Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Trojan Again!!!.. and again... and again...

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Trojan Again!!!.. and again... and again...

Unread postby Ryuji35 » April 12th, 2006, 2:41 am

I can't believe after just a few days of trojan-free life, here they are again!! Now, it's something called SVCHOST.exe, and a virus called sk0.exe (not sure) ................ and I can see NETwork Monitor anagin and Spoolsv :twisted: :twisted: :twisted: :evil: :evil: :evil: :evil: :evil:

oh well, here's my log!!!!!


Logfile of HijackThis v1.99.1
Scan saved at 2:45:24 PM, on 4/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\windows\mousepad10.exe
C:\Program Files\Common Files\Windows\services32.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\aG9tZQ\command.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasServAlert.exe
C:\Program Files\HighjackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mousepad] c:\windows\mousepad10.exe
O4 - HKLM\..\Run: [keyboard] c:\windows\keyboard10.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [E06ADXRC_3471343] "C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE" -m
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 6136860062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7990772500
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://activex.microsoft.com/controls/i ... iemenu.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lob ... ttings.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\aG9tZQ\command.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Windows Service Drivers (svcservice) - Unknown owner - C:\WINDOWS\svchost.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia
Advertisement
Register to Remove

Unread postby agrarianmonk » April 12th, 2006, 3:18 am

Hi again,

I'm checking your log and will be back as soon as I research all of the items.
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby agrarianmonk » April 12th, 2006, 11:10 am

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby Ryuji35 » April 12th, 2006, 11:52 am

I've done a scan with Ewido just this evening, well maybe should want a look (after this my computer calm down, I don't know if this is only temporary). I have saved a report just in case. It's after my uninstall list.

ABC Amber LIT Converter
Adobe Photoshop CS
Adobe Reader 6.0
ccCommon
Chikka (3.0.47)
D-Link DFM-562IS HSFi PCI Modem
ewido anti-malware
FreeStyle Online
GetRight
Gunbound Philippines
HijackThis 1.99.1
hp deskjet 3500
HP Photo and Imaging 2.0 - Deskjet Series
hp print screen utility
Internet Worm Protection
iPod for Windows 2005-09-23
iTunes
LiveReg (Symantec Corporation)
LiveUpdate 3.0 (Symantec Corporation)
Logitech Print Service
Logitech QuickCam
Logitech® Camera Driver
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft AntiSpyware
Microsoft Encarta Premium 2006
Microsoft Office XP Professional with FrontPage
Microsoft Text-to-Speech Engine 4.0 (English)
Nero OEM
Network Monitor
Nokia PC Connectivity SDK 3.0a
Norton AntiVirus 2005
Norton AntiVirus 2005 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton WMI Update
nProtect KeyCrypt
NVIDIA Drivers
Privacy Guardian 4.0
QuickTime
Real Alternative 1.37
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 8 (KB911565)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896426)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905495)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Shareaza version 2.2.0.0
Shockwave
SPBBC
Symantec
Symantec Script Blocking Installer
SymNet
Tantra
Toolbar888
Update for Windows XP (KB835409)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB828741
Windows XP Hotfix - KB835732
Windows XP Hotfix - KB842773
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB883939
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892944
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Hotfix - KB897715
Windows XP Hotfix - KB905915
WinRAR archiver
WinZip
XviD MPEG-4 Codec
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
*************************************************************

Here's my Ewido report:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 10:37:29 PM, 4/12/2006
+ Report-Checksum: 973FBF1E

+ Scan result:

HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj.1 -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
[124] C:\windows\mousepad10.exe -> Hijacker.VB.ly : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GQR1BUVE\keyboard10[1].exe -> Downloader.Adload.am : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GQR1BUVE\nem220[1].dll -> Downloader.Dyfuca : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\HIATUME6\newname10[1].exe -> Downloader.Adload.ae : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N2S2A7JV\mousepad10[1].exe -> Hijacker.VB.ly : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\N2S2A7JV\optimize[1].exe -> Downloader.Dyfuca.ex : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OYZRJ2UD\drsmartload45a[1].exe -> Downloader.Adload.an : Cleaned with backup
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OYZRJ2UD\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000169.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\006C023A-A624-4F42-805C-6EA177.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\00708A6F-28A9-47D9-94B4-57175F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\00C126A3-99A5-4784-BC85-43591C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\01224957-74CD-4291-BE12-7041D1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\01622619-A830-4D73-A387-8FCF75.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\017A8B23-345A-4D15-8C2C-8D02EA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\02F249D1-9703-4078-8C8F-D1A831.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\03ECC030-99D4-4C14-914C-3808DD.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\04145E0C-E742-4958-822D-62056B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\046B4408-0B36-4813-B960-BF3B9A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\04F07CB0-4ED3-4486-BE3D-956BC4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\051D2D67-CE2C-47F2-A96F-8110F9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0551B60A-96BC-4486-BC82-AFC0E2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\05CC8626-A75C-4EFD-B85D-1EC64F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\070057E3-36E4-4057-BCA9-8B65E6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\071D05B0-24E8-415D-9F6B-26979C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\089AB2C7-9DA1-444C-AE30-955AB3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\08A1DC51-7D5B-41D5-A9AE-11BCB0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\08B2C0AB-6DC1-45D8-9B9D-67B397.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\08E4DCC6-EA7D-4FEF-A26B-A0F4D5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\08EF7FB3-06F9-4C15-804F-06867C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0921FC46-23B7-4889-BE05-77A15A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0AC2827C-9DB3-4FED-996E-54EEA0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0B9D8566-A4E7-4CCB-884A-785681.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0BA51D48-948E-4FD8-810F-71322F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0C0D3948-45E0-4E74-8E43-54264A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0C9E6D93-0CE4-4C55-83CB-4BFF61.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0D03108E-31DF-4047-8435-EBAE56.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0D4127C1-3DEE-4C0C-A36D-9785A9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0D95FC13-C98F-457B-8AB2-2CEF72.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0DA24EA4-8369-4B6F-A7F7-276B71.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0DFE2E36-E4F0-45C7-9B4B-289CB0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0E760C79-A527-4DA7-8906-2BC082.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0E9D44DE-E59B-4D12-B2E5-C07931.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0EC982C8-D13D-4F2D-9843-F3B9DA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\0FBA111E-0EBA-459D-9212-01125C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1000B2A4-08A0-4F3B-8F38-836FB3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\10053F94-1BE3-4E53-B8C3-22DC3F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1027D6B8-F846-4EBD-8EBA-98B902.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\102AA96C-58AA-4AFF-A6A3-A62977.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\10432E47-6BDE-4E29-992D-F9AC24.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\107A8B05-A3D0-45AB-AA68-A719B0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\111BED20-392A-462E-9903-DC62C9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1136CC05-2A76-4BCD-BF8C-6F232A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1289A664-C236-4D1E-B6A5-DDA45E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\12CF084B-E603-4A83-AEB7-ADEBCC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\13144488-33CF-4ECC-91FE-6EDD89.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\13DAAE49-81BA-4415-A8D2-E13874.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\142C1051-3201-442F-AFC7-9BF2A3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1529CD99-6933-422B-959F-95392A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\165CCCEF-83A6-478B-A71D-1ADB41.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\16A94233-A6AE-49AF-AC97-6BD437.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\170E102D-D429-458E-994A-58B52B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\174E8732-9B47-45C1-89E3-C5F261.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\17966502-3025-4A08-B59F-21D3E9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1825A771-3968-4073-BFF3-3F8643.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\18AEE01D-EABC-4C18-9BD2-B23910.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\18B96A55-7797-4E65-A592-7DB3D7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\190081D5-EB02-4519-9E7C-34BA78.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\193A70C1-09CD-491B-83AE-9B1E48.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\19400985-21EB-4416-BA90-146C63.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\199B5671-6663-46D4-969D-49C245.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\19A1B469-43BC-4136-AD33-8F13D3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\19E5F2D3-B4DD-4ECF-B0BC-64FCAF.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1A687538-C746-451E-988A-6C71A3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1AD21E5D-436A-46AA-BDC4-7240A3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1B8389A0-90C4-4309-BCFE-9F7739.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1BAB64B6-A5A6-4F8E-9D62-D481CE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1BD76609-BE5A-4099-A425-FAC270.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1C9D5BB8-30E2-4E09-8DFA-6568A2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1CB5D2DF-4CBB-42C0-939C-054BF9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1CE742B6-6CDC-42B5-A54A-DB1DAC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1D12273D-E999-4C78-BD9F-741801.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1D4EC284-41C9-4A7A-B5B0-41ECA3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1E83ECCB-D688-4BB8-9B1E-620021.