Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

ICQ posílá samo viry do CL

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

ICQ posílá samo viry do CL

#1 Příspěvek od poly-filip »

Lidi z mého CL si stěžují že z mého ICQ jim chodí spousta odkazů tak jsem začal hledat a našel jsme pár věcí zde které jsem udělal a posílám log . Předem děkuji za kontrolu

Mám stejný problém s ICQ posílám log z RSIT (je možné že najdete i jiné mouchy ) předem moc děkuji

Logfile of random's system information tool 1.06 (written by random/random)
Run by POLLY at 2010-01-03 17:58:22
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 7 GB (13%) free of 55 GB
Total RAM: 767 MB (35% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:58:23, on 3.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\System32\Ati2evxx.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
C:\WINDOWS.0\system32\svchost.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jucheck.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS.0\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS.0\system32\wuauclt.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Documents and Settings\POLLY.POLY\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\POLLY.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = start.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\POLLY.POLY\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
R3 - URLSearchHook: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PCCBHO.CPCCBHO - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\POLLY.POLY\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O2 - BHO: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O3 - Toolbar: BS Player Toolbar - {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - C:\Program Files\BS_Player\tbBS_1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Soltek] C:\WINDOWS.0\System32\autorun.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS.0\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O9 - Extra 'Tools' menuitem: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS.0\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS.0\system32\ati2sgag.exe
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe

--
End of file - 9762 bytes

======Scheduled tasks folder======

C:\WINDOWS.0\tasks\PCConfidential.job
C:\WINDOWS.0\tasks\RegPowerClean.job
C:\WINDOWS.0\tasks\RPCReminder.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]
PCCBHO.CPCCBHO - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll [2008-04-01 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\POLLY.POLY\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-10-05 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
BS Player Toolbar - C:\Program Files\BS_Player\tbBS_1.dll [2009-11-16 2166296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200]
{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - BS Player Toolbar - C:\Program Files\BS_Player\tbBS_1.dll [2009-11-16 2166296]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-08-12 339968]
"Soltek"=C:\WINDOWS.0\System32\autorun.exe [2001-10-29 61440]
"SunJavaUpdateSched"=C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe [2004-02-22 32881]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-26 85160]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-10-14 49152]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS.0\system32\ctfmon.exe [2004-08-17 15360]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2007-09-18 171464]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-10-09 25623336]
"AdobeBridge"=C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe [2008-08-28 13145448]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]

C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Documents and Settings\POLLY.POLY\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS.0\system32\Ati2evxx.dll [2004-08-12 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4d1073a8-db45-11de-8019-0069000c02d6}]
shell\AutoRun\command - SIDEBAR.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{59ab004f-e7e9-11de-802f-0069000c02d6}]
shell\AutoRun\command - H:\WUDFHOST.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8e8c5abd-e8a8-11de-8031-0069000c02d6}]
shell\AutoRun\command - I:\P4P.EXE


======File associations======

.scr - open - c:\WINDOWS.0\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-01-03 17:58:22 ----D---- C:\rsit
2010-01-03 17:48:25 ----D---- C:\Program Files\Trend Micro
2010-01-03 17:41:24 ----A---- C:\avenger.txt
2010-01-03 17:26:29 ----D---- C:\Avenger
2009-12-25 14:03:05 ----SHD---- C:\found.002
2009-12-23 16:02:05 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2009-12-23 15:56:21 ----D---- C:\Program Files\Adobe Media Player
2009-12-23 15:53:24 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-12-23 15:48:28 ----D---- C:\Program Files\Common Files\Macrovision Shared
2009-12-21 20:32:16 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\BitZipper
2009-12-21 20:32:12 ----D---- C:\Program Files\BitZipper
2009-12-21 20:29:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Winferno
2009-12-21 20:28:13 ----D---- C:\Program Files\Common Files\Winferno
2009-12-21 20:24:26 ----A---- C:\WINDOWS.0\system32\WINUTIL5.DLL
2009-12-21 20:24:26 ----A---- C:\WINDOWS.0\system32\WINLCTL5.DLL
2009-12-21 20:24:24 ----A---- C:\WINDOWS.0\system32\CapiCom.dll
2009-12-21 20:24:23 ----D---- C:\Program Files\Winferno
2009-12-21 18:29:52 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\HPAppData
2009-12-17 21:42:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Canon
2009-12-17 21:33:10 ----D---- C:\Program Files\Canon
2009-12-17 21:18:57 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\HP Product Assistant
2009-12-17 21:18:57 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\HP
2009-12-17 21:18:39 ----D---- C:\Program Files\Hewlett-Packard
2009-12-17 21:18:34 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2009-12-17 21:18:14 ----D---- C:\Program Files\Common Files\HP
2009-12-17 21:17:24 ----DC---- C:\WINDOWS.0\system32\DRVSTORE
2009-12-17 21:17:09 ----D---- C:\Program Files\HP
2009-12-11 15:29:01 ----A---- C:\WINDOWS.0\system32\ptpusb.dll
2009-12-11 15:28:59 ----A---- C:\WINDOWS.0\system32\ptpusd.dll
2009-12-10 17:49:41 ----HDC---- C:\WINDOWS.0\$NtUninstallKB970430$
2009-12-10 17:49:35 ----HDC---- C:\WINDOWS.0\$NtUninstallKB974318$
2009-12-10 17:49:21 ----HDC---- C:\WINDOWS.0\$NtUninstallKB976325$
2009-12-10 17:49:12 ----HDC---- C:\WINDOWS.0\$NtUninstallKB973904$
2009-12-10 17:49:07 ----HDC---- C:\WINDOWS.0\$NtUninstallKB974392$
2009-12-10 17:48:56 ----HDC---- C:\WINDOWS.0\$NtUninstallKB971737$
2009-12-08 19:20:00 ----A---- C:\WINDOWS.0\system32\aswBoot.exe

======List of files/folders modified in the last 1 months======

2010-01-03 17:48:55 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Skype
2010-01-03 17:48:36 ----D---- C:\WINDOWS.0\Prefetch
2010-01-03 17:48:25 ----RD---- C:\Program Files
2010-01-03 17:43:32 ----D---- C:\WINDOWS.0\Temp
2010-01-03 17:42:09 ----A---- C:\WINDOWS.0\system32\auto.ini
2010-01-03 17:41:25 ----D---- C:\WINDOWS.0\system32
2010-01-03 17:41:24 ----D---- C:\WINDOWS.0\system32\drivers
2010-01-03 17:40:13 ----A---- C:\WINDOWS.0\SchedLgU.Txt
2010-01-03 17:40:03 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\ICQ
2010-01-03 17:28:38 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\skypePM
2009-12-31 13:47:20 ----D---- C:\WINDOWS.0\system32\CatRoot2
2009-12-29 09:24:33 ----D---- C:\Program Files\ICQ6.5
2009-12-25 14:05:29 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Adobe
2009-12-23 16:38:58 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Adobe
2009-12-23 16:38:57 ----D---- C:\Program Files\Adobe
2009-12-23 16:06:29 ----SD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Microsoft
2009-12-23 16:00:09 ----SHD---- C:\WINDOWS.0\Installer
2009-12-23 16:00:08 ----HD---- C:\Config.Msi
2009-12-23 15:57:40 ----D---- C:\Program Files\Common Files\Adobe
2009-12-23 15:55:36 ----RSD---- C:\WINDOWS.0\Fonts
2009-12-23 15:53:24 ----D---- C:\Program Files\Common Files
2009-12-21 20:28:15 ----SD---- C:\WINDOWS.0\Tasks
2009-12-19 18:43:21 ----D---- C:\Program Files\Mozilla Firefox
2009-12-18 10:25:22 ----D---- C:\WINDOWS.0
2009-12-17 21:59:36 ----SD---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Microsoft
2009-12-17 21:58:52 ----HD---- C:\WINDOWS.0\inf
2009-12-17 21:19:57 ----D---- C:\WINDOWS.0\WinSxS
2009-12-17 21:18:42 ----D---- C:\WINDOWS.0\twain_32
2009-12-17 21:04:52 ----RSHDC---- C:\WINDOWS.0\system32\dllcache
2009-12-10 18:35:14 ----A---- C:\WINDOWS.0\system32\PerfStringBackup.INI
2009-12-10 17:49:38 ----A---- C:\WINDOWS.0\imsins.BAK
2009-12-10 17:49:11 ----HD---- C:\WINDOWS.0\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS.0\system32\drivers\Aavmker4.sys [2009-08-17 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS.0\system32\drivers\aswSP.sys [2009-08-17 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS.0\system32\drivers\aswTdi.sys [2009-08-17 51376]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS.0\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 ISODisk;ISODisk; C:\WINDOWS.0\system32\drivers\ISODisk.sys [2006-04-26 9600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS.0\System32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R2 adfs;adfs; C:\WINDOWS.0\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS.0\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS.0\system32\drivers\aswMon2.sys [2009-08-17 94160]
R2 EIO;EIO; \??\C:\WINDOWS.0\system32\drivers\EIO.sys []
R3 aswRdr;aswRdr; C:\WINDOWS.0\system32\drivers\aswRdr.sys [2009-08-17 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS.0\System32\DRIVERS\ati2mtag.sys [2004-08-12 786944]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS.0\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS.0\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS.0\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS.0\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS.0\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS.0\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS.0\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS.0\system32\drivers\viaudios.sys [2004-06-18 152192]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS.0\System32\Drivers\vulfntr.sys [2002-10-30 10240]
S3 a10q8yqx;a10q8yqx; C:\WINDOWS.0\system32\drivers\a10q8yqx.sys []
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS.0\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
S3 usbprint;Třída USB Printer; C:\WINDOWS.0\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS.0\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS.0\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS.0\System32\Drivers\vulfnth.sys [2002-10-23 6912]
S4 IntelIde;IntelIde; C:\WINDOWS.0\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-08-17 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS.0\System32\Ati2evxx.exe [2004-08-12 389120]
R2 Autodesk Data Management Job Dispatch;Autodesk Data Management Job Dispatch; C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe [2008-02-18 32768]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-08-17 138680]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS.0\system32\svchost.exe [2004-08-17 14336]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-01-22 29178224]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS.0\System32\svchost.exe [2004-08-17 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS.0\System32\svchost.exe [2004-08-17 14336]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-08-17 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-08-17 352920]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS.0\system32\svchost.exe [2004-08-17 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS.0\system32\ati2sgag.exe [2004-08-12 516096]
S2 Autodesk EDM Server;Autodesk EDM Server; C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe [2008-02-18 57344]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-16 79360]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-23 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-01-22 45272]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-01-22 242544]

