Hi pskelley,
Here we go:
ComboFix 07-08-04.3 - "ROBERIO" 2007-08-08 10:38:46.3 [GMT -3:00] - NTFS
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1046.18.Verdadeiro
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp1.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp28.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp2A.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp3.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp52.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp6.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp67.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp71.tmp.exe
C:\DOCUME~1\ROBERIO\DADOSD~1\tmp74.tmp.exe
C:\WINDOWS\system32\dn906d962a.dat
C:\WINDOWS\system32\tmp3.tmp.dll
C:\WINDOWS\system32\tmp52.tmp.dll
C:\WINDOWS\system32\tmp74.tmp.dll
((((((((((((((((((((((((( Files Created from 2007-07-08 to 2007-08-08 )))))))))))))))))))))))))))))))
2007-08-07 23:16 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-08-07 23:10 <DIR> d-------- C:\DOCUME~1\ROBERIO\.housecall6.6
2007-08-07 18:57 131,385 --a------ C:\WINDOWS\ssqrro.dll
2007-08-06 12:39 131,376 --a------ C:\WINDOWS\khiiff.dll
2007-08-06 11:38 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-06 11:36 <DIR> d-------- C:\VundoFix Backups
2007-08-06 09:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DADOSD~1\Spybot - Search & Destroy
2007-08-06 01:34 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-05 20:24 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2007-08-05 20:05 61,440 --a------ C:\WINDOWS\system32\NI_DFD_1_5.dll
2007-08-05 20:05 393,216 --a------ C:\WINDOWS\system32\NI_IRC_1_2.dll
2007-08-05 19:22 56,320 --a------ C:\WINDOWS\system32\DeltTray.exe
2007-08-04 23:15 84,992 --a------ C:\WINDOWS\WebAssist.dll
2007-08-04 11:01 <DIR> d-------- C:\DOCUME~1\ROBERIO\DADOSD~1\uTorrent
2007-08-04 11:01 <DIR> d-------- C:\Arquivos de programas\uTorrent
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-08 07:24 --------- d-------- C:\Arquivos de programas\eMule
2007-08-06 01:58 --------- d-------- C:\Arquivos de programas\Wireless Combo
2007-08-06 01:55 --------- d-------- C:\Arquivos de programas\MFR6
2007-08-06 01:52 --------- d-------- C:\Arquivos de programas\GbPlugin
2007-08-06 01:48 --------- d-------- C:\Arquivos de programas\DAEMON Tools
2007-08-06 01:44 --------- d-------- C:\Arquivos de programas\Ultra Tag Editor
2007-08-06 01:32 --------- d-------- C:\Arquivos de programas\Sibelius Software
2007-08-06 00:58 --------- d-------- C:\Arquivos de programas\Native Instruments
2007-08-05 23:21 --------- d-------- C:\DOCUME~1\ROBERIO\DADOSD~1\BSplayer Pro
2007-08-04 15:11 --------- d-------- C:\Arquivos de programas\Total Video Converter
2007-08-03 23:41 --------- d-------- C:\DOCUME~1\ROBERIO\DADOSD~1\Sibelius Software
2007-07-19 09:57 5018 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-07-10 19:41 --------- d-------- C:\DOCUME~1\ROBERIO\DADOSD~1\Skype
2007-07-02 11:53 240 --a------ C:\WINDOWS\system32\RfmDat2.dat
2007-06-22 22:04 --------- d-------- C:\Arquivos de programas\PDFCreator
2007-06-13 20:05 --------- d-------- C:\Arquivos de programas\MSINSTR
2007-05-09 13:06 2096 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Ogg Vorbis Codec.dat
2007-05-09 13:06 164352 --a------ C:\WINDOWS\system32\SpoonUninstall.exe
2007-05-09 12:47 3003 --a------ C:\WINDOWS\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat
2007-05-09 12:46 574 --a------ C:\WINDOWS\system32\SpoonUninstall-dBPowerAMP Dalet codec R1.dat
2007-05-09 12:46 3460 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Musepack Codec.dat
2007-05-09 12:46 2159 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
2007-05-09 12:46 1936 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat
2007-05-09 12:45 747 --a------ C:\WINDOWS\system32\SpoonUninstall-dBPowerAMP AIFF codec r3.dat
2007-05-09 12:45 2294 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Monkeys Audio Codec.dat
2007-05-09 12:45 2077 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP FLAC Codec.dat
2007-05-09 12:41 20906 --a------ C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
2007-01-30 10:42 604 --ah----- C:\Arquivos de programas\STLL Notifier
2006-05-28 12:46 397306 --a------ C:\Arquivos de programas\wunauclt.zip
2006-05-28 12:46 397306 --a------ C:\Arquivos de programas\wunauclt.tbe
2007-01-27 12:46:02 56 --sh--r C:\WINDOWS\system32\00B4E7D36B.sys
