log