-----------------EOF-----------------

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#2 Příspěvek od Unlimited_Killer »

Vy jste dělal Avanger? Poprosím o log.
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#3 Příspěvek od poly-filip »

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\WINDOWS.0\accm.exe" not found!
Deletion of file "C:\WINDOWS.0\accm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\acq32.exe" not found!
Deletion of file "C:\WINDOWS.0\acq32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\ais32.exe" not found!
Deletion of file "C:\WINDOWS.0\ais32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\alerter.exe" not found!
Deletion of file "C:\WINDOWS.0\alerter.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\aorvno91m.txt" not found!
Deletion of file "C:\WINDOWS.0\aorvno91m.txt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\attcfg.tmp" not found!
Deletion of file "C:\WINDOWS.0\attcfg.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\avistat.tmp" not found!
Deletion of file "C:\WINDOWS.0\avistat.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\b6iqdkku.scf" not found!
Deletion of file "C:\WINDOWS.0\b6iqdkku.scf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\brwmark.ini" not found!
Deletion of file "C:\WINDOWS.0\brwmark.ini" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\c6wsq6.reg" not found!
Deletion of file "C:\WINDOWS.0\c6wsq6.reg" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cc2.exe" not found!
Deletion of file "C:\WINDOWS.0\cc2.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cc3.exe" not found!
Deletion of file "C:\WINDOWS.0\cc3.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cc5.exe" not found!
Deletion of file "C:\WINDOWS.0\cc5.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\ccsserv.exe" not found!
Deletion of file "C:\WINDOWS.0\ccsserv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cct2.exe" not found!
Deletion of file "C:\WINDOWS.0\cct2.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cesm9q.reg" not found!
Deletion of file "C:\WINDOWS.0\cesm9q.reg" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\concfg.tmp" not found!
Deletion of file "C:\WINDOWS.0\concfg.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cserv32.exe" not found!
Deletion of file "C:\WINDOWS.0\cserv32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\cservv32.exe" not found!
Deletion of file "C:\WINDOWS.0\cservv32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\dbmdata.tmp" not found!
Deletion of file "C:\WINDOWS.0\dbmdata.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\dqpdroc.ini" not found!
Deletion of file "C:\WINDOWS.0\dqpdroc.ini" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\eba2h6cc.dat" not found!
Deletion of file "C:\WINDOWS.0\eba2h6cc.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\eevmwk.reg" not found!
Deletion of file "C:\WINDOWS.0\eevmwk.reg" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\egadata.tmp" not found!
Deletion of file "C:\WINDOWS.0\egadata.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\f3da8e.reg" not found!
Deletion of file "C:\WINDOWS.0\f3da8e.reg" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\f8or9s.exe" not found!
Deletion of file "C:\WINDOWS.0\f8or9s.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\ftg71cj1qx.dat" not found!
Deletion of file "C:\WINDOWS.0\ftg71cj1qx.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\gen.exe" not found!
Deletion of file "C:\WINDOWS.0\gen.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\hv4e05.dll" not found!
Deletion of file "C:\WINDOWS.0\hv4e05.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\chater.exe" not found!
Deletion of file "C:\WINDOWS.0\chater.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\irk.exe" not found!
Deletion of file "C:\WINDOWS.0\irk.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\md2icut9a2.dll" not found!
Deletion of file "C:\WINDOWS.0\md2icut9a2.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msout.exe" not found!
Deletion of file "C:\WINDOWS.0\msout.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msserrv32.exe" not found!
Deletion of file "C:\WINDOWS.0\msserrv32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msserv.exe" not found!
Deletion of file "C:\WINDOWS.0\msserv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msserv32.exe" not found!
Deletion of file "C:\WINDOWS.0\msserv32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msupdtwiz.c" not found!
Deletion of file "C:\WINDOWS.0\msupdtwiz.c" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msupdtwiz.dat" not found!
Deletion of file "C:\WINDOWS.0\msupdtwiz.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msupdtwiz.exe" not found!
Deletion of file "C:\WINDOWS.0\msupdtwiz.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msupdtwiz.s" not found!
Deletion of file "C:\WINDOWS.0\msupdtwiz.s" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\msupdtwiz.z" not found!
Deletion of file "C:\WINDOWS.0\msupdtwiz.z" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\mswiiz32.exe" not found!
Deletion of file "C:\WINDOWS.0\mswiiz32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\mswiizz32.exe" not found!
Deletion of file "C:\WINDOWS.0\mswiizz32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\mswiz32.exe" not found!
Deletion of file "C:\WINDOWS.0\mswiz32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\nmac32.exe" not found!
Deletion of file "C:\WINDOWS.0\nmac32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\npp32.exe" not found!
Deletion of file "C:\WINDOWS.0\npp32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\ptr.exe" not found!
Deletion of file "C:\WINDOWS.0\ptr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\reg.exe" not found!
Deletion of file "C:\WINDOWS.0\reg.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\reggserv.exe" not found!
Deletion of file "C:\WINDOWS.0\reggserv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sccsd32.exe" not found!
Deletion of file "C:\WINDOWS.0\sccsd32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serrv.c" not found!
Deletion of file "C:\WINDOWS.0\serrv.c" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serrv.dat" not found!
Deletion of file "C:\WINDOWS.0\serrv.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serrv.exe" not found!
Deletion of file "C:\WINDOWS.0\serrv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serrv.wax" not found!
Deletion of file "C:\WINDOWS.0\serrv.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serv.exe" not found!
Deletion of file "C:\WINDOWS.0\serv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\serv.wax" not found!
Deletion of file "C:\WINDOWS.0\serv.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\skcc32.exe" not found!
Deletion of file "C:\WINDOWS.0\skcc32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\skcsd32.exe" not found!
Deletion of file "C:\WINDOWS.0\skcsd32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\skksd32.exe" not found!
Deletion of file "C:\WINDOWS.0\skksd32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\smm126.exe" not found!
Deletion of file "C:\WINDOWS.0\smm126.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\spow32.exe" not found!
Deletion of file "C:\WINDOWS.0\spow32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.c" not found!
Deletion of file "C:\WINDOWS.0\sqhost.c" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.dat" not found!
Deletion of file "C:\WINDOWS.0\sqhost.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.exe" not found!
Deletion of file "C:\WINDOWS.0\sqhost.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.s" not found!
Deletion of file "C:\WINDOWS.0\sqhost.s" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.wax" not found!
Deletion of file "C:\WINDOWS.0\sqhost.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sqhost.z" not found!
Deletion of file "C:\WINDOWS.0\sqhost.z" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sscrs.exe" not found!
Deletion of file "C:\WINDOWS.0\sscrs.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sserrvv.c" not found!
Deletion of file "C:\WINDOWS.0\sserrvv.c" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sserrvv.exe" not found!
Deletion of file "C:\WINDOWS.0\sserrvv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sserrvv.s" not found!
Deletion of file "C:\WINDOWS.0\sserrvv.s" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sserrvv.wax" not found!
Deletion of file "C:\WINDOWS.0\sserrvv.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\sserrvv.z" not found!
Deletion of file "C:\WINDOWS.0\sserrvv.z" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\stm.exe" not found!
Deletion of file "C:\WINDOWS.0\stm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\svccc32.exe" not found!
Deletion of file "C:\WINDOWS.0\svccc32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\t2serv.dll" not found!
Deletion of file "C:\WINDOWS.0\t2serv.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\t2serv.s" not found!
Deletion of file "C:\WINDOWS.0\t2serv.s" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\t2serv.wax" not found!
Deletion of file "C:\WINDOWS.0\t2serv.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\tifc32.exe" not found!
Deletion of file "C:\WINDOWS.0\tifc32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\tpup.dat" not found!
Deletion of file "C:\WINDOWS.0\tpup.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\tpup.exe" not found!
Deletion of file "C:\WINDOWS.0\tpup.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\tpup.wax" not found!
Deletion of file "C:\WINDOWS.0\tpup.wax" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\tpup.z" not found!
Deletion of file "C:\WINDOWS.0\tpup.z" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\update86.exe" not found!
Deletion of file "C:\WINDOWS.0\update86.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\wincrt.exe" not found!
Deletion of file "C:\WINDOWS.0\wincrt.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\wnet32.exe" not found!
Deletion of file "C:\WINDOWS.0\wnet32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\wqpd32.exe" not found!
Deletion of file "C:\WINDOWS.0\wqpd32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\1.tmp" not found!
Deletion of file "C:\WINDOWS.0\system32\1.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\11.tmp" not found!
Deletion of file "C:\WINDOWS.0\system32\11.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\aclekern.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\aclekern.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\actidmoc.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\actidmoc.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\adpticmp.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\adpticmp.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\advacfgb.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\advacfgb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\advacfgb.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\advacfgb.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\alerter.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\alerter.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\alrsbatt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\alrsbatt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\amcconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\amcconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\appconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\appconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\appmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\appmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\appstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\appstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atkcadpt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\atkcadpt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atkcadpt.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\atkcadpt.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atmconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\atmconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atmprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\atmprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atmstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\atmstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\atrconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\atrconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\attmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\attmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\attperf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\attperf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\attprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\attprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\attstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\attstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\audconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\audconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\audmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\audmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\audperf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\audperf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\audprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\audprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\audstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\audstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\brwconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\brwconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\brwmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\brwmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\brwperf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\brwperf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\brwprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\brwprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\brwstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\brwstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ccfgcscd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ccfgcscd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ccfgcscd.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ccfgcscd.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ccfgwshb.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ccfgwshb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgbphot.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgbphot.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgcrs.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgcrs.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgd3d.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgd3d.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgdei.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgdei.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgdsk.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgdsk.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgdss.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgdss.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgdxt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgdxt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgfsd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgfsd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgisr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgisr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgmmprm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgmmprm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgmplus.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgmplus.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cfgmwmid.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\cfgmwmid.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\clicsaml.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\clicsaml.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\clicsaml.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\clicsaml.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confapp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confapp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confatm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confatm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confatt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confatt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confaud.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confaud.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confbrw.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confbrw.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confcon.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confcon.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confega.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confega.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confifc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confifc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confjpg.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confjpg.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\confwmv.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\confwmv.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\conmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\conmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\conperf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\conperf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\conprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\conprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\constat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\constat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cp8xpqj.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\cp8xpqj.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\creconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\creconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\crsconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\crsconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\crypds16.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\crypds16.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\crypmapi.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\crypmapi.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\crypmapi.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\crypmapi.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\cssewmpd.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\cssewmpd.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\decconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\decconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\deiconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\deiconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\deiprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\deiprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\deiprov.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\deiprov.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\deskmcd3.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\deskmcd3.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dfssrasc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dfssrasc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dfssrasc.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dfssrasc.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagamc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagamc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagcre.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagcre.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagcrs.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagcrs.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagd3d.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagd3d.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagdei.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagdei.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagdsk.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagdsk.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagdss.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagdss.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagdxt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagdxt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagfsd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagfsd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\diagisr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\diagisr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dic.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dic.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dmimmdt2.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dmimmdt2.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\docpfram.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\docpfram.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dpugmswe.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dpugmswe.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dpvacdfv.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dpvacdfv.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\drmvndde.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\drmvndde.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\drmvndde.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\drmvndde.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dskconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dskconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dsprcdfv.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dsprcdfv.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dsprcdfv.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dsprcdfv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dsqudisp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dsqudisp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dssconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dssconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dsseds32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dsseds32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dsseds32.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dsseds32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dxdimqtr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dxdimqtr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dxtconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dxtconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dxtmmnmd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dxtmmnmd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dxtmmnmd.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\dxtmmnmd.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\dxtmsft3.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\dxtmsft3.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\e1.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\e1.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\e1.sys" not found!
Deletion of file "C:\WINDOWS.0\system32\e1.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\egaavi.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\egaavi.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\egamgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\egamgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\egastat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\egastat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\egperf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\egperf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\encddpva.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\encddpva.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\evenncob.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\evenncob.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\fpwppgpm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\fpwppgpm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\fsdconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\fsdconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\fsxsh4.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\fsxsh4.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\glu3panm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\glu3panm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\gpkrmssi.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\gpkrmssi.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\gtmqf608r7.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\gtmqf608r7.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\hypewmv9.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\hypewmv9.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\i57ff9ieo.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\i57ff9ieo.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\iasamsre.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\iasamsre.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\icmpdx3j.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\icmpdx3j.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\icmuwmad.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\icmuwmad.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ifcconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ifcconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ifcmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ifcmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ifcstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ifcstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\imagalrs.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\imagalrs.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\inetzlco.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\inetzlco.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\inetzlco.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\inetzlco.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\inketype.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\inketype.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\inpufm20.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\inpufm20.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipnardch.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipnardch.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipsecmon.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipsecmon.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipsmwebh.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipsmwebh.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipv6rasm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipv6rasm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipv6rasm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipv6rasm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxpextm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxpextm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxsshdo.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxsshdo.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxsshdo.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxsshdo.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxwersv.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxwersv.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxwscri.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxwscri.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipxwshel.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ipxwshel.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ipsemsw3.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ipsemsw3.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\isrconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\isrconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\isrprf32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\isrprf32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\isrprov.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\isrprov.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\iuennwcf.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\iuennwcf.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ixssregw.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ixssregw.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ixsswmas.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ixsswmas.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\j2t3crh.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\j2t3crh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgawmsne.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jgawmsne.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgdwadsn.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jgdwadsn.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgdwadsn.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\jgdwadsn.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgmdwstd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jgmdwstd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgsdrpcn.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jgsdrpcn.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jgsdrpcn.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\jgsdrpcn.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jpgconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\jpgconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\jpgmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jpgmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#4 Příspěvek od poly-filip »

