This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Help Please: Infection

76 min read

This thread's last reply is from November 22, 2006, 9:33 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Bob4

No, I already tried that. It did,t work.

srs
Just to let you know I haven't left. I am trying to find a scanner that I think will work. I would like to run at least one more before asking for another log. I wil be back.
Bob4

Thanks again for presevering with this.

srs
Well wasn't that fun tonight.. my wifes anti virus went bonkers tonight. No biggie thank goodness. Much easier having the machine right in front of you. ;)


OK srs let's try and see if we can't get at least one of these to work.
_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.



___________________________
  • Create a folder on your desktop called Sysclean.
  • Go to http://www.trendmicro.com/download/dcs.asp and download sysclean package to the folder you made.
  • Go to http://www.trendmicro.com/download/pattern.asp and download the Virus Pattern File (Official Pattern Release) to your desktop.
    This file will be called lptXXX.zip (XXX represents the version number)
  • Unzip lptXXX.zip and you'll get the file lpt$vpn.XXX. Read here how to unzip/extract properly.
  • Move the lpt$vpn.XXX to the Sysclean-folder you created on your desktop.
  • Open the sysclean-folder and doubleclick sysclean.com.
  • DO NOT Check: "Automatically clean or delete detected files".
  • Click scan.

Open your sysclean-folder and copy and paste the contents of sysclean.log in your next reply.


____________________

I would like to see another log from combo fix also please.

Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Bob4

Sorry for not responding sooner. For some reason it was not until a little while ago that I received notification that you had posted something. I will now attempt to do what you have suggested, and report back.

Thanks
srs
Whew, I thought I lost you. Feel free just to check back if you don't recieve an email. I usualy respond withing 24hrs.
Bob4

I could not get Kaspersky to run.

I am running the Trend program. As you asked, I unchecked "automatically delet or clean" option and ran the scan. It is now regularly asking whether I want to "clean", "delete" or "leave alone" whenever it detects a virus. I have been selecting "leave alone". I hope that is what you wanted me to do? There are very many of them.

srs
Bob4

With no disrespect to you (and I am very grateful for your effort and time), I think that the time may have come to make the hard decision and start again with a reformat and a clean instal of everything. I say that for 2 reasons. Firts, set out in the next post is part of the sysclean log. The full log is massive. Second as I was watching sysclean do its thing, it showed that there were literally thousands of the "xxyxyy.t" files all over my machine. Even if we were to remove the infection, how would I able to remove all those files?

What do you think?

srs
Bob4

sysclean log:

/--------------------------------------------------------------\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\--------------------------------------------------------------/


2006-11-15, 12:56:02, Running scanner "C:\Documents and Settings\Suresh Senathirajah\Desktop\Sysclean\TSC.BIN"...
2006-11-15, 12:56:10, Scanner "C:\Documents and Settings\Suresh Senathirajah\Desktop\Sysclean\TSC.BIN" has finished running.
2006-11-15, 12:56:10, TSC Log:

Damage Cleanup Engine (DCE) 3.98(Build 1012)
Windows XP(Build 2600: Service Pack 1)

Start time : Wed Nov 15 2006 12:56:03

Load Damage Cleanup Template (DCT) "C:\Documents and Settings\Suresh Senathirajah\Desktop\Sysclean\tsc.ptn" (version 804) [success]

Complete time : Wed Nov 15 2006 12:56:09
Execute pattern count(2970), Virus found count(0), Virus clean count(0), Clean failed count(0)

2006-11-15, 13:48:07, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 11/15/2006 12:56:27
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 923 (142578 Patterns) (2006/11/14) (392300)
Command Line: C:\Documents and Settings\Suresh Senathirajah\Desktop\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB C:\*.* /P=C:\Documents and Settings\Suresh Senathirajah\Desktop\Sysclean