2007-02-25 21:00:00 43 --sha-w C:\WINDOWS\Temp\removalfile.bat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{73ec3f30-e7bd-4721-a32b-a2556398b002}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{85589B5D-D53D-4237-A677-46B82EA275F3}]
2007-08-04 23:15 84992 --a------ C:\WINDOWS\WebAssist.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ptipbmf"="ptipbmf.dll" [2003-06-20 12:06 C:\WINDOWS\system32\ptipbmf.dll]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 11:22]
"nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 11:22]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 05:53 C:\WINDOWS\SOUNDMAN.EXE]
"AVG7_CC"="C:\ARQUIV~1\Grisoft\AVG7\avgcc.exe" [2007-04-19 07:18]
"Pinnacle WebUpdater"="C:\Arquivos de programas\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" [2006-03-26 11:10]
"DAEMON Tools"="C:\Arquivos de programas\DAEMON Tools\daemon.exe" [2005-12-10 11:57]
C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\
Activar programa de Leading Scroll.lnk - C:\Arquivos de programas\Wireless Combo\MulMouse.exe [2007-01-27 13:33:31]
Media Key.lnk - C:\Arquivos de programas\Wireless Combo\MagicKey.exe [2007-01-27 13:33:32]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E37CB5F0-51F5-4395-A808-5FA49E399F83}"= C:\Arquivos de programas\GbPlugin\gbieh.dll [2007-06-25 09:24 332616]
"{E37CB5F0-51F5-4395-A808-5FA49E399007}"= C:\Arquivos de programas\GbPlugin\gbiehabn.dll [2007-07-23 22:39 339376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mqbcan]
mqbcan.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\sstttrp.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Iniciar^Programas^Inicializar^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Menu Iniciar\Programas\Inicializar\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
"C:\Arquivos de programas\Arquivos comuns\Acronis\Schedule2\schedhlp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
C:\Arquivos de programas\Acronis\TrueImageHome\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
C:\Arquivos de programas\SyncroSoft\Pos\H2O\cledx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Arquivos de programas\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Arquivos de programas\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHmon05]
C:\WINDOWS\system32\hphmon05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD05]
C:\Arquivos de programas\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\I downloaded pirated Software from P2P ]
C:\WINDOWS\system32\Sims 2 Pets.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
"c:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\isuspm.exe" -startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
"C:\Arquivos de programas\Arquivos comuns\InstallShield\UpdateService\issch.exe" -start
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Arquivos de programas\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Arquivos de programas\Arquivos comuns\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Arquivos de programas\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Share-to-Web Namespace Daemon]
C:\Arquivos de programas\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Arquivos de programas\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Arquivos de programas\Java\jre1.5.0_11\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemOptimizer]
rundll32.exe "C:\WINDOWS\khiiff.dll",forkonce
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
C:\Arquivos de programas\Acronis\TrueImageHome\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"C:\Arquivos de programas\Winamp\Winampa.exe"
R0 fasttx2k;fasttx2k;C:\WINDOWS\system32\drivers\fasttx2k.sys
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys
R1 mapledxp;mapledxp;C:\WINDOWS\system32\drivers\mapledxp.SYS
R1 moufiltr;Mouse Filter Driver;C:\WINDOWS\system32\drivers\moufiltr.sys
R1 UsbFltr;WayTechMUSBFilterDriver;C:\WINDOWS\system32\drivers\UsbFltr.sys
R2 GbpSv;Gbp Service;C:\Arquivos de programas\GbPlugin\GbpSv.exe
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R3 3xHybrid;Pinnacle PCTV 110i service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
R3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS
R3 DELTA;Service for Delta Driver (WDM);C:\WINDOWS\system32\DRIVERS\delta.sys
R3 ElbyDelay;ElbyDelay;C:\WINDOWS\system32\Drivers\ElbyDelay.sys
R3 IntelC51;IntelC51;C:\WINDOWS\system32\DRIVERS\IntelC51.sys
R3 IntelC52;IntelC52;C:\WINDOWS\system32\DRIVERS\IntelC52.sys
R3 IntelC53;IntelC53;C:\WINDOWS\system32\DRIVERS\IntelC53.sys
R3 mohfilt;mohfilt;C:\WINDOWS\system32\DRIVERS\mohfilt.sys
S3 MPE;Filtro BDA MPE;C:\WINDOWS\system32\DRIVERS\MPE.sys
S3 MSSQL$PINNACLESYS;MSSQL$PINNACLESYS;"C:\Arquivos de programas\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS
S3 SQLAgent$PINNACLESYS;SQLAgent$PINNACLESYS;"C:\Arquivos de programas\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS
Contents of the 'Scheduled Tasks' folder
2007-06-25 21:00:00 C:\WINDOWS\Tasks\At1.job - C:\WINDOWS\dr.exe
2007-06-25 20:00:00 C:\WINDOWS\Tasks\At10.job - C:\WINDOWS\dr.exe
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At11.job
2007-06-25 11:00:00 C:\WINDOWS\Tasks\At12.job - C:\WINDOWS\system32\wunauclt.exe
2007-06-25 20:00:00 C:\WINDOWS\Tasks\At13.job - C:\WINDOWS\dr.exe
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At14.job - C:\WINDOWS\user32.exe
2007-06-25 11:00:00 C:\WINDOWS\Tasks\At15.job - C:\WINDOWS\system32\wunauclt.exe
2007-06-25 17:00:00 C:\WINDOWS\Tasks\At16.job - C:\WINDOWS\system32\wunauclt.exe
2007-06-25 21:00:00 C:\WINDOWS\Tasks\At17.job - C:\WINDOWS\dr.exe
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At18.job - C:\WINDOWS\system32\wunauclt.exe
2007-08-08 03:00:30 C:\WINDOWS\Tasks\At19.job - C:\WINDOWS\system32\3w2y18no.exe
2007-06-25 11:00:00 C:\WINDOWS\Tasks\At2.job - C:\WINDOWS\system32\wunauclt.exe
2007-08-08 04:00:30 C:\WINDOWS\Tasks\At20.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 05:00:30 C:\WINDOWS\Tasks\At21.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 06:01:29 C:\WINDOWS\Tasks\At22.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 07:00:30 C:\WINDOWS\Tasks\At23.job
2007-08-08 08:00:30 C:\WINDOWS\Tasks\At24.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 09:00:30 C:\WINDOWS\Tasks\At25.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 10:00:30 C:\WINDOWS\Tasks\At26.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 11:00:30 C:\WINDOWS\Tasks\At27.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 12:00:30 C:\WINDOWS\Tasks\At28.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 13:00:30 C:\WINDOWS\Tasks\At29.job
2007-06-25 17:00:00 C:\WINDOWS\Tasks\At3.job - C:\WINDOWS\system32\wunauclt.exe
2007-08-07 14:00:30 C:\WINDOWS\Tasks\At30.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 15:00:30 C:\WINDOWS\Tasks\At31.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 16:01:23 C:\WINDOWS\Tasks\At32.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 17:00:30 C:\WINDOWS\Tasks\At33.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 18:00:30 C:\WINDOWS\Tasks\At34.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 19:00:30 C:\WINDOWS\Tasks\At35.job
2007-08-07 20:00:30 C:\WINDOWS\Tasks\At36.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 21:00:30 C:\WINDOWS\Tasks\At37.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 22:00:30 C:\WINDOWS\Tasks\At38.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-07 23:00:30 C:\WINDOWS\Tasks\At39.job - C:\WINDOWS\system32\3w2y18no.exe
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At4.job - C:\WINDOWS\system32\wunauclt.exe
2007-08-08 00:00:30 C:\WINDOWS\Tasks\At40.job
2007-08-08 01:00:30 C:\WINDOWS\Tasks\At41.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-08 02:00:30 C:\WINDOWS\Tasks\At42.job - C:\WINDOWS\system32\3w2y18no.exe
2007-08-06 14:52:54 C:\WINDOWS\Tasks\At43.job
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At5.job - C:\WINDOWS\user32.exe
2007-06-25 20:00:00 C:\WINDOWS\Tasks\At6.job - C:\WINDOWS\dr.exe
2007-06-25 17:00:00 C:\WINDOWS\Tasks\At7.job - C:\WINDOWS\system32\wunauclt.exe
2007-06-25 23:00:00 C:\WINDOWS\Tasks\At8.job
2007-06-25 21:00:00 C:\WINDOWS\Tasks\At9.job - C:\WINDOWS\dr.exe
2007-06-28 05:37:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#7200#BR4AV2F071I5.job - C:\Arquivos de programas\HP\hpcoretech\comp\hpdarc.exe
2007-08-08 13:36:00 C:\WINDOWS\Tasks\HP Usg Daily.job
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-08-08 10:40:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-08 10:40:33
C:\ComboFix-quarantined-files.txt ... 2007-08-08 10:40
--- E O F ---
VundoFix V6.5.7
Checking Java version...
Sun Java not detected
Scan started at 10:31:13 2007-08-08
Listing files found while scanning....
C:\WINDOWS\cbxuur.dll
C:\WINDOWS\ruuxbc.ini
C:\WINDOWS\system32\tmp2A.tmp.dll
Beginning removal...
Attempting to delete C:\WINDOWS\cbxuur.dll
C:\WINDOWS\cbxuur.dll Has been deleted!
Attempting to delete C:\WINDOWS\ruuxbc.ini
C:\WINDOWS\ruuxbc.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\tmp2A.tmp.dll
C:\WINDOWS\system32\tmp2A.tmp.dll Has been deleted!
Performing Repairs to the registry.
Done!