Error: file "C:\WINDOWS.0\system32\jpgstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\jpgstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\kbdcrtut.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\kbdcrtut.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\kbdfnmmk.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\kbdfnmmk.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\kbdfwshe.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\kbdfwshe.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\libdprin.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\libdprin.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\loghatkc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\loghatkc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\lprmneth.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\lprmneth.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\lprmneth.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\lprmneth.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mcd3mscm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mcd3mscm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mcd3stor.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mcd3stor.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mdhcdpnl.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mdhcdpnl.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mdhcdpnl.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mdhcdpnl.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mfcscoma.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mfcscoma.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mididpnh.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mididpnh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ml7swr.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ml7swr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mmfubits.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mmfubits.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mmfubits.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mmfubits.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mp4sglmf.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mp4sglmf.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mprmsfma.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mprmsfma.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mprwanp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mprwanp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mprwanp.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mprwanp.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mqadscp3.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mqadscp3.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mqqmdisp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mqqmdisp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mqqmdisp.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mqqmdisp.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mqqmkbdu.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mqqmkbdu.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msihftpw.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msihftpw.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msisnwcf.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msisnwcf.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msjidpmo.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msjidpmo.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mslskern.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mslskern.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msnepngf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msnepngf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msormsxm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msormsxm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msormsxm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msormsxm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mspradme.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mspradme.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mspradsn.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mspradsn.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msrdtscf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msrdtscf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msrdwint.dat" not found!
Deletion of file "C:\WINDOWS.0\system32\msrdwint.dat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msrdwint.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msrdwint.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msrdwint.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msrdwint.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msssfpwp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msssfpwp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msssfpwp.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msssfpwp.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msssmsda.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\msssmsda.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\msssmsda.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\msssmsda.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mstsodbc.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\mstsodbc.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\mtxdmsid.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\mtxdmsid.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\narrdfss.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\narrdfss.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\narrwshr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\narrwshr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\netfrtm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\netfrtm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\netstraf.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\netstraf.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\netstraf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\netstraf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\nlhtjgdw.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\nlhtjgdw.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\nmevmsas.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\nmevmsas.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\npptdpnm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\npptdpnm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\npptdpnm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\npptdpnm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ntlamsht.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ntlamsht.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\oaklrass.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\oaklrass.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\odtemdt2.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\odtemdt2.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\offfmsre.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\offfmsre.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\olecmsre.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\olecmsre.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\osunuxth.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\osunuxth.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\osunuxth.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\osunuxth.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\p2psifmo.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\p2psifmo.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\panmavic.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\panmavic.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\panmavic.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\panmavic.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\panmnets.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\panmnets.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\panmnets.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\panmnets.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\pngfmsne.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\pngfmsne.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\psapdani.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\psapdani.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\psbaavic.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\psbaavic.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\psbamtxe.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\psbamtxe.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\psbamtxe.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\psbamtxe.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\qasfole2.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\qasfole2.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\rdpwmsjt.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\rdpwmsjt.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\rtutdmin.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\rtutdmin.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\samsusrr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\samsusrr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\samsusrr.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\samsusrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sbeddem.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\sbeddem.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sbeddem.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\sbeddem.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sbeddem.z1" not found!
Deletion of file "C:\WINDOWS.0\system32\sbeddem.z1" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sccsumdm.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\sccsumdm.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sccsumdm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\sccsumdm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\scp3sdhc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\scp3sdhc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\scrilprh.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\scrilprh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\scsm.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\scsm.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sfcfdmsc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\sfcfdmsc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sfcfdmsc.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\sfcfdmsc.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\shfoxpob.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\shfoxpob.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\shfoxpob.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\shfoxpob.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\shsvmdim.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\shsvmdim.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\slbipsch.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\slbipsch.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\slbipsch.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\slbipsch.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\smlomswc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\smlomswc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\smlomswc.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\smlomswc.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\snmpmmcn.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\snmpmmcn.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ssdprasa.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ssdprasa.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statamc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statamc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statcre.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statcre.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statcrs.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statcrs.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statd3d.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statd3d.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statdei.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statdei.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statdsk.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statdsk.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statdss.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statdss.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statdxt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statdxt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statfsd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statfsd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\statisr.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\statisr.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\stcisxum.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\stcisxum.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\strmatkc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\strmatkc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\strmwin8.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\strmwin8.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sysshtic.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\sysshtic.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\sysshtic.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\sysshtic.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\tlntrass.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\tlntrass.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\trafracp.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\trafracp.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\trkwpipa.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\trkwpipa.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\trkwvga2.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\trkwvga2.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\tscfvjoy.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\tscfvjoy.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ujn6oqt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\ujn6oqt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\ulibofff.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\ulibofff.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\uregdeve.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\uregdeve.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\uregdeve.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\uregdeve.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vb5dmspo.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\vb5dmspo.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vbscqdv.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\vbscqdv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vdshlicw.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\vdshlicw.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vgnb4c.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\vgnb4c.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vmhevnet.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\vmhevnet.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vmhevnet.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\vmhevnet.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vp31srsv.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\vp31srsv.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vsutxpob.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\vsutxpob.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\vwipsti_.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\vwipsti_.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\w3sskbda.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\w3sskbda.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wdmicpui.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wdmicpui.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wiadwmis.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\wiadwmis.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\winbpowr.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\winbpowr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmadmsst.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmadmsst.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmadmsst.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\wmadmsst.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmnecomc.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmnecomc.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmpcmsyu.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\wmpcmsyu.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmpcskdl.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmpcskdl.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmpssdpb.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmpssdpb.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmspmsv1.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmspmsv1.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmspmsv1.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\wmspmsv1.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#5 Příspěvek od poly-filip »