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1F46F6BE-3C23-4E14-895F-1ADD6D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1F48B2F7-C640-4A2A-AD7D-BF7F36.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\1F8069FD-9026-46DE-861B-52BC5E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\20401B64-2990-4642-9EE6-D80E5E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\20B38A7F-8964-4A3C-8BD9-FAB61A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\21355D99-A44C-4D44-9735-075E84.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2192043B-781E-497F-B78B-FC1DAB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\22293F34-C3C0-48C7-8F0D-7FCEE3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2257CD89-6AB4-453A-A1AB-E6BE0C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\22CA626E-4E96-4D62-94BA-59C108.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\22D87486-18B3-4524-A046-956D0D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\23647C27-1017-410D-A98D-094572.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\23BD6FC2-3C94-4275-992D-32D6D1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2506F7BD-0867-4693-B525-773E61.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2535A980-F7FD-4A83-98C5-DBDEB1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\25B0E26F-97CC-4796-A803-DE6F3B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\25C90315-0593-4387-90FE-F8BA3D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\263A1B45-8608-4707-8B84-8E9884.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\265C9B91-688A-4FF1-9452-D0FC54.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\26A0BFB9-30BC-441C-95E4-27A16A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\26D35220-7DDC-4707-8E1C-6420C3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\26F3A8A3-FB7A-48DD-A218-C800BA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\26FD989B-AF5E-4756-84B0-41849C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\27004281-858F-44D3-AA82-8DDDB5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\27A3E69D-620A-4D75-9288-5CE683.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2881722E-97DF-45E8-BEB6-4B01F7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\28EB5850-98D5-4974-90FD-190B7A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2A9FED99-E073-4F10-85EA-37DF1B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2AF18DAF-B2B7-43C0-AB3F-136E26.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2AFA3105-B6A0-4929-97E2-FD052A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2B28D9E3-2908-40D9-B1D1-9B1358.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2B8B547B-1A47-4FA2-9BD1-BE0A0C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2BA9F1D0-E6E1-4312-9748-88C82F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2BD68CEE-6A55-43B3-A0B9-685721.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2C3BDC53-7593-4AA7-B1CE-3D66A1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2D42B280-F6EE-41DE-9DF6-177F20.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2D6B140F-0F4E-4368-8535-10BD4F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2D771ABD-0599-44DD-8AE7-82E9F4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2E4513A1-B4B8-4630-B233-266E11.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2EC45536-AAAC-41E7-9F63-4FF39D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2ED192A8-327B-4F1D-8A7C-AC42F3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2F1225E0-026E-4DCF-BEEB-D08649.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2FE4D17A-A13E-437C-9CA5-C5BB51.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\2FEF636A-D45A-47B7-8811-E3FCF3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\304C0722-6483-49B5-BD36-82E614.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3057DA4B-C2F8-462A-B5AE-7AE10D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\31AA2146-01AD-430A-8154-2D9822.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\323400D3-3346-489D-861A-D6B71E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3269A988-979C-4391-B0D9-67CDF4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\328B6F0F-9566-4168-A495-BF8F5D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\32ED87D9-C5AE-4D89-A45D-9F72AC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3351F62D-53E3-4FBF-925B-2A3F53.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3394F325-FA64-4FEC-BECA-E61E05.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\341FF4B2-05DC-4C39-A906-74209D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\34301812-E278-4F96-A913-E9C78C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\348562E1-5053-4B4F-BA1A-20B959.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\34917AE1-59BB-4E64-91A5-FB511F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\374AB27E-470E-4B1C-A89C-521022.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\37538AAD-2964-4718-ADC3-B89C65.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\378E38C9-1EB0-482E-A675-347080.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\37B03147-E3AA-44FE-BD29-33C226.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\37DE0E83-07A2-4ABA-A46A-209E04.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\382587C3-1B1B-4A92-9CEB-F5BCE6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\38D93576-C904-4C79-8D3F-9A1F96.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\391DB376-21BB-41D0-AECD-2B0F02.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\39BAE9AD-2802-46D7-B4D0-C13751.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3B4027F3-9E44-4C57-8CB0-569F22.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3B611813-9B39-444E-8880-5DD946.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3BB527FD-0DE8-45F5-B91C-8D965D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3BF958DA-C3C9-4F99-A351-13D2A4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3C075C84-E76A-4509-8EF1-B5E54E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3C14B417-3759-4149-9A54-E89EFE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3C262AEF-CD2C-4C73-BD2B-41E16B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3D34B9AD-818C-4DB8-AE16-C99D55.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3D34CB23-11D1-473D-954C-998CEA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3DEA3761-26EB-47C5-B92E-EF3763.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3DFF051E-D1CA-4C87-BF0E-FCC6F1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3ECC77C9-6644-4115-B6C2-DDD387.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3EE630AA-BE60-46DC-924A-CB1523.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3FAB39BF-4E64-4077-9305-F49AE7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\3FDCBC02-C9E3-44F6-ABAF-479636.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\40061ECE-A7AB-43F1-8151-F598D8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\412B9BE2-D25F-478D-A75C-263699.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4234B128-46A4-4B25-8E85-6F6EEE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\43F5A469-831C-4005-AABE-F8B5BC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\44046ECC-9FA0-47EA-9CFD-C1B68F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\440CE075-CF3B-47A2-A6DA-C81431.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4452CC97-330A-4D47-A4E2-21596B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\447951A3-1905-41D5-8D70-915D0B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\452C91F4-09B6-403B-A9A9-3A91C0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\45A26404-375D-495E-B604-4F5E91.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\45B58BF5-04FD-4721-896B-364423.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\461F2661-F791-4556-9B28-261A1F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\467CB26F-A32F-4B14-9DC5-68DABF.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\46C531AC-5274-405B-82AD-A73D07.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\46CE8596-9BF3-4494-B5BD-8C9208.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\47577247-8109-4866-BCF9-E3AA9D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\47E7EFEA-165D-406A-97E4-9627F2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4874B4CB-6D29-45D0-8088-51EF2F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\48B4F111-A727-47BB-9482-CB7080.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\495F4CD2-696A-49A9-B92B-861F65.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\496435E7-418E-4D44-8BFA-06D5E3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\49BA5FB4-BEB6-4EE1-AC05-C12F82.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4A7D31B7-0A8D-4EAB-9897-FBA1E4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4AA27893-E91D-4429-8452-8D2DF4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4AF690E1-F679-4920-B23A-67F333.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4B67652B-4A45-490E-951F-159C7D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4B8AA0D3-6F85-45C3-9AAA-1E8298.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4BADD58D-E871-4AD9-9C29-DB5814.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4BD2A060-1917-4472-9DA2-7C4FBC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4D356C2F-46C7-44BF-B91C-E837FB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4D62CEBE-C9DB-4F92-83CF-DECF6F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4D9AAB65-F48C-4382-93BA-B33196.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4DD951D3-2396-4ED7-8206-F7ED12.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4DDC9819-95E1-4A72-86B4-74D2FD.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4E9EB3A3-C4F4-4C67-AE10-58E332.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4F06FA55-D0F6-4E77-895D-4C0C4F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\4FCCF1C0-F312-421B-A645-55B689.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5095DDA8-1627-4BCF-8511-676766.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\510E32A4-444B-4BE3-844F-A294D8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\51B7006A-D93D-48A5-A3DA-874984.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\52629B01-F044-4C1E-9ED0-B4B4D3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\52A1AD8A-96C8-4D7C-9081-160DAE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\52B26EF2-F592-49A0-A261-85A741.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5321A146-96D5-4E6E-A0C2-57F74F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\53A5A657-CC40-4BCF-92F3-9B9FC0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\54EA464D-8438-4CE3-B74E-EE45AB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\551D1F51-B610-4938-BE4F-703436.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\553B5CB9-7155-4647-9270-90F69C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\55F38D3D-A521-4D1A-877C-6268DA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\587A4DF5-A180-47F6-A2E9-B07242.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\588E4987-9F5D-4435-8197-D610B1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\58BE162D-1266-4526-A371-827041.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\59550E5B-EAD1-4868-AFD2-EBCCCE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\59862BA0-D6EF-496B-AA05-149509.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\598BF79B-9688-4F78-8E00-412925.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\59EEF072-CB36-4EBA-9A56-45E517.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5A4464B1-EE91-4F04-A511-2D2238.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5ADD08B0-8677-4396-B17E-42F490.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5B02FCEB-6F4E-41D2-8138-2A5AD1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5B29F1E4-8380-4C22-B92E-59370D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5B5544C8-5C7C-4B14-9A11-3C160E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5B680A9B-0025-40AE-9C75-E12812.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5BED41A6-84D8-49DB-8BAA-A730C1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5C1C576D-B934-4F8D-B325-8CD20F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5C57F28E-CCD0-465D-A642-98F6DB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5C5D4C30-E631-4BF4-9395-0B034D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5CD7A32D-8486-4174-B1D4-32C058.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5D1AA0D2-2EE4-4063-A925-059310.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5D398ABA-8C30-4FEA-B143-38DED3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5D5ADC9A-23BE-4835-B63E-EACA71.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5D8C1176-7727-4366-B216-8F24FB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5EF6312B-A8D2-409B-8ED8-5A0232.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5F01B68F-6C53-4048-9371-C17C15.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5F0726E3-F8D6-40D4-B84C-968F6D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5FC99913-0B6F-4889-A586-F9BAD0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\5FDEDD24-9C08-4FDD-9A4D-D36696.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6000C6FD-DEA4-46DA-915B-6BAD1D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\601D9A12-F7CB-4B7A-8204-1835CC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\601F531A-C442-482C-BA31-E802BA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\609D2FD4-A09D-4809-9810-C52CF4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\60F4F886-EF69-4B1C-965D-FE3E44.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\61205B7F-840B-4116-B887-3F2AB6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\61BCB417-BF4E-44CF-A8D2-B2EED6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\61BDC6F5-C7E6-4B6A-9AA7-58FA34.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\62D9BFC1-7F57-40BB-8E46-4B309F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6478B41B-145F-4725-A16F-EDBCDF.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\64FC6DF4-4854-4CAE-B078-0A654A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\65B4C08D-5A5A-4F7F-B937-7EC937.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\65C0C417-AD47-4816-8D26-D401B2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\66311BDD-0D8A-4C25-9C57-0A4A87.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6671C6F7-082D-4263-B38A-2FDD40.