C:\!KillBox\jao4p2q.exe [PE_LUDER.M-O]
C:\DELL\ATAPI.EXE [PE_LUDER.A]
C:\DELL\NTFSTYPE.EXE [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\ae6iqJ6.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\aL5D.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\avgas-setup-7.5.0.50.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\ccsetup134.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\rustbfix.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\A13fgdv.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\A55t2K5.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\a8VIDrF.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\AJfSsK0.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\AjvVg2M.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\aSh008g.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\bDRJnan.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\BfgXmðW.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\c13qwh4.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\C4ckG7X.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\c5A.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\C7I3NU8.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\cDa4f68.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\cFglxrt.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\CJ1VAEV.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\cl4tT3s.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\CQ6u3T4.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\D2HR6mL.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\dH316Fc.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\dj4u5Q7.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\DK5E67f.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\du6p8ex.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\eedG16K.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\F1E0w56.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\f3iBg3b.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\f5D0qX7.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\fM1O1al.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\FW7s6HP.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\g4r8CXa.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\ga84eCg.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\GlES545.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\gT414ts.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\GT7JvJ8.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\h6uV.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\HjbwR8c.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\HKV01wh.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\hmNFd01.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\holO2WF.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\hu3x35N.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\huE.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\i0asNk2.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\I6eKPLi.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\iIomvm3.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\iO2ntMT.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\iz6bd66.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\izoBwUw.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\j0b4s2S.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\j8R1O63.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\jbipMeG.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\jgfUkag.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Jl3Bpr3.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\k6J6QxN.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Kf47egI.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\KVfJ7mG.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\lKwaNs6.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\LoWX707.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\M544437.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\n3RFe12.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\nB633X8.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\NB8DQlm.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\nq7G1ur.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\nzou7sU.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\OH0Tli4.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\P2gseed.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\p821SnA.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Process.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\q02p6PF.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Q0d4455.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\q0n6.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\q5AG0WJ.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\qBIaeM1.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\qUd4p0A.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\RBn7083.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Reboot.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\restart.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\SiIj6E4.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\sn4t766.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\sswknFH.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\t2VDTð4.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\tfPHWCb.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\Tj14X4D.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\tjXhrEa.