Error: file "C:\WINDOWS.0\system32\wmvconf.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmvconf.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmvconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\wmvconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmvmgr32.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmvmgr32.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wmvstat.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wmvstat.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wshtlprh.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wshtlprh.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wstdactx.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wstdactx.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wuapsecu.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wuapsecu.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\wupstlnt.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\wupstlnt.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\xactcomr.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\xactcomr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\xpspqdvd.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\xpspqdvd.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\xpspqdvd.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\xpspqdvd.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\yapconf.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\yapconf.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\zlcocard.dll" not found!
Deletion of file "C:\WINDOWS.0\system32\zlcocard.dll" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS.0\system32\zlcocard.exe" not found!
Deletion of file "C:\WINDOWS.0\system32\zlcocard.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

Registry value "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs" replaced with dummy successfully.

Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\advacfgb" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\advacfgb" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\atkcadpt" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\atkcadpt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\appmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\appmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\attmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\attmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\atmmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\atmmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\audmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\audmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\brwmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\brwmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ccfgcscd" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ccfgcscd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\clicsaml" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\clicsaml" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\conmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\conmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crsconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crsconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypmapi" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypmapi" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dbgmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dbgmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\decstat" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\decstat" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dfssrasc" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dfssrasc" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\deiconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\deiconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dpvacdfv" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dpvacdfv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drmvndde" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\drmvndde" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dskconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dskconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dsprcdfv" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dsprcdfv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dssconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dssconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dsseds32" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dsseds32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dssmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dssmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxdimqtr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxdimqtr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxtconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxtconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxtmmnmd" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dxtmmnmd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsdconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fsdconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\inketype" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\inketype" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\inetzlco" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\inetzlco" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipv6rasm" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipv6rasm" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipxsshdo" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ipxsshdo" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\isrconf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\isrconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jgsdrpcn" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jgsdrpcn" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jgdwadsn" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jgdwadsn" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jpgmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jpgmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\libdprin" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\libdprin" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lprmneth" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\lprmneth" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhcdpnl" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mdhcdpnl" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mmfubits" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mmfubits" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mprwanp" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mprwanp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mqqmdisp" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\mqqmdisp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msormsxm" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msormsxm" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msrdwint" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msrdwint" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msssfpwp" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msssfpwp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msssmsda" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\msssmsda" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\netstraf" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\netstraf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\npptdpnm" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\npptdpnm" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\odtemdt2" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\odtemdt2" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\osunuxth" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\osunuxth" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\panmavic" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\panmavic" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pngfmsne" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pngfmsne" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psbamtxe" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\psbamtxe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\samsusrr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\samsusrr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sccsumdm" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sccsumdm" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sbeddem" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sbeddem" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sfcfdmsc" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sfcfdmsc" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\shfoxpob" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\shfoxpob" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\slbipsch" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\slbipsch" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\smlomswc" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\smlomswc" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sysshtic" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sysshtic" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\uregdeve" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\uregdeve" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmadmsst" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmadmsst" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vmhevnet" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vmhevnet" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmspmsv1" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmspmsv1" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmvmgr" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wmvmgr" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wstdactx" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wstdactx" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xpspqdvd" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xpspqdvd" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zlcocard" not found!
Deletion of registry key "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\zlcocard" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|acq32.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|acq32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|adpticmp"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|adpticmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|amcdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|amcdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|appdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|appdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|atmconf"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|atmconf" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|atmdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|atmdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|audiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|audiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|brwdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|brwdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ccsserv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ccsserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ciodiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ciodiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cfgmwmid"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cfgmwmid" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|chater.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|chater.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|crediag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|crediag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cserv32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cserv32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cservv32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|cservv32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|davctool"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|davctool" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dic.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dic.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dssdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dssdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dxtdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dxtdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|egdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|egdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fsddiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fsddiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|gen.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|gen.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|himem.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|himem.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|icmuwmad"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|icmuwmad" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|idl32.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|idl32.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ifcdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ifcdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ipxwshel"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ipxwshel" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|isrdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|isrdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ixssregw"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ixssregw" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|jpgdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|jpgdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mac.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mac.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqadscp3"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mqadscp3" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mspradme"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mspradme" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserrv32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserrv32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserv32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msserv32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msupdtwiz"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|msupdtwiz" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiiz32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiiz32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiizz32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiizz32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiz32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|mswiz32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|reggserv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|reggserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|serrv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|serrv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|serv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|serv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SoundMnEx32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SoundMnEx32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sqhost"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sqhost" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sscrs.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sscrs.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sserrvv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sserrvv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sys32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|sys32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|t2serv"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|t2serv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|tpup"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|tpup" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ulibofff"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ulibofff" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|update86.exe"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|update86.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wmvdiag"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wmvdiag" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

Error: could not delete registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wqpd32"
Deletion of registry value "HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wqpd32" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#6 Příspěvek od Unlimited_Killer »