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\66788E70-464D-4A42-A618-DDE8FA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6728498F-9EBC-4F49-82E4-CAEB8F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\67441FB4-91B4-4C6F-85AE-9D1E93.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\678D7E96-E3A8-4447-9822-C44E24.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\686682BC-8836-497F-969C-6256B3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\688F7AB5-9A1B-4259-809D-9A0B88.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\68A53E4F-DC84-4365-B5FB-97CF74.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\693525DC-04AD-4244-B63E-611F16.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6995A541-AC58-4094-AE13-8126F8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\69A29EE0-7451-41B3-B288-632F75.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6A6DA4A6-BFBD-418F-B989-B86E3F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6AB2F259-2E39-4379-904D-9AA08E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6B331952-B034-4241-9C88-6BE470.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6BF6CBD7-D04B-4634-9FF4-EF7040.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6BF76FA3-AB51-403E-A7C9-6BBF2A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6C45C1AB-C3D4-4720-A000-35E012.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6C7676A5-CFA9-43BD-9C43-C657F5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6D6392E1-1654-4268-9672-0DC7D4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6DA2BDE6-AAFF-40F3-91E3-C4B94C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6DAC9EBD-1643-443A-8FF9-427593.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6DECF55B-D2C3-4179-8DBE-ECFD1D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6E3C1E33-9662-479C-9A75-5273B1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\6E57FA10-9D05-4030-BFF6-295F96.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\71AACE38-9BCE-4510-9BFA-C37A55.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\71C2BCA0-8E69-4A80-8FF3-70C393.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\71EB8B34-A9C5-4497-91DA-B47778.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\72A3F40D-3573-448B-8A34-33244F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\72E3BE9E-DEE6-4AB7-8190-C24C0B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\72EC1F4D-7375-4040-9472-B26E02.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\72F20809-52B4-45C5-B981-845E4C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\73124DE4-26EF-42DF-BF95-E3F21F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\73188E43-9EB8-44B2-8767-802008.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\73F2D7B1-0FC8-4072-A332-178D6D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\746CF2B9-1227-4820-B15D-F85C1D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7470AC9B-7C2F-4E2B-A81D-84CE8C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\74C1D3C2-8D1B-4C71-8AB3-B78FD3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\752ED31C-4E08-4EE5-8FDA-DF288E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\75A565BA-3DE6-4B11-B687-4F8A4D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\76165C05-584A-4DEE-942D-0336CB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\76B193AA-E7AC-4312-934E-616309.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7708B0FA-02A5-4EC0-B950-4E67F5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\770E3B35-A5D4-4FC0-A7DC-ED228F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\77150067-E9F9-4EBC-849E-138878.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\78AD4BDB-CC48-4D15-AFFE-52CE7C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\78AD8D60-450A-411F-BA72-A318DB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\792401CC-EC5F-49EC-B991-F28F55.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\793686E5-5498-4079-9FB6-05E1C7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7B96BAFC-F22A-4BD5-9514-822A69.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7BA55E6D-620F-42D7-B060-BC4D64.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7D63AE14-0C01-466A-98BD-CECA0F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7F527061-3A63-45A5-B83B-B82F2E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7F6761F4-8155-408E-BD8C-8D8627.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7F715192-119E-4DA6-8AC2-6555DB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7F73CA67-32B2-4AAE-BDB2-E5DB20.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7FC5EFD8-5567-4402-979E-C17F88.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\7FE19DB4-FCD7-4A87-A25F-9CAB60.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\80050EAE-5E09-4D07-AFE9-4C92E0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\803D23E3-1086-41C2-A318-66DC6C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\80821FDF-E28A-4223-A867-A662F9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\808A04FF-D4F3-4FA8-9F90-B11250.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8094DE6B-51A4-4795-B167-E8F53E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8144479A-E066-47B8-B426-B02E0F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\81E0ECDF-6BD1-46EA-82B3-481AE5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8203014B-02DE-4CDB-9811-B3CBCC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\823F60F3-665F-4E12-AB50-072940.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\82C6546A-F2A0-4128-AF1C-3BD8AC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\82EE4F65-CDF5-483D-B10B-A9176B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\832CF0F8-2CDD-413E-A59A-145F00.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\835873EB-5D64-47FD-A152-20AE82.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\84254C6F-39C8-4AE3-A835-0D2AAB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8497F2E2-55A6-4373-B99B-6E6C1D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\84D9CBF3-E33B-4330-A2A6-F9E423.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8519A276-9DE0-409D-8083-589C7D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\85B78D1A-6A4F-4DC7-A18C-2435A0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\85E779ED-B80F-4421-A56E-50FC99.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\862AAC11-B222-4477-A17F-FCE4C1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\86576D9F-016A-4D7C-B91B-7DDACE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\870C5A10-AAC7-47CF-910D-BB0B96.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\872BEB4F-CFE5-40A3-8152-2222AA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\87415729-6CBE-4BBB-93ED-757A9D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\87652D98-2C24-4A23-8347-F2AA80.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8795F690-17AF-455B-99EE-368AAE.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\89E24C59-462D-4A2A-A023-109BD6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8A99E58B-27BF-40B8-B7CB-D17A72.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8BC0C2D0-03FA-408B-A313-25FE98.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8C830F62-41E9-4739-97DD-1822B8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8C8CE0E1-0B05-4CD4-958A-F9FA6D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8D16F9E1-9A2B-4942-BD84-A8E74E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8D75DCA8-4D6B-4B58-9A62-263888.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8D9E9ED1-2A22-4BF3-82F7-98A76B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8DDF40AC-EF8A-402A-9150-6FA3DD.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8EB70985-C22D-4CAA-97D4-5E5A04.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8F282F78-69D4-4D88-95EC-CD4E60.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\8F6DAF9F-B374-4AB0-86A1-B7BEE1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9019C7A0-4F2E-436D-8B6A-153C5D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9097669F-D484-4E21-97F0-3C5BA6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\911A0FDE-8534-42E6-9E97-908F03.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9195228A-BAF0-458B-9454-6BB54E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\91D327D8-4D73-4248-9016-421FDD.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\91F5C92A-033E-470B-A8CA-F30DE5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\91FE3E5B-D00C-4422-8B15-A776B3.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9237548E-FF84-4B8C-B819-7DD7B4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\92FC007E-8B0A-4E67-8850-EF9A59.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9316A026-ED64-42CF-8D67-F708AA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\937F37BA-97CD-4537-9567-8A51EA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\93B1E168-1F01-4D7A-A7E1-EE4448.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\94B8B159-606B-4021-8B3C-AFCCB0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\959136A7-99F0-431E-A410-93DABB.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\96912862-41E0-4EEA-8D5F-FFAE59.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\96C11CBD-80B1-4B5C-9A88-FF39CA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\96EA1544-E3E1-4569-8799-4A81C9.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\977640F4-C148-4A4B-9490-B937F1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\98CC29DB-9FB1-4BEC-BE54-7EC7A4.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9A21AE4B-1019-4C84-B7BD-CECA5A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9B1C6B85-DC56-408C-9849-E98F92.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9B7DF028-3AA2-4D95-8FE7-DC8019.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9CEC8B73-C13D-4083-B006-7F435D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9D3EB2F7-3AAD-464D-8B7E-79B84C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9E6E6FA0-C0F4-44B9-8294-8AF92C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9ED56C8E-D0C2-498A-8B17-D2B27F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9EFC565F-9452-4C4A-ABD2-C6E154.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9F034333-CB3E-4A41-B92A-8F8359.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9F4A965F-EA3F-44B8-B609-F2B143.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\9FADC542-44F1-4A22-BAC0-972737.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A00CC9FA-5FC9-4644-BE35-31C7A5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A025179C-1735-4C23-9905-38FC8E.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A090ED64-9C79-4BEF-96C2-56A01A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A1F4E582-DADB-40AC-9DB4-35C8D1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A2721251-6DE8-46F9-85A1-B0ADA1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A289ADEA-1C0C-484C-BED1-601464.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A2AE6BEF-0291-435E-B943-E2AA73.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A32A35D6-3C44-4857-9E90-7FE7C5.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A3543212-160F-47E8-B268-90CF21.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A3AB7D0A-B9C6-4D3E-BFB0-8131D8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A3CD3945-CF49-446E-9843-396C9C.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A3DADB96-2DC3-45C5-ABE8-A0CFF0.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A42209CD-4EB6-43E9-B7EC-24E3A2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A4301FD5-9DF4-46D7-9350-291C18.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A48EF0B2-D33D-4188-AACF-FF9F12.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A4B966DE-FCC9-4478-BAF3-1DA3E1.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A52FF806-AD23-46C3-9916-6DBC23.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A5749878-09A6-4EE3-8F74-15A643.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A63EB37D-914D-4593-A228-D8C64F.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A6F5713A-3FA1-4C04-B395-861C80.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A78F9988-B624-475A-B583-8E17B7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A7A4FB6D-889E-41F6-A340-8CDFFA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A7A56F87-8177-4B2C-ACA1-957F66.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A7C02226-2348-4A22-BE40-18C151.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A8088B70-C67F-47C1-A5A0-FA4670.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A92CE836-D077-40F5-A9ED-482A6A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A92EE02E-E518-4AF5-B654-200034.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\A939B24A-87A7-4973-8636-B4D57D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AA12DC29-FA2A-4142-A03B-E27102.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AA33F64B-F432-467A-B5D7-9F946D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AB525A03-2530-4883-88A8-2B5CC6.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\ABAFF36E-4FCD-4133-B383-3F25B7.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\ABF228A2-7E7A-4536-936B-E8BF1A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AC47F914-3AC6-4D9E-A7BC-332B8D.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AC7DF87B-F378-43F0-B43F-06F50B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AE57B5C6-98F3-41CE-BB6E-222D6B.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AE8E4D1B-3EA2-4B1A-98DE-7C0CDC.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AF6709D7-526B-4D99-8115-373650.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AFA5BD17-F7EB-4B87-A9C6-737FEF.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\AFFD0465-C1C6-4A4F-8D46-151458.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B00F9BA9-9889-473C-87F1-2230A2.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B0769079-FCA1-43E9-9775-2B6ACF.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B094EE47-1F99-4C77-A8B2-9501AA.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B15A2ED5-0EFA-47E7-94B6-E4A990.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B23FBD72-4C56-4613-BF6E-E39030.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B2BD4E70-74B1-4723-A848-2F5F2A.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B2D211DA-E750-47AF-9C6A-86ADD8.asq -> Backdoor.SdBot.xd : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\B2E6B5C9-394C-474C-8448-F88DE7.asq ->
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby agrarianmonk » April 12th, 2006, 11:21 pm

Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Toolbar888
Network Monitor


Shareaza version 2.2.0.0
*Shareaza is optional; however, any time you are running any type of P2P application, you are much more prone to infection by malware. I suggest you remove it.
(filesharing is likely the reason you got reinfected)

I did not recognize the following programs: if you or someone else did not purposely install them, please also remove:

Tantra

*******************************

1. I notice you already have Ewido Anti-Malware installed:
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Then click on Start Update.
  • The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates

2. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping F8 until a menu appears. Highlight Safe Mode and hit enter.

4. Once in Safe Mode, Open Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • You will be prompted to clean the first infection.
  • Select "Perform action on all infections", then proceed.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close ewido anti-malware.

5. Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • In the scriptline to execute field type or paste c:\bfu\alcanshorty.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Reboot into normal windows and post the contents of Ewido text report that you saved and a new HiJackThis log.

***********************************
Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

in your next post, please include:
  • ewido log
  • panda scan
  • new hijackthis log


(please use separate posts to ensure the logs don't get cut off)
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby Ryuji35 » April 13th, 2006, 4:33 am

Hi,

I've done what you've told me except these:


>>Toolbar888

I can't remove it. everytime I click this, nothing happens. even an error message won't appear. It just stays there :( :(

>>Network Monitor

This time i was given an error message. it says that a script error. Missing file: "C:\windows\uninstall_nvmon.vrb" (I hope i've typed correctly) so it also stays there.


About Tantra, it's an online game here run by ABS-CBN TV network so it's completely Okay.

I'll ask my sister about Shareaza. I know that it wasn't access for 2 and a half weeks so I know that the virus did not came in there. but my suspicions was Yahoo! Messenger because everytime my mom use it, these viruses attack (although maybe its just a coincidence)


AND about Panda activeScan. It gives me the same error as kaspersky. There is no window everytime I click the "scan my PC" so I gave it up... :(

the following posts are my logs:
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby Ryuji35 » April 13th, 2006, 4:34 am

Logfile of HijackThis v1.99.1
Scan saved at 4:26:22 PM, on 4/13/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\HighjackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard10.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [E06ADXRC_3471343] "C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE" -m
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 6136860062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7990772500
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://activex.microsoft.com/controls/i ... iemenu.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lob ... ttings.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\aG9tZQ\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Windows Service Drivers (svcservice) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby Ryuji35 » April 13th, 2006, 4:36 am

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 4:20:06 PM, 4/13/2006
+ Report-Checksum: 50D723EC

+ Scan result:

HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Adware.MoneyTree : Error during cleaning
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj.1 -> Adware.MoneyTree : Error during cleaning
C:\Documents and Settings\home\Cookies\home@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\home\Cookies\home@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup


::Report End

Thanks :)
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby agrarianmonk » April 13th, 2006, 9:50 pm

Please download the Killbox by Option^Explicit and Save it to your desktop.

Note: In the event you already have Killbox, this is a new version that I need you to download.

Some security programs with active monitoring processes are known to interfere with automatic scanners and can actually prevent HJT fixes from taking effect.

Please turn off or disable any of the following programs you may have,

MS AntiSpyware

Right-click on the Microsoft Anti-Spyware icon in the system tray again to open Microsoft Anti-Spyware.

1. Click on the Options menu and choose Settings.
2. In the left pane column click on "Real Time Protection".
3. Under Startup Options, uncheck "Enable (MSAS) Security Agents on startup (recommended)"
4. Under Real-time spyware threat protection, uncheck and "Enable real-time spyware threat protection" (recommended).
5. Click the Save button and close Microsoft AntiSpyware.

Finally, right-click on the MSAS icon in the system tray and select "Shutdown Microsoft Antispyware".

**********************
  • Copy the contents of the Quote Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DyFuCA_BH.BHObj]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DyFuCA_BH.BHObj.1]



Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

*********************

1. Go to Start > Run and type Services.msc then hit Ok
Scroll down and find the below service:

Command Service (cmdService)

2. When you find it, double-click on it. In the next window that opens, under the General tab click the Stop button, then click the drop-down box to change the Startup Type to Disabled. Now hit Apply and then Ok.

Repeat steps 1-2 for the following service:

Windows Service Drivers (svcservice)


3. Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard10.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\aG9tZQ\command.exe (file missing)
O23 - Service: Windows Service Drivers (svcservice) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Now close all windows other than HiJackThis, then click Fix Checked.

4. Still in HijackThis, click on the Config button (bottom right), click on Misc Tools, then click on Delete an NT Service. A window will pop up. Enter the below item into that field (make sure there are NO spaces before or after the name):

cmdService

Click OK.

5. It should pull up information about the service, then ask if you want to reboot. Click NO.

Repeat steps 4-5, but input the following:

svcservice.

Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

**********************

  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • End Explorer Shell While Killing File
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\WINDOWS\svchost.exe
    C:\WINDOWS\aG9tZQ\
    C:\windows\keyboard10.exe

  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).

If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

*************************************

After the Reboot, let's try a online Java Antivirus Scan:

TrendMicroâ„¢ HouseCall Java Scan
  • Please go HERE to run the Trend Microâ„¢ HouseCall Scan.
  • Click Scan now. It's free!
  • Read and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • Under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.

In your next post, please include:
  • trend micro scan log
  • new hijackthis log
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby Ryuji35 » April 14th, 2006, 7:14 am

I've done everything you said.

