This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please help with this hijackthis log

73 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, My friends computer has various things that keep coming back after being removed by pestpatrol. cws.homesearch , trojan.downloader, smartfinder. please help me, Thanks, KT
Here's the log…..

Logfile of HijackThis v1.99.1
Scan saved at 8:46:23 PM, on 9/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\atlcm.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\atlys.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLHOS~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLServiceHost.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\PestPatrol\PestPatrol.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\DOCUME~1\ed\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kmbhclhamlyllkmjbq.net/KZOMnM3u…7ZksIfQdcOG.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdot.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://webcoolsearch.com/?id=54
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r5.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com
R3 - Default URLSearchHook is missing
F1 - win.ini: run=fntldr.exe C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
O2 - BHO: Class - {D9E4FCE9-DD60-AD26-B07D-BFB00720C50B} - C:\WINDOWS\system32\ipsr32.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104100680\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [waol.exe] C:\Program Files\America Online 9.0b\waol.exe
O4 - HKLM\..\Run: [atlcm.exe] C:\WINDOWS\atlcm.exe
O4 - HKLM\..\Run: [tonsdataheartfast] C:\Documents and Settings\All Users\Application Data\Gplfortonsdata\Glue Face.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [sdkwu.exe] C:\WINDOWS\sdkwu.exe
O4 - HKLM\..\Run: [crkf.exe] C:\WINDOWS\crkf.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {2F685524-FB34-4244-B524-761636A70983} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {9A2FFE23-1DF0-44AE-AD29-A4591B5D2A36} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {E0B4D805-9A8D-4107-B3E0-8FF1859BA3DE} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp (file missing)
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlys.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello ktheerman. :wavey:

There is quite a collection of malware on that computer. We will try to knock it out all at once as most are closely related.

You may want to print out these instructions or save them to your desktop as a text file with Notepad because we will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet.
  • Move HijackThis to Permanent Folder: ***Very Important***
    HijackThis needs to be unzipped into a permanent folder in order to save backups just in case something goes wrong.
    • Go to Start > My Computer > and double click on C:.
    • Now right click an open area and click New > folder and change the folder name to HJT.
    • Extract HijackThis from the zipped file into this new folder.
  • Prepare CWShredder for use:
    • Download CWShredder.
    • Save CWShredder.exe to a convenient location.
    • Please do not do anything with it yet.
  • Prepare AboutBuster for use:
    • Download AboutBuster.
    • Unzip the contents of AboutBuster.zip and an AboutBuster directory will be created.
    • You should not run the program yet so click the "X" to exit the program.
  • Prepare HSfix.reg for use:
    • Download HSfix.
    • Unzip the contents of HSfix.zip (HSfix.reg) to your desktop.
    • Delete the HSfix.zip folder.
    • Please do not do anything with it yet.
  • Reconfigure Windows XP to show hidden files:
    • Click Start. Open My Computer.
    • Select the Tools menu and click Folder Options. Select the View Tab.
    • Under the Hidden files and folders heading select "Show hidden files and folders".
    • Uncheck the "Hide protected operating system files (recommended)" option.
    • Uncheck the "Hide file extensions for known file types" option.
    • Click Yes to confirm. Click OK.
Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
To return to normal mode just restart your computer as you normally would.


  • Disable the offending service.
    • Go to Start->Run and type Services.msc then hit Ok
    • Scroll down and find the service called : Remote Procedure Call (RPC) Helper << There are two similar named services, be sure to fix the correct one.
    • When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.
  • Stop The Running Processes
    • Press control-alt-delete to get into the task manager and end the following processes if they exist:

      atlcm.exe
      atlys.exe
  • Delete the following files/folders (if found):
    • C:\WINDOWS\atlcm.exe
      C:\WINDOWS\sdkwu.exe
      C:\WINDOWS\crkf.exe
      C:\WINDOWS\Web\oslogo.bmp
      C:\WINDOWS\system32\atlys.exe
      C:\WINDOWS\system32\vduxw.dll
      C:\WINDOWS\system32\ipsr32.dll

      C:\Documents and Settings\ed\Application Data\BROWSE~1 << Wholde Folder - name begins with Browse
      C:\Documents and Settings\All Users\Application Data\Gplfortonsdata << Whole Folder
    • If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
  • Fix with Hijackthis:
    • R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
      R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
      R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\system32\searchbar.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.kmbhclhamlyllkmjbq.net/KZOMnM3u…7ZksIfQdcOG.htm
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.searchdot.net
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\vduxw.dll/sp.html#37049
      R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdot.net
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = C:\WINDOWS\secure.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://webcoolsearch.com/?id=54
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
      R3 - Default URLSearchHook is missing

      F1 - win.ini: run=fntldr.exe C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe

      O2 - BHO: Class - {D9E4FCE9-DD60-AD26-B07D-BFB00720C50B} - C:\WINDOWS\system32\ipsr32.dll

      O4 - HKLM\..\Run: [atlcm.exe] C:\WINDOWS\atlcm.exe
      O4 - HKLM\..\Run: [tonsdataheartfast] C:\Documents and Settings\All Users\Application Data\Gplfortonsdata\Glue Face.exe
      O4 - HKLM\..\Run: [sdkwu.exe] C:\WINDOWS\sdkwu.exe
      O4 - HKLM\..\Run: [crkf.exe] C:\WINDOWS\crkf.exe
      O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe

      O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp (file missing)

      O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\atlys.exe
    • With all other programs and browsers closed, click fix checked.
  • Remove the offending service:
    • Double-click on HSfix.reg you downloaded earlier.
    • When it asks you to merge the information to the registry click "Yes".
  • Run CWShredder:
    • Double-click on CWShredder.exe.
    • Click "Fix ->" and click "OK" at the prompt.
    • CWShredder will scan and clean your system of CWS files.
    • Click "Next->" and then "Exit".
  • Run AboutBuster and save the logs:
    • Browse to where you saved AboutBuster and run AboutBuster.exe.
    • Click "Begin Removal" to start the scan.
    • When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK.
    • Another information window will open. Click on Exit.
    • AboutBuster will inform you that a log has been created. Click OK.
  • Clean out temporary files:
    • Start | Run | type cleanmgr | OK
    • Let it scan your system for files to remove.
    • Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
    • Click "OK" to remove them.
    • Click "Yes" to confirm the deletion.
  • Restart your computer normally to return to normal mode.
  • Free TrendMicro Housecall scan:
    • You'll need to use Internet Explorer or Netscape browsers to run this scan.
    • Vist the TrendMicro Housecall website.
    • Select your country from the drop-down list and click "Go".
    • Choose "Yes" at the ActiveX Security Warning prompt.
    • Please wait while the Housecall engine is updated.
    • Select the drives to be scanned by placing a check in their respective boxes.
    • Check the "Auto Clean" box.
    • Click "SCAN" in order to begin scanning your system.
    • Please be patient while Housecall scans your system for malicious files.
    • If not auto-cleaned, remove anything it finds.
    • Click "Close" to exit the Housecall scanner.
    • Choose "Yes" at the HouseCall message prompt.
  • Prepare your reply:
    • Please post a fresh HijackThis log as a reply to this thread.
    • Please post the AboutBuster log.
    • Please note any complications you had.
Thanks for the detailed instructions, Alsocom.

When I put the computer in safe mode - i could only get on the system as the administrator - not the account that I originally ran hijackthis from. There were several entries that I couldn't find that you instructed to remove with hijack this.

Additionally, my friends pc's EI is essentially useless at this point - lots of errors and crashing, so i couldn't run the trend scan. His mcafee is erroring too. I ran pest patrol - and there is still a CSW.homesearch that won't be cleaned off. It says that the access to the registry is denied.

Here's a new Hijackthis log….

Thanks alot for working on this with me….

KT

Logfile of HijackThis v1.99.1
Scan saved at 5:56:45 PM, on 10/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Comcast\BBClient\Programs\RegCon.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\WINDOWS\system32\d3uc32.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLHOS~1.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\d3hq.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdot.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r5.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {4938D58C-9A8F-5AC3-0E95-C2FD02537590} - C:\WINDOWS\system32\iptq.dll
O2 - BHO: Class - {4B4BF72B-6C7F-079E-30DB-E0CDC91EBCF6} - C:\WINDOWS\system32\addio.dll
O2 - BHO: Class - {E2B4FCC5-E7C0-FD6E-9969-152F9F01DBD7} - C:\WINDOWS\mfcyi.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104100680\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [waol.exe] C:\Program Files\America Online 9.0b\waol.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [d3uc32.exe] C:\WINDOWS\system32\d3uc32.exe
O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\Program Files\PestPatrol\ppclean.exe" "clean" "ts:20051002175255" "cws" "2"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {2F685524-FB34-4244-B524-761636A70983} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {9A2FFE23-1DF0-44AE-AD29-A4591B5D2A36} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {E0B4D805-9A8D-4107-B3E0-8FF1859BA3DE} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Does your friend have the Windows XP install cd's? We'll try another scanner to see if it can clean the infection.
Make sure to post all of the requested logs as I need to see them.

Please download the trial version of Ewido security suite.

Install and Update Ewido:
  • Download and install Ewido security suite.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch Ewido, there should be an icon on your desktop for it to double-click.
    • The program will prompt you to update, click the OK button.
    • The program will now go to the main screen.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
  • Once the updates are installed, close the program.

Reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').


Stop The Running Processes
  • Press control-alt-delete to get into the task manager and end the following processes if they exist:
d3uc32.exe
d3hq.exe




Delete the following files:


C:\WINDOWS\system32\iptq.dll
C:\WINDOWS\system32\addio.dll
C:\WINDOWS\system32\d3uc32.exe
C:\WINDOWS\system32\d3hq.exe
C:\WINDOWS\mfcyi.dll

C:\Documents and Settings\ed\Application Data\BROWSE~1 << Whole Folder with name beginning with Browse.

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Fix with Hijackthis:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchdot.net
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {4938D58C-9A8F-5AC3-0E95-C2FD02537590} - C:\WINDOWS\system32\iptq.dll
O2 - BHO: Class - {4B4BF72B-6C7F-079E-30DB-E0CDC91EBCF6} - C:\WINDOWS\system32\addio.dll
O2 - BHO: Class - {E2B4FCC5-E7C0-FD6E-9969-152F9F01DBD7} - C:\WINDOWS\mfcyi.dll

O4 - HKLM\..\Run: [d3uc32.exe] C:\WINDOWS\system32\d3uc32.exe
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe


With all other programs and browsers closed, click fix checked.



Run AboutBuster and save the logs:
  • Browse to where you saved AboutBuster and run AboutBuster.exe.
  • Click "Begin Removal" to start the scan.
  • When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK.
  • Another information window will open. Click on Exit.
  • AboutBuster will inform you that a log has been created. Click OK.




Scanning With Ewido:
  • Launch Ewido again.
    • Click on scanner
    • Click on Complete System Scan and the scan will begin.
    • While the scan is in progress you will be prompted to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the boxes that say "Perform action on all infections"and "Create encrypted backup" then choose clean and click OK.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report.
    • Save the report.txt file to your desktop.
  • Now close ewido security suite.

Reboot the computer.


Prepare your reply:
  • Please post a fresh HijackThis log as a reply to this thread.
  • Please post the AboutBuster log.
  • Please post the Ewido log.
  • Please note any complications you had.
Hi Alan,

Sorry for not posting all the logs you requested earlier. I've followed your latest instructions and here's the stuff - the virus scan found 1024 infected items…. all got cleaned with the scanning software you gave me the link to. But the log is HUGE - including in separate post (or posts, we'll see)

Thank you,
KT

Logfile of HijackThis v1.99.1
Scan saved at 9:12:52 PM, on 10/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\PESTPA~1\PPControl.exe
C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLServiceHost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r5.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com
R3 - Default URLSearchHook is missing
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [PestPatrol Control Center] C:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104100680\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [waol.exe] C:\Program Files\America Online 9.0b\waol.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL; Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {2F685524-FB34-4244-B524-761636A70983} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {9A2FFE23-1DF0-44AE-AD29-A4591B5D2A36} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {E0B4D805-9A8D-4107-B3E0-8FF1859BA3DE} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3hq.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Mcafee.com Corporation - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

AboutBuster Log - I think the one I ran tonight is appended to the one I ran the last time….

AboutBuster 5.0 reference file 31
Scan started on [10/2/2005] at [5:01:37 PM]
————————————————
No Ads Found!
————————————————
Removed File! : C:\Windows\apikb32.exe
Removed File! : C:\Windows\appym32.exe
Removed File! : C:\Windows\d3ly.exe
Removed File! : C:\Windows\eynlc.dat
Removed File! : C:\Windows\ieeh32.exe
Removed File! : C:\Windows\iesn.exe
Removed File! : C:\Windows\ipik.exe
Removed File! : C:\Windows\javaxw32.exe
Removed File! : C:\Windows\mfcqv32.exe
Removed File! : C:\Windows\netsb32.exe
Removed File! : C:\Windows\netxb.exe
Removed File! : C:\Windows\orgip.dat
Removed File! : C:\Windows\pdbtr.dat
Removed File! : C:\Windows\sdkno.exe
Removed File! : C:\Windows\sdktv32.exe
Removed File! : C:\Windows\stbaa.dat
Removed File! : C:\Windows\udxmg.dat
Removed File! : C:\Windows\wingl32.exe
Removed File! : C:\Windows\wintj.exe
Removed File! : C:\Windows\winya.exe
Removed File! : C:\Windows\System32\addgh32.exe
Removed File! : C:\Windows\System32\addvv.exe
Removed File! : C:\Windows\System32\apihk.exe
Removed File! : C:\Windows\System32\apiue.exe
Removed File! : C:\Windows\System32\apphz32.exe
Removed File! : C:\Windows\System32\atlwq32.exe
Removed File! : C:\Windows\System32\atlym.exe
Removed File! : C:\Windows\System32\atlys.exe
Removed File! : C:\Windows\System32\atlza.exe
Removed File! : C:\Windows\System32\d3ow32.exe
Removed File! : C:\Windows\System32\fhdvq.dat
Removed File! : C:\Windows\System32\hzuvv.dat
Removed File! : C:\Windows\System32\iebn32.exe
Removed File! : C:\Windows\System32\iehr32.exe
Removed File! : C:\Windows\System32\ierp32.exe
Removed File! : C:\Windows\System32\iphl.exe
Removed File! : C:\Windows\System32\javacc32.exe
Removed File! : C:\Windows\System32\javaqw32.exe
Removed File! : C:\Windows\System32\mfchj32.exe
Removed File! : C:\Windows\System32\ntrv32.exe
Removed File! : C:\Windows\System32\poebz.dat
Removed File! : C:\Windows\System32\sbwpd.dat
Removed File! : C:\Windows\System32\winto32.exe
Removed File! : C:\Windows\System32\wuzgp.dat
Removed File! : C:\Windows\System32\xltrp.dat
Removed File! : C:\Windows\System32\zwrnu.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 5:02:14 PM


AboutBuster 5.0 reference file 31
Scan started on [10/4/2005] at [7:48:51 PM]
————————————————
No Ads Found!
————————————————
Removed File! : C:\Windows\dsacd.dat
Removed File! : C:\Windows\txvgd.dll
Removed File! : C:\Windows\uzgkq.dll
Removed File! : C:\Windows\System32\aqcbg.dat
Removed File! : C:\Windows\System32\niodq.dll
Removed File! : C:\Windows\System32\qphni.dat
Removed File! : C:\Windows\System32\vvlpr.dat
Removed File! : C:\Windows\System32\ztovn.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 7:49:22 PM








Here's the 1st part of the virus scan ….


———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 9:01:12 PM, 10/4/2005
+ Report-Checksum: EBF1738D

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{07D80144-9372-FEAC-AEDD-21AE8732F067} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{15E6172A-5F7D-3085-1E94-14DA8D1A4479} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3B9E0A95-3EBA-124F-52D1-033C73734625} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{52CA0FCE-F9E0-2125-6CA6-2627141A47E9} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9D7705A4-9543-9869-8249-F62AC961BDA5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9E2092B1-77DB-2A6A-A476-8BAA6CC65237} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B30EFD56-F6AF-2F6B-C3AB-6571E5627F1F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BCA18F7D-4CAB-D300-286E-432722FFB0FB} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{C2E5E32B-0FD0-16A5-10FE-EDA2D4478683} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DB054D56-EEA3-C985-BEDB-3E646A49FA44} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{DB3FF0A6-7AD3-085E-3E59-A4318E82D4A8} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{E8A06DEA-6626-407D-5720-FE211C989AC1} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F80F0D50-2D6C-75C3-606A-3DFE0F4FC5D0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FF1518B7-D821-1BF0-0368-AD32CBCF17E0} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Dsi -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Mserv -> Spyware.Daemonize : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{1A00C40B-DA85-4aa3-A67F-582D9347EECD} -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{BC3BBF86-E4EC-4412-9676-8355468B3B05} -> Spyware.Maxspeed : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA Software Installer -> Spyware.SafeSurfing : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PGate -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2126944957-588702989-414624371-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
:mozilla.8:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.21:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.22:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\ed\Cookies\ed@66.220.17[1].txt -> Spyware.Cookie.66.220.17.154 : Cleaned with backup
C:\Documents and Settings\ed\Cookies\[removed][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\ed\Cookies\[removed][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\ed\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\ed\Local Settings\Temp\2E1.tmp -> TrojanDownloader.WinShow.ay : Cleaned with backup
C:\install_tag002.exe -> Spyware.PurityScan : Cleaned with backup
C:\ms32.tmp -> TrojanDownloader.Small.azk : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040427231959312.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040517233711015.zip/Program Files/common files/sq/uwa.exe -> Spyware.Sqwire : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040626224604734.zip/WINDOWS/preinstt.exe -> Spyware.BiSpy : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040808113230390.zip/WINDOWS/svchost.exe -> TrojanSpy.Tofger.t : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040813232920890.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040826202105843.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20040828194623718.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20041015225328484.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20041015225328484.zip/Documents and Settings/ed/Application Data/Browse dale sign/funkbodymesssoftware.exe -> Spyware.Lop : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20041029095324390.zip/Documents and Settings/patrick/Local Settings/Temp/NDrv.exe -> TrojanDownloader.PurityScan.j : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20041029095324390.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20041029095324390.zip/Documents and Settings/ed/Application Data/Browse dale sign/Cashaxisstopidle.exe -> Spyware.Lop : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050404003340.zip/WINDOWS/system32/drivers/etc/hosts -> Spyware.XmlMimeFilter : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050819083104.zip/WINDOWS/system32/atlkn.exe -> Trojan.Agent.em : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/bbovn.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/SYSTEM32/etylp.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/SYSTEM32/mujfw.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/SYSTEM32/qougv.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/SYSTEM32/tshpq.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/SYSTEM32/vczlb.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/WINDOWS/xaecb.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20050929202756.zip/SaveInstCsSm.exe -> TrojanDownloader.Small.kl : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051001150739.zip/WINDOWS/SYSTEM32/zdugr.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051001153252.zip/WINDOWS/pidrw.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051001153252.zip/WINDOWS/SYSTEM32/qsuhh.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051002174035.zip/WINDOWS/nhspt.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051002174035.zip/WINDOWS/ruhaf.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051002174035.zip/WINDOWS/SYSTEM32/rsges.dll -> Spyware.SearchPage : Cleaned with backup
C:\Program Files\PestPatrol\Quarantine\20051002174035.zip/WINDOWS/netfv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\S-1-5-21-2126944957-588702989-414624371-500\Dc1.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\S-1-5-21-2126944957-588702989-414624371-500\Dc2.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\RECYCLER\S-1-5-21-2126944957-588702989-414624371-500\Dc3.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\RECYCLER\S-1-5-21-2126944957-588702989-414624371-500\Dc4.exe -> Trojan.Agent.bi : Cleaned with backup
C:\RECYCLER\S-1-5-21-2126944957-588702989-414624371-500\Dc5.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\setup233.exe -> TrojanDownloader.Agent.ac : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0593896.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0593896.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0594850.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0594850.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0595858.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0595858.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0596852.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP291\A0596852.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0597872.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0597872.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0598850.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0598850.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP292\A0599852.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP293\A0599880.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP293\A0599880.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP294\A0599895.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP294\A0599895.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP294\A0600851.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP294\A0600851.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0600924.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0600924.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0601874.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0601874.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602854.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602854.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602902.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602902.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0603906.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0603906.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0603942.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0603942.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604902.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604902.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604939.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604939.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604966.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP296\A0604966.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0605015.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0605015.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0605966.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0605966.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606002.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606002.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606033.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606033.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606062.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606062.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606110.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606110.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606139.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606139.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606168.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606168.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0607160.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0607160.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0607186.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0607186.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608188.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608188.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608214.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608214.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608253.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608253.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608282.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0608282.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0609284.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0609284.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610288.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610288.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610313.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610313.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610342.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610342.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610384.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610384.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0610398.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0610398.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0610422.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0610422.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0611419.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP298\A0611419.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0611448.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0611448.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0612417.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0613421.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0613421.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0614417.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0614447.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0614447.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0617546.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0617546.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0617578.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP299\A0617578.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0617608.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0617608.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0618578.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0618609.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0618609.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619681.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619681.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619709.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619709.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619749.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP300\A0619749.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0619783.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0619783.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0620747.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0620747.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0621743.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP301\A0621743.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621774.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621774.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621779.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621779.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621807.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0621807.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0622807.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0622839.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0622839.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0622854.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0622854.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0622876.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0622876.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623881.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623881.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623902.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623902.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623936.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP303\A0623936.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP304\A0623954.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP304\A0623954.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP304\A0624932.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP304\A0624974.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP304\A0624974.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0624989.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0624989.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0625007.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0625007.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0626009.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0626009.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0627013.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0627013.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0629102.ini:bfueh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632095.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632095.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632095.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632125.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632125.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0632125.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0632148.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0632148.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0632148.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633253.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633253.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633253.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633280.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633280.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633280.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633305.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633305.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP306\A0633305.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP307\A0633333.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP307\A0633333.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP307\A0633333.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP307\A0634315.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP307\A0634315.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0634345.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0634345.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0634345.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0634345.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635307.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635307.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635307.PIF:owodd -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635307.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635307.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635342.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635343.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635343.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635343.PIF:owodd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635343.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635343.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635368.ini:eynlcf -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP308\A0635369.prx:wzgrwq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636396.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636396.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636396.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636396.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636399.ini:dfgqhd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0636402.ini:eynlcf -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637400.ini:eynlcf -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637461.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637461.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637461.PIF:nhbltc -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637461.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637461.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E
Not sure what happened to your other two posts. I received three email containing your replies but only one is showing up in this thread. :scratch:


Open notepad and copy and paste the following text into it:
dir %Windir%\tasks /a h > files.txt
notepad files.txt

Save this as findjobs.bat, choose to save it as *all files* and place it on your desktop.

Doubleclick on findjobs.bat and save the content of the textfile you get as findjobs.txt.



Reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').


Delete the following files:


C:\WINDOWS\txvgd.dll

C:\Documents and Settings\ed\Application Data\BROWSE~1 << Whole Folder with name beginning with Browse or Brow Se.

If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.



Fix with Hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R3 - Default URLSearchHook is missing

O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe

O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3hq.exe (file missing)


With all other programs and browsers closed, click fix checked.



Scanning With Ewido:
  • Launch Ewido again.
    • Click on scanner
    • Click on Complete System Scan and the scan will begin.
    • While the scan is in progress you will be prompted to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the boxes that say "Perform action on all infections"and "Create encrypted backup" then choose clean and click OK.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report.
    • Save the report.txt file to your desktop.
  • Now close ewido security suite.
Run AboutBuster and save the logs:
  • Browse to where you saved AboutBuster and run AboutBuster.exe.
  • Click "Begin Removal" to start the scan.
  • When it has finished, AboutBuster will open a 'Scan Completed' window. Click OK.
  • Another information window will open. Click on Exit.
  • AboutBuster will inform you that a log has been created. Click OK.

Reboot the computer.


Prepare your reply:
  • Please post a fresh HijackThis log as a reply to this thread.
  • Please post the AboutBuster log.
  • Please post the Ewido log. << should be much smaller this time
  • Please post the contents of the findjobs.txt
  • Please note any complications you had.
Alan,

Hmmm… very weird. The 2 replies ended up in the one post and then the 3rd was lost….

Ok…Followed your instructions and am having problems with finding all the entries you're asking me to fix with Hijackthis. When I'm in Safe Mode and logged in as Administrator (i can't seem to log in as ed in safe mode)- running hijackthis doesn't show certain entries in order for me to fix them. They only show up when I run the exe in normal mode under the Ed account. Can I only fix things with hijackthis in safe mode?

(for example: these don't show up in safe mode….
R3 - Default URLSearchHook is missing, R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049)

Thanks….

Here's the log ran afterall the instructions.. as Ed

Logfile of HijackThis v1.99.1
Scan saved at 9:12:21 PM, on 10/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Comcast\BBClient\Programs\RegCon.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLHOS~1.EXE
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLServiceHost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r5.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com
R3 - Default URLSearchHook is missing
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104100680\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [waol.exe] C:\Program Files\America Online 9.0b\waol.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {2F685524-FB34-4244-B524-761636A70983} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {9A2FFE23-1DF0-44AE-AD29-A4591B5D2A36} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {E0B4D805-9A8D-4107-B3E0-8FF1859BA3DE} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\d3hq.exe (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


AboutBuster Log
AboutBuster 5.0 reference file 31
Scan started on [10/2/2005] at [5:01:37 PM]
————————————————
No Ads Found!
————————————————
Removed File! : C:\Windows\apikb32.exe
Removed File! : C:\Windows\appym32.exe
Removed File! : C:\Windows\d3ly.exe
Removed File! : C:\Windows\eynlc.dat
Removed File! : C:\Windows\ieeh32.exe
Removed File! : C:\Windows\iesn.exe
Removed File! : C:\Windows\ipik.exe
Removed File! : C:\Windows\javaxw32.exe
Removed File! : C:\Windows\mfcqv32.exe
Removed File! : C:\Windows\netsb32.exe
Removed File! : C:\Windows\netxb.exe
Removed File! : C:\Windows\orgip.dat
Removed File! : C:\Windows\pdbtr.dat
Removed File! : C:\Windows\sdkno.exe
Removed File! : C:\Windows\sdktv32.exe
Removed File! : C:\Windows\stbaa.dat
Removed File! : C:\Windows\udxmg.dat
Removed File! : C:\Windows\wingl32.exe
Removed File! : C:\Windows\wintj.exe
Removed File! : C:\Windows\winya.exe
Removed File! : C:\Windows\System32\addgh32.exe
Removed File! : C:\Windows\System32\addvv.exe
Removed File! : C:\Windows\System32\apihk.exe
Removed File! : C:\Windows\System32\apiue.exe
Removed File! : C:\Windows\System32\apphz32.exe
Removed File! : C:\Windows\System32\atlwq32.exe
Removed File! : C:\Windows\System32\atlym.exe
Removed File! : C:\Windows\System32\atlys.exe
Removed File! : C:\Windows\System32\atlza.exe
Removed File! : C:\Windows\System32\d3ow32.exe
Removed File! : C:\Windows\System32\fhdvq.dat
Removed File! : C:\Windows\System32\hzuvv.dat
Removed File! : C:\Windows\System32\iebn32.exe
Removed File! : C:\Windows\System32\iehr32.exe
Removed File! : C:\Windows\System32\ierp32.exe
Removed File! : C:\Windows\System32\iphl.exe
Removed File! : C:\Windows\System32\javacc32.exe
Removed File! : C:\Windows\System32\javaqw32.exe
Removed File! : C:\Windows\System32\mfchj32.exe
Removed File! : C:\Windows\System32\ntrv32.exe
Removed File! : C:\Windows\System32\poebz.dat
Removed File! : C:\Windows\System32\sbwpd.dat
Removed File! : C:\Windows\System32\winto32.exe
Removed File! : C:\Windows\System32\wuzgp.dat
Removed File! : C:\Windows\System32\xltrp.dat
Removed File! : C:\Windows\System32\zwrnu.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 5:02:14 PM


AboutBuster 5.0 reference file 31
Scan started on [10/4/2005] at [7:48:51 PM]
————————————————
No Ads Found!
————————————————
Removed File! : C:\Windows\dsacd.dat
Removed File! : C:\Windows\txvgd.dll
Removed File! : C:\Windows\uzgkq.dll
Removed File! : C:\Windows\System32\aqcbg.dat
Removed File! : C:\Windows\System32\niodq.dll
Removed File! : C:\Windows\System32\qphni.dat
Removed File! : C:\Windows\System32\vvlpr.dat
Removed File! : C:\Windows\System32\ztovn.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 7:49:22 PM


AboutBuster 5.0 reference file 31
Scan started on [10/5/2005] at [8:54:48 PM]
————————————————
No Ads Found!
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 8:55:11 PM


Virus scan…57 or so viruses found….
———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 8:53:23 PM, 10/5/2005
+ Report-Checksum: E76A4EFA

+ Scan result:

:mozilla.8:C:\Documents and Settings\ed\Application Data\Mozilla\Firefox\Profiles\731liudk.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651316.exe -> Spyware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651322.exe -> TrojanDownloader.Agent.ac : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651328.ini:bfueh -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651330.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651336.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651337.INI:djjdux -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651338.exe -> TrojanDownloader.Harnig.c : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651340.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651342.ini:dfgqhd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651345.isu:tsxgji -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651346.OLD:ygfamr -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651347.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651348.ini:nnejjo -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651349.exe -> TrojanDownloader.Donn.aa : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651352.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651353.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651354.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651355.exe -> TrojanDownloader.Delf.bj : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651358.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651360.dll -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651365.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651367.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651368.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651374.ini:sguvwi -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651375.ini:eynlcf -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651375.ini:isamdf -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651378.prx:vvmwum -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651378.prx:wzgrwq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651379.prx:ypnybr -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651380.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651381.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651382.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651383.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:adgcsm -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:brigxu -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:bstnun -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:cknzny -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:eockez -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:epujfv -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:fcfbo -> TrojanDownloader.Agent.pe : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:gfrrjd -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:hpmzk -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:hwyasc -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:jirmm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:jsbisd -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:mdzslg -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:meoalg -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:nhbltc -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:sxmqhs -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:tsatre -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:uzkaxg -> Spyware.SearchPage : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:vddeqw -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:xajwrl -> Trojan.Agent.em : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:ymwat -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651384.PIF:zyrwz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32:wlaa.dll -> TrojanDownloader.Small.azk : Cleaned with backup


::Report End
You didn't post the results of findjobs.bat in your last reply. This will show if there are any lop entries set to reinstall themselves.

Open notepad and copy and paste the following text into it:
dir %Windir%\tasks /a h > files.txt
notepad files.txt

Save this as findjobs.bat, choose to save it as *all files* and place it on your desktop.

Doubleclick on findjobs.bat and save the content of the textfile you get as findjobs.txt.



Disable the offending service.
  • Go to Start->Run and type Services.msc then hit Ok
  • Scroll down and find the service called : Remote Procedure Call (RPC) Helper
  • When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. If you don´t find this service listed go ahead with the next steps.

Remove the offending service:
  • Double-click on HSfix.reg you downloaded earlier.
  • When it asks you to merge the information to the registry click "Yes".


Fix with Hijackthis:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\txvgd.dll/sp.html#37049
R3 - Default URLSearchHook is missing
O4 - HKCU\..\Run: [iso barb] C:\DOCUME~1\ed\APPLIC~1\BROWSE~1\wait trans.exe


With all other programs and browsers closed, click fix checked.



Reboot the computer.


