Beste mensen,
Op deze zonnige zaterdag heb ik maar eens besloten om iets te doen aan mijn computer. Zo verschijnen er tijdens het browsen (in Firefox) continue pop-ups, verstuur ik blijkbaar via MSN (wat ik tijden geleden al van mijn computer af heb gegooid) de welbekende spam berichtjes, en ook via mijn hotmail is er al een spam-mail naar mijn hele adreslijst gestuurd.
Kortom, tijd om er iets aan te doen. Ik heb de 11 stappen ondernomen die beschreven staan op deze website en hierbij dan mijn logjes. Kan iemand mij verder helpen, of is dat wellicht niet meer nodig?(ik heb er niet zoveel verstand van…)
Mijn dank is groot!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:48, on 30-5-2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {03846DF8-1D85-4B6C-8180-01AC6D367904} - (no file)
O2 - BHO: (no name) - {07EBEC2A-7230-419C-BA45-19B96D6B55AD} - (no file)
O2 - BHO: (no name) - {0FCF22E1-E6D5-4726-A518-38FB4CDB71F0} - C:\WINDOWS\system32\nnnlmMgf.dll (file missing)
O2 - BHO: (no name) - {1B7D0A67-890F-4431-9EC3-1F80EAF3674D} - (no file)
O2 - BHO: (no name) - {4426BF2F-35E8-41F1-A7A2-0C6AE6D24455} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E18FB6B-057E-4BB5-BC90-1AC2A71083FE} - (no file)
O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90637898-4422-4048-AA2A-00422D01C7FF} - C:\WINDOWS\system32\geBttSij.dll (file missing)
O2 - BHO: (no name) - {A71483CC-C8E6-41C6-AFE3-E24356F8C715} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: (no name) - {CDB6F941-003D-42BC-BF5D-C28E63E69FFB} - (no file)
O2 - BHO: (no name) - {ea9e7ccd-67be-45d1-8278-93dd5ad78ef1} - (no file)
O2 - BHO: (no name) - {FBFD382A-AC6E-4EB7-8944-F97D358B378D} - (no file)
O2 - BHO: (no name) - {FC598582-8386-4ABB-9F87-DC3DD7AAFAFB} - C:\WINDOWS\system32\yayvUOij.dll (file missing)
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: “C:\Program Files\Analog Devices\SoundMAX\smax4.exe” /tray
O4 - HKLM\..\Run: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: “C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe” /startup
O4 - HKLM\..\Run: C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: “C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe”
O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: nwiz.exe /install
O4 - HKLM\..\Run: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”
O4 - HKLM\..\Run: “C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe”
O4 - HKLM\..\Run: “C:\Program Files\ESET\ESET Smart Security\egui.exe” /hide /waitservice
O4 - HKLM\..\Run: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: “C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe” -atboottime
O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”
O4 - HKLM\..\Run: “C:\Program Files\Winamp\winampa.exe”
O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background
O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User ‘LOCAL SERVICE’)
O4 - HKUS\S-1-5-20\..\RunOnce: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User ‘NETWORK SERVICE’)
O4 - HKUS\S-1-5-18\..\RunOnce: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User ‘SYSTEM’)
O4 - HKUS\.DEFAULT\..\RunOnce: rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User ‘Default user’)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra ‘Tools’ menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {34DC6011-88B5-4EA9-BA7A-DC7B4F4437FE} (JordanUploader Class) - http://foto.hema.nl/ips-opdata/layout/hema/objects/jordan.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://hema.nl/xupload/XUpload.ocx
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: prio.dll C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL tgrepk.dll cqioye.dll baampi.dll pumcoo.dll mhffdl.dll
O20 - Winlogon Notify: qoMeFuvW - C:\WINDOWS\
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PDExchange - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDExchange.exe
O23 - Service: RMWPService - Apache Software Foundation - C:\Program Files\Reference Manager 12 Demo\WebPublisher\thirdparty\Apache2\bin\RMWP_Apache_Admin.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
–
End of file - 11846 bytes
Malwarebytes' Anti-Malware 1.37
Database versie: 2195
Windows 5.1.2600 Service Pack 2
30-5-2009 10:47:30
mbam-log-2009-05-30 (10-47-30).txt
Scan type: Snelle Scan
Objecten gescand: 81419
Verstreken tijd: 4 minute(s), 10 second(s)
Geheugenprocessen geïnfecteerd: 0
Geheugenmodulen geïnfecteerd: 3
Registersleutels geïnfecteerd: 13
Registerwaarden geïnfecteerd: 4
Registerdata bestanden geïnfecteerd: 6
Mappen geïnfecteerd: 0
Bestanden geïnfecteerd: 85
Geheugenprocessen geïnfecteerd:
(Geen kwaadaardige items gevonden)
Geheugenmodulen geïnfecteerd:
C:\WINDOWS\system32\pwiibd.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMeFuvW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tuvWmJda.dll (Trojan.Vundo) -> Delete on reboot.