TrendMicro WORKS on my computer!!! :D :D the problem is, it keeps telling me that I have got a very slow connection so it will take 4-5 hours to scan and download the components (I've got 31.2 kbps) but I am having my 384 kbps connection either tomorrow or on Monday (because it is Holy Week in here that causes the connection delay) so if you could please wait, I'll post the log either tomorrow or until monday....


I have checked my Task Manager. here, I saw many svchost.exe running. I also saw spoolsv.exe there. I've tried to end all the processes but my computer starts to reboot evrytime I try. and there they are again.
Is that okay? (just thought to report: :)

The following post is my HJT log:
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby Ryuji35 » April 14th, 2006, 7:15 am

Logfile of HijackThis v1.99.1
Scan saved at 7:14:51 PM, on 4/14/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\carpserv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
C:\Program Files\Common Files\Nokia\Services\ServiceLayer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\HighjackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/def ... .yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Encarta Web Companion Helper Object - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Common Files\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [E06ADXRC_3471343] "C:\Program Files\Microsoft Encarta\Encarta Premium 2006\EDICT.EXE" -m
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid= ... lcid=0x409
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 6136860062
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7990772500
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://activex.microsoft.com/controls/i ... iemenu.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lob ... ttings.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe (file missing)
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby agrarianmonk » April 14th, 2006, 12:10 pm

I have checked my Task Manager. here, I saw many svchost.exe running. I also saw spoolsv.exe there. I've tried to end all the processes but my computer starts to reboot evrytime I try. and there they are again.
Is that okay? (just thought to report: Smile


Having multiple instances of svchost.exe and spoolsv.exe is normal and not something to be worried about. if you'll notice, both svchost.exe and spoolsv.exe are running from you c:\windows\system32 folder, which is indicates that they are legitimate files made by microsoft. the reason you system reboots everytime you end task them is because those files are necessary for the stability of your computer.

i'll await the results of the trend micro scan.
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby Ryuji35 » April 16th, 2006, 11:12 am

Hi! sorry for the delay....

I have finished scanning trendMicro, but there is no log that appears? where is the log? I'll just try to write everything the "result Page" says

Ive got "WORM_SDBOT.JB" (this was the one that the trendmicro cannot delete automatically) that is all

for detected Vulnerabilities, I'll post it next:
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby Ryuji35 » April 16th, 2006, 11:13 am

(MS02-072) Unchecked Buffer in Windows Shell Could Enable System Compromise (329390)




Vulnerability Identifier: CAN-2002-1327
Discovery Date: Dec 18, 2002
Risk: Critical
Vulnerability Assessment Pattern File: 008
Affected Software:
Microsoft Windows XP Home Edition
Microsoft Windows XP Media Center Edition
Microsoft Windows XP Professional
Microsoft Windows XP Tablet PC Edition

Description:

This vulnerability enables a remote attacker to execute arbitrary code by creating an .MP3 or .WMA file that contains a corrupt custom attribute. This is caused by a buffer overflow in the Windows Shell function in Microsoft Windows XP.
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia

Unread postby Ryuji35 » April 16th, 2006, 11:13 am

(MS03-001) Unchecked Buffer in Locator Service Could Lead to Code Execution (810833)




Vulnerability Identifier: CAN-2003-0003
Discovery Date: Jan 22, 2003
Risk: Highly Critical
Vulnerability Assessment Pattern File: 008
Related Malware: AGOBOT FAMILY, WORM_GAOBOT.AC, WORM_MUMU.C, WORM_NACHI.B, WORM_NACHI.C, WORM_NACHI.D, WORM_NACHI.F, WORM_NACHI.G, WORM_NACHI.I, WORM_NACHI.K, WORM_RBOT.AA, WORM_RBOT.AB, WORM_RBOT.AF, WORM_RBOT.BZ, WORM_RBOT.R, WORM_RBOT.TW, WORM_RBOT.W, WORM_RBOT.WU, WORM_SDBOT.BV, WORM_SDBOT.DZ, WORM_SDBOT.FB, WORM_SDBOT.FC, WORM_SDBOT.FD, WORM_SDBOT.FE, wORM_SDBOT.FQ, WORM_SDBOT.G, WORM_SDBOT.GO, WORM_SDBOT.IG, WORM_SDBOT.IY, WORM_SDBOT.JG, WORM_SDBOT.JS, WORM_SDBOT.JY, WORM_SDBOT.K, WORM_SDBOT.KY, WORM_SDBOT.M, WORM_SDBOT.ZY, WORM_SPYBOT.AP, WORM_SPYBOTER.CY, WORM_SPYBOTER.CZ
Affected Software:
Microsoft Windows 2000
Microsoft Windows NT 4.0
Microsoft Windows NT Server 4.0 Terminal Server Edition
Microsoft Windows XP

Description:

This vulnerability enables local users to execute arbitrary code through an RPC call. This is caused by a buffer overflow in the RPC Locator service for Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP.
Ryuji35
Regular Member
 
Posts: 85
Joined: January 15th, 2006, 8:27 pm
Location: Asia
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 53 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware