• Registrarse
  • Iniciar sesión


  • Página 1 de 3 123 ÚltimoÚltimo
    Resultados 1 al 10 de 30

    Zoomex, searchab.com, tuvaro.com.(solucionado)

    Resumen del tema: Zoomex, searchab.com, tuvaro.com.(solucionado) - Hola, mi ordenador está infectado con zoomex. Además cuando abro internet explorer entra a la siguiente dirección: searchab.com. Hasta hoy luego se redireccionaba a google, ahora se va a Tuvaro.com. El ordenador ya iba muy ...

      
    1. #1
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      Bien Zoomex, searchab.com, tuvaro.com.(solucionado)

      Hola, mi ordenador está infectado con zoomex. Además cuando abro internet explorer entra a la siguiente dirección: searchab.com. Hasta hoy luego se redireccionaba a google, ahora se va a Tuvaro.com.

      El ordenador ya iba muy lento pero esta semana entró el zoomex y ya era literalmente inutilizable. Leí las indicaciones que habían recibido otros e hice lo siguiente:

      1. Pasé el malwarebytes anti-malware. (Informe abajo)
      2. Pasé ESET Online Scanner, que en dos ocasiones se quedó trabado en el mismo archivo, al 99% de escaneado y que no hizo la limpieza. (No puedo incluir el informe porque era de 1700 archivos infectados y supera el límite de carácteres permitidos -200.000 de más!!-)
      3. AT-Destroyer (by InfoSpyware), se quedó trabado al 22%. Tuve que reiniciar forzando el apagado y cuando volví a encender y entre al Internet Explorer apareció Tuvaro.com.

      ¿Qué puedo hacer?

      Muchas gracias.



      Malwarebytes Anti-Malware (Versión de Prueba) 1.70.0.1100
      www.malwarebytes.org

      Versión de la Base de Datos: v2013.03.13.12

      Windows Vista Service Pack 2 x86 NTFS
      Internet Explorer 9.0.8112.16421
      PROPIETARIO :: PROPIETARIO1 [administrador]

      Protección: Habilitado

      13/03/2013 21:47:57
      mbam-log-2013-03-13 (21-47-57).txt

      Tipos de Análisis: Análisis Completo (C:\|D:\|F:\|)
      Opciones de análisis activado: Memoria | Inicio | Registro | Sistema de archivos | Heurística/Extra | Heurística/Shuriken | PUP | PUM
      Opciones de análisis desactivados: P2P
      Objetos examinados: 508475
      Tiempo transcurrido: 12 hora(s), 26 minuto(s), 28 segundo(s)

      Procesos en Memoria Detectados: 1
      C:\ProgramData\Premium\ZoomEx\ZoomEx.exe (Trojan.Startpage) -> 200 -> Se eliminarán al reiniciar.

      Módulos de Memoria Detectados: 0
      (No se han detectado elementos maliciosos)

      Claves del Registro Detectados: 1
      HKCU\SOFTWARE\fcn (Rogue.Residue) -> En cuarentena y eliminado con éxito.

      Valores del Registro Detectados: 1
      HKLM\SOFTWARE\Mozilla\Firefox\extensions|[email protected] (Adware.ClickPotato) -> datos: C:\Program Files\ClickPotatoLite\bin\10.0.668.0\firefox\extensions -> En cuarentena y eliminado con éxito.

      Elementos de Datos del Registro Detectados: 1
      HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (Hijack.StartPage) -> Malo: (http://searchab.com/?aff=7&uid=4914d220-64f3-11e2-9c4f-00112ffb4d51) Bueno: (http://www.google.com) -> En cuarentena y reparado con éxito.

      Carpetas Detectadas: 1
      C:\$Recycle$ (Trojan.Spyeyes) -> En cuarentena y eliminado con éxito.

      Archivos Detectados: 1
      C:\ProgramData\Premium\ZoomEx\ZoomEx.exe (Trojan.Startpage) -> Se eliminarán al reiniciar.

      fin)

    2. #2
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      re: Zoomex, searchab.com, tuvaro.com

      Este es el informe del ESET, aunque le he quitado muchísimas líneas de caracteres que hacían referencia a lo mismo (creo).


      ------------------------------------------------------------------------------------------------------------
      ESETSmartInstaller@High as CAB hook log:
      OnlineScanner.ocx - registred OK
      ESETSmartInstaller@High as downloader log:
      all ok
      # version=8
      # OnlineScannerApp.exe=1.0.0.1
      # OnlineScanner.ocx=1.0.0.6920
      # api_version=3.0.2
      # EOSSerial=cfee9c2c1725334a971da0b80238c4bc
      # engine=13391
      # end=stopped
      # remove_checked=true
      # archives_checked=true
      # unwanted_checked=true
      # unsafe_checked=true
      # antistealth_checked=true
      # utc_time=2013-03-15 10:15:24
      # local_time=2013-03-15 11:15:24 (+0100, Hora estándar romance)
      # country="Spain"
      # lang=1033
      # osver=6.0.6002 NT Service Pack 2
      # compatibility_mode=5892 16776574 100 100 50242389 200918453 0 0
      # scanned=309611
      # found=1701
      # cleaned=0
      # scan_time=3153
      sh=43DD701963184ED313ACC7805C60F2F60E5AAABF ft=1 fh=c71c00114984669f vn="a variant of Win32/SProtector.A application" ac=I fn="C:\Program Files\ZoomEx\sprotector.dll"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run100A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run101E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1068.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run106A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1077.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1096.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run10A8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1109.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1126.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run114C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run11C1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1223.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run129D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run139A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run13E6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run13F1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run13F5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1430.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run153B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run153C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run153D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run153E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1540.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run154A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run1589.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run15D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run15E6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\ProgramData\Premium\ZoomEx\run15F9.tmp"


      ...

      ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPrivCnta13.zip"
      sh=CE0F047BBE41552D30529ECFB45B0B88335CCF01 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPrivCnta16.zip"
      sh=E473AA4D7A12909D9A31B2AD72DC8257F928D1C6 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPrivCnta4.zip"
      sh=2896D85DF5D560E5538A948C9FDAB061366B361C ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\WinPrivCnta7.zip"
      sh=A696C5A0D50145AFDE3D3A71F70B1C3006AC2199 ft=1 fh=da0003b6601dbc17 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\ProgramData\Zoomex\50ff38ad71dd6.dll"
      sh=468A5C00A055735868FB3987E653A3180B5170A0 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.F application" ac=I fn="C:\ProgramData\Zoomex\settings.ini"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run100A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run101E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1068.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run106A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1077.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1096.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run10A8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1109.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1126.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run114C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run11C1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1223.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run129D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run139A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run13E6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run13F1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run13F5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run1430.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run153B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run153C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run153D.tmp"

      ...

      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run997.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9970.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9973.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9974.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9977.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run99A4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9A02.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9A12.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9A13.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9A14.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9B2B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9B5C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9B77.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9C05.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9C78.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9CC3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9D4D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9D53.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9DAE.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9DD8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9E64.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9E69.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9E87.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9F96.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9FA1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\run9FB5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA059.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA08A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA098.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA140.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA174.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA181.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA200.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA22D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA24B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA2AD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA2CC.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA2DB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA2E5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA318.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA427.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA472.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA48E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA509.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA5D7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA673.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA691.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA6A1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA746.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA768.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA778.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA79B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA7DB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA815.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA83C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA923.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA940.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA955.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runA9A0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAA1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAA8E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAAF4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAB20.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runABC3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runACA9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runACCD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runACF3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAD2.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAD25.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runADD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runADF5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAE3E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAE61.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAEBC.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAEBE.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAF94.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runAF96.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB075.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB084.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB0BC.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB10.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB11.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB12F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB187.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB1C7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB1C8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB217.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB226.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB237.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB239.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB35F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB41C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB616.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB61A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB640.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB647.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB64D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB695.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB706.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB769.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB773.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB813.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB897.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB89C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB949.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB993.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB9C9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runB9F1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBA1C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBAAE.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBAB5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBBF7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBBFA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBC25.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBC26.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBC93.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBCE4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBD1B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBD3C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBD8C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBDA8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBDE8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBDF9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBDFB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBE04.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBE1B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBE1C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBEBA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBF8C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runBFE8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC02A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC115.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC256.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC2FA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC348.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC367.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC3B4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC3E8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC4B2.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC50E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC51D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC54F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC597.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC5F1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC67E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC6A0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC783.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC7AA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC7BA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC7D5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC84D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC865.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC8DD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC925.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC92D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runC9CF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCA0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCA24.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCA2A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCA75.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCAA2.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCAD3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCAE4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCB22.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCB25.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCB65.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCB8B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCC3D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCD07.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCD42.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCD56.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCEA4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCF19.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCF4B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runCF7E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD022.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD05C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD15.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD189.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD1BA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD262.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD2A4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD30A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD33A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD33F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD34E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD37B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD3DB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD40B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD53E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD5AE.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD5FE.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD62B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD62C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD636.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD66B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD6D4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD773.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD7B0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD869.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD8C5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD8C7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD91A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD95C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runD989.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDAD6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDBB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDC22.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDC26.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDC72.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDD0E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDDF7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDE2E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDEA5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runDF40.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE01D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE028.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE097.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE0A4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE110.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE172.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE17D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE1A0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE254.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE325.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE354.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE400.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE47E.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE4AB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE5A5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE5E4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE634.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE635.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE641.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE6B9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE757.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE77A.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE7AA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE7B9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE7C6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE7EB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE869.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE8CD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE8EB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE91F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE993.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runE9CF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEA98.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEAED.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEB52.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEC1C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEC38.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runED65.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEDAF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEE4F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEE50.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEEF7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEEF9.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runEFCF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF01F.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF086.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF0C7.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF0DB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF0E8.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF156.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF163.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF1A3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF233.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF24.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF246.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF25D.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF269.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF2AA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF2D1.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF31C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF40C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF428.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF47.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF511.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF572.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF59B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF5E2.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF5E5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF5EA.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF6F5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF76B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF772.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF7A3.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF8B4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF8E6.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF964.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runF9EF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFA46.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFA9C.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFAE5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFAEF.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFB43.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFB73.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFB85.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFBC5.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFBE2.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFC56.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFC7B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFC90.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFCCD.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFD93.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFDA4.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFE46.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFE73.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFE81.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFE92.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFEF0.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFEFB.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFF68.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFF7B.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFF94.tmp"
      sh=2A66DF9B2896C82E7F0ED2692674B76C3FD817E1 ft=1 fh=19a25d7f65819511 vn="Win32/GenUpdater application" ac=I fn="C:\Users\All Users\Premium\ZoomEx\runFFA8.tmp"
      sh=6F31285AEF8D70D04A3C5E5F432156BA619DC6DB ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPrivCnta13.zip"
      sh=CE0F047BBE41552D30529ECFB45B0B88335CCF01 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPrivCnta16.zip"
      sh=E473AA4D7A12909D9A31B2AD72DC8257F928D1C6 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPrivCnta4.zip"
      sh=2896D85DF5D560E5538A948C9FDAB061366B361C ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip worm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\WinPrivCnta7.zip"
      sh=A696C5A0D50145AFDE3D3A71F70B1C3006AC2199 ft=1 fh=da0003b6601dbc17 vn="a variant of Win32/Adware.MultiPlug.I application" ac=I fn="C:\Users\All Users\Zoomex\50ff38ad71dd6.dll"
      sh=468A5C00A055735868FB3987E653A3180B5170A0 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.F application" ac=I fn="C:\Users\All Users\Zoomex\settings.ini"
      sh=DBF418458ADFE065C2AD029A6C3497BB5E3361B0 ft=0 fh=0000000000000000 vn="Win32/Adware.MultiPlug.H application" ac=I fn="C:\Users\PROPIETARIO\AppData\Local\Google\Chrome\User Data\Default\Extensions\dijblbmdbjdlifpbkgnjfnfimpehhhpl\1\50ff38ad71b969.01237126.js"
      sh=06D315E206C62B3041C943EFC3A774CF3934CCDD ft=0 fh=0000000000000000 vn="a variant of Java/JShrink.A application" ac=I fn="C:\Users\PROPIETARIO\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63\e4836bf-30ffbb9e"
      sh=7D180877FA44B633A7CD2AE5791B459FC7E16D65 ft=1 fh=d2daedf55764cb4c vn="a variant of Win32/SoftonicDownloader.A application" ac=I fn="C:\Users\PROPIETARIO\Downloads\SoftonicDownloader39076.exe"
      sh=320D41DBACF5DC6395712D0626F1E13A7478DEA7 ft=1 fh=ba1d7954395bca7d vn="a variant of Win32/SoftonicDownloader.E application" ac=I fn="C:\Users\PROPIETARIO\Downloads\SoftonicDownloader_para_eset-online-scanner.exe"
      sh=52097269E4C910E10DC57C25884A12F9F9B3BF98 ft=1 fh=7895a005566480d9 vn="a variant of Win32/SoftonicDownloader.E application" ac=I fn="C:\Users\PROPIETARIO\Downloads\SoftonicDownloader_para_malwarebytes-anti-malware.exe"
      sh=00D8B88C2A97EDF5D5E7135ED611AFC416F5C690 ft=1 fh=f6d0513f6fedd190 vn="Win32/Toolbar.SearchSuite application" ac=I fn="F:\VIDEOS\MCP\iLividSetupV1.exe"

    3. #3
      Moderador
      Avatar de ErdrickBass
      Registrado
      jul 2009
      Ubicación
      Cd Juarez, Mex.
      Mensajes
      8.927

      re: Zoomex, searchab.com, tuvaro.com

      Hola 45marazabala
      Y bienvenido al foro de InfoSpyware

      Temas de interes y utilidad:
      Prueba lo siguiente porfavor:

      Descarga AdwCleaner:
      Ejecutalo de la siguiente forman y de preferencia colocalo en el escritorio:
      • Ejecutalo con todos los programas cerrados y Desactiva temporalmente el Antivirus y/o Antispyware. Si usas windows vista o seven ejecutalo como administrador.
      • Presionas y das en Supresion/Delete y esperas a que el programa haga lo suyo.
      • Al terminar se abrira un reporte en un archivo de texto, cuyo contenido deberas copiar y pegar en tu proxima respuesta.


      Nos traerias el reporte de AdwCleaner(C:\AdwCleaner[R*].txt, donde * es un numero dependiendo de cuantas veces lo ejecutaste). Nos comentarias ademas como sigue todo.

      Saludos
      El cielo azul es infinitamente alto y cristalino

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    4. #4
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      re: Zoomex, searchab.com, tuvaro.com

      Hola,
      Gracias por la bienvenida!
      Ejecuté AdwCleaner, aunque no me pidió indicaciones de dónde descargarse o de ejecutarlo como administrador (seguro que se podía, pero no se cómo).
      Este es el informe:
      # AdwCleaner v2.114 - Fichero creado el 16/03/2013 a 20:42:33
      # Actualizado el 05/03/2013 por Xplode
      # Sistema operativo : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
      # Usuario : PROPIETARIO - PROPIETARIO1
      # Modo de inicio : Normal
      # Ejecutado desde : C:\Users\PROPIETARIO\Downloads\adwcleaner.exe
      # Opción [Supresión]


      ***** [Servicios] *****


      ***** [Ficheros / Carpetas] *****

      Carpeta Suprimido : C:\Program Files\Conduit
      Carpeta Suprimido : C:\Program Files\softonic.com4
      Carpeta Suprimido : C:\ProgramData\Ask
      Carpeta Suprimido : C:\ProgramData\clsoft ltd
      Carpeta Suprimido : C:\ProgramData\InstallMate
      Carpeta Suprimido : C:\ProgramData\Zoomex
      Carpeta Suprimido : C:\Users\PROPIETARIO\AppData\LocalLow\Conduit
      Carpeta Suprimido : C:\Users\PROPIETARIO\AppData\LocalLow\ShoppingReport2
      Carpeta Suprimido : C:\Users\PROPIETARIO\AppData\LocalLow\softonic.com4
      Carpeta Suprimido : C:\Users\PROPIETARIO\AppData\LocalLow\Zoomex
      Fichero Suprimido : C:\Users\PROPIETARIO\AppData\Local\sqmqo.dat
      Fichero Suprimido : C:\Users\PROPIETARIO\AppData\Local\sqmqo_nav.dat
      Fichero Suprimido : C:\Users\PROPIETARIO\AppData\Local\sqmqo_navps.dat
      Fichero Suprimido : C:\Users\Public\Desktop\iLivid.lnk

      ***** [Registro] *****

      Clave Supprimida : HKCU\Software\AppDataLow\Software\Conduit
      Clave Supprimida : HKCU\Software\AppDataLow\Software\ShoppingReport2
      Clave Supprimida : HKCU\Software\AppDataLow\Software\softonic.com4
      Clave Supprimida : HKCU\Software\AppDataLow\SProtector
      Clave Supprimida : HKCU\Software\AppDataLow\Toolbar
      Clave Supprimida : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\clickpotatolitesa
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ScanQuery
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ShoppingReport2
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\softonic.com4 Toolbar
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0974848A-B5BC-49F2-9778-307742B4A55D}
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0974848A-B5BC-49F2-9778-307742B4A55D}
      Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6A1220C9-811A-44A1-B1FB-EA943B7097AD}
      Clave Supprimida : HKCU\Software\Softonic
      Clave Supprimida : HKCU\Software\StartSearch
      Clave Supprimida : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{0974848A-B5BC-49F2-9778-307742B4A55D}
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{6A1220C9-811A-44A1-B1FB-EA943B7097AD}
      Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
      Clave Supprimida : HKLM\SOFTWARE\Classes\Toolbar.CT2431232
      Clave Supprimida : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
      Clave Supprimida : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
      Clave Supprimida : HKLM\Software\Conduit
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0974848A-B5BC-49F2-9778-307742B4A55D}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6A1220C9-811A-44A1-B1FB-EA943B7097AD}
      Clave Supprimida : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
      Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\softonic.com4 Toolbar
      Clave Supprimida : HKLM\Software\softonic.com4
      Clave Supprimida : HKLM\SOFTWARE\Software
      Clave Supprimida : HKLM\Software\SP Global
      Clave Supprimida : HKLM\Software\SProtector
      Valor Supprimida : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{0974848A-B5BC-49F2-9778-307742B4A55D}]
      Valor Supprimida : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{0974848A-B5BC-49F2-9778-307742B4A55D}]
      Valor Supprimida : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{0974848A-B5BC-49F2-9778-307742B4A55D}]

      ***** [Navegadores] *****

      -\\ Internet Explorer v9.0.8112.16470

      [OK] El registro no contiene ninguna entrada ilegítima.

      -\\ Google Chrome v25.0.1364.172

      Fichero : C:\Users\PROPIETARIO\AppData\Local\Google\Chrome\User Data\Default\Preferences

      [OK] El fichero no contiene ninguna entrada ilegítima.

      *************************

      AdwCleaner[S1].txt - [5592 octets] - [16/03/2013 20:42:33]

      ########## EOF - C:\AdwCleaner[S1].txt - [5652 octets] ##########

      He mirado en Panel de control, Programas, y ya no está el ZoomEx. Cambié la página de inicio del IE en Opciones de Internet y parece que fuera bien.

      De todas maneras, sigue muuuy lento. El Norton me abre alertas por uso intensivo de disco. Cuando doy una orden "piensa" un buen rato.

      ¿Se podría hacer algo más?

      Mil gracias por la ayuda!!

      Saludos,

    5. #5
      Moderador
      Avatar de ErdrickBass
      Registrado
      jul 2009
      Ubicación
      Cd Juarez, Mex.
      Mensajes
      8.927

      re: Zoomex, searchab.com, tuvaro.com

      Buenas

      aunque no me pidió indicaciones de dónde descargarse o de ejecutarlo como administrador (seguro que se podía, pero no se cómo)
      No se a que te refieras con eso

      Yo te di una pagina para que lo descargases, las letras azules que puse dentro de un recuadro son un link y si pinchas en el te abrira una pagina de donde te lo podias descargar. Si no era eso lo que decias me avisas. Por lo que veo en los repotes anteriores dedusco que lo buscaste en softonic

      Si hablas sobre la ubicacion, el programa no te dio especificaciones pero yo si
      Ejecutalo de la siguiente forman y de preferencia colocalo en el escritorio
      Claro que si no te decimos en donde colocar el programa antes de ejecutarlos no hay problema. No se si a esto te referias.

      Ahora si lo que decias era de ejecutarlo como administrador, haces click derecho y eliges Ejecuta como Administrador

      Si no queda muy claro que se tiene a que me refieo me avisas y con gusto trato de explicarme. Si nada de lo que mensione tenia que ver con tu comentario nos avisas.

      Ejecuta AdwCleaner y presiona Desisntalar.

      Realiza lo siguiente porfavor:

      Lee los siguientes puntos y limpia el cache de java(como son enlaces los veras de un color diferente, y al hacer click sobre ellos te llevaran al articulo de interes):
      1. La herramienta antivirus ha detectado un virus. ¿Está relacionado con Java?
      2. ¿Cómo puedo borrar la memoria caché de Java?



      Revisa el siguiente enlace con detenimiento, y apliques los consejos que dicen ahi dependiendo de si uses java, para que y que navegadores tienes:
      • Si no usas Java Desisntalalo.
      • Si usas java, ademas de los consejos de como desactivarlo en donde no lo uses, actualizalo de la siguiente forma:
        1. Descarga e instala Java de su pagina oficial: Descarga gratuita de software de Java
        2. Ejecuta JavaRa (Manual de JavaRa) y si descargas la version 2 procede de la siguiente forma:
          1. Ejecuta JavaRa como administrador, y presiona donde dice Update JavaRa Definitions, presionas en Download desactivando previamente cualquier programa de seguridad. Despues presionas en Back.
          2. Ve a Remove JRE y elimina todos los que te aparescan anteriores a la actual ya sea presionando Run Uninstaller(ejecutar el desisntalador del programa) o Next(JavaRa lo eliminara manualmente).
          3. Despues ve a Aditional Task y marca donde dice Remove Outdated Firefox Extensions y presiona Run.
        3. Desinstala cualquier version de Java anterior a la actual, en este caso 7 update 17

      Nota: cuando quieras verificar tu version de Java puedes ir a este enlace: Verificar la versión de Java
      Descarga USBfix
      Ejecuta USBfix segun su manual y con estas especificaciones:
      • De no ejecutarlo en modo seguro como se indica, desactiva temporalmente tu antivirus y cualquier programa de seguridad.
      • Conecta cualquier memoria USB, pendrive, o dispositivo extraible que quieras desinfectar y proteger en el proceso.
      • Presiona Supresion o Deletion y espera que el programa haga lo suyo.

      Nota: USBFix creara una carpeta oculta denominada ''Autorun.inf'' en cada partición, USB o disco extraíble conectado durante el análisis. Por favor, no elimine esa carpeta . Le protegerá de futuras infecciones.
      Nos comentarias como te fue, cualquier duda que tengas y nos traerias el reporte de USBfix(c:\usbfix.txt). Ademas nos comentas como sigue el sistema para ver como poseguir dependiendo de si es necesario.

      Saludos
      El cielo azul es infinitamente alto y cristalino

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    6. #6
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      re: Zoomex, searchab.com, tuvaro.com.(solucionado)

      Hola,
      Gracias por las explicaciones detalladas. Ahora sí las he podido seguir bien.

      1. AdwCleaner: Lo ejecuté otra vez, ahora siguiendo correctamente tus indicaciones. Luego lo desinstalé.
      Este es el reporte:


      # AdwCleaner v2.114 - Fichero creado el 17/03/2013 a 10:37:32
      # Actualizado el 05/03/2013 por Xplode
      # Sistema operativo : Windows Vista (TM) Home Premium Service Pack 2 (32 bits)
      # Usuario : PROPIETARIO - PROPIETARIO1
      # Modo de inicio : Normal
      # Ejecutado desde : C:\Users\PROPIETARIO\Desktop\adwcleaner.exe
      # Opción [Supresión]


      ***** [Servicios] *****


      ***** [Ficheros / Carpetas] *****


      ***** [Registro] *****


      ***** [Navegadores] *****

      -\\ Internet Explorer v9.0.8112.16470

      [OK] El registro no contiene ninguna entrada ilegítima.

      -\\ Google Chrome v25.0.1364.172

      Fichero : C:\Users\PROPIETARIO\AppData\Local\Google\Chrome\User Data\Default\Preferences

      [OK] El fichero no contiene ninguna entrada ilegítima.

      *************************

      AdwCleaner[S1].txt - [5721 octets] - [16/03/2013 20:42:33]
      AdwCleaner[S2].txt - [968 octets] - [17/03/2013 09:18:23]
      AdwCleaner[S3].txt - [900 octets] - [17/03/2013 10:37:32]

      ########## EOF - C:\AdwCleaner[S3].txt - [959 octets] ##########


      2. Borré el caché de Java (en el Panel de control de java) y luego desinstalé Java. No se si lo utilizo para algo. Si veo que lo necesito lo volvería a instalar como me indicaste.

      3. Descargué USBfix de Infospyware. Lo ejecuté en modo seguro. Me dio la siguiente advertencia: No se encuentra el motor de secuencias de comandos "VBScript" para la secuencia "C:/UsbFix/Av.vbs". Acepté. Luego escaneó hasta el 97% y se quedó trabado. Finalicé desde Administrador de tareas, volví a ejecutarlo y ocurrió lo mismo.

      El equipo continúa lentísimo y Norton a cada rato pone carteles de Alerta de rendimiento: uso intensido de memoria por:
      - Proceso host por los servicios de windows
      - Internet explorer
      - Indizador de Microsoft Windows Search
      - ...

      Se volvió a cambiar la página de inicio de Internet Explorer, esta vez a: MSN.fr - Actus France et Monde - Magazine People & Féminin

      Saludos.

    7. #7
      Moderador
      Avatar de ErdrickBass
      Registrado
      jul 2009
      Ubicación
      Cd Juarez, Mex.
      Mensajes
      8.927

      re: Zoomex, searchab.com, tuvaro.com.(solucionado)

      Buenas

      ¿Podrias revisar si se alcanzo a generar algo del reporte de USBfix? Lo encontraras en c:\usbfix.txt.

      Si no se generlo nada ejecutalo nuevamente pero usa la opcion Buscar y nos pegas ese reporte.

      Nos comentas.

      Saludos
      El cielo azul es infinitamente alto y cristalino

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    8. #8
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      re: Zoomex, searchab.com, tuvaro.com.(solucionado)

      Hola,
      No se generó ningún reporte.
      Ejecuté nuevamente en modo seguro y en opción Buscar.
      Me dio otra vez la advertencia: No se encuentra el motor de secuencias de comandos "VBScript" para la secuencia "C:/UsbFix/Av.vbs".
      Acepté y cuando terminó de buscar apareció el siguiente aviso: Windows no puede encontrar el archivo C:/UsbFix(Scan1)PROPIIETARIO1.txt. Asegurese de que el nombre esté escrito correctamente e inténtelo de nuevo.
      Volví a intentarlo y pasó lo mismo. Así que sigo sin reporte.
      Estuve haciendo cosas con el ordenador y para usar carpetas está mucho mejor. Se queda atontado con el IE.
      Saludos,

    9. #9
      Moderador
      Avatar de ErdrickBass
      Registrado
      jul 2009
      Ubicación
      Cd Juarez, Mex.
      Mensajes
      8.927

      re: Zoomex, searchab.com, tuvaro.com.(solucionado)

      Buenas

      Ejecuta USBfix y presiona Desisntalar, para cualquier cosa revisa el anexo sobre el bug de USBfix de su manual.

      Es algo extraño lo que te pasa con IE y USBfix. Aunque lo bueno es que va mejor otras cosas del ordenador.

      Si te parece realiza lo siguiente porfavor:

      Descarga DrWeb Cureit:
      Ejecuta Drweb según su manual y con estas especificaciones:
      • Cuando inicie el programa ejecutalo en su modo de proteccion mejorada preferentemente. Y siguiendo el manual.
      • Despues de aceptar los terminos de uso ve al boton que tiene forma de llave inglesa, y en Configuración te vas a Log y eliges Mínimo:

      • Eliges la opción Seleccione Objetos a escanear, y marcas todas las opciones; te vas a haga clic para seleccionar y añade todas las carpetas y unidades adicionales que quieras que sean escaneadas por el programa. Para iniciar el escaneo presionas sobre Comenzando escaneo:


      • Curas, Mueves y Eliminas, lo que encuentre según te de la opción y con ese orden de preferencia.
      • Si te detecta el archivo Hosts permite que DrWeb lo restaure.
      • Abres el reporte al finalizar como lo indica la imagen.

      Nos traerias el reporte de DrWeb (de no poder guardarlo como se indica, un reporte se genera sobre %userprofile%\DoctorWeb\CureIt.log) y nos comentarias el estado del sistema.

      Saludos
      El cielo azul es infinitamente alto y cristalino

      * Síguenos en nuestro Twitter y hazte nuestro amigo en Facebook.
      * Infórmate de las ultimas amenazas de la red desde: InfoSpyware Blog
      * No se resuelven dudas por Privados ni por E-mail, ya que para eso esta el foro.

    10. #10
      Usuario Avatar de marazabala
      Registrado
      mar 2013
      Ubicación
      España
      Mensajes
      16

      re: Zoomex, searchab.com, tuvaro.com.(solucionado)

      Hola,
      Ya pasé el Dr.WEb. No apareció el link al reporte en la última pantalla pero pude encontrarlo luego.

      =============================================================================
      Dr.Web Scanner SE for Windows v7.0.100.12030
      (c) Doctor Web, Ltd., 1992-2012
      Scan session started 2013/03/17 22:56:01
      Module location : c:\users\propietario\appdata\local\temp\A135D454-55C14DC0-7FF23E78-25F4A634\
      =============================================================================
      OPTION [Automatic Apply Actions] NO
      OPTION [Turn Off Computer After Scan] NO
      OPTION [Use Sound Alerts] NO
      OPTION [Block Network] NO
      OPTION [Protect Process] NO
      OPTION [Protect Raw Disk] NO
      Using language: "Spanish (Español)"
      Available instances: 6
      Instances used: 6
      Platform: Windows Vista Premium x86 (Build 6002), Service Pack 2
      API Version: 2.2
      Scanning Engine version: 8.0.2.12140
      Virus Finding Engine version: 7.0.4.9250
      Total 101 virus bases are loaded from c:\users\propietario\appdata\local\temp\A135D454-55C14DC0-7FF23E78-25F4A634
      t6q4r0ri 7.0 67dd24992b5cbe928f4242ceeff58994e59c43a9 2013/03/17 21:00:27 1943 records - OK
      519kqjg7 7.0 f5d1425097a34628f8d752212dabf9732d209c98 2011/07/25 16:20:03 1 record - OK
      8k4lkbcw 7.0 f93fc1366af0311a0eb62e010f9f9639037f1d71 2013/03/16 20:02:47 8852 records - OK
      6k9wrkm3 7.0 d196879775b0dc0ee8286f2e4def9adedb5b88df 2013/03/11 04:05:36 12046 records - OK
      45stwixp 7.0 0db61d4e3235481da8493523538ced712db362c2 2013/03/04 04:05:18 21747 records - OK
      8bf4ns2g 7.0 65f99faf227b51883c9f1c854a3f76806b60affb 2013/02/25 04:06:28 11540 records - OK
      5ykawn12 7.0 17bd7383b9c4b214c5c9029171db8ae1455984a0 2013/02/18 04:06:38 15568 records - OK
      k2hza9z2 7.0 cbe8774953ae403e49370d552b522a5839aa9fdb 2013/02/11 04:06:00 18805 records - OK
      1ks8msi8 7.0 fb6865c02a3680338e4ee0603579107227313b2b 2013/02/04 04:06:01 32488 records - OK
      q901fjvl 7.0 95fcd2e24cd9b2ec2610656ffa70b8bf46e86a8b 2013/01/28 04:04:52 15470 records - OK
      3wn9qf8m 7.0 3d710b3dd4580a7eca8c74d2c886d48f5b8b5172 2013/01/21 04:06:27 30093 records - OK
      femc4xh0 7.0 bddde0b5426b7e5bebd61e1239ca529c87ae6e36 2013/01/14 04:04:41 16158 records - OK
      bdfzj680 7.0 bc40bd9330301e8d7796f489d03357fb711b3121 2013/01/07 04:04:45 19597 records - OK
      e90tfh6v 7.0 805b6089c867549c75f843eac96b759c3f8d101f 2012/12/31 04:05:41 18184 records - OK
      hpaylrfv 7.0 c12a817c1f95bb9fd8238ef0d5f68868a8d95686 2012/12/24 04:05:33 30183 records - OK
      294ew0am 7.0 33def496782eb5b7b1cc93fdb036a1b62fa6a2fd 2012/12/17 04:06:21 25519 records - OK
      jrj1q50y 7.0 422abae03c588822f412aa9aae50578a1d61737e 2012/12/10 04:05:04 20358 records - OK
      x2oje5fy 7.0 a4f0d0ecad4fb6e0afdb1925f4e0b7863b9d03fa 2012/12/03 04:06:19 20133 records - OK
      uqgbiccg 7.0 86daa918ee3de1e4c1e5dea6f9b5f63544cf8814 2012/11/26 04:05:22 27311 records - OK
      xdsceebi 7.0 6556881c748e1f894eb9c7943ebae67017e1aec2 2012/11/19 04:06:09 29434 records - OK
      ps5rklca 7.0 559141ef34f9e6226bb58560e9b52e4cc5165150 2012/11/12 04:06:22 26900 records - OK
      zrmy3gv6 7.0 cc55013e63ff89319ec772e34d77056c7108cd3b 2012/11/05 04:05:22 25164 records - OK
      xgoenkg6 7.0 f477dc247d9b562bb64fd4f46a7dcbdf7124eb60 2012/10/29 04:06:37 30226 records - OK
      zp68ddts 7.0 abaf5f7fda7308fcf7573b193bbf2116723e9802 2012/10/22 05:04:37 16441 records - OK
      3lff5xsz 7.0 5adc85528fb49e201d4bc61eca580d6839cc4a4c 2012/10/15 05:05:04 26289 records - OK
      x1cgfsz7 7.0 da8cf3fbd81206bb3d8103347a439f920a74bbe2 2012/10/08 05:05:51 27278 records - OK
      85zsqumk 7.0 5988744d3cb357f1a013427d466e2d79ab5f8907 2012/10/01 05:05:11 17444 records - OK
      7h93sv7x 7.0 d4a0dabf4a4df0f79805c6ccdc025f796765e786 2012/09/24 05:06:30 21205 records - OK
      i6ifg1f2 7.0 82ed005784d9e258213070a0cd8bfceff345018d 2012/09/17 05:05:43 11686 records - OK
      1xxskvf4 7.0 a95ae63004b8d857c2db055f4e47c15bfc97f626 2012/09/10 05:04:34 12677 records - OK
      jml5im2f 7.0 c39bf233d25242ae9ed8cf204b9b788c8f45ab79 2012/09/03 05:05:28 10118 records - OK
      v72n9s85 7.0 d37b5484b009947b7cdd3837dafe8148615401c2 2012/08/27 05:05:26 12602 records - OK
      m5i4qxnc 7.0 41bf1347794ab7060dec7aaecc1d1d95cf6fecb5 2012/08/20 05:04:05 18298 records - OK
      dy000iuy 7.0 1a997511e5892aaeb69b3db70e06676af36382e3 2012/08/13 05:05:19 17126 records - OK
      vowjjump 7.0 f7226c59914e3683e538e668c3b664af3232654d 2012/08/06 05:03:53 20539 records - OK
      ktf0uz16 7.0 4035c8d3b617bf935a317a8c57efaa8e835a61f4 2012/07/30 05:05:26 19330 records - OK
      r9aoj9fn 7.0 09b55bc000f184ed426f1d8b9665669346fe5e71 2012/07/23 05:05:34 19692 records - OK
      hicseopk 7.0 f746c097f298e94faa9db94e6f64ef9fd4a7b010 2012/07/16 05:05:43 14727 records - OK
      wboflxhl 7.0 792a6a25a17e764390440cd4c2c6ca5a97ab162f 2012/07/09 05:04:33 19485 records - OK
      2ykffco1 7.0 ca9905c39e3d93428a4db65a192debe9fbd7acf7 2012/07/02 05:04:55 22898 records - OK
      3pp8mf2l 7.0 dc29c610b866c66ba5327e7830452b2460149a35 2012/06/25 05:05:17 20551 records - OK
      rx7xlge9 7.0 c28739bea153508d12942ac9a61abd475d0a0404 2012/06/18 05:03:35 9661 records - OK
      7h25mpze 7.0 e5b5835a7c512120c5348e31483a4caa2a845d28 2012/06/11 05:04:32 23632 records - OK
      gu17kxf4 7.0 61853ce89026ef0ebbd80174f1b7dd5d25bbc63a 2012/06/04 05:04:41 12423 records - OK
      orl8okuq 7.0 4e6c9897e153b47ca97b7da48ceed23e555a7761 2012/05/28 05:04:26 15493 records - OK
      dj9uh1dl 7.0 35f4c105cecd8ec1fd01714abebf30f8f3efb96e 2012/05/21 05:03:29 13065 records - OK
      bsueyjv6 7.0 3522aa84677411aa7d67796bb05ea3ab62f02a71 2012/05/14 05:04:24 16238 records - OK
      l8nz7twh 7.0 7597333540eda537bd42c0a17d4a6526ad247a2e 2012/05/07 05:04:33 11570 records - OK
      wb3e1c5b 7.0 867814380363bc6ad605acf4b96e02c54dbd60f7 2012/04/30 05:03:28 15478 records - OK
      5g33o70i 7.0 3c04f402d91a19039cb9c223c435dc4ea1bb3da4 2012/04/23 05:05:05 11881 records - OK
      fly8z4qy 7.0 8d0220a2a50b367e61a51d3b29c2659cde41bb7f 2012/04/16 05:03:29 13578 records - OK
      1o59lrqv 7.0 b79dc6f5832ad390108d1880694ec538e8b34bb0 2012/04/09 05:05:02 14292 records - OK
      jqy3ifyk 7.0 8ff7cc095c43c2154275b7a54a89bf365e8daf4a 2012/04/02 05:03:24 14084 records - OK
      jwlmlv8w 7.0 9502a428b32be4ad08556134e271c9ba03195398 2012/03/26 05:04:43 19126 records - OK
      i8akw68e 7.0 28c2fabbc645aff41baac12b911a8499ea163536 2012/03/19 04:03:23 14920 records - OK
      0l1hzc84 7.0 86de597ff06e58206f94263f2eef33cb41b2530c 2012/03/12 04:03:25 19017 records - OK
      j88c3cb6 7.0 5bd1d666e7c9ca70c34e591dc6c55314ce4b11af 2012/03/05 04:04:32 19691 records - OK
      y63f1h9k 7.0 15a9d10c451d2fcf124700f29f557d9bf338e671 2012/02/27 04:03:21 23605 records - OK
      r0smqblv 7.0 5647d941e5358105ca6558dce78873f06c48d5dc 2012/02/20 04:03:45 19067 records - OK
      gagznb0k 7.0 c9b2600cb665ce34e0ccd0f19e0a88cd44437f51 2012/02/13 04:04:49 19019 records - OK
      97t4aujn 7.0 9df2e129e78a9d9ab491186da1329c1dd1190e17 2012/02/06 04:05:25 28028 records - OK
      ur19o2pk 7.0 b69b9504a51b8777b8e95a4680dc8ac1d8d8c25d 2012/01/30 04:08:41 29444 records - OK
      k9t7la07 7.0 3d7431bdee1a22d6329e017f348db7760f2645ac 2012/01/23 09:22:13 19353 records - OK
      icu3ufxb 7.0 e04570f78fb00d758abdf77c534a460980e102c0 2012/01/16 04:12:31 20747 records - OK
      mo46wc7t 7.0 2de2479b112c4416e2375343f57ca789b042aecc 2012/01/09 04:04:30 28052 records - OK
      muh20xjj 7.0 c4bd9612ff1f71d8bd23b4f1bc114eed1ae2ee6b 2012/01/02 04:04:40 12183 records - OK
      9wsp3kk0 7.0 28b1d218ade8f05fdc8550c7456ac3b74f705208 2011/12/26 04:03:33 19984 records - OK
      54z83mtc 7.0 539e41e8f3d97a6f347600c7cef903d9f34e0518 2011/12/19 04:08:45 22627 records - OK
      v6lx49d3 7.0 f8e81968965f555bce0d02fc9933fee840b97aaf 2011/12/12 21:20:22 49580 records - OK
      w5h0dvio 7.0 14751e0f442bba3efc08ee12d82a2815c61cfeb6 2011/12/04 09:00:00 45195 records - OK
      rpv5znwi 7.0 5bc1f5e30792d018658f2dcdb35fc0bcbdcf4e1e 2011/12/04 08:00:00 171075 records - OK
      brh4bm67 7.0 0f948a7d416c556bfc8a8be2c2c39f998fee6d9e 2011/12/04 07:00:00 170820 records - OK
      h1ds960u 7.0 9357c3cc73a4a374346a678f197daa22496c7ae5 2011/12/04 06:00:00 171279 records - OK
      joyl61ez 7.0 ae56b06b3d6f1e13c5f10cce4ed68f2cccbf3298 2011/12/04 05:00:00 170253 records - OK
      wv8p83no 7.0 fdaab5c1079d02c94f20d07c39d638cad79d8771 2011/12/04 04:00:00 170291 records - OK
      b2gukz7p 7.0 b59d8841e65d7670b2aae7f2b65734269f6c4fe3 2011/12/04 03:00:00 170501 records - OK
      ndtqc8n8 7.0 3946b1d195434cf7a70d144da71c87559475c58f 2011/12/04 02:00:00 353582 records - OK
      8wt4gcnn 7.0 8df4695f74ea5949551df6044720694e204b13d7 2011/12/04 01:00:00 852776 records - OK
      tm4fmev5 7.0 8cb1ff15894b0b2a5dd3de14058672b4e64cea94 2013/03/17 21:00:57 614 records - OK
      ehbnso3t 7.0 6cb68b8fab821702ef054f864ff44917414e50fa 2013/02/04 04:13:43 2078 records - OK
      na9dusdx 7.0 cfbe9cf43615f7856e4c35f0fc02e2baf12e39e7 2012/12/17 04:14:14 1725 records - OK
      5ntdberp 7.0 047694e79b1a8d295f27ea9c6565062404f84a57 2012/11/12 04:12:52 2050 records - OK
      529zk457 7.0 f3413603f4ee1c88018a78c1f6faf2abeb8fa8c1 2012/09/24 05:13:14 1456 records - OK
      w5tl969p 7.0 8871f579eeb7e5e7b70c6dd898afd27391d7daf4 2012/06/25 05:12:36 1421 records - OK
      eq8nk3en 7.0 3ee43130fe7fec4b367a791892a444d0a791b29b 2012/03/26 05:12:30 1385 records - OK
      jbygymte 7.0 fddc5d687537580c7166dbf117d591593bc62261 2012/01/23 05:56:09 1653 records - OK
      5nivtdgp 7.0 9b620207e5d05b091e2fcbe7bbf0f16ed042b14a 2013/03/17 21:00:49 1728 records - OK
      vm2tg95b 7.0 8893c0d254eb40c78b5c78ea17fbc3be60ea6304 2013/01/21 04:24:33 2016 records - OK
      c3vbl3lv 7.0 cdf3a9d2dcab57f90c378d9eefacbfd358a42699 2012/12/10 04:23:23 1620 records - OK
      wdqljduc 7.0 c0726ba000e840272f0810b89051e6daa8799084 2012/11/05 04:23:16 1658 records - OK
      4plu8mh9 7.0 216611859de0125bf130d6324d43c9115cb05def 2012/10/08 05:23:20 1465 records - OK
      e363vpcl 7.0 264c14ad60c4423ec292f5f8b182e4448504dfa9 2012/09/10 05:23:14 1588 records - OK
      kp1xib2n 7.0 33197bfe9efefa9db33725d240757103c625b601 2012/07/23 05:22:36 1702 records - OK
      37nthzn1 7.0 74d8e114edb84b95bc09d5a2a36191d15a61e2cb 2012/06/11 05:22:36 1659 records - OK
      2r4z46o2 7.0 79ca8239f310688d2b9c314fa3d738a34985cce3 2012/04/30 05:22:34 1670 records - OK
      1hyegy7j 7.0 aac27e986e3731e5260cb76f5b14558e36660dec 2012/03/12 04:22:28 1729 records - OK
      jh3ky1nc 7.0 fa5c96b8be693a20c2a295e3545419e6f117fdc4 2012/01/30 04:23:00 1523 records - OK
      jtzwmkco 7.0 e9b21e0a3578ef2e2067f4876309671ddc78f65f 2011/12/19 04:22:29 1805 records - OK
      j2sbdz1i 7.0 8f7a8f6f55130f6becc5331ab38dc2108746b8aa 2011/12/04 00:00:00 26456 records - OK
      61q3wrti 7.0 e6d52b11d2f7d405ccd31347da3b6fde69825168 2011/12/03 23:00:00 74279 records - OK
      swr970ju 7.0 e20ffde4bbc58e0585b0b3b2f324bc91272c2360 2011/12/03 22:00:00 1 record - OK
      Total records count: 3730997
      Anti-rootkit module version (API 5.00 / 5.00)

      Using c:\users\propietario\appdata\local\temp\A135D454-55C14DC0-7FF23E78-25F4A634\jdaukbt0.key as Dr.Web (R) Key file
      This Dr.Web (R) Key is for 1 computer (A User)
      -----------------------------------------------------------------------------
      Start scanning
      -----------------------------------------------------------------------------
      Command line used:-rpcep:\pipe\2021916648 -rpcpr:np /protmode

      Object(s) to scan:
      - Scan processes in memory
      - Scan boot sectors
      - Scan startup directory
      - Scan system restore points
      - Scanning for rootkits
      - C:\
      - D:\
      - E:\
      - F:\
      - G:\
      - H:\
      - I:\
      - J:\
      - K:\
      - L:\
      - C:\aqua_bitmap.cpp
      - C:\AT-Destroyer.txt
      - C:\autoexec.bat
      - C:\bootmgr
      - C:\BOOTSECT.BAK
      - C:\CMLoader.log
      - C:\config.sys
      - C:\FINIS_IT.TXT
      - C:\IO.SYS
      - C:\MSDOS.SYS
      - C:\PA207.DAT
      - C:\pagefile.sys
      - C:\prefs.js
      - C:\RHDSetup.log
      - C:\YServer.txt
      - C:\{03C31669-22DC-41B2-8B5F-A90AA9EEAE5E}
      - C:\{0BEC7430-6870-4F55-AB0C-DD2536456D1B}
      - C:\{1F600609-B810-41D8-8E35-55F92C211107}
      - C:\{20F6B596-39B3-4F96-AF37-751E5216C8D6}
      - C:\{27556B00-CBDF-4F0E-B1AC-3FD45C69D3B5}
      - C:\{3B30F156-041E-414A-A123-1FF8EC327F62}
      - C:\{5EABBFA8-804A-4F2F-AC19-D4614A9502F8}
      - C:\{97B6F285-9772-40A2-8DCE-331ACE9CE995}
      - C:\{B67D3322-9C77-448D-865A-99F0BAC4F375}
      - C:\{B7B8A1E1-EE9A-4B0F-AE28-057CD85CC106}
      - C:\{C247D930-B6EB-4D2F-BC5C-F9168CD783CD}
      - C:\{DA6EE1C0-770C-4C54-A569-E18BD45EB3FE}
      - C:\{F0DFBD82-E196-422C-8539-2E7299D69610}
      - C:\Windows\system32\
      - C:\Users\PROPIETARIO\Documents\
      - C:\Windows\TEMP\
      - C:\Users\PROPIE~1\AppData\Local\Temp\

      c:\users\propietario\appdata\local\temp\2127955c2b.sys - file not found
      c:\users\propietario\appdata\local\temp\2022e26801.sys - file not found
      c:\windows\system32\drivers\dump_diskdump.sys - file not found
      c:\windows\system32\drivers\dump_nvstor32.sys - file not found
      System Process - file not found
      C:\Windows\system32\drivers\etc\hosts - probably infected with DFH.HOSTS.corrupted
      C:\Windows\system32\drivers\etc\hosts - infected
      Process :0 - read error
      Process System:4 - read error
      Process audiodg.exe:1292 - read error
      C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45b7395c-8cc7-11e2-9c93-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45b73980-8cc7-11e2-9c93-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45b73988-8cc7-11e2-9c93-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45b73990-8cc7-11e2-9c93-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{42ac7c33-8e72-11e2-af3b-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45d959a8-79ef-11e2-aad6-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45d959e4-79ef-11e2-aad6-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{45d95a29-79ef-11e2-aad6-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{746b798c-8c07-11e2-9b1e-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{b20a8622-8edb-11e2-9f25-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{b20a862a-8edb-11e2-9f25-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{b20a8632-8edb-11e2-9f25-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{b20a863a-8edb-11e2-9f25-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda16d-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda19b-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda1d4-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda205-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda25f-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{c5093e44-82c1-11e2-aa96-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda2a6-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\System Volume Information\{cbdda2fd-83e6-11e2-9539-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      D:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      D:\System Volume Information\{b20a863b-8edb-11e2-9f25-00112ffb4d51}{3808876b-c176-4e48-b7ae-04046e6cc752} - read error
      C:\pagefile.sys - read error
      C:\Archivos de programa - directory
      C:\Boot\BCD - read error
      C:\Boot\BCD.LOG - read error
      C:\Documents and Settings - directory
      C:\Program Files\Archivos comunes - directory
      C:\Program Files\Software Downloader\WS_ABP_setup.exe\script.bin - is adware program Adware.Downware.135
      C:\Program Files\Servicios en línea\OrangeES\orangeSetup.exe\IGOSUNG.EXE - probably infected with DLOADER.Trojan
      C:\Program Files\Software Downloader\WS_ABP_setup.exe - infected container
      C:\Program Files\Servicios en línea\OrangeES\orangeSetup.exe - infected container
      C:\Program Files\Windows NT\Accesorios - directory
      C:\ProgramData\Application Data - directory
      C:\ProgramData\Datos de programa - directory
      C:\ProgramData\Desktop - directory
      C:\ProgramData\Documentos - directory
      C:\ProgramData\Documents - directory
      C:\ProgramData\Escritorio - directory
      C:\ProgramData\Favorites - directory
      C:\ProgramData\Favoritos - directory
      C:\ProgramData\Menú Inicio - directory
      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log - read error
      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log - read error
      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb - read error
      C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb - read error
      C:\ProgramData\Microsoft\Windows\Start Menu\Programas - directory
      C:\ProgramData\Norton\00000082\00000114\000004e7\cltLMS1.dat - read error
      C:\ProgramData\Norton\00000082\00000114\000004e7\cltLMS2.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_ISDATAPR_{FF9AC67A-E394-46ae-B150-B3365343F166}G - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_NPC.Tray.{1AFE47BB-FCF1-4096-9039-1FEBC9A0CCCF}1 - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_RDRPluginG - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_{4E9CB39A-5F78-4887-A3D6-2790DE9DDE11}1 - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_SNDPluginG - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_SvcMgr-A2B50D70-5EA1-45a0-A983-0DB9E7101676G - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_UI.Host.{1AFE47BB-FCF1-4096-9039-1FEBC9A0CCCF}1 - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_ISDATAPR_{E8EFD4CD-DE52-4444-9511-EFF3B158724B}1 - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\CmnClnt\_lck\_AVPAPP_{BB639333-810A-4bf8-85F5-C537857F55FC}1 - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\bash.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\BashHeuristic.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\ClientIDS.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\DAAlert.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\DADown.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\firewall.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\nco2.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\Performance.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\navscan.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\navthr.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\Logs\SymNetDrv.dat - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.6.0.29\QBackup\index.qbs - read error
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\SrtETmp - directory
      C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SRTSP\Quarantine - directory
      C:\ProgramData\Plantillas - directory
      C:\ProgramData\Start Menu - directory
      C:\ProgramData\Templates - directory
      C:\System Volume Information - directory
      C:\Users\All Users\Datos de programa - directory
      C:\Users\All Users\Desktop - directory
      C:\Users\All Users\Application Data - directory
      C:\Users\All Users\Documents - directory
      C:\Users\All Users\Favoritos - directory
      C:\Users\All Users\Escritorio - directory
      C:\Users\All Users\Favorites - directory
      C:\Users\All Users\Documentos - directory
      C:\Users\All Users\Menú Inicio - directory
      C:\Users\All Users\Plantillas - directory
      C:\Users\All Users\Start Menu - directory
      C:\Users\Default User - directory
      C:\Users\All Users\Templates - directory
      C:\Users\Default\AppData\Local\Datos de programa - directory
      C:\Users\Default\AppData\Local\History - directory
      C:\Users\Default\AppData\Local\Application Data - directory
      C:\Users\Default\AppData\Local\Historial - directory
      C:\Users\Default\AppData\Local\Temporary Internet Files - directory
      C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programas - directory
      C:\Users\Default\Application Data - directory
      C:\Users\Default\Configuración local - directory
      C:\Users\Default\Documents\Mi música - directory
      C:\Users\Default\Documents\Mis imágenes - directory
      C:\Users\Default\Documents\Mis vídeos - directory
      C:\Users\Default\Documents\My Music - directory
      C:\Users\Default\Documents\My Pictures - directory
      C:\Users\Default\Entorno de red - directory
      C:\Users\Default\Cookies - directory
      C:\Users\Default\Datos de programa - directory
      C:\Users\Default\Documents\My Videos - directory
      C:\Users\Default\Impresoras - directory
      C:\Users\Default\My Documents - directory
      C:\Users\Default\Local Settings - directory
      C:\Users\Default\Menú Inicio - directory
      C:\Users\Default\Plantillas - directory
      C:\Users\Default\PrintHood - directory
      C:\Users\Default\Mis documentos - directory
      C:\Users\Default\Reciente - directory
      C:\Users\Default\SendTo - directory
      C:\Users\Default\Start Menu - directory
      C:\Users\Default\Templates - directory
      C:\Users\Default\Recent - directory
      C:\Users\Default\NetHood - directory
      C:\Users\PROPIETARIO\ntuser.dat - read error
      C:\Users\PROPIETARIO\ntuser.dat.LOG1 - read error
      C:\Users\PROPIETARIO\ntuser.dat.LOG2 - read error
      C:\Users\PROPIETARIO\AppData\Local\Datos de programa - directory
      C:\Users\PROPIETARIO\AppData\Local\Historial - directory
      C:\Users\PROPIETARIO\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 - read error
      C:\Users\PROPIETARIO\AppData\Local\Microsoft\Windows\UsrClass.dat - read error
      C:\Users\PROPIETARIO\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 - read error
      C:\Users\PROPIETARIO\AppData\Local\Temporary Internet Files - directory
      C:\Users\PROPIETARIO\AppData\Local\Temp\~nsu.tmp\Au_.exe - infected with Trojan.Siggen3.1716
      C:\Users\PROPIETARIO\AppData\Local\Temp\~nsu.tmp\Au_.exe - infected
      C:\Users\PROPIETARIO\AppData\Roaming\Microsoft\Windows\Start Menu\Programas - directory
      C:\Users\PROPIETARIO\AppData\Roaming\Skype\shared_dynco\dc.lock - read error
      C:\Users\PROPIETARIO\AppData\Roaming\Skype\shared_httpfe\queue.lock - read error
      C:\Users\PROPIETARIO\Configuración local - directory
      C:\Users\PROPIETARIO\Cookies - directory
      C:\Users\PROPIETARIO\Datos de programa - directory
      C:\Users\PROPIETARIO\Desktop\K-Lite_Codec_Pack_630_Full.exe - container, password protected
      C:\Users\PROPIETARIO\Documents\Mi música - directory
      C:\Users\PROPIETARIO\Documents\Mis imágenes - directory
      C:\Users\PROPIETARIO\Documents\Mis vídeos - directory
      C:\Users\PROPIETARIO\Downloads\K-Lite_Codec_Pack_630_Full.exe - container, password protected
      C:\Users\PROPIETARIO\Downloads\klcp_update_650_20101018.exe - container, password protected
      C:\Users\PROPIETARIO\Downloads\SoftonicDownloader_para_malwarebytes-anti-malware.exe - is adware program Adware.Downware.910
      C:\Users\PROPIETARIO\Downloads\SoftonicDownloader_para_malwarebytes-anti-malware.exe - infected
      C:\Users\PROPIETARIO\Entorno de red - directory
      C:\Users\PROPIETARIO\Impresoras - directory
      C:\Users\PROPIETARIO\Menú Inicio - directory
      C:\Users\PROPIETARIO\Mis documentos - directory
      C:\Users\PROPIETARIO\Plantillas - directory
      C:\Users\PROPIETARIO\Reciente - directory
      C:\Users\PROPIETARIO\SendTo - directory
      C:\Users\Public\Documents\Mi música - directory
      C:\Users\Public\Documents\Mis imágenes - directory
      C:\Users\Public\Documents\Mis vídeos - directory
      C:\Users\Public\Documents\My Music - directory
      C:\Users\Public\Documents\My Pictures - directory
      C:\Users\Public\Documents\My Videos - directory
      C:\Windows\ServiceProfiles\LocalService\ntuser.dat - read error
      C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 - read error
      C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 - read error
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - read error
      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - read error
      C:\Windows\ServiceProfiles\NetworkService\ntuser.dat - read error
      C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 - read error
      C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 - read error
      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 - read error
      C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 - read error
      C:\Windows\System32\LogFiles\WMI\RtBackup - directory
      C:\Windows\System32\catroot2\edb.log - read error
      C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
      C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
      C:\Windows\System32\config\components - read error
      C:\Windows\System32\config\COMPONENTS.LOG1 - read error
      C:\Windows\System32\config\default - read error
      C:\Windows\System32\config\COMPONENTS.LOG2 - read error
      C:\Windows\System32\config\DEFAULT.LOG1 - read error
      C:\Windows\System32\config\DEFAULT.LOG2 - read error
      C:\Windows\System32\config\sam - read error
      C:\Windows\System32\config\SAM.LOG1 - read error
      C:\Windows\System32\config\SAM.LOG2 - read error
      C:\Windows\System32\config\security - read error
      C:\Windows\System32\config\SECURITY.LOG1 - read error
      C:\Windows\System32\config\SECURITY.LOG2 - read error
      C:\Windows\System32\config\software - read error
      C:\Windows\System32\config\SOFTWARE.LOG1 - read error
      C:\Windows\System32\config\SOFTWARE.LOG2 - read error
      C:\Windows\System32\config\system - read error
      C:\Windows\System32\config\SYSTEM.LOG1 - read error
      C:\Windows\System32\config\SYSTEM.LOG2 - read error
      C:\Windows\System32\config\RegBack\COMPONENTS - read error
      C:\Windows\System32\config\RegBack\DEFAULT - read error
      C:\Windows\System32\config\RegBack\SAM - read error
      C:\Windows\System32\config\RegBack\SECURITY - read error
      C:\Windows\System32\config\RegBack\SOFTWARE - read error
      C:\Windows\System32\config\RegBack\SYSTEM - read error
      D:\System Volume Information - directory
      F:\Ricky\The.Queen.of.Versailles.2012.1080p.BluRay.x264-GECKOS_[PublicHD]_secure.exe\script.bin - is adware program Adware.Siggen.25598
      F:\Ricky\The.Queen.of.Versailles.2012.1080p.BluRay.x264-GECKOS_[PublicHD]_secure.exe - infected container
      F:\Ricky\VIDEO\Jesus_Camp_(2006)_secure.exe\script.bin - is adware program Adware.Siggen.25598
      F:\Ricky\VIDEO\Jesus_Camp_(2006)_secure.exe - infected container
      F:\System Volume Information - directory
      F:\VIDEOS\MCP\iLividSetupV1.exe - is adware program Adware.Bandoo.1
      F:\VIDEOS\MCP\iLividSetupV1.exe - infected
      H:\AUTORUN.INF - read error
      I: - read error
      J: - read error
      K: - read error
      L: - read error
      C:\pagefile.sys - read error
      C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 - read error
      C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 - read error
      C:\Windows\system32\LogFiles\WMI\RtBackup - directory
      C:\Windows\system32\catroot2\edb.log - read error
      C:\Windows\system32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb - read error
      C:\Windows\system32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb - read error
      C:\Windows\system32\config\components - read error
      C:\Windows\system32\config\COMPONENTS.LOG1 - read error
      C:\Windows\system32\config\COMPONENTS.LOG2 - read error
      C:\Windows\system32\config\default - read error
      C:\Windows\system32\config\DEFAULT.LOG1 - read error
      C:\Windows\system32\config\DEFAULT.LOG2 - read error
      C:\Windows\system32\config\sam - read error
      C:\Windows\system32\config\SAM.LOG1 - read error
      C:\Windows\system32\config\SAM.LOG2 - read error
      C:\Windows\system32\config\security - read error
      C:\Windows\system32\config\SECURITY.LOG2 - read error
      C:\Windows\system32\config\SECURITY.LOG1 - read error
      C:\Windows\system32\config\software - read error
      C:\Windows\system32\config\SOFTWARE.LOG1 - read error
      C:\Windows\system32\config\SOFTWARE.LOG2 - read error
      C:\Windows\system32\config\system - read error
      C:\Windows\system32\config\SYSTEM.LOG2 - read error
      C:\Windows\system32\config\SYSTEM.LOG1 - read error
      C:\Windows\system32\config\RegBack\COMPONENTS - read error
      C:\Windows\system32\config\RegBack\DEFAULT - read error
      C:\Windows\system32\config\RegBack\SAM - read error
      C:\Windows\system32\config\RegBack\SECURITY - read error
      C:\Windows\system32\config\RegBack\SOFTWARE - read error
      C:\Windows\system32\config\RegBack\SYSTEM - read error
      C:\Users\PROPIETARIO\Documents\Mi música - directory
      C:\Users\PROPIETARIO\Documents\Mis imágenes - directory
      C:\Users\PROPIETARIO\Documents\Mis vídeos - directory
      C:\Users\PROPIETARIO\AppData\Local\Temp\~nsu.tmp\Au_.exe - infected with Trojan.Siggen3.1716

      Total 394417259150 bytes in 321065 files scanned (944521 objects)
      Total 320826 files (943965 objects) are clean
      Total 6 files (7 objects) are infected
      Total 2 files are suspicious
      Total 145 files (452 objects) are raised error condition
      Scan time is 11:05:53.573

      -----------------------------------------------------------------------------
      Start curing
      -----------------------------------------------------------------------------
      C:\Windows\system32\drivers\etc\hosts - cured, reboot required
      C:\Program Files\Software Downloader\WS_ABP_setup.exe - quarantined
      C:\Program Files\Servicios en línea\OrangeES\orangeSetup.exe - quarantined
      C:\Users\PROPIETARIO\AppData\Local\Temp\~nsu.tmp\Au_.exe - incurable, quarantined
      C:\Users\PROPIETARIO\Downloads\SoftonicDownloader_para_malwarebytes-anti-malware.exe - quarantined
      F:\Ricky\The.Queen.of.Versailles.2012.1080p.BluRay.x264-GECKOS_[PublicHD]_secure.exe - quarantined
      F:\Ricky\VIDEO\Jesus_Camp_(2006)_secure.exe - quarantined
      F:\VIDEOS\MCP\iLividSetupV1.exe - quarantined

      Total 394417259150 bytes in 321065 files scanned (944521 objects)
      Total 320826 files (943965 objects) are clean
      Total 6 files (7 objects) are infected
      Total 2 files are suspicious
      Total 8 files are neutralized
      Total 145 files (452 objects) are raised error condition
      Scan time is 11:05:53.573


      El ordenador en cuanto lo reinicié tardaba 4 minutos en abrir el IE o el Chrome. Después de un ratito, tarda un minuto en abrirlos. En general parece estar mejor.

      Saludos

    Página 1 de 3 123 ÚltimoÚltimo