Question
-
Topic
-
path of a virus
Lockedim infected with a virus, when i scan with AV all are done but when i restart my pc a file named wmsetup.dll come again into %temp%, i want to know the path for wmsetup.dll that come everytime when i connect to the net, i scanned with combofix and this the files that are removed:
C:\Program Files\Messenger\msgmr.dll
C:\WINDOWS\AppPatch\AcSpecf.dll
C:\WINDOWS\AppPatch\AcSpecf.sdb
C:\WINDOWS\AppPatch\AcXtrnel.sdb
C:\WINDOWS\Downloaded Program Files\ThunderAdvise.dll
C:\WINDOWS\Fonts\Framdee.ttf
C:\WINDOWS\system32\[u]0[/u]8223B03.dll
C:\WINDOWS\system32\122B901E.cfg
C:\WINDOWS\system32\122B901E.dll
C:\WINDOWS\system32\12B02216.dll
C:\WINDOWS\system32\43ACDCC5.cfg
C:\WINDOWS\system32\43ACDCC5.dll
C:\WINDOWS\system32\4901228.sys
C:\WINDOWS\system32\495271CA.cfg
C:\WINDOWS\system32\495271CA.dll
C:\WINDOWS\system32\4BF9CBA3.cfg
C:\WINDOWS\system32\4BF9CBA3.dll
C:\WINDOWS\system32\4D023DE9.dll
C:\WINDOWS\system32\4F34C688.dll
C:\WINDOWS\system32\58FF3024.dll
C:\WINDOWS\system32\7ADC2AB1.cfg
C:\WINDOWS\system32\7ADC2AB1.dll
C:\WINDOWS\system32\9CA963CA.cfg
C:\WINDOWS\system32\9CA963CA.dll
C:\WINDOWS\system32\A8FC611B.dll
C:\WINDOWS\system32\D91BC61E.cfg
C:\WINDOWS\system32\D91BC61E.dll
C:\WINDOWS\system32\DA63E650.cfg
C:\WINDOWS\system32\DA63E650.dll
C:\WINDOWS\system32\DE02F764.cfg
C:\WINDOWS\system32\DE02F764.dll
C:\WINDOWS\system32\drivers\eth8023.sys
C:\WINDOWS\system32\drivers\HBKernel32.sys
C:\WINDOWS\system32\E3367679.dll
C:\WINDOWS\system32\E4814792.cfg
C:\WINDOWS\system32\E4814792.dll
C:\WINDOWS\system32\EC7DA7DC.dll
C:\WINDOWS\system32\HBBO.dll
C:\WINDOWS\system32\HBCHIBI.dll
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\HBQQFFO.dll
C:\WINDOWS\system32\HBZHUXIAN.dll
C:\WINDOWS\system32\system.exe
C:\WINDOWS\temp\wmsetup.dll