Vidím, že jste použil nějaký obecný skript nalezený na Internetu.
To bych Vám pro příště moc neporučoval - každý PC vyžaduje specifický přístup.
Zatím to projedeme ComboFixem. Něco sám odstraní a něco domažeme.
Pro jistotu připojte všechny USB klíče do PC - možná je něco na flashkách.

~~~

Vložte sem log z ComboFix.

Stáhněte a uložte na Plochu ComboFix, poté ho spusťte s administrátorským oprávněním.
Ještě před spuštěním vypněte rezidentní štít antiviru, či antispywaru.
Po spuštění se Vám zobrazí licenční podmínky, klikněte na 'Ano'. Budete také dotázán na instalaci konzole pro zotavení, klikněte na 'Ano'.
Celý sken bude trvat tak 5-10 minut, v závislosti na tom, kolika soubory se bude CF prodírat. Váš PC bude pravděpodobně restartován, tak se toho neděste. Než úplně skončí sken, nic nedělejte, hlavně neklikejte do spuštěného okna s ComboFixem.
Po skončení skenu na Vás vypadne log, který vkopírujete sem.
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#7 Příspěvek od poly-filip »

Zde je log:

ComboFix 10-01-04.01 - POLLY 05.01.2010 17:55:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.767.425 [GMT 1:00]
Spuštěný z: c:\documents and settings\POLLY.POLY\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 100105-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\ICQ6.5\ICQLRun.exe
c:\recycler\S-1-5-21-57989841-412668190-682003330-1003
c:\windows.0\Downloaded Program Files\IDropPTB.dll
c:\windows.0\system32\autorun.ini
c:\windows.0\system32\ieuinit.inf

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-05 do 2010-01-05 )))))))))))))))))))))))))))))))
.

2010-01-03 16:58 . 2010-01-03 16:58 -------- d-----w- C:\rsit
2010-01-03 16:48 . 2010-01-03 16:48 -------- d-----w- c:\program files\Trend Micro
2009-12-25 13:03 . 2009-12-25 13:03 -------- d-----w- C:\found.002
2009-12-23 14:56 . 2009-12-23 14:56 -------- d-----w- c:\program files\Adobe Media Player
2009-12-23 14:53 . 2009-12-23 14:53 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-23 14:48 . 2009-12-23 14:48 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-21 19:32 . 2009-12-21 19:32 -------- d-----w- c:\program files\BitZipper
2009-12-21 19:28 . 2009-12-21 19:28 -------- d-----w- c:\program files\Common Files\Winferno
2009-12-21 19:24 . 2006-10-09 12:06 495616 ----a-w- c:\windows.0\system32\WINUTIL5.DLL
2009-12-21 19:24 . 2006-05-17 07:40 393216 ----a-w- c:\windows.0\system32\WINLCTL5.DLL
2009-12-21 19:24 . 2009-12-21 19:28 -------- d-----w- c:\program files\Winferno
2009-12-17 20:33 . 2009-12-17 20:57 -------- d-----w- c:\program files\Canon
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Common Files\HP
2009-12-17 20:17 . 2009-12-17 20:17 -------- dc----w- c:\windows.0\system32\DRVSTORE
2009-12-17 20:17 . 2009-12-17 20:18 -------- d-----w- c:\program files\HP
2009-12-17 20:15 . 2009-12-17 20:29 175675 ----a-w- c:\windows.0\hpoins27.dat
2009-12-17 20:15 . 2008-01-18 15:56 932 ------w- c:\windows.0\hpomdl27.dat
2009-12-17 20:04 . 2004-08-03 22:01 25856 -c--a-w- c:\windows.0\system32\dllcache\usbprint.sys
2009-12-17 20:04 . 2004-08-03 22:01 25856 ----a-w- c:\windows.0\system32\drivers\usbprint.sys
2009-12-11 14:29 . 2001-10-24 11:25 5632 ----a-w- c:\windows.0\system32\ptpusb.dll
2009-12-11 14:28 . 2004-08-17 14:49 159232 ----a-w- c:\windows.0\system32\ptpusd.dll
2009-12-11 14:28 . 2004-08-03 21:58 15104 -c--a-w- c:\windows.0\system32\dllcache\usbscan.sys
2009-12-11 14:28 . 2004-08-03 21:58 15104 ----a-w- c:\windows.0\system32\drivers\usbscan.sys
2009-12-08 18:20 . 2009-08-17 17:04 23152 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2009-12-08 18:20 . 2009-08-17 17:04 51376 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2009-12-08 18:20 . 2009-08-17 17:03 26944 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2009-12-08 18:20 . 2009-08-17 17:06 93392 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2009-12-08 18:20 . 2009-08-17 17:06 94160 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2009-12-08 18:20 . 2009-08-17 17:05 114768 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2009-12-08 18:20 . 2009-08-17 17:05 20560 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2009-12-08 18:20 . 2009-08-17 17:02 97480 ----a-w- c:\windows.0\system32\AvastSS.scr
2009-12-08 18:20 . 2009-08-17 17:10 1279456 ----a-w- c:\windows.0\system32\aswBoot.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 17:01 . 2009-10-26 16:42 -------- d-----w- c:\program files\ICQ6.5
2009-12-23 14:57 . 2009-08-26 17:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-10 17:35 . 2001-10-25 12:00 95694 ----a-w- c:\windows.0\system32\perfc005.dat
2009-12-10 17:35 . 2001-10-25 12:00 475458 ----a-w- c:\windows.0\system32\perfh005.dat
2009-12-02 14:10 . 2009-11-24 12:39 -------- d-----w- c:\program files\QIP Infium
2009-11-27 11:44 . 2009-11-27 11:44 -------- d-----w- c:\program files\Image Resize Guide
2009-11-27 11:44 . 2009-11-27 11:44 -------- d-----w- c:\program files\Two Pilots
2009-11-16 18:08 . 2009-08-26 19:01 -------- d-----w- c:\program files\BS_Player
2009-11-16 17:53 . 2009-11-16 17:53 -------- d-----w- c:\program files\Alwil Software
2009-11-15 23:10 . 2009-11-15 22:56 -------- d-----w- c:\program files\Keyfinder Advanced 2010 (Trial Version)
2009-10-29 05:48 . 2002-09-20 17:05 663040 ----a-w- c:\windows.0\system32\wininet.dll
2009-10-21 06:03 . 2009-10-16 18:47 25088 ----a-w- c:\windows.0\system32\httpapi.dll
2009-10-21 06:03 . 2009-10-16 18:47 75776 ----a-w- c:\windows.0\system32\strmfilt.dll
2009-10-20 14:58 . 2009-10-16 18:47 263552 ----a-w- c:\windows.0\system32\drivers\http.sys
2009-10-16 18:50 . 2009-09-27 09:23 76499 ----a-w- c:\windows.0\PCHealth\HelpCtr\OfflineCache\index.dat
2009-10-16 18:50 . 2009-09-27 09:23 2700 ----a-w- c:\windows.0\PCHealth\HelpCtr\PackageStore\SkuStore.bin
2009-10-16 18:48 . 2009-09-27 09:24 8972 ----a-w- c:\windows.0\PCHealth\HelpCtr\Config\Cntstore.bin
2009-10-13 10:53 . 2002-09-20 17:04 267776 ----a-w- c:\windows.0\system32\oakley.dll
2009-10-12 13:54 . 2002-09-20 17:04 69632 ----a-w- c:\windows.0\system32\raschap.dll
2009-10-12 13:54 . 2002-09-20 17:04 112640 ----a-w- c:\windows.0\system32\rastls.dll
2009-10-11 07:45 . 2009-10-11 07:45 56 ---ha-w- c:\windows.0\system32\ezsidmv.dat
2009-10-05 17:34 . 2009-11-24 12:40 118000 ----a-w- c:\program files\mozilla firefox\components\qippipe.dll
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_1.dll" [2009-11-16 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
2009-11-16 18:09 2166296 ----a-w- c:\program files\BS_Player\tbBS_1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"= "c:\program files\BS_Player\tbBS_1.dll" [2009-11-16 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5}"= "c:\program files\BS_Player\tbBS_1.dll" [2009-11-16 2166296]

[HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"Soltek"="c:\windows.0\System32\autorun.exe" [2001-10-29 61440]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_04\bin\jusched.exe" [2004-02-22 32881]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\System32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\POLLY.POLY\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users.WINDOWS.0\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 aswSP;avast! Self Protection;c:\windows.0\system32\drivers\aswSP.sys [8.12.2009 19:20 114768]
R1 ISODisk;ISODisk;c:\windows.0\system32\drivers\ISODisk.sys [27.9.2009 11:11 9600]
R2 aswFsBlk;aswFsBlk;c:\windows.0\system32\drivers\aswFsBlk.sys [8.12.2009 19:20 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.10.2009 17:44 222456]
S0 sptd;sptd;c:\windows.0\system32\drivers\sptd.sys [27.9.2009 11:13 685816]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Obsah adresáře 'Naplánované úlohy'

2010-01-05 c:\windows.0\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe [2009-12-21 13:10]

2010-01-05 c:\windows.0\Tasks\RegPowerClean.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe [2009-12-21 13:48]

2010-01-05 c:\windows.0\Tasks\RPCReminder.job
- c:\program files\Winferno\RegistryPowerCleaner\RPCReminder.exe [2009-12-21 13:34]
.
.
------- Doplňkový sken -------
.
uStart Page = start.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\POLLY.POLY\Data aplikací\Mozilla\Firefox\Profiles\0h2vx0kk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://start.qip.ru
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\components\qippipe.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava11.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava12.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava13.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava14.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava32.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJPI142_04.dll
FF - plugin: c:\program files\Opera\program\plugins\NPOJI610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-05 18:02
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(640)
c:\windows.0\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
.
Celkový čas: 2010-01-05 18:05:56
ComboFix-quarantined-files.txt 2010-01-05 17:05

Před spuštěním: 8 962 961 408
Po spuštění: 9 769 660 416

WindowsXP-KB310994-SP2-Home-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

- - End Of File - - 0FDBCC2E6020CA1F560401FC6FC07EE6

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#8 Příspěvek od Unlimited_Killer »

Jedeme dál.

~~~

Otevřete si Poznámkový blok a zkopírujte do něj

Kód: Vybrat vše

KillAll::

Folder::
C:\found.002
c:\program files\Winferno
c:\program files\Common Files\Winferno

Collect::
c:\windows.0\Tasks\RPCReminder.job
c:\windows.0\Tasks\RegPowerClean.job
c:\windows.0\Tasks\PCConfidential.job

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}"=-
[-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
[-HKEY_CLASSES_ROOT\clsid\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-
"Adobe Reader Speed Launcher"=-
"HP Software Update"=-

Drivers::
ICQ Service

Extra::
FireFox::
FF - ProfilePath - c:\documents and settings\POLLY.POLY\Data aplikací\Mozilla\Firefox\Profiles\0h2vx0kk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - QIP Search
FF - prefs.js: browser.startup.homepage - hxxp://start.qip.ru
FF - prefs.js: keyword.URL - hxxp://search.qip.ru/search?from=FF&query=
FF - component: c:\program files\Mozilla Firefox\components\qippipe.dll
uRun::
uStart Page = start.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
uložte to na Plochu jako CFScript.txt Pak jej myší přetáhněte nad ComboFix (!musí být na Ploše!) a pusťte.

Obrázek

ComboFix vykoná příkazy ze skriptu, PC může být opět restartován.
Po skončení mi sem dejte log, který na Vás po dočistění vybafne.
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#9 Příspěvek od poly-filip »

Dobrý den dnes nebudu doma koukám na stránky v PPC takže log sem hodím zítra odpoledne .děkuji za vaše rady doufám že dáme PC nějak dohromady .

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#10 Příspěvek od Unlimited_Killer »

0K. Zítra budu čekat. :)
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#11 Příspěvek od poly-filip »

Dobrý den tak tady to je :

ComboFix 10-01-04.01 - POLLY 07.01.2010 15:49:52.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.767.441 [GMT 1:00]
Spuštěný z: c:\documents and settings\POLLY.POLY\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\POLLY.POLY\Plocha\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 100107-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

file zipped: c:\windows.0\Tasks\PCConfidential.job
file zipped: c:\windows.0\Tasks\RegPowerClean.job
file zipped: c:\windows.0\Tasks\RPCReminder.job
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\found.002
c:\found.002\file0000.chk
c:\program files\Common Files\Winferno
c:\program files\Common Files\Winferno\WSE2007.dll
c:\program files\Mozilla Firefox\components\qippipe.dll
c:\program files\Winferno
c:\program files\Winferno\PC Confidential\DeleteIndex.exe
c:\program files\Winferno\PC Confidential\Graphics\HandPoint.ico
c:\program files\Winferno\PC Confidential\PCCBHO.dll
c:\program files\Winferno\PC Confidential\PCCL.DLL
c:\program files\Winferno\PC Confidential\PCConfidential.exe
c:\program files\Winferno\PC Confidential\PCConfidential.chm
c:\program files\Winferno\PC Confidential\PCCST.exe
c:\program files\Winferno\PC Confidential\unins000.dat
c:\program files\Winferno\PC Confidential\unins000.exe
c:\program files\Winferno\PC Confidential\WinCMR.dll
c:\program files\Winferno\PC Confidential\WinfernoSoftware.url
c:\program files\Winferno\RegistryPowerCleaner\CHives.dll
c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe
c:\program files\Winferno\RegistryPowerCleaner\regpowerclean.chm
c:\program files\Winferno\RegistryPowerCleaner\RPCL.DLL
c:\program files\Winferno\RegistryPowerCleaner\RPCReminder.exe
c:\program files\Winferno\RegistryPowerCleaner\SysRst.exe
c:\program files\Winferno\RegistryPowerCleaner\unins000.dat
c:\program files\Winferno\RegistryPowerCleaner\unins000.exe
c:\program files\Winferno\RegistryPowerCleaner\WinCMR.dll
c:\windows.0\Tasks\PCConfidential.job
c:\windows.0\Tasks\RegPowerClean.job
c:\windows.0\Tasks\RPCReminder.job

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-12-07 do 2010-01-07 )))))))))))))))))))))))))))))))
.

2010-01-03 16:58 . 2010-01-03 16:58 -------- d-----w- C:\rsit
2010-01-03 16:48 . 2010-01-03 16:48 -------- d-----w- c:\program files\Trend Micro
2009-12-23 14:56 . 2009-12-23 14:56 -------- d-----w- c:\program files\Adobe Media Player
2009-12-23 14:53 . 2009-12-23 14:53 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-23 14:48 . 2009-12-23 14:48 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-12-21 19:32 . 2009-12-21 19:32 -------- d-----w- c:\program files\BitZipper
2009-12-21 19:24 . 2006-10-09 12:06 495616 ----a-w- c:\windows.0\system32\WINUTIL5.DLL
2009-12-21 19:24 . 2006-05-17 07:40 393216 ----a-w- c:\windows.0\system32\WINLCTL5.DLL
2009-12-17 20:33 . 2009-12-17 20:57 -------- d-----w- c:\program files\Canon
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-17 20:18 . 2009-12-17 20:18 -------- d-----w- c:\program files\Common Files\HP
2009-12-17 20:17 . 2009-12-17 20:17 -------- dc----w- c:\windows.0\system32\DRVSTORE
2009-12-17 20:17 . 2009-12-17 20:18 -------- d-----w- c:\program files\HP
2009-12-17 20:15 . 2009-12-17 20:29 175675 ----a-w- c:\windows.0\hpoins27.dat
2009-12-17 20:15 . 2008-01-18 15:56 932 ------w- c:\windows.0\hpomdl27.dat
2009-12-17 20:04 . 2004-08-03 22:01 25856 -c--a-w- c:\windows.0\system32\dllcache\usbprint.sys
2009-12-17 20:04 . 2004-08-03 22:01 25856 ----a-w- c:\windows.0\system32\drivers\usbprint.sys
2009-12-11 14:29 . 2001-10-24 11:25 5632 ----a-w- c:\windows.0\system32\ptpusb.dll
2009-12-11 14:28 . 2004-08-17 14:49 159232 ----a-w- c:\windows.0\system32\ptpusd.dll
2009-12-11 14:28 . 2004-08-03 21:58 15104 -c--a-w- c:\windows.0\system32\dllcache\usbscan.sys
2009-12-11 14:28 . 2004-08-03 21:58 15104 ----a-w- c:\windows.0\system32\drivers\usbscan.sys
2009-12-08 18:20 . 2009-08-17 17:04 23152 ----a-w- c:\windows.0\system32\drivers\aswRdr.sys
2009-12-08 18:20 . 2009-08-17 17:04 51376 ----a-w- c:\windows.0\system32\drivers\aswTdi.sys
2009-12-08 18:20 . 2009-08-17 17:03 26944 ----a-w- c:\windows.0\system32\drivers\aavmker4.sys
2009-12-08 18:20 . 2009-08-17 17:06 93392 ----a-w- c:\windows.0\system32\drivers\aswmon.sys
2009-12-08 18:20 . 2009-08-17 17:06 94160 ----a-w- c:\windows.0\system32\drivers\aswmon2.sys
2009-12-08 18:20 . 2009-08-17 17:05 114768 ----a-w- c:\windows.0\system32\drivers\aswSP.sys
2009-12-08 18:20 . 2009-08-17 17:05 20560 ----a-w- c:\windows.0\system32\drivers\aswFsBlk.sys
2009-12-08 18:20 . 2009-08-17 17:02 97480 ----a-w- c:\windows.0\system32\AvastSS.scr
2009-12-08 18:20 . 2009-08-17 17:10 1279456 ----a-w- c:\windows.0\system32\aswBoot.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 17:01 . 2009-10-26 16:42 -------- d-----w- c:\program files\ICQ6.5
2009-12-23 14:57 . 2009-08-26 17:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-10 17:35 . 2001-10-25 12:00 95694 ----a-w- c:\windows.0\system32\perfc005.dat
2009-12-10 17:35 . 2001-10-25 12:00 475458 ----a-w- c:\windows.0\system32\perfh005.dat
2009-12-02 14:10 . 2009-11-24 12:39 -------- d-----w- c:\program files\QIP Infium
2009-11-27 11:44 . 2009-11-27 11:44 -------- d-----w- c:\program files\Image Resize Guide
2009-11-27 11:44 . 2009-11-27 11:44 -------- d-----w- c:\program files\Two Pilots
2009-11-16 18:08 . 2009-08-26 19:01 -------- d-----w- c:\program files\BS_Player
2009-11-16 17:53 . 2009-11-16 17:53 -------- d-----w- c:\program files\Alwil Software
2009-11-15 23:10 . 2009-11-15 22:56 -------- d-----w- c:\program files\Keyfinder Advanced 2010 (Trial Version)
2009-10-29 05:48 . 2002-09-20 17:05 663040 ------w- c:\windows.0\system32\wininet.dll
2009-10-21 06:03 . 2009-10-16 18:47 25088 ----a-w- c:\windows.0\system32\httpapi.dll
2009-10-21 06:03 . 2009-10-16 18:47 75776 ----a-w- c:\windows.0\system32\strmfilt.dll
2009-10-20 14:58 . 2009-10-16 18:47 263552 ----a-w- c:\windows.0\system32\drivers\http.sys
2009-10-16 18:50 . 2009-09-27 09:23 76499 ----a-w- c:\windows.0\PCHealth\HelpCtr\OfflineCache\index.dat
2009-10-16 18:50 . 2009-09-27 09:23 2700 ----a-w- c:\windows.0\PCHealth\HelpCtr\PackageStore\SkuStore.bin
2009-10-16 18:48 . 2009-09-27 09:24 8972 ----a-w- c:\windows.0\PCHealth\HelpCtr\Config\Cntstore.bin
2009-10-13 10:53 . 2002-09-20 17:04 267776 ----a-w- c:\windows.0\system32\oakley.dll
2009-10-12 13:54 . 2002-09-20 17:04 69632 ----a-w- c:\windows.0\system32\raschap.dll
2009-10-12 13:54 . 2002-09-20 17:04 112640 ----a-w- c:\windows.0\system32\rastls.dll
2009-10-11 07:45 . 2009-10-11 07:45 56 ---ha-w- c:\windows.0\system32\ezsidmv.dat
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]
"AdobeBridge"="c:\program files\Adobe\Adobe Bridge CS4\Bridge.exe" [2008-08-28 13145448]
"ICQ"="c:\program files\ICQ6.5\ICQ.exe" [2009-11-16 172792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"Soltek"="c:\windows.0\System32\autorun.exe" [2001-10-29 61440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\System32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\POLLY.POLY\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

c:\documents and settings\All Users.WINDOWS.0\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R0 sptd;sptd;c:\windows.0\system32\drivers\sptd.sys [27.9.2009 11:13 685816]
R1 aswSP;avast! Self Protection;c:\windows.0\system32\drivers\aswSP.sys [8.12.2009 19:20 114768]
R1 ISODisk;ISODisk;c:\windows.0\system32\drivers\ISODisk.sys [27.9.2009 11:11 9600]
R2 aswFsBlk;aswFsBlk;c:\windows.0\system32\drivers\aswFsBlk.sys [8.12.2009 19:20 20560]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [26.10.2009 17:44 222456]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Doplňkový sken -------
.
uStart Page = start.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\POLLY.POLY\Data aplikací\Mozilla\Firefox\Profiles\0h2vx0kk.default\
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPJPI142_04.dll
FF - plugin: c:\program files\Java\j2re1.4.2_04\bin\NPOJI610.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava11.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava12.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava13.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava14.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJava32.dll
FF - plugin: c:\program files\Opera\program\plugins\NPJPI142_04.dll
FF - plugin: c:\program files\Opera\program\plugins\NPOJI610.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-PCConfidential_is1 - c:\program files\Winferno\PC Confidential\unins000.exe
AddRemove-RegPowerClean_is1 - c:\program files\Winferno\RegistryPowerCleaner\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-07 15:59
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x831D51E8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75a0fc3
\Driver\ACPI -> ACPI.sys @ 0xf7331cb8
\Driver\atapi -> 0x831d51e8
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x8057807e
ParseProcedure -> ntkrnlpa.exe @ 0x80576ce0
NDIS: VIA PCI 10/100Mb Fast Ethernet Adapter -> SendCompleteHandler -> NDIS.sys @ 0xf71f6ba0
PacketIndicateHandler -> NDIS.sys @ 0xf7203b21
SendHandler -> NDIS.sys @ 0xf71e187b
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(700)
c:\windows.0\system32\Ati2evxx.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2556)
c:\windows.0\system32\msi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows.0\System32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows.0\system32\Ati2evxx.exe
c:\program files\Skype\Phone\Skype.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows.0\system32\wscntfy.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Celkový čas: 2010-01-07 16:03:26 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-01-07 15:03
ComboFix2.txt 2010-01-05 17:05

Před spuštěním: 9 546 199 040
Po spuštění: 9 460 011 008

- - End Of File - - 34D79EF0E7DC54B0A63758B07B02D5B8

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#12 Příspěvek od Unlimited_Killer »

0K. Prosím o nový log z RSIT. Podle něj se zařídím.
A vy používáte nějaký emulátor mechanik [Daemon/Alcohol]?
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#13 Příspěvek od poly-filip »

Dobrý den ano používám DEAMON (1-2x za čas na instalaci )a jak jsem se koukal do programů tak tu mám i ISOdisk (nevím kde se to tam vzalo myslím že to je něco na podobný styl) tady je log.


Logfile of random's system information tool 1.06 (written by random/random)
Run by POLLY at 2010-01-08 21:22:31
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 9 GB (17%) free of 55 GB
Total RAM: 767 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:22:36, on 8.1.2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS.0\System32\smss.exe
C:\WINDOWS.0\system32\winlogon.exe
C:\WINDOWS.0\system32\services.exe
C:\WINDOWS.0\system32\lsass.exe
C:\WINDOWS.0\System32\Ati2evxx.exe
C:\WINDOWS.0\system32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS.0\system32\spoolsv.exe
C:\WINDOWS.0\system32\Ati2evxx.exe
C:\WINDOWS.0\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe
C:\Program Files\ICQ6.5\ICQ.exe
C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
C:\WINDOWS.0\system32\svchost.exe
C:\Program Files\ICQ6Toolbar\ICQ Service.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS.0\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS.0\System32\svchost.exe
C:\WINDOWS.0\system32\wscntfy.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\POLLY.POLY\Plocha\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\POLLY.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = start.qip.ru
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: PCCBHO.CPCCBHO - {22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF} - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Soltek] C:\WINDOWS.0\System32\autorun.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [AdobeBridge] "C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe" -stealth
O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS.0\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra 'Tools' menuitem: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: HP Chytrý výběr - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS.0\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS.0\system32\ati2sgag.exe
O23 - Service: Autodesk Data Management Job Dispatch - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe
O23 - Service: Autodesk EDM Server - Autodesk - C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ICQ Service - Unknown owner - C:\Program Files\ICQ6Toolbar\ICQ Service.exe

--
End of file - 8482 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2007-11-06 322880]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]
PCCBHO.CPCCBHO - C:\Program Files\Winferno\PC Confidential\PCCBHO.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2007-11-06 542016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{855F3B16-6D32-4fe6-8A56-BBB695989046} - ICQToolBar - C:\Program Files\ICQ6Toolbar\ICQToolBar.dll [2008-12-09 958200]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-08-12 339968]
"Soltek"=C:\WINDOWS.0\System32\autorun.exe [2001-10-29 61440]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-26 31016]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-08-17 81000]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2009-05-26 85160]
"hpqSRMon"=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2007-08-22 80896]
"AdobeCS4ServiceManager"=C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"=C:\Program Files\DAEMON Tools\daemon.exe [2007-09-18 171464]
"Skype"=C:\Program Files\Skype\\Phone\Skype.exe [2009-10-09 25623336]
"AdobeBridge"=C:\Program Files\Adobe\Adobe Bridge CS4\Bridge.exe [2008-08-28 13145448]
"ICQ"=C:\Program Files\ICQ6.5\ICQ.exe [2009-11-16 172792]

C:\Documents and Settings\All Users.WINDOWS.0\Nabídka Start\Programy\Po spuštění
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Documents and Settings\POLLY.POLY\Nabídka Start\Programy\Po spuštění
Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS.0\system32\Ati2evxx.dll [2004-08-12 86016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-26 2210608]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\ICQ6.5\ICQ.exe"="C:\Program Files\ICQ6.5\ICQ.exe:*:Enabled:ICQ6"
"C:\Program Files\Skype\Plugin Manager\skypePM.exe"="C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======File associations======

.scr - open - c:\WINDOWS.0\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 months======

2010-01-07 16:03:27 ----A---- C:\ComboFix.txt
2010-01-05 17:53:21 ----A---- C:\Boot.bak
2010-01-05 17:53:08 ----RASHD---- C:\cmdcons
2010-01-05 17:49:22 ----A---- C:\WINDOWS.0\NIRCMD.exe
2010-01-05 17:49:22 ----A---- C:\WINDOWS.0\MBR.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\zip.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\SWXCACLS.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\SWSC.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\SWREG.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\sed.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\PEV.exe
2010-01-05 17:49:21 ----A---- C:\WINDOWS.0\grep.exe
2010-01-05 17:47:48 ----D---- C:\WINDOWS.0\ERDNT
2010-01-05 17:45:48 ----D---- C:\Qoobox
2010-01-05 16:30:46 ----A---- C:\avenger.txt
2010-01-03 17:58:22 ----D---- C:\rsit
2010-01-03 17:48:25 ----D---- C:\Program Files\Trend Micro
2010-01-03 17:26:29 ----D---- C:\Avenger
2009-12-23 16:02:05 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\FLEXnet
2009-12-23 15:56:21 ----D---- C:\Program Files\Adobe Media Player
2009-12-23 15:53:24 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-12-23 15:48:28 ----D---- C:\Program Files\Common Files\Macrovision Shared
2009-12-21 20:32:16 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\BitZipper
2009-12-21 20:32:12 ----D---- C:\Program Files\BitZipper
2009-12-21 20:29:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Winferno
2009-12-21 20:24:26 ----A---- C:\WINDOWS.0\system32\WINUTIL5.DLL
2009-12-21 20:24:26 ----A---- C:\WINDOWS.0\system32\WINLCTL5.DLL
2009-12-21 20:24:24 ----A---- C:\WINDOWS.0\system32\CapiCom.dll
2009-12-21 18:29:52 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\HPAppData
2009-12-17 21:42:00 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Canon
2009-12-17 21:33:10 ----D---- C:\Program Files\Canon
2009-12-17 21:18:57 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\HP Product Assistant
2009-12-17 21:18:57 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\HP
2009-12-17 21:18:39 ----D---- C:\Program Files\Hewlett-Packard
2009-12-17 21:18:34 ----D---- C:\Program Files\Common Files\Hewlett-Packard
2009-12-17 21:18:14 ----D---- C:\Program Files\Common Files\HP
2009-12-17 21:17:24 ----DC---- C:\WINDOWS.0\system32\DRVSTORE
2009-12-17 21:17:09 ----D---- C:\Program Files\HP
2009-12-11 15:29:01 ----A---- C:\WINDOWS.0\system32\ptpusb.dll
2009-12-11 15:28:59 ----A---- C:\WINDOWS.0\system32\ptpusd.dll
2009-12-10 17:49:41 ----HDC---- C:\WINDOWS.0\$NtUninstallKB970430$
2009-12-10 17:49:35 ----HDC---- C:\WINDOWS.0\$NtUninstallKB974318$
2009-12-10 17:49:21 ----HDC---- C:\WINDOWS.0\$NtUninstallKB976325$
2009-12-10 17:49:12 ----HDC---- C:\WINDOWS.0\$NtUninstallKB973904$
2009-12-10 17:49:07 ----HDC---- C:\WINDOWS.0\$NtUninstallKB974392$
2009-12-10 17:48:56 ----HDC---- C:\WINDOWS.0\$NtUninstallKB971737$

======List of files/folders modified in the last 1 months======

2010-01-08 21:22:17 ----D---- C:\WINDOWS.0\Prefetch
2010-01-08 20:56:31 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Skype
2010-01-08 20:37:14 ----D---- C:\WINDOWS.0\Temp
2010-01-08 20:35:15 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\skypePM
2010-01-08 20:34:00 ----A---- C:\WINDOWS.0\system32\auto.ini
2010-01-08 20:04:25 ----A---- C:\WINDOWS.0\SchedLgU.Txt
2010-01-07 19:29:26 ----D---- C:\WINDOWS.0\system32\CatRoot2
2010-01-07 16:03:29 ----D---- C:\WINDOWS.0\system32\drivers
2010-01-07 15:58:09 ----D---- C:\WINDOWS.0
2010-01-07 15:58:09 ----A---- C:\WINDOWS.0\system.ini
2010-01-07 15:55:49 ----SD---- C:\WINDOWS.0\Tasks
2010-01-07 15:55:49 ----RD---- C:\Program Files
2010-01-07 15:54:04 ----D---- C:\WINDOWS.0\system32
2010-01-07 15:54:04 ----D---- C:\WINDOWS.0\AppPatch
2010-01-07 15:54:00 ----D---- C:\Program Files\Common Files
2010-01-05 18:48:06 ----D---- C:\Program Files\Mozilla Firefox
2010-01-05 18:01:46 ----SD---- C:\WINDOWS.0\Downloaded Program Files
2010-01-05 18:01:46 ----D---- C:\Program Files\ICQ6.5
2010-01-05 17:53:21 ----RASH---- C:\boot.ini
2010-01-03 17:40:03 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\ICQ
2009-12-25 14:05:29 ----D---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Adobe
2009-12-23 16:38:58 ----D---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Adobe
2009-12-23 16:38:57 ----D---- C:\Program Files\Adobe
2009-12-23 16:06:29 ----SD---- C:\Documents and Settings\All Users.WINDOWS.0\Data aplikací\Microsoft
2009-12-23 16:00:09 ----SHD---- C:\WINDOWS.0\Installer
2009-12-23 16:00:08 ----D---- C:\Config.Msi
2009-12-23 15:57:40 ----D---- C:\Program Files\Common Files\Adobe
2009-12-23 15:55:36 ----RSD---- C:\WINDOWS.0\Fonts
2009-12-17 21:59:36 ----SD---- C:\Documents and Settings\POLLY.POLY\Data aplikací\Microsoft
2009-12-17 21:58:52 ----HD---- C:\WINDOWS.0\inf
2009-12-17 21:19:57 ----D---- C:\WINDOWS.0\WinSxS
2009-12-17 21:18:42 ----D---- C:\WINDOWS.0\twain_32
2009-12-17 21:04:52 ----RSHDC---- C:\WINDOWS.0\system32\dllcache
2009-12-10 18:35:14 ----A---- C:\WINDOWS.0\system32\PerfStringBackup.INI
2009-12-10 17:49:38 ----A---- C:\WINDOWS.0\imsins.BAK
2009-12-10 17:49:11 ----HD---- C:\WINDOWS.0\$hf_mig$

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS.0\system32\drivers\Aavmker4.sys [2009-08-17 26944]
R1 aswSP;avast! Self Protection; C:\WINDOWS.0\system32\drivers\aswSP.sys [2009-08-17 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS.0\system32\drivers\aswTdi.sys [2009-08-17 51376]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS.0\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232]
R1 ISODisk;ISODisk; C:\WINDOWS.0\system32\drivers\ISODisk.sys [2006-04-26 9600]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS.0\System32\DRIVERS\kbdhid.sys [2004-08-17 14848]
R2 adfs;adfs; C:\WINDOWS.0\system32\drivers\adfs.sys [2008-08-14 74720]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS.0\system32\DRIVERS\aswFsBlk.sys [2009-08-17 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS.0\system32\drivers\aswMon2.sys [2009-08-17 94160]
R2 EIO;EIO; \??\C:\WINDOWS.0\system32\drivers\EIO.sys []
R3 aswRdr;aswRdr; C:\WINDOWS.0\system32\drivers\aswRdr.sys [2009-08-17 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS.0\System32\DRIVERS\ati2mtag.sys [2004-08-12 786944]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver; C:\WINDOWS.0\System32\DRIVERS\fetnd5.sys [2001-08-17 27165]
R3 hidusb;Ovladač třídy standardu HID; C:\WINDOWS.0\System32\DRIVERS\hidusb.sys [2001-10-25 9600]
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS.0\System32\DRIVERS\mouhid.sys [2001-10-25 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS.0\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS.0\System32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS.0\System32\DRIVERS\usbehci.sys [2004-08-03 26624]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS.0\System32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS.0\System32\DRIVERS\usbuhci.sys [2004-08-03 20480]
R3 VIAudio;Vinyl AC'97 Audio Controller (WDM); C:\WINDOWS.0\system32\drivers\viaudios.sys [2004-06-18 152192]
R3 vulfntrs;VIA USB Roothub Lower Filter; C:\WINDOWS.0\System32\Drivers\vulfntr.sys [2002-10-30 10240]
S3 ad5zxh83;ad5zxh83; C:\WINDOWS.0\system32\drivers\ad5zxh83.sys []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 usbprint;Třída USB Printer; C:\WINDOWS.0\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS.0\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS.0\System32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 vulfnths;VIA USB Host Controller Lower Filter; C:\WINDOWS.0\System32\Drivers\vulfnth.sys [2002-10-23 6912]
S4 IntelIde;IntelIde; C:\WINDOWS.0\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-08-17 18752]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS.0\System32\Ati2evxx.exe [2004-08-12 389120]
R2 Autodesk Data Management Job Dispatch;Autodesk Data Management Job Dispatch; C:\Program Files\Autodesk\Data Management Server 2009\Server\Dispatch\Connectivity.WindowsService.JobDispatch.exe [2008-02-18 32768]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-08-17 138680]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS.0\system32\svchost.exe [2004-08-17 14336]
R2 ICQ Service;ICQ Service; C:\Program Files\ICQ6Toolbar\ICQ Service.exe [2008-10-19 222456]
R2 MSSQL$AUTODESKVAULT;SQL Server (AUTODESKVAULT); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-01-22 29178224]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS.0\System32\svchost.exe [2004-08-17 14336]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS.0\System32\svchost.exe [2004-08-17 14336]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2007-02-10 89968]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-08-17 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-08-17 352920]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS.0\system32\svchost.exe [2004-08-17 14336]
S2 ATI Smart;ATI Smart; C:\WINDOWS.0\system32\ati2sgag.exe [2004-08-12 516096]
S2 Autodesk EDM Server;Autodesk EDM Server; C:\Program Files\Autodesk\Data Management Server 2009\Server\Webserver\Connectivity.EDMWS.Server.exe [2008-02-18 57344]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 Autodesk Licensing Service;Autodesk Licensing Service; C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe [2009-10-16 79360]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS.0\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-12-23 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-26 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-01-22 45272]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; c:\WINDOWS.0\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-01-22 242544]

-----------------EOF-----------------

Uživatelský avatar
Unlimited_Killer
Přítel fóra
Přítel fóra
Příspěvky: 1969
Registrován: 24 srp 2009 16:18

Re: ICQ posílá samo viry do CL

#14 Příspěvek od Unlimited_Killer »

0K, havěť už tam nevidím.
Jen dočistíme a otestujeme.

~~~

Stáhněte OTM na Plochu. Spusťte ho dvojklikem na OTM.exe, pokud máte Vistu, pravým tlačítkem na soubor -> Run as Administrator [spustit jako administrátor].
Do levého okna 'Paste Instructions for Items to be Moved' vkopírujte následující skript:

Kód: Vybrat vše

:reg
[HKLM\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://google.cz"
"Default_Search_URL"=-
[HKLM\Software\Microsoft\Internet Explorer\Search]
"SearchAssistant"=-
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-

:files
C:\Program Files\ICQ6Toolbar

:services
ICQ Service

:commands
[emptytemp]
[reboot]
Poté klikněte na červené tlačítko 'MoveIt!'.
V zeleném okně vpravo by se měl zobrazit log, ten vkopírujete sem do fóra. Pokud se zobrazí hláška k restartování, klikněte na Yes. Po restartu log najdete v C:\_OTM\MovedFiles

~~~

Otestujte na VirusTotal soubory:

Kód: Vybrat vše

C:\WINDOWS.0\System32\autorun.exe
Jednoduše tam vkopírujete cesty, co jsem napsal do code, když Vám to napíše, že soubor byl testován, dejte otestovat znovu. Poté jsem vložíte linky (odkazy) na jednotlivé testy.

~~~

Spusťte přejmenované HiJackThis - C:\Program Files\Trend Micro\HijackThis\jmeno_usera.exe
Klikněte na 'Do a system scan only'.
U níže uvedených položek udělejte fajfku do čtverečku a poté klikněte na 'Fix Checked'.
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra 'Tools' menuitem: PC Confidential - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: PC Confidential - {925DAB62-F9AC-4221-806A-057BFB1014AA} - C:\Program Files\Winferno\PC Confidential\PCConfidential.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
Pokud by tam nějaká položka nebyla, vynechte ji.

~~~

Odinstalujte ComboFix
Start >> Spustit >> vkopírujte do okénka:

Kód: Vybrat vše

ComboFix /Uninstall
>> stiskněte Enter
To odinstaluje ComboFix a smaže s ním související soubory a složky.

~~~

Stáhněte MBAM a postupujte podle popisu. Zatím nic nemažte, MBAM má občas falešné detekce.
Potom mi sem vložte log.
inactive

poly-filip
Návštěvník
Návštěvník
Příspěvky: 21
Registrován: 03 led 2010 17:53

Re: ICQ posílá samo viry do CL

#15 Příspěvek od poly-filip »

OTM :

All processes killed
Error: Unable to interpret <reg> in the current context!
Error: Unable to interpret <[HKLM\Software\Microsoft\Internet Explorer\Main]> in the current context!
Error: Unable to interpret <"Start Page"="http://google.cz"> in the current context!
Error: Unable to interpret <"Default_Search_URL"=-> in the current context!
Error: Unable to interpret <[HKLM\Software\Microsoft\Internet Explorer\Search]> in the current context!
Error: Unable to interpret <"SearchAssistant"=-> in the current context!
Error: Unable to interpret <[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]> in the current context!
Error: Unable to interpret <"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-> in the current context!
Error: Unable to interpret <[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]> in the current context!
Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]> in the current context!
Error: Unable to interpret <"{855F3B16-6D32-4fe6-8A56-BBB695989046}"=-> in the current context!
========== FILES ==========
C:\Program Files\ICQ6Toolbar folder moved successfully.
========== SERVICES/DRIVERS ==========
Service ICQ Service stopped successfully!
Service ICQ Service deleted successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: All Users.WINDOWS.0

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: Default User.WINDOWS.0
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService.NT AUTHORITY
->Temp folder emptied: 65716 bytes
->Temporary Internet Files folder emptied: 32902 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService.NT AUTHORITY
->Temp folder emptied: 32768 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Polly
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 13961290 bytes
->FireFox cache emptied: 24489290 bytes

User: POLLY.POLY
->Temp folder emptied: 14103 bytes
->Temporary Internet Files folder emptied: 5347231 bytes
->FireFox cache emptied: 96653234 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1152453 bytes
%systemroot%\System32 .tmp files removed: 2504 bytes
Windows Temp folder emptied: 35287 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 725038 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 136,00 mb


OTM by OldTimer - Version 3.1.4.0 log created on 01092010_112802

Files moved on Reboot...
File C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Temp\Perflib_Perfdata_560.dat not found!
File C:\WINDOWS.0\temp\_avast4_\Webshlock.txt not found!
C:\WINDOWS.0\temp\Perflib_Perfdata_5f0.dat moved successfully.

Registry entries deleted on Reboot...

Odpovědět