Prepare your reply:
  • Please post a fresh HijackThis log as a reply to this thread.
  • Please post the contents of the findjobs.txt
  • Please note any complications you had.
Alan,

Okay… sorry about the findjobs.txt - i forgot to include it …

Here's everything… no complications…

Thanks,
Kristin

Logfile of HijackThis v1.99.1
Scan saved at 7:36:00 PM, on 10/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLHOS~1.EXE
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\COMMON~1\AOL\110410~1\EE\AOLServiceHost.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r5.attbi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r5.attbi.com
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [SAClient] "C:\Program Files\Comcast\BBClient\Programs\RegCon.exe" /admincheck
O4 - HKLM\..\Run: [SAUpdate] "C:\Program Files\Comcast\BBClient\Programs\SAUpdate.exe"
O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] C:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\aol\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1104100680\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [waol.exe] C:\Program Files\America Online 9.0b\waol.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Support - {2F685524-FB34-4244-B524-761636A70983} - http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {9A2FFE23-1DF0-44AE-AD29-A4591B5D2A36} - http://www.comcast.net (file missing) (HKCU)
O9 - Extra button: Help - {E0B4D805-9A8D-4107-B3E0-8FF1859BA3DE} - http://www.comcast.net/memberservices/ (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://bin.mcafee.com/molbin/shared/mcinsc…76/mcinsctl.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Findjobs.txt

Volume in drive C has no label.
Volume Serial Number is FC56-1593

Directory of C:\WINDOWS\tasks

10/04/2005 09:31 PM .
10/04/2005 09:31 PM ..
10/05/2005 09:00 PM 252 A0070A31918488C9.job
10/05/2005 09:00 PM 268 A02C6E519187E24D.job
10/05/2005 09:00 PM 268 A2CF928B91840CDB.job
10/05/2005 09:00 PM 260 A4939A6A91841092.job
10/05/2005 09:00 PM 234 A59479759187ED61.job
10/05/2005 09:00 PM 260 A847200C9184D8FC.job
10/05/2005 09:00 PM 260 A87058859187CF59.job
10/05/2005 09:00 PM 268 A93B5CB59058D839.job
10/05/2005 09:00 PM 260 A994E6D991839E31.job
10/05/2005 09:00 PM 268 AA987D1E9187F176.job
10/05/2005 09:00 PM 234 AAB04C6F9187C0BB.job
10/05/2005 09:00 PM 260 AB6C43019187F8A1.job
10/05/2005 09:00 PM 260 ABF84FA39187C6BF.job
10/05/2005 09:00 PM 268 AC5353429184C5E2.job
10/05/2005 09:00 PM 260 AD7BE52B91849977.job
10/05/2005 09:00 PM 268 AD84D350919F4B00.job
10/05/2005 09:00 PM 268 ADA8620491841528.job
10/05/2005 09:00 PM 268 ADB0236A9187D3BE.job
10/05/2005 09:00 PM 260 ADBFB5CB91842977.job
10/05/2005 09:00 PM 268 ADD7BBAF91842F93.job
10/05/2005 09:00 PM 268 AE2F8DB991843E85.job
10/05/2005 09:00 PM 264 AE9FA61591845649.job
10/05/2005 09:00 PM 260 AE9FAAC791842437.job
08/29/2002 05:00 AM 65 DESKTOP.INI
06/08/2003 02:37 PM 258 ISP signup reminder 1.job
10/07/2005 07:18 PM 6 SA.DAT
26 File(s) 6,333 bytes

Directory of C:\Documents and Settings\ed\Desktop
23 added tasks is a new record for me. :rofl:

Open notepad and copy and paste the following text into it:
%systemdrive%
cd C:\WINDOWS\Tasks
attrib -r -s -h A0070A31918488C9.job
del A0070A31918488C9.job
attrib -r -s -h A02C6E519187E24D.job
del A02C6E519187E24D.job
attrib -r -s -h A2CF928B91840CDB.job
del A2CF928B91840CDB.job
attrib -r -s -h A4939A6A91841092.job
del A4939A6A91841092.job
attrib -r -s -h A59479759187ED61.job
del A59479759187ED61.job
attrib -r -s -h A847200C9184D8FC.job
del A847200C9184D8FC.job
attrib -r -s -h A87058859187CF59.job
del A87058859187CF59.job
attrib -r -s -h A93B5CB59058D839.job
del A93B5CB59058D839.job
attrib -r -s -h A994E6D991839E31.job
del A994E6D991839E31.job
attrib -r -s -h AA987D1E9187F176.job
del AA987D1E9187F176.job
attrib -r -s -h AAB04C6F9187C0BB.job
del AAB04C6F9187C0BB.job
attrib -r -s -h AB6C43019187F8A1.job
del AB6C43019187F8A1.job
attrib -r -s -h ABF84FA39187C6BF.job
del ABF84FA39187C6BF.job
attrib -r -s -h AC5353429184C5E2.job
del AC5353429184C5E2.job
attrib -r -s -h AD7BE52B91849977.job
del AD7BE52B91849977.job
attrib -r -s -h AD84D350919F4B00.job
del AD84D350919F4B00.job
attrib -r -s -h ADA8620491841528.job
del ADA8620491841528.job
attrib -r -s -h ADB0236A9187D3BE.job
del ADB0236A9187D3BE.job
attrib -r -s -h ADBFB5CB91842977.job
del ADBFB5CB91842977.job
attrib -r -s -h ADD7BBAF91842F93.job
del ADD7BBAF91842F93.job
attrib -r -s -h AE2F8DB991843E85.job
del AE2F8DB991843E85.job
attrib -r -s -h AE9FA61591845649.job
del AE9FA61591845649.job
attrib -r -s -h AE9FAAC791842437.job
del AE9FAAC791842437.job

Save this as remjob.bat, choose to save it as *all files* and place it on your desktop.

Doubleclick on remjob.bat. A doswindow will open and close again, this is normal.

Afterwards, doubleclick on findjobs.bat again and paste the content of the txtfile you get in your next reply.


Click here to download mwavscan.
  • Double-click it to run it.
  • Read then accept the agreement.
  • Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
  • Once it finds something, it will prompt you so click OK.
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it with the mouse, copy it (CTRL+C), and paste (CTRL+V) it in your next reply.
Note : It will find many orphaned registry entries so please do not be alarmed by the amount of items that show.
Alan, I guess all those tasks are pretty busy… Here's the log from the virus scan.. It's too big for one post - so I'm going to try to break it up into a couple of posts again…. Object "srchasst Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "virtumonde Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "spediabar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "spediabar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "look2me Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "browseraid Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "startsurfing Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "clipgenie Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\LRUN32.EXE" refers to invalid object "C:\WINDOWS\LRUN32.EXE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE" refers to invalid object "C:\WINDOWS\ORUN32.EXE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\udfrinst.exe" refers to invalid object "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\udfrinst.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Favorites\Financial Links\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\My Documents\My Pictures\Dell Image Expert Images\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\WMPLYR\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VSRCPLIN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DELLCUSTOM\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\AUDP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\AUSTRM\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDBURNING\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RMJPLN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDEXTRACT\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDINFO\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDROMS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\COMMON\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DATACACHE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DEVICES\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FIRSTRUN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DTDRPLINDIR\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\EPLUGINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FAUST\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FFTRANSCDIR\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FIRSTRUN_LOCALGUIDE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FLASH\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FREE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\GEMSETUP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\GEMXMLBIN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\HOWTO\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\HOWTOHANDLER\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\JSCRIPT\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MinAim\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MINHELP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3PL\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3PLN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGIMG\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGROOT\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGUI\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MULTICST\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNDEVICEINI\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNENGINE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNPLUGINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNRPPLUGINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNSUPPORT\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDMGR\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYER\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERPLUGINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERPLUGOCX\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERUNINST\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLSHARED\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLUS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RACODECS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJBRES\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJBVIZ\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJDLG\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJMPMED\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJMPZIP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RMXPLN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RNADMIN\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RTPLINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RV9CODECS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RVCODECS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\SECURITY\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\SKINS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TDWNMGR\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TEMPLATES\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TFILESYS\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\UI\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\UPDATE\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VIDP\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VIZ\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VMPG\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\Alert\bin\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\Alert\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\DSLogDB\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Support\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\bin\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Alert\0\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Alert\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\iPod\System Software 2.1\". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\iPod\iPod Updater 2004-11-15\". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".728". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".aby". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ARL". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BAG". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".CBZ". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cgi". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".CH_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dlr". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".elog". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".FO_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".GI_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".HT_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".info". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".JP_". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".LDZ". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".tmp". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object "OpenWithList". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "CasProg". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Dbi". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Delete Pile Program". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "DyFuCA Software Installer". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "HSA". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ieupdate". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{BE20E2F5-1903-4AAE-B1AF-2046E586C925}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Optimizer". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Optimizer Active Alert". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Internet Optimizer Software Installer". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ISTsvc". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB821557". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823182". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823559". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824105". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824141". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824146". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB825119". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828028". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828035". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828741". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB835732". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB837001". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "McAfee.com Personal Firewall Plus". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Mcafee.com SecurityCenter". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "MUSICMATCH Jukebox". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "PGate". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329170". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329441". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329834". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810565". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810577". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810833". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q811493". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q814033". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q815021". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817287". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817606". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q828026". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QuickTime". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "RVP". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Spybot - Search & Destroy_is1". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SW". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "TTOOL_UNINSTALL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Viewpoint Manager". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wcmdmgr.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "WhenUSearch". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "WinTools". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtdmmp". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtwebdriver". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{43FCA273-9534-40DB-B7C5-D7758875616A}". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8F5734D4-E8EE-449C-97AE-B4F9BE9932BF}". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0025F2F6-5458-478E-997C-76BBB056B3D6}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{029235E5-3AB4-4CDC-8007-B24EF9442577}" refers to invalid object "C:\WINDOWS\System32\iprxrip.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{030CD4FD-3EC2-4D16-BCCA-45186B8E7497}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\WEBSER~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0402874E-D6FB-743D-B498-368C43E6321A}" refers to invalid object "C:\WINDOWS\system32\iedw32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{04EF3013-E124-8D59-21C6-88169F2874A5}" refers to invalid object "C:\WINDOWS\system32\addzk32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0913F24C-3C2E-194B-01C2-D48D08959AE9}" refers to invalid object "C:\WINDOWS\system32\atlkn.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0AD31460-EF0E-402B-93CB-D92615A5C2E1}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\AOLCON~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{11405E5B-9008-4121-B33C-7F6C5692F862}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\ADDRES~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{21D57F07-6235-EB86-0AF1-F0E67B88EA23}" refers to invalid object "C:\WINDOWS\d3mo.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{21DB24D5-9DD7-4F6F-993A-5FB0980EC5DB}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{22803C10-1FD3-11D5-BE64-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\g2p.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{250B0184-3052-4EFB-AAA7-24429B8C0627}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\CTABridge.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{28E74E8D-7B99-4486-AE32-11B67F93B54B}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2C0CB75A-8DC8-E8EE-4EAA-230D9CA1A150}" refers to invalid object "C:\WINDOWS\system32\winto32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2E3934B7-9E71-C91C-B349-631575C35CD7}" refers to invalid object "C:\WINDOWS\mfcgh32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{35FE0D30-27F3-4E6A-82AE-784EF9B43D83}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Alerts.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3ED232B4-0346-4A74-A883-B85B69ADA6A4}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{446C4F9B-A819-F5F2-56CE-199D78FB32E5}" refers to invalid object "C:\WINDOWS\system32\mfchj32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4493EDDC-F245-479B-B256-09296B14C5B8}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Mail.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4A6A6A8F-EBB4-AAE6-AB7A-CD9C0D9D7348}" refers to invalid object "C:\WINDOWS\crln.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4D6B069D-B60E-C772-38DC-E2FEB648DEE4}" refers to invalid object "C:\WINDOWS\d3ly.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4EDDDDBC-3528-41AA-AA6E-237AA8092C08}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Buddy.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{55C2F961-D23F-7B86-44B7-962846EE65E5}" refers to invalid object "C:\WINDOWS\system32\apihk.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5696745A-F3BD-11D4-8A1D-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5A63D47D-1BA2-48ff-9955-31207899BE01}" refers to invalid object "c:\program files\mcafee.com\shared\mcinfo.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{601C435E-D784-F23F-4818-96DF3B83A3DC}" refers to invalid object "C:\WINDOWS\system32\ierp32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{639368F3-5ADE-6C41-BF69-7897B569B04F}" refers to invalid object "C:\WINDOWS\system32\netxf.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6833E600-F6D8-11D4-8A1F-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6E0CC0B9-ABA4-30B7-B603-911363B847DB}" refers to invalid object "C:\WINDOWS\system32\mfcmm32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6EC0CC36-5464-73BB-CF4A-7A72D78A827C}" refers to invalid object "C:\WINDOWS\appym32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6EC73435-F769-6D32-369A-4013F3F1991E}" refers to invalid object "C:\WINDOWS\sdktv32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6EDA439D-F7C7-11d4-8A20-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6F2F7312-647A-C992-D9BF-8F4A5CC18F6E}" refers to invalid object "C:\WINDOWS\system32\javajz.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7881BD18-10B6-EE7F-059F-3C7704C7184F}" refers to invalid object "C:\WINDOWS\system32\d3ow32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{78D0C657-22F0-4E19-A34A-757B14A30344}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7DACA09B-5B6E-B969-E0AC-A6A120621F84}" refers to invalid object "C:\WINDOWS\wincs.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{823FA5B2-FD5A-4EA5-BCF9-18FCCC9884D2}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\PUBLIS~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{86CAB821-53B9-C20C-BE18-8DD22A88DF5B}" refers to invalid object "C:\WINDOWS\msod32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8DA5DF2C-798A-4CAB-8BB7-672C53DDDE94}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\FAVORI~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8DF52C0D-3744-50B3-97E4-9D507D91453A}" refers to invalid object "C:\WINDOWS\system32\javacc32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{982D3E66-F915-EF10-FC67-9BF515D09562}" refers to invalid object "C:\WINDOWS\wingl32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9D569E8E-19DD-0917-0E06-21143150B6DF}" refers to invalid object "C:\WINDOWS\d3xh.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9D6022B0-B852-04CC-AA3A-235E6174F8F7}" refers to invalid object "C:\WINDOWS\system32\addha.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9DE50DE0-49AA-0D80-A389-29CD986CADDE}" refers to invalid object "C:\WINDOWS\netxb.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9E8C5DCC-A484-2DBF-E4C6-4844CBB11692}" refers to invalid object "C:\WINDOWS\system32\ipzy32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{A0B65408-65FF-4FDF-9CF0-3763C3CA29C4}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\IMs.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{ADF7D058-9CAD-060E-7351-7054ECD9E8CA}" refers to invalid object "C:\WINDOWS\netsb32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B02F4EEB-78D3-414D-8814-7E88F4828C28}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B12350DF-883F-1429-D2AA-DBFD3F847558}" refers to invalid object "C:\WINDOWS\addbp.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B2DAA0AB-D319-3448-13E7-FA6452D9FE0B}" refers to invalid object "C:\WINDOWS\system32\addvv.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B343E2B5-8457-02FA-13C5-881C72A433AD}" refers to invalid object "C:\WINDOWS\mfcqv32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BF4C25B5-CD0A-4770-B2F5-750A4407957F}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C3AF7850-1A2F-1166-5EC3-90C3C4850D8F}" refers to invalid object "C:\WINDOWS\netfv32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C5CF4CAD-122C-B1C9-D29C-6A5CE8BA43F1}" refers to invalid object "C:\WINDOWS\system32\crhq32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C657669A-754D-4E13-BB96-B7269F2078F0}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C768249C-9E14-7E41-12D5-3DFD3D066F3C}" refers to invalid object "C:\WINDOWS\iesn.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CC5851A4-7E43-177D-648D-888A21EA3B62}" refers to invalid object "C:\WINDOWS\winya.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CE707B3C-380F-1747-2626-6C5910CC299C}" refers to invalid object "C:\WINDOWS\d3ni32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{CF2874E0-A53C-6EDE-A0EF-0B55B6D2B4C1}" refers to invalid object "C:\WINDOWS\system32\apphz32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D5392B4A-DF48-9B6F-1D4F-9959345122DB}" refers to invalid object "C:\WINDOWS\system32\atlys.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DBD550DE-453A-61BF-2376-AD088E0F2472}" refers to invalid object "C:\WINDOWS\system32\ntrv32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DC9C2FB9-F3C3-A770-CC5F-83E4FC7CC182}" refers to invalid object "C:\WINDOWS\system32\apiue.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{DF0E9111-01DF-11D5-BA23-001083780941}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\CalPrinting.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E5151CBE-F61D-11D4-BA21-001083780941}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\CalPrinting.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F3206ECF-B7F9-4E61-9D15-ACC0627E2C59}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\WEBSER~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F6D48516-14C1-2153-B6DD-B6ED7283E8A2}" refers to invalid object "C:\WINDOWS\d3we32.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FF2ECDB6-D065-22AB-597F-B4F5E5C40344}" refers to invalid object "C:\WINDOWS\system32\iphl.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FF516801-7DA3-2EF0-8785-4C8CAE4FE21E}" refers to invalid object "C:\WINDOWS\system32\iehr32.exe". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{155B3F27-CDEE-4FE2-8CC5-8D08882FDE15}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Buddy.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{2DBDEE9B-56B8-4E14-8A48-D20C64AAA673}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\FAVORI~1.DLL". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{4C0E82A0-EF04-432E-9C8A-551A5656ACC8}" refers to invalid object "C:\Program Files\America Online 8.0\ehtmview.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{4F0876E2-8ECB-4C93-94AD-4E1EAAF7C0F8}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\CTABridge.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{5696743D-F3BD-11D4-8A1D-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\IE_NDS.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{5C15D2EF-34AB-48FC-876C-3A64961E10C1}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Mail.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{6883B133-1B30-45E1-842F-B8670389559D}" refers to invalid object "c:\program files\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{6F3F3EF2-AA93-487B-A25C-BD67735E53B9}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\Alerts.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{7D3F5DE4-E980-4407-A10F-9AC771ABAAE6}" refers to invalid object "C:\Program Files\AOL Toolbar\toolbar.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{95117066-315E-4CAE-BE3D-E7897D3F98BC}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\IMs.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{989E6670-3798-4C35-AA11-EB4E18F404C4}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\PUBLIS~1.DLL". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{A73B6F3D-FD35-4992-AB4B-4AD729BB20E7}" refers to invalid object "c:\program files\mcafee.com\shared\mcinfo.exe". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{D3470F50-AB2B-40B4-B75E-057BB3487550}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\WEBSER~1.DLL". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{D6D80D13-633A-444C-9829-4A3013D7FFBB}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\AOLCON~1.DLL". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{E5151CB1-F61D-11D4-BA21-001083780941}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\CalPrinting.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{EADCE179-1CC2-11D5-BE60-001083023C0D}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\g2p.dll". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{F0F69A8F-9388-4EEE-9977-BD8AB18C5733}" refers to invalid object "C:\PROGRA~1\AOLCOM~1\ADDRES~1.DLL". Action Taken: No Action Taken. Entry "HKCR\.mp4" refers to invalid object "QuickTime.mp4". Action Taken: No Action Taken. Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\AOL.IEToolbar" refers to invalid object "{4982D40A-C53B-4615-B15B-B5B5E98D167C}". Action Taken: No Action Taken. Entry "HKCR\AOL.IEToolbar.1" refers to invