![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
very aggressive virus
PLease help, I have been totally disabled by this virus. Keeps popping up adult friend finder and some winvirus ani virus. I ran grisoft, adaware, and cwshredder. here is the logfile, thanks.
Logfile of HijackThis v1.99.1 Scan saved at 4:26:25 PM, on 6/25/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\Tmasy\tmasy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Rob\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmasy\Tmasy.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
Let's see how aggressive it is.
1. Download & save this file to Desktop -> http://download.bleepingcomputer.com...a/ComboFix.exe 2. Double click on combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log & a fresh HJT log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
__________________
Question - what have you done for the community today? |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
Re: very aggressive virus
thanks for your help.
"Rob" - 2007-06-25 17:18:08 - ComboFix 07-06-26.4 - Service Pack 2 NTFS (((((((((((((((((((((((((((((((((((((((((((( V Log ))))))))))))))))))))))))))))))))))))))))))))))))))))))) C:\WINDOWS\system32\kekbplon.dll C:\WINDOWS\system32\rwemhgky.dll C:\WINDOWS\system32\vbcehdst.dll C:\WINDOWS\system32\ttvwa.bak1 C:\WINDOWS\system32\ttvwa.ini C:\WINDOWS\system32\tsdhecbv.ini C:\WINDOWS\system32\ttvwa.bak1 C:\WINDOWS\system32\ttvwa.ini C:\WINDOWS\system32\awvtt.dll C:\WINDOWS\system32\yayvtqn.dll * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\bold.log C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007 C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode C:\DOCUME~1\Rob\APPLIC~1.\icroso~1.net C:\DOCUME~1\Rob\APPLIC~1.\pppatc~1 C:\Documents and Settings\Rob.\err.log C:\Program Files\Common Files\winantispyware 2007 C:\Program Files\Common Files\winantispyware 2007\err.log C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe C:\Program Files\inetget2 C:\Program Files\poolsv C:\Program Files\poolsv\k11u72.exe C:\Program Files\poolsv\svhost.exe C:\Program Files\poolsv\wr-1-0000077.exe C:\Program Files\poolsv\YazzleBundle-1549.exe C:\Program Files\svhost C:\Program Files\svhost\wr-1-0000077.exe C:\Program Files\web buying C:\Program Files\web buying\v1.7.4\wbuninst.exe C:\Program Files\web buying\v1.7.4\webbuying.exe C:\Program Files\Windows Media Player\rtele.html C:\temp\0b9 C:\temp\0b9\tmpTF.log C:\temp\iee C:\temp\iee\tmpZTF.log C:\temp\tn3 C:\WINDOWS\b122.exe C:\WINDOWS\b136.exe C:\WINDOWS\cs_cache.ini C:\WINDOWS\poolsv.exe C:\WINDOWS\rau001978.exe C:\WINDOWS\retadpu1000106.exe C:\WINDOWS\retadpu77.exe C:\WINDOWS\svhost.exe C:\WINDOWS\system32\a4 C:\WINDOWS\system32\a4\mwspasrt83122.exe C:\WINDOWS\system32\drivers\core.cache.dsk C:\WINDOWS\system32\drivers\core.sys C:\WINDOWS\system32\kDS7yGOH.exe C:\WINDOWS\system32\o09PrEz C:\WINDOWS\system32\o09PrEz\o09PrEz1099.exe C:\WINDOWS\system32\win C:\WINDOWS\tasks\At1.job C:\WINDOWS\tasks\At10.job C:\WINDOWS\tasks\At11.job C:\WINDOWS\tasks\At12.job C:\WINDOWS\tasks\At13.job C:\WINDOWS\tasks\At14.job C:\WINDOWS\tasks\At15.job C:\WINDOWS\tasks\At16.job C:\WINDOWS\tasks\At17.job C:\WINDOWS\tasks\At18.job C:\WINDOWS\tasks\At19.job C:\WINDOWS\tasks\At2.job C:\WINDOWS\tasks\At20.job C:\WINDOWS\tasks\At21.job C:\WINDOWS\tasks\At22.job C:\WINDOWS\tasks\At23.job C:\WINDOWS\tasks\At24.job C:\WINDOWS\tasks\At3.job C:\WINDOWS\tasks\At4.job C:\WINDOWS\tasks\At5.job C:\WINDOWS\tasks\At6.job C:\WINDOWS\tasks\At7.job C:\WINDOWS\tasks\At8.job C:\WINDOWS\tasks\At9.job C:\WINDOWS\wr.txt C:\WINDOWS\xmlhelper2.dll ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_CORE -------\LEGACY_DOMAINSERVICE -------\LEGACY_NDNET1 -------\LEGACY_NET_AGENT -------\LEGACY_WINDOWS_OVERLAY_COMPONENTS -------\core -------\DomainService -------\NDnet1 -------\Net Agent ((((((((((((((((((((((((( Files Created from 2007-05-25 to 2007-06-25 ))))))))))))))))))))))))))))))) 2007-06-25 17:17 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-25 14:33 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2007-06-25 14:33 <DIR> d-------- C:\Program Files\Trend Micro 2007-06-25 13:05 2,580 --a------ C:\WINDOWS\system32\ctoxfqtw.exe 2007-06-25 12:53 122,900 --a------ C:\WINDOWS\system32\bknpsyci.exe 2007-06-25 12:50 4,628 --a------ C:\WINDOWS\system32\nrtapfnl.exe 2007-06-25 10:09 941,920 -r-hs---- C:\WINDOWS\hembviqA.exe 2007-06-25 10:09 46,592 --a------ C:\WINDOWS\hembviq.exe 2007-06-25 10:09 192,599 --a------ C:\WINDOWS\system32\qwinkndt.exe 2007-06-25 10:09 172,544 --a------ C:\WINDOWS\system32\xlocnio.dll 2007-06-25 10:08 79,872 --a------ C:\WINDOWS\system32\drivers\FOPN.sys 2007-06-25 10:08 <DIR> d-------- C:\WINDOWS\system32\A5 2007-06-25 10:08 <DIR> d-------- C:\WINDOWS\system32\A3 2007-06-25 10:08 <DIR> d-------- C:\WINDOWS\system32\A2 2007-06-25 10:08 <DIR> d-------- C:\WINDOWS\system32\A1 2007-06-25 10:08 <DIR> d-------- C:\Temp 2007-06-25 10:07 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-25 15:57:34 -------- d-----w C:\DOCUME~1\Rob\APPLIC~1\AdobeUM 2007-04-05 22:04:44 82,944 ----a-w C:\WINDOWS\system32\ws2_32.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {17be8de2-d0b7-440a-b008-259490885357}=C:\WINDOWS\system32\mciayle.dll [] {2B76833F-1842-478A-B3DD-F63945569602}=C:\Program Files\Internet Explorer\meqocaho83122.dll [2007-06-18 14:59] {53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04] {85589B5D-D53D-4237-A677-46B82EA275F3}=C:\WINDOWS\xmlhelper2.dll [] {857d16e9-fe06-4885-9463-1da08980ee28}=C:\WINDOWS\system32\xlocnio.dll [2007-06-25 10:09] {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:55] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 09:53 C:\WINDOWS\AGRSMMSG.exe] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "NoColorChoice"=0 (0x0) "NoSizeChoice"=0 (0x0) "NoDispScrSavPage"=0 (0x0) "NoDispCPL"=0 (0x0) "NoVisualStyleChoice"=0 (0x0) "NoDispSettingsPage"=0 (0x0) "NoDispAppearancePage"=0 (0x0) "NoDispBackgroundPage"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoActiveDesktopChanges"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSaveSettings"=0 (0x0) "NoThemesTab"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] Source= C:\Program Files\Windows Media Player\rtele.html FriendlyName= [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mciayle] mciayle.dll [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec7068b0-78bc-11da-9164-c51da37d5ccb}] AutoRun\command- E:\LaunchU3.exe HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4b218e3e-bc98-4770-93d3-2731b9329278} %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383} %SystemRoot%\system32\ie4uinit.exe ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-25 18 29Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** Completion time: 2007-06-25 18:08:54 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-06-25 18:08 C:\ComboFix2.txt ... 2007-04-12 22:37 --- E O F --- |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
hijack log
Logfile of HijackThis v1.99.1
Scan saved at 7:05:25 PM, on 6/25/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Trend Micro\Tmasy\Tmasy.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Rob\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {17be8de2-d0b7-440a-b008-259490885357} - C:\WINDOWS\system32\mciayle.dll (file missing) O2 - BHO: (no name) - {2B76833F-1842-478A-B3DD-F63945569602} - C:\Program Files\Internet Explorer\meqocaho83122.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xmlhelper2.dll (file missing) O2 - BHO: (no name) - {857d16e9-fe06-4885-9463-1da08980ee28} - C:\WINDOWS\system32\xlocnio.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmasy\Tmasy.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O20 - Winlogon Notify: mciayle - mciayle.dll (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe |
|
|
|
|
#5 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
Before fixing anything, open notepad and Copy/Paste the text in the box below into it:
Code:
@echo off For %%g in ( C:\WINDOWS\system32\mciayle.dll "C:\Program Files\Internet Explorer\meqocaho83122.dll" C:\WINDOWS\system32\xlocnio.dll ) do catchme -l nul -k %%g >nul echo.Please submit the file, catchme.zip located on Desktop pause exit Double click on Submit.bat & allow it to generate a zipped file on your Desktop called catchme.zip Please submit catchme.zip to this site → http://www.bleepingcomputer.com/subm....php?channel=4 The file must be uploaded before proceeding to the next step. --------------- Do a HijackThis scan & place a check next to these items and select "Fix checked": O2 - BHO: (no name) - {17be8de2-d0b7-440a-b008-259490885357} - C:\WINDOWS\system32\mciayle.dll (file missing) O2 - BHO: (no name) - {2B76833F-1842-478A-B3DD-F63945569602} - C:\Program Files\Internet Explorer\meqocaho83122.dll O2 - BHO: BHOAd - {85589B5D-D53D-4237-A677-46B82EA275F3} - C:\WINDOWS\xmlhelper2.dll (file missing) O2 - BHO: (no name) - {857d16e9-fe06-4885-9463-1da08980ee28} - C:\WINDOWS\system32\xlocnio.dll O20 - Winlogon Notify: mciayle - mciayle.dll (file missing) --------------- Open notepad and copy/paste the text in the quotebox below into it: Code:
File::
C:\WINDOWS\system32\ctoxfqtw.exe
C:\WINDOWS\system32\bknpsyci.exe
C:\WINDOWS\system32\nrtapfnl.exe
C:\WINDOWS\hembviqA.exe
C:\WINDOWS\hembviq.exe
C:\WINDOWS\system32\qwinkndt.exe
C:\WINDOWS\system32\xlocnio.dll
C:\WINDOWS\system32\drivers\FOPN.sys
Folder::
C:\WINDOWS\system32\A5
C:\WINDOWS\system32\A3
C:\WINDOWS\system32\A2
C:\WINDOWS\system32\A1
Registry::
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{17be8de2-d0b7-440a-b008-259490885357}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{2B76833F-1842-478A-B3DD-F63945569602}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
[-hkey_local_machine\software\microsoft\windows\currentversion\explorer\browser helper objects\{857d16e9-fe06-4885-9463-1da08980ee28}]
[-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mciayle]
![]() Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe Then post the resultant log --------------- Please perform an online scan using Internet Explorer at http://www.kaspersky.com/virusscanner Answer Yes, when prompted to install an ActiveX component.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%. --------------- In your next post, please include fresh logs from:
__________________
Question - what have you done for the community today? |
|
|
|
|
#6 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
This is to be performed after you have posted the required logs.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update. Updating Java:
__________________
Question - what have you done for the community today? |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
Re: very aggressive virus
combofix log, thank you so much for your help
"Rob" - 2007-06-26 11:00:57 - ComboFix 07-06-26.4 - Service Pack 2 NTFS Command switches used :: C:\Documents and Settings\Rob\Desktop\ComboFix-Do.txt ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\Program Files\Windows Media Player\rtele.html C:\WINDOWS\hembviq.exe C:\WINDOWS\hembviqA.exe C:\WINDOWS\system32\A1 C:\WINDOWS\system32\A2 C:\WINDOWS\system32\A2\wen2.exe C:\WINDOWS\system32\A3 C:\WINDOWS\system32\A3\wr620.exe C:\WINDOWS\system32\A5 C:\WINDOWS\system32\A5\bk53.exe C:\WINDOWS\system32\bknpsyci.exe C:\WINDOWS\system32\ctoxfqtw.exe C:\WINDOWS\system32\drivers\FOPN.sys C:\WINDOWS\system32\nrtapfnl.exe C:\WINDOWS\system32\qwinkndt.exe ((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 ))))))))))))))))))))))))))))))) 2007-06-25 17:17 49,152 --a------ C:\WINDOWS\nircmd.exe 2007-06-25 14:33 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys 2007-06-25 14:33 <DIR> d-------- C:\Program Files\Trend Micro 2007-06-25 10:08 <DIR> d-------- C:\Temp 2007-06-25 10:07 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-06-25 15:57:34 -------- d-----w C:\DOCUME~1\Rob\APPLIC~1\AdobeUM 2007-04-05 22:04:44 82,944 ----a-w C:\WINDOWS\system32\ws2_32.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04] {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:55] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 09:53 C:\WINDOWS\AGRSMMSG.exe] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "NoColorChoice"=0 (0x0) "NoSizeChoice"=0 (0x0) "NoDispScrSavPage"=0 (0x0) "NoDispCPL"=0 (0x0) "NoVisualStyleChoice"=0 (0x0) "NoDispSettingsPage"=0 (0x0) "NoDispAppearancePage"=0 (0x0) "NoDispBackgroundPage"=0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoActiveDesktopChanges"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSaveSettings"=0 (0x0) "NoThemesTab"=0 (0x0) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ec7068b0-78bc-11da-9164-c51da37d5ccb}] AutoRun\command- E:\LaunchU3.exe HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4b218e3e-bc98-4770-93d3-2731b9329278} %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383} %SystemRoot%\system32\ie4uinit.exe ************************************************************************** catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-06-26 11:02:02 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-06-26 11:02:27 C:\ComboFix-quarantined-files.txt ... 2007-06-26 11:02 C:\ComboFix2.txt ... 2007-06-25 18:08 C:\ComboFix3.txt ... 2007-04-12 22:37 --- E O F --- |
|
|
|
|
#8 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
Please perform an online scan using Internet Explorer at http://www.kaspersky.com/virusscanner
Answer Yes, when prompted to install an ActiveX component.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
__________________
Question - what have you done for the community today? |
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
Re: very aggressive virus
Having trouble with Kapersky, something about my security setting which I cannot alter. I will work on it. here is the hjt.
Logfile of HijackThis v1.99.1 Scan saved at 12:02:17 PM, on 6/26/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Trend Micro\Tmasy\Tmasy.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\DOCUME~1\Rob\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 O4 - Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmasy\Tmasy.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe |
|
|
|
|
#10 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
If you cannot get Kaspersky to work, try this other scanner:
![]() Please perform an online scan using Internet Explorer at this website - http://www.bitdefender.com/scan8/ie.html Under SCANNING OPTIONS, use the following Settings:
Once finished, click on the Details button to view the results. To the upper right of the results you will see an option saying "Click here to export the scan results" Post the log of the scan results in your next reply
__________________
Question - what have you done for the community today? |
|
|
|
|
#11 (permalink) |
|
Registered User
Join Date: Jan 2005
Posts: 47
OS: XP
|
Re: very aggressive virus
sorry for the lapse, i was out of town. here is the bit report
BitDefender Online Scanner Scan report generated at: Sat, Jun 30, 2007 - 10:29:54 Scan path: C:\; Statistics Time 00:33:11 Files 106273 Folders 2606 Boot Sectors 2 Archives 870 Packed Files 7911 Results Identified Viruses 28 Infected Files 63 Suspect Files 4 Warnings 0 Disinfected 0 Deleted Files 67 Engines Info Virus Definitions 636076 Engine build AVCORE v1.0 (build 2410) (i386) (Jun 12 2007 21:08:27) Scan plugins 14 Archive plugins 38 Unpack plugins 6 E-mail plugins 6 System plugins 1 Scan Settings First Action Disinfect Second Action Delete Heuristics Yes Enable Warnings Yes Scanned Extensions *; Exclude Extensions Scan Emails Yes Scan Archives Yes Scan Packed Yes Scan Files Yes Scan Boot Yes Scanned File Status C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir Infected with: Trojan.Downloader.VB.VDP C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir Disinfection failed C:\QooBox\Quarantine\C\Program Files\poolsv\k11u72.exe.vir Deleted C:\QooBox\Quarantine\C\Program Files\poolsv\svhost.exe.vir Suspected of: Generic.Malware.SB.E906854C C:\QooBox\Quarantine\C\Program Files\poolsv\svhost.exe.vir Disinfection failed C:\QooBox\Quarantine\C\Program Files\poolsv\svhost.exe.vir Deleted C:\QooBox\Quarantine\C\Program Files\poolsv\wr-1-0000077.exe.vir Infected with: Trojan.Downloader.Agent.YEG C:\QooBox\Quarantine\C\Program Files\poolsv\wr-1-0000077.exe.vir Disinfection failed C:\QooBox\Quarantine\C\Program Files\poolsv\wr-1-0000077.exe.vir Deleted C:\QooBox\Quarantine\C\Program Files\svhost\wr-1-0000077.exe.vir Infected with: Trojan.Downloader.Agent.YEG C:\QooBox\Quarantine\C\Program Files\svhost\wr-1-0000077.exe.vir Disinfection failed C:\QooBox\Quarantine\C\Program Files\svhost\wr-1-0000077.exe.vir Deleted C:\QooBox\Quarantine\C\Program Files\Web Buying\v1.7.4\webbuying.exe.vir Infected with: MemScan:Trojan.Agent.AOM C:\QooBox\Quarantine\C\Program Files\Web Buying\v1.7.4\webbuying.exe.vir Disinfection failed C:\QooBox\Quarantine\C\Program Files\Web Buying\v1.7.4\webbuying.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Trojan.Popwin.BK C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Deleted C:\QooBox\Quarantine\C\WINDOWS\b122.exe.vir=>(NSIS o) Update failed C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Rootkit.Agent.EV C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir=>(NSIS o)=>lzma_solid_nsis0002 Deleted C:\QooBox\Quarantine\C\WINDOWS\b136.exe.vir=>(NSIS o) Update failed C:\QooBox\Quarantine\C\WINDOWS\hembviq.exe.vir Infected with: Trojan.Zlob.AVP C:\QooBox\Quarantine\C\WINDOWS\hembviq.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\hembviq.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\hembviqA.exe.vir Infected with: Trojan.Click.JX C:\QooBox\Quarantine\C\WINDOWS\hembviqA.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\hembviqA.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\retadpu1000106.exe.vir Infected with: Trojan.Downloader.Agent.YFI C:\QooBox\Quarantine\C\WINDOWS\retadpu1000106.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\retadpu1000106.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\retadpu77.exe.vir Infected with: Trojan.Downloader.Agent.YFI C:\QooBox\Quarantine\C\WINDOWS\retadpu77.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\retadpu77.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\svhost.exe.vir Suspected of: Generic.Malware.SB.E906854C C:\QooBox\Quarantine\C\WINDOWS\svhost.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\svhost.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\A3\wr620.exe.vir Infected with: Trojan.Downloader.JISG C:\QooBox\Quarantine\C\WINDOWS\system32\A3\wr620.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\A3\wr620.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\A4\mwspasrt83122.exe.vir Infected with: Dropped:Trojan.Downloader.Adload.NCJ C:\QooBox\Quarantine\C\WINDOWS\system32\A4\mwspasrt83122.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\A4\mwspasrt83122.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\A5\bk53.exe.vir Infected with: MemScan:Trojan.Zlob.AVP C:\QooBox\Quarantine\C\WINDOWS\system32\A5\bk53.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\A5\bk53.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\awvtt.dll.vir Infected with: MemScan:Trojan.Virtumod.ALX C:\QooBox\Quarantine\C\WINDOWS\system32\awvtt.dll.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\awvtt.dll.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\bknpsyci.exe.vir Infected with: Trojan.Fotomoto.A C:\QooBox\Quarantine\C\WINDOWS\system32\bknpsyci.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\bknpsyci.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\ctoxfqtw.exe.vir Infected with: Trojan.LowZones.SA C:\QooBox\Quarantine\C\WINDOWS\system32\ctoxfqtw.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\ctoxfqtw.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\core.sys.vir Infected with: Rootkit.Agent.EV C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\core.sys.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\core.sys.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\kDS7yGOH.exe.vir Infected with: BehavesLike:Win32.ExplorerHijack C:\QooBox\Quarantine\C\WINDOWS\system32\kDS7yGOH.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\kDS7yGOH.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\kekbplon.dll.vir Infected with: Trojan.Spy.VBStat.B C:\QooBox\Quarantine\C\WINDOWS\system32\kekbplon.dll.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\nrtapfnl.exe.vir Infected with: Trojan.Clicker.Agent.NP C:\QooBox\Quarantine\C\WINDOWS\system32\nrtapfnl.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\nrtapfnl.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\o09PrEz\o09PrEz1099.exe.vir Infected with: Trojan.Downloader.VB.VDP C:\QooBox\Quarantine\C\WINDOWS\system32\o09PrEz\o09PrEz1099.exe.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\o09PrEz\o09PrEz1099.exe.vir Deleted C:\QooBox\Quarantine\C\WINDOWS\system32\yayvtqn.dll.vir Infected with: MemScan:Trojan.Virtumod.AMA C:\QooBox\Quarantine\C\WINDOWS\system32\yayvtqn.dll.vir Disinfection failed C:\QooBox\Quarantine\C\WINDOWS\system32\yayvtqn.dll.vir Deleted C:\QooBox\Quarantine\catchme2007-06-25_180628.76.zip=>core.sys Infected with: Rootkit.Agent.EV C:\QooBox\Quarantine\catchme2007-06-25_180628.76.zip=>core.sys Disinfection failed C:\QooBox\Quarantine\catchme2007-06-25_180628.76.zip=>core.sys Deleted C:\QooBox\Quarantine\catchme2007-06-25_180628.76.zip Updated C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>meqocaho83122.dll Infected with: Trojan.Downloader.Adload.NCJ C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>meqocaho83122.dll Disinfection failed C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>meqocaho83122.dll Deleted C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip Updated C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>xlocnio.dll Infected with: Trojan.Agent.AOM C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>xlocnio.dll Disinfection failed C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip=>xlocnio.dll Deleted C:\QooBox\Quarantine\catchme2007-06-26_110200.31.zip Updated C:\QooBox\Quarantine\WINDOWS\system32\winlogon.exe.vir Infected with: Trojan.Keylogger.iOpus.A C:\QooBox\Quarantine\WINDOWS\system32\winlogon.exe.vir Disinfection failed C:\QooBox\Quarantine\WINDOWS\system32\winlogon.exe.vir Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP407\A0019540.exe Infected with: Trojan.Keylogger.iOpus.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP407\A0019540.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP407\A0019540.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP409\A0019582.exe Infected with: Trojan.Keylogger.iOpus.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP409\A0019582.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP409\A0019582.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP417\A0020957.exe Infected with: Trojan.Keylogger.iOpus.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP417\A0020957.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP417\A0020957.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024550.exe Infected with: Trojan.Downloader.Agent.YEG C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024550.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024550.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024551.exe Infected with: Trojan.Downloader.Agent.YFI C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024551.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024551.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024560.exe Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024560.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024560.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024561.exe Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024561.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024561.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024598.exe Infected with: Trojan.Downloader.TSUpdate.D C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024598.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024598.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024600.exe Infected with: Trojan.Downloader.Zlob.BQW C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024600.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024600.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024609.exe Infected with: Trojan.Dropper.Zeno.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024609.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024609.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024610.exe Infected with: Trojan.Dropper.Zeno.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024610.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024610.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024613.exe Infected with: Trojan.Downloader.Agent.AMG C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024613.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0024613.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026623.dll Infected with: Trojan.Dropper.Searchy.B C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026623.dll Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026623.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026624.dll Infected with: Trojan.Dropper.Searchy.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026624.dll Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026624.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026625.dll Infected with: Trojan.Dropper.Searchy.C C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026625.dll Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP472\A0026625.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026638.exe Infected with: Trojan.Downloader.Agent.YFI C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026638.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026638.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026639.exe Infected with: Trojan.Downloader.Agent.YFI C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026639.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026639.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026640.exe Infected with: BehavesLike:Win32.ExplorerHijack C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026640.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026640.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026642.exe Infected with: MemScan:Trojan.Agent.AOM C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026642.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026642.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026643.exe Infected with: Dropped:Trojan.Downloader.Adload.NCJ C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026643.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026643.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026645.exe Infected with: Trojan.Downloader.VB.VDP C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026645.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026645.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026646.exe Suspected of: Generic.Malware.SB.E906854C C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026646.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026646.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026647.exe Infected with: Trojan.Downloader.Agent.YEG C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026647.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026647.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026649.exe Infected with: Trojan.Downloader.Agent.YEG C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026649.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026649.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026650.exe Infected with: Trojan.Downloader.VB.VDP C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026650.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026650.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026651.exe=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Trojan.Popwin.BK C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026651.exe=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026651.exe=>(NSIS o)=>lzma_solid_nsis0002 Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026651.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026652.exe=>(NSIS o)=>lzma_solid_nsis0002 Infected with: Rootkit.Agent.EV C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026652.exe=>(NSIS o)=>lzma_solid_nsis0002 Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026652.exe=>(NSIS o)=>lzma_solid_nsis0002 Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026652.exe=>(NSIS o) Update failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026655.exe Suspected of: Generic.Malware.SB.E906854C C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026655.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026655.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026658.dll Infected with: Trojan.Spy.VBStat.B C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026658.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026663.sys Infected with: Rootkit.Agent.EV C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026663.sys Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026663.sys Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026664.dll Infected with: MemScan:Trojan.Virtumod.ALX C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026664.dll Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026664.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026665.dll Infected with: MemScan:Trojan.Virtumod.AMA C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026665.dll Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026665.dll Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026739.exe Infected with: MemScan:Trojan.Zlob.AVP C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026739.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026739.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026740.exe Infected with: Trojan.Downloader.JISG C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026740.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026740.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026742.exe Infected with: Trojan.LowZones.SA C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026742.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026742.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026743.exe Infected with: Trojan.Fotomoto.A C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026743.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026743.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026744.exe Infected with: Trojan.Clicker.Agent.NP C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026744.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026744.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026745.exe Infected with: Trojan.Click.JX C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026745.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026745.exe Deleted C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026746.exe Infected with: Trojan.Zlob.AVP C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026746.exe Disinfection failed C:\System Volume Information\_restore{738BF8DB-BEF3-4B97-95AA-8296109F9F31}\RP473\A0026746.exe Deleted Last edited by sUBs; 06-30-2007 at 10:12 AM. |
|
|
|
|
#12 (permalink) |
|
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
Join Date: May 2005
Posts: 24,410
OS: N/A
|
Re: very aggressive virus
Log looks good. It didn't find anything that was unexpected.
C:\QooBox\ is ComboFix's quarantine folder. You can safely delete it C:\System Volume Information\ is where System Restore's cache is stored. Whatever is in there can't harm you unless you choose to perform a manual restore. Nevertheless, we shall be reseting/clearing the cache in a little while ---------------------- Now that your system is clean, kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein - http://computercops.biz/postlite7736-.html After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved.
__________________
Question - what have you done for the community today? |
|
|
| Thread Tools | |
|
|