Registersleutels geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63a94501-30e6-4095-adec-ee6e4b480284} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63a94501-30e6-4095-adec-ee6e4b480284} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fbfd382a-ac6e-4eb7-8944-f97d358b378d} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomefuvw (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{fbfd382a-ac6e-4eb7-8944-f97d358b378d} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4426bf2f-35e8-41f1-a7a2-0c6ae6d24455} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{4426bf2f-35e8-41f1-a7a2-0c6ae6d24455} (Trojan.BHO.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{61a8d553-a08f-4224-817a-c2b875d0aaa0} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63a94501-30e6-4095-adec-ee6e4b480284} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{fbfd382a-ac6e-4eb7-8944-f97d358b378d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4426bf2f-35e8-41f1-a7a2-0c6ae6d24455} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registerwaarden geïnfecteerd:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{61a8d553-a08f-4224-817a-c2b875d0aaa0} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{61a8d553-a08f-4224-817a-c2b875d0aaa0} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{fbfd382a-ac6e-4eb7-8944-f97d358b378d} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
Registerdata bestanden geïnfecteerd:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\tuvwmjda -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Mappen geïnfecteerd:
(Geen kwaadaardige items gevonden)
Bestanden geïnfecteerd:
C:\WINDOWS\system32\pwiibd.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\qoMeFuvW.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\tuvWmJda.dll (Trojan.BHO.H) -> Delete on reboot.
c:\WINDOWS\system32\couwdtnf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\aquwngwh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\djkcpisk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\djwrhe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\fvijjt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\gcmbhewj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\lolwcykk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\lsyrnupm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\nyiahimk.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\ocewkg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\vnvcim.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\vrvbdjbs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\baxxxcpa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\beovhjex.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\dnqggh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\dvdofz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\gvqofi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\gywxwp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\hlqgji.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\kgvccq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\kuydmgrp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\lbpbbwvx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\ldvwgdjx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\pxnhfqbr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\qnmcxhki.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\rursqqnc.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\rypcielx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\shhrtu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\skuqvr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\sppmzr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\suqddq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\tlfqkwes.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\wlsabowf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jevtmndv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\onhynkor.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\orobxsck.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\otpedx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\owloakir.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\oyjvdf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\worypemq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\acsqpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\amtcqz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\bnowlqfa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\cammrtrc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\dyhbuo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\ecajfe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\inldoh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\nfxlvh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\nmkrkwna.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\noekag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\webkxl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\hswuyatk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jkffqykp.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jkgpfu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jostlt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\imjwpssf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mvnwix.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mvxinaui.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\qqcjsn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\qxjtfvim.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xdbgdgag.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\diilbnyb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\rklimz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\pqoxfsgd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xspeea.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xttwod.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\xvfnuawa.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\yabdhv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\ylmjsvbf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\zqapmi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\zrcuff.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\frsvedwa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jtcqtjxy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\jyggrlys.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\sxkveh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\tojkxujs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\trdiss.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\serauth2.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hktage.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\dumckmox.dll (Trojan.Vundo) -> Quarantined and deleted successfully.