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\TlS7j3j.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\tSSXI6f.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\uDFNJ8b.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\UJiC47u.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\UKrxmee.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\unzip.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\uqQEIia.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\uUMk66u.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\V10bFOw.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\vde4m10.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\VIa1K2n.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\vj3V1a0.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\VOjAKlS.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\VPv5Kbu.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\vzQAl45.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\w5c53lw.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\w6cHCN0.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\WDb11LT.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\X3633XT.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\xJTI5fJ.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\xNdRX07.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\SmitfraudFix\SmitfraudFix\øc3PUdU.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Desktop\Unused Desktop Shortcuts\blbeta.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\Desktop\Unused Desktop Shortcuts\hijackthis_sfx.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\fiXvgg0.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\Fk5uP4V.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\kCehMIý.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\cwshredder.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\HijackThis.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\KillBox.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\l2mfix\Process.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\l2mfix\restart.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\l2mfix\zip.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\MicrosoftAntiSpywareInstall.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\SymNRT.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\UStorageTools2.65.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\My Documents\Down Loaded\winzip90.exe [PE_LUDER.A]
C:\Documents and Settings\Suresh Senathirajah\RahcX1W.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\XprKEIb.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\ø2fT.exe [PE_LUDER.M-O]
C:\Documents and Settings\Suresh Senathirajah\øodfoDe.exe [PE_LUDER.M-O]
C:\DRIVERS\MODEM\BCMSMD2K.EXE [PE_LUDER.A]
C:\DRIVERS\MODEM\BCMSMHOM.EXE [PE_LUDER.A]
C:\DRIVERS\MODEM\BCMSMLOG.EXE [PE_LUDER.A]
C:\DRIVERS\MODEM\BCMSMMON.EXE [PE_LUDER.A]
C:\DRIVERS\MODEM\BCMSMMSG.EXE [PE_LUDER.A]
C:\DRIVERS\MODEM\BCMSMU.EXE [PE_LUDER.A]
C:\DRIVERS\MOUSE\ONBOARD\APNTEX.EXE [PE_LUDER.A]
C:\DRIVERS\MOUSE\ONBOARD\APOINT.EXE [PE_LUDER.A]
C:\DRIVERS\MOUSE\ONBOARD\EZCAPT.EXE [PE_LUDER.A]
C:\DRIVERS\MOUSE\ONBOARD\UNINSTAP.EXE [PE_LUDER.A]
C:\DRIVERS\VIDEO\ADDON\DMCPL.EXE [PE_LUDER.A]
C:\DRIVERS\VIDEO\ADDON\NVSVC32.EXE [PE_LUDER.A]
C:\DRIVERS\VIDEO\ADDON\NWIZ.EXE [PE_LUDER.A]
C:\fixwareout\SUB\download.exe [PE_LUDER.A]
C:\fixwareout\SUB\unzip.exe [PE_LUDER.A]
C:\Garmin\MapSource.exe [PE_LUDER.A]
C:\Garmin\UnlockWizard.exe [PE_LUDER.A]
C:\GMER\gmer.exe [PE_LUDER.A]
C:\I386\ACTMOVIE.EXE [PE_LUDER.A]
C:\I386\AegisI5.exe [PE_LUDER.A]
C:\I386\AGENTSVR.EXE [PE_LUDER.A]
C:\I386\AHUI.EXE [PE_LUDER.A]
C:\I386\ALG.EXE [PE_LUDER.A]
C:\I386\ASR_PFU.EXE [PE_LUDER.A]
C:\I386\AT.EXE [PE_LUDER.A]
C:\I386\ATTRIB.EXE [PE_LUDER.A]
C:\I386\AUTOFMT.EXE [PE_LUDER.A]
C:\I386\BacsTray.exe [PE_LUDER.A]
C:\I386\BCMWLD2K.EXE [PE_LUDER.A]
C:\I386\BCMWLTRY.EXE [PE_LUDER.A]
C:\I386\BCMWLU00.EXE [PE_LUDER.A]
C:\I386\BOOTCFG.EXE [PE_LUDER.A]
C:\I386\BOOTOK.EXE [PE_LUDER.A]
C:\I386\CACLS.EXE [PE_LUDER.A]
C:\I386\CALC.EXE [PE_LUDER.A]
C:\I386\CB32.EXE [PE_LUDER.A]
C:\I386\CHKDSK.EXE [PE_LUDER.A]
C:\I386\CIPHER.EXE [PE_LUDER.A]
C:\I386\CLEANMGR.EXE [PE_LUDER.A]
C:\I386\cliconfg.exe [PE_LUDER.A]
C:\I386\CMMON32.EXE [PE_LUDER.A]
C:\I386\COMP.EXE [PE_LUDER.A]
C:\I386\CONF.EXE [PE_LUDER.A]
C:\I386\CONTROL.EXE [PE_LUDER.A]
C:\I386\ControlSuite.exe [PE_LUDER.A]
C:\I386\CONVERT.EXE [PE_LUDER.A]
C:\I386\CSCRIPT.EXE [PE_LUDER.A]
C:\I386\CSRSS.EXE [PE_LUDER.A]
C:\I386\CTFMON.EXE [PE_LUDER.A]
C:\I386\DFRGFAT.EXE [PE_LUDER.A]
C:\I386\DIANTZ.EXE [PE_LUDER.A]
C:\I386\DISKPERF.EXE [PE_LUDER.A]
C:\I386\DLIMPORT.EXE [PE_LUDER.A]
C:\I386\dmcpl.exe [PE_LUDER.A]
C:\I386\DRW\DWWIN.EXE [PE_LUDER.A]
C:\I386\DRWTSN32.EXE [PE_LUDER.A]
C:\I386\DSentry.exe [PE_LUDER.A]
C:\I386\DVDPLAY.EXE [PE_LUDER.A]
C:\I386\DVDUPGRD.EXE [PE_LUDER.A]
C:\I386\DWWIN.EXE [PE_LUDER.A]
C:\I386\dxdiag.exe [PE_LUDER.A]
C:\I386\eventcreate.exe [PE_LUDER.A]
C:\I386\EXPAND.EXE [PE_LUDER.A]
C:\I386\FINGER.EXE [PE_LUDER.A]
C:\I386\FIXMAPI.EXE [PE_LUDER.A]
C:\I386\FONTVIEW.EXE [PE_LUDER.A]
C:\I386\FORCEDOS.EXE [PE_LUDER.A]
C:\I386\FSUTIL.EXE [PE_LUDER.A]
C:\I386\FTP.EXE [PE_LUDER.A]
C:\I386\GPRESULT.EXE [PE_LUDER.A]
C:\I386\GPUPDATE.EXE [PE_LUDER.A]
C:\I386\ICWCONN2.EXE [PE_LUDER.A]
C:\I386\ICWRMIND.EXE [PE_LUDER.A]
C:\I386\INETWIZ.EXE [PE_LUDER.A]
C:\I386\IPCONFIG.EXE [PE_LUDER.A]
C:\I386\IPSEC6.EXE [PE_LUDER.A]
C:\I386\IPXROUTE.EXE [PE_LUDER.A]
C:\I386\ISIGNUP.EXE [PE_LUDER.A]
C:\I386\javaw.exe [PE_LUDER.A]
C:\I386\LABEL.EXE [PE_LUDER.A]
C:\I386\LNKSTUB.EXE [PE_LUDER.A]
C:\I386\LODCTR.EXE [PE_LUDER.A]
C:\I386\LOGAGENT.EXE [PE_LUDER.A]
C:\I386\LSASS.EXE [PE_LUDER.A]
C:\I386\MAKECAB.EXE [PE_LUDER.A]
C:\I386\migwiz.exe [PE_LUDER.A]
C:\I386\MMC.EXE [PE_LUDER.A]
C:\I386\MNMSRVC.EXE [PE_LUDER.A]
C:\I386\MOBSYNC.EXE [PE_LUDER.A]
C:\I386\MPLAY32.EXE [PE_LUDER.A]
C:\I386\MPNOTIFY.EXE [PE_LUDER.A]
C:\I386\MQSVC.EXE [PE_LUDER.A]
C:\I386\MQTGSVC.EXE [PE_LUDER.A]
C:\I386\MSDTC.EXE [PE_LUDER.A]
C:\I386\MSG.EXE [PE_LUDER.A]
C:\I386\MSHEARTS.EXE [PE_LUDER.A]
C:\I386\MSHTA.EXE [PE_LUDER.A]
C:\I386\MSTINIT.EXE [PE_LUDER.A]
C:\I386\narrator.exe [PE_LUDER.A]
C:\I386\NDDEAPIR.EXE [PE_LUDER.A]
C:\I386\NETSETUP.EXE [PE_LUDER.A]
C:\I386\NPPAGENT.EXE [PE_LUDER.A]
C:\I386\NTBACKUP.EXE [PE_LUDER.A]
C:\I386\NTSD.EXE [PE_LUDER.A]
C:\I386\NTVDM.EXE [PE_LUDER.A]
C:\I386\nvsvc32.exe [PE_LUDER.A]
C:\I386\nwiz.exe [PE_LUDER.A]
C:\I386\ODBCAD32.EXE [PE_LUDER.A]
C:\I386\ODBCCONF.EXE [PE_LUDER.A]
C:\I386\OOBEBALN.EXE [PE_LUDER.A]
C:\I386\openfiles.exe [PE_LUDER.A]
C:\I386\orun32.exe [PE_LUDER.A]
C:\I386\osk.exe [PE_LUDER.A]
C:\I386\OSUNINST.EXE [PE_LUDER.A]
C:\I386\ounins32_s.exe [PE_LUDER.A]
C:\I386\PATHPING.EXE [PE_LUDER.A]
C:\I386\PING.EXE [PE_LUDER.A]
C:\I386\RCP.EXE [PE_LUDER.A]
C:\I386\RDPCLIP.EXE [PE_LUDER.A]
C:\I386\RDSADDIN.EXE [PE_LUDER.A]
C:\I386\REG.EXE [PE_LUDER.A]
C:\I386\regtlib.exe [PE_LUDER.A]
C:\I386\REPLACE.EXE [PE_LUDER.A]
C:\I386\RESET.EXE [PE_LUDER.A]
C:\I386\RmvBACST.exe [PE_LUDER.A]
C:\I386\RSH.EXE [PE_LUDER.A]
C:\I386\RSM.EXE [PE_LUDER.A]
C:\I386\RSMSINK.EXE [PE_LUDER.A]
C:\I386\RSMUI.EXE [PE_LUDER.A]
C:\I386\RSTRUI.EXE [PE_LUDER.A]
C:\I386\RUNAS.EXE [PE_LUDER.A]
C:\I386\RUNONCE.EXE [PE_LUDER.A]
C:\I386\SAPISVR.EXE [PE_LUDER.A]
C:\I386\SC.EXE [PE_LUDER.A]
C:\I386\SCANOST.EXE [PE_LUDER.A]
C:\I386\SDBINST.EXE [PE_LUDER.A]
C:\I386\SECEDIT.EXE [PE_LUDER.A]
C:\I386\SETUP_WM.EXE [PE_LUDER.A]
C:\I386\SHRPUBW.EXE [PE_LUDER.A]
C:\I386\SHUTDOWN.EXE [PE_LUDER.A]
C:\I386\SMLOGSVC.EXE [PE_LUDER.A]
C:\I386\SORT.EXE [PE_LUDER.A]
C:\I386\SS3DFO.SCR [PE_LUDER.A]
C:\I386\SSBEZIER.SCR [PE_LUDER.A]
C:\I386\SSFLWBOX.SCR [PE_LUDER.A]
C:\I386\SSPIPES.SCR [PE_LUDER.A]
C:\I386\SSTEXT3D.SCR [PE_LUDER.A]
C:\I386\SVCHOST.EXE [PE_LUDER.A]
C:\I386\SYNCAPP.EXE [PE_LUDER.A]
C:\I386\systeminfo.exe [PE_LUDER.A]
C:\I386\TASKKILL.EXE [PE_LUDER.A]
C:\I386\tfswcmd.exe [PE_LUDER.A]
C:\I386\tfswctrl.exe [PE_LUDER.A]
C:\I386\TFTP.EXE [PE_LUDER.A]
C:\I386\TOUR.EXE [PE_LUDER.A]
C:\I386\TSCUPGRD.EXE [PE_LUDER.A]
C:\I386\TYPEPERF.EXE [PE_LUDER.A]
C:\I386\UNLODCTR.EXE [PE_LUDER.A]
C:\I386\UNREGMP2.EXE [PE_LUDER.A]
C:\I386\UNSECAPP.EXE [PE_LUDER.A]
C:\I386\UPS.EXE [PE_LUDER.A]
C:\I386\USERINIT.EXE [PE_LUDER.A]
C:\I386\usersid.exe [PE_LUDER.A]
C:\I386\USRMLNKA.EXE [PE_LUDER.A]
C:\I386\USRPRBDA.EXE [PE_LUDER.A]
C:\I386\USRSHUTA.EXE [PE_LUDER.A]
C:\I386\VERIFIER.EXE [PE_LUDER.A]
C:\I386\VSSADMIN.EXE [PE_LUDER.A]
C:\I386\VSSVC.EXE [PE_LUDER.A]
C:\I386\W32TM.EXE [PE_LUDER.A]
C:\I386\WB32.EXE [PE_LUDER.A]
C:\I386\WBEMTEST.EXE [PE_LUDER.A]
C:\I386\WINMGMT.EXE [PE_LUDER.A]
C:\I386\WINMINE.EXE [PE_LUDER.A]
C:\I386\WINNT32.EXE [PE_LUDER.A]
C:\I386\WINVER.EXE [PE_LUDER.A]
C:\I386\WISPTIS.EXE [PE_LUDER.A]
C:\I386\WLTRYSVC.EXE [PE_LUDER.A]
C:\I386\WMIADAP.EXE [PE_LUDER.A]
C:\I386\WMIPRVSE.EXE [PE_LUDER.A]
C:\I386\WMPLAYER.EXE [PE_LUDER.A]
C:\I386\WPABALN.EXE [PE_LUDER.A]
C:\I386\WPNPINST.EXE [PE_LUDER.A]
C:\I386\WSCRIPT.EXE [PE_LUDER.A]
C:\I386\WUAUCLT.EXE [PE_LUDER.A]
C:\I386\XCOPY.EXE [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\acroaum.exe [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\setup.exe [PE_LUDER.A]
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU_\setup.exe [PE_LUDER.A]
C:\Program Files\Apoint\ApntEx.exe [PE_LUDER.A]
C:\Program Files\Apoint\Apoint.exe [PE_LUDER.A]
C:\Program Files\Apoint\Ezcapt.exe [PE_LUDER.A]
C:\Program Files\Apoint\Uninstap.exe [PE_LUDER.A]
C:\Program Files\BigPond\BIGPOND.EXE [PE_LUDER.A]
C:\Program Files\CCleaner\ccleaner.exe [PE_LUDER.A]
C:\Program Files\CCleaner\mwrWnMO.exe [PE_LUDER.M-O]
C:\Program Files\CCleaner\nnm44js.exe [PE_LUDER.M-O]
C:\Program Files\CCleaner\plKjf5o.exe [PE_LUDER.M-O]
C:\Program Files\CCleaner\q2Cr815.exe [PE_LUDER.M-O]
C:\Program Files\CCleaner\uninst.exe [PE_LUDER.A]
C:\Program Files\CCleaner\xK4vMbU.exe [PE_LUDER.M-O]
C:\Program Files\Common Files\InstallShield\Driver\7\Intel 32\IDriver.exe [PE_LUDER.A]
C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe [PE_LUDER.A]
C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver2.exe [PE_LUDER.A]
C:\Program Files\Common Files\InstallShield\engine\6\Intel 32\knlwrap.exe [PE_LUDER.A]
C:\Program Files\Common Files\InstallShield\Professional\RunTime\0700\Intel32\DotNetInstaller.exe [PE_Luder.A]
C:\Program Files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe [PE_Luder.A]
C:\Program Files\Common Files\InstallShield\Professional\RunTime\10\01\Intel32\DotNetInstaller.exe [PE_Luder.A]
C:\Program Files\Common Files\Java\Update\Base Images\j2re1.4.2-b28\patch-j2re1.4.2_03-b02\patchjre.exe [PE_LUDER.A]
C:\Program Files\Common Files\Logitech\Bluetooth\SWHCIInit.exe [PE_LUDER.A]
C:\Program Files\Common Files\Logitech\WebColct\WebColct.exe [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\MODI\11.0\MSPOCRDC.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\NoteSync Forms\InkForm.exe [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\NoteSync Forms\VoiceFrm.exe [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOICONS.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\VS7JIT.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Real\Update\rnuninst.exe [PE_LUDER.A]
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [PE_LUDER.A]
C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSETUP.EXE [PE_LUDER.A]
C:\Program Files\Common Files\Symantec Shared\SEVINST.EXE [PE_LUDER.A]
C:\Program Files\CyberLink\PowerDVD\CLTEST.EXE [PE_LUDER.A]
C:\Program Files\CyberLink\PowerDVD\DDTESTER.EXE [PE_LUDER.A]
C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe [PE_LUDER.A]
C:\Program Files\Dell\Media Experience\PCM2.exe [PE_LUDER.A]
C:\Program Files\Dell\Media Experience\PCMService.exe [PE_LUDER.A]
C:\Program Files\Dell\QuickSet\powerset.exe [PE_LUDER.A]
C:\Program Files\Dell\QuickSet\quickset.exe [PE_LUDER.A]
C:\Program Files\Dell\SolutionCenter\DellSC.exe [PE_LUDER.A]
C:\Program Files\Dell\SolutionCenter\Register.exe [PE_LUDER.A]
C:\Program Files\ewido anti-spyware 4.0\a6n8Wr8.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\bzljuA8.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\CC68hg8.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\dABTv0t.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\egw7kMI.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\ewido.exe [PE_LUDER.A]
C:\Program Files\ewido anti-spyware 4.0\f1AG8X0.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\HpPJ3mi.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\l30u4gt.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\lRrax4j.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\nE1l6x3.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\nV14KuJ.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\o0p3Mub.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\PK7nS78.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\qKv8W8h.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\qXwb0lW.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\tO87lux.exe [PE_LUDER.M-O]
C:\Program Files\ewido anti-spyware 4.0\Uninstall.exe [PE_LUDER.A]
C:\Program Files\ewido anti-spyware 4.0\v62ANr2.exe [PE_LUDER.M-O]
C:\Program Files\Executive Software\Diskeeper\Connect.exe [PE_LUDER.A]
C:\Program Files\Executive Software\Diskeeper\DfrgNTFS.exe [PE_LUDER.A]
C:\Program Files\Executive Software\Diskeeper\DkIcon.exe [PE_LUDER.A]
C:\Program Files\Executive Software\Diskeeper\DkPerf.exe [PE_LUDER.A]
C:\Program Files\Executive Software\Diskeeper\DSK2-BUS.EXE [PE_LUDER.A]
C:\Program Files\Executive Software\Diskeeper Setup\setup.exe [PE_LUDER.A]
C:\Program Files\Google\Google Earth\GoogleEarth.exe [PE_LUDER.A]
C:\Program Files\Google\Google Earth\gpsbabel.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hpiris.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppavdx0.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppcfg.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppcopy.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppcoverpageeditor.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppdocsmart.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\HppFaxComMg.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppFaxUpload.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppgfax.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hpphpd.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppinstlinks.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppLnDest.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppphotoeditor.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppscan.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppsearchindex.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppsoftconfigpage.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\hppwp2wsupt.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\api_iris.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\api_iris_img_log.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\ljrcg_img.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\readiris.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\regipe.exe [PE_LUDER.A]
C:\Program Files\Hewlett-Packard\LaserJet 33xx\Readiris\Regri50.exe [PE_LUDER.A]
C:\Program Files\InstallShield Installation Information\{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}\setup.exe [PE_LUDER.A]
C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe [PE_LUDER.A]
C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterUninstall.exe [PE_LUDER.A]
C:\Program Files\iTunes\iTunes.exe [PE_LUDER.A]
C:\Program Files\iTunes\iTunesHelper.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\javaw.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\jpicpl32.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\keytool.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\kinit.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\klist.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\ktab.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\orbd.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\policytool.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\rmid.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\rmiregistry.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\servertool.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\bin\tnameserv.exe [PE_LUDER.A]
C:\Program Files\Java\j2re1.4.2_03\javaws\javaws.exe [PE_LUDER.A]
C:\Program Files\Lavasoft\Ad-Aware SE Personal\UNWISE.EXE [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\keyboard_tp.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\k_comm.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\k_play.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\k_work.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mediapad_tp.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mouse_tp.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mp_comm.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mp_distance.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mp_nearby.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\mp_work.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\m_feature.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\m_moves.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\r_comfort.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\fscommand\setpoint.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\LRFWiz.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\MediaPlayerMgr.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\k_comm.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\k_play.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\k_work.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\mp_comm.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\mp_distance.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\mp_nearby.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\mp_work.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\m_feature.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\m_moves.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\r_comfort.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\Quicktour\fscommand\setpoint.exe [PE_LUDER.A]
C:\Program Files\Logitech\SetPoint\quicktour.exe [PE_LUDER.A]
C:\Program Files\Messenger\MSMSGSIN.EXE [PE_LUDER.A]
C:\Program Files\Microsoft ActiveSync\CEAPPMGR.EXE [PE_LUDER.A]
C:\Program Files\Microsoft ActiveSync\dbexport.exe [PE_LUDER.A]
C:\Program Files\Microsoft ActiveSync\FormInst.exe [PE_LUDER.A]
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe [PE_LUDER.A]
C:\Program Files\Microsoft AntiSpyware\TempUpdates\microsoftantispywareinstall.exe [PE_LUDER.A]
C:\Program Files\Microsoft AntiSpyware\TempUpdates\windowsdefender.exe [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\1033\UNPACK.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\Business Contact Manager\EnableBCM.exe [PE_Luder.A]
C:\Program Files\Microsoft Office\OFFICE11\DSSM.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\MSE7.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\MSQRY32.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\PROFLWIZ.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\SELFCERT.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\UNBIND.EXE [PE_LUDER.A]
C:\Program Files\Microsoft Office\OFFICE11\WAVTOASF.EXE [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\COM\DISTRIB.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\COM\replmerg.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\COM\snapshot.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Backup\0818\osql.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\Backup\0818\svrnetcn.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\bcp.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\cnfgsvr.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\OSQL.EXE [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\scm.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SVRNETCN.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\Backup\0818\sqlservr.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\cmdwrap.exe [PE_LUDER.A]
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlmaint.exe [PE_LUDER.A]
C:\Program Files\Microsoft Visual Studio .NET 2003\Crystal Reports\confiis4.exe [PE_LUDER.A]
C:\Program Files\MSN\MSNCoreFiles\COPYMAR.EXE [PE_LUDER.A]
C:\Program Files\MSN\MSNCoreFiles\DW.EXE [PE_LUDER.A]
C:\Program Files\MSN\MSNCoreFiles\MSN6.EXE [PE_LUDER.A]
C:\Program Files\MSN\MSNCoreFiles\Setup\MSNUNIN.EXE [PE_LUDER.A]
C:\Program Files\MSN\MSNCoreFiles\UPDATE.EXE [PE_LUDER.A]
C:\Program Files\Norton AntiVirus\JlPn2rc.exe [PE_LUDER.M-O]
C:\Program Files\Norton AntiVirus\K8JTf08.exe [PE_LUDER.M-O]
C:\Program Files\Norton AntiVirus\wm18can.exe [PE_LUDER.M-O]
C:\Program Files\Real\RealPlayer\Setup\setup.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\assistant.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\audio.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\ereg.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\launchaco.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\mergemycmds.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\modmerge.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\natlink.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\nsadmin.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\nsbrowse.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\savewave.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\tutorial.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\vcmigrat.exe [PE_LUDER.A]
C:\Program Files\ScanSoft\NaturallySpeaking\Program\vocbldr.exe [PE_LUDER.A]
C:\Program Files\Sonic\DLA\dlaunin.exe [PE_LUDER.A]
C:\Program Files\Sonic\DLA\install\dla.exe [PE_LUDER.A]
Bob4

Combofx log:

Suresh Senathirajah - 06-11-15 13:53:26.54 Service Pack 1
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Suresh Senathirajah\Desktop"

((((((((((((((((((((((((((((((( Files Created from 2006-10-15 to 2006-11-15 ))))))))))))))))))))))))))))))))))


2006-11-15 13:11 5,705 --a------ C:\WINDOWS\SYSTEM32\rn5S84I.exe
2006-11-15 12:11 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\XprKEIb.exe
2006-11-13 13:29 5,705 --a------ C:\WINDOWS\SYSTEM32\HL8K86l.exe
2006-11-13 13:22 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\ae6iqJ6.exe
2006-11-10 11:07 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\RahcX1W.exe
2006-11-10 10:02 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\fiXvgg0.exe
2006-11-09 20:24 5,705 --a------ C:\WINDOWS\SYSTEM32\rekTIj0.exe
2006-11-09 20:24 16,457 ---h----- C:\WINDOWS\SYSTEM32\wservice.exe
2006-11-09 17:23 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\Fk5uP4V.exe
2006-11-09 11:15 5,705 --a------ C:\WINDOWS\SYSTEM32\i0Nk23L.exe
2006-11-09 11:02 5,705 --a------ C:\WINDOWS\SYSTEM32\MKcUFa2.exe
2006-11-09 10:56 5,705 --a------ C:\WINDOWS\SYSTEM32\qNekBES.exe
2006-11-08 23:59 5,705 --a------ C:\WINDOWS\SYSTEM32\RLUUch0.exe
2006-11-08 22:43 5,705 --a------ C:\Documents and Settings\Suresh Senathirajah\aL5D.exe
2006-11-08 20:53 5,705 --a------ C:\WINDOWS\SYSTEM32\a17a00B.exe
2006-11-08 14:50 5,705 --a------ C:\WINDOWS\SYSTEM32\C7TcI7I.exe
2006-11-08 13:25 80 --a------ C:\WINDOWS\gmer_uninstall.cmd
2006-11-07 23:44 5,705 C:\Documents and Settings\Suresh Senathirajah\o2fT.exe
2006-11-07 21:21 5,705 C:\Documents and Settings\Suresh Senathirajah\kCehMIy.exe
2006-11-07 15:41 65,568 --a------ C:\WINDOWS\SYSTEM32\lzx32.sys
2006-11-07 15:18 5,705 --a------ C:\WINDOWS\SYSTEM32\Lr2uX67.exe
2006-11-07 14:55 5,705 C:\Documents and Settings\Suresh Senathirajah\oodfoDe.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-15 12:14 -------- d-------- C:\Program Files\Norton AntiVirus
2006-11-15 12:14 -------- d-------- C:\Program Files\Modem Helper
2006-11-15 12:14 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-11-15 12:14 -------- d-------- C:\Program Files\Messenger
2006-11-15 12:14 -------- d-------- C:\Program Files\iTunes
2006-11-15 12:14 -------- d-------- C:\Program Files\HijackThis
2006-11-15 12:14 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
2006-11-15 12:13 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-11-15 12:13 -------- d-------- C:\Program Files\CCleaner
2006-11-15 12:13 -------- d-------- C:\Program Files\BigPond
2006-11-15 12:13 -------- d-------- C:\Program Files\Apoint
2006-11-08 08:39 -------- d-------- C:\Program Files\SymNetDrv
2006-11-08 08:39 -------- d-------- C:\Program Files\Symantec
2006-11-07 23:58 -------- d-------- C:\Program Files\Common Files
2006-11-07 23:20 -------- d-------- C:\Program Files\Windows NT
2006-11-07 23:20 -------- d-------- C:\Program Files\Windows Media Player
2006-11-07 23:20 -------- d-------- C:\Program Files\U-Storage Tools2.65
2006-11-07 23:20 -------- d-------- C:\Program Files\TrojanHunter 4.2
2006-11-07 23:20 -------- d-------- C:\Program Files\SpywareBlaster
2006-11-07 15:15 -------- d-------- C:\Program Files\Microsoft AntiSpyware
2006-11-07 13:43 -------- d-------- C:\Program Files\ewido anti-malware
2006-10-17 12:39 -------- d-------- C:\Documents and Settings\Suresh Senathirajah\Application Data\Google
2006-10-17 12:35 -------- d-------- C:\Program Files\Google


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"UpdateService"="C:\\WINDOWS\\System32\\wservice.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"UStorag"="c:\\program files\\u-storage tools2.65\\ustorage.exe sys_auto_run C:\\Program Files\\U-Storage Tools2.65"
"THGuard"="\"C:\\Program Files\\TrojanHunter 4.2\\THGuard.exe\""
"nwiz"="nwiz.exe /installquiet"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"HP SchedIndexer"="C:\\Program Files\\Hewlett-Packard\\LaserJet 33xx\\hppschedindexer.exe"
"HP AutoIndexer"="C:\\Program Files\\Hewlett-Packard\\LaserJet 33xx\\hppautoindexer.exe"
"Pofovery Service"="C:\\WINDOWS\\System32\\suchost.exe"
"UpdateService"="C:\\WINDOWS\\System32\\wservice.exe"
"adir"="C:\\WINDOWS\\System32\\adirss.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000006

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"taskdir"="C:\\WINDOWS\\System32\\taskdir.exe"
"UpdateService"="C:\\WINDOWS\\System32\\wservice.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"taskdir"="C:\\WINDOWS\\System32\\taskdir.exe"
"UpdateService"="C:\\WINDOWS\\System32\\wservice.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{825875B5-93F3-429D-FF34-660B206D897C}"="Scan Driver32"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-15 13:53:44.25
C:\ComboFix.txt ... 06-11-15 13:53
C:\ComboFix2.txt ... 06-11-08 13:00
Hello SRS,
If you think your ready to reformat and have everthing you need to do so. I have to suggest you do this. Damn I hate loosing. ;)
To be honest here I wouldn't save anything from this computer to replace later. As this is a file infector any( and from what I see in the log you sent) many programs / files may (are) be infected and may reintrduce the infection. Along with that many programs would have to be removed and replaced. And I could not guarantee the security of your computer when we were all done..
I do want to thank you for the chance to try and rid this thing for you. It was a valuble learning experience for me. Also frustrating for you I know.
If you think we havent been watched by many take a look at the views for this post. ;)

Heres a link by one of highly respected fighters for reformattning. It's also a good place to read about malware.
http://spyware-free.us/tutorials/reformat/
This topic is now closed due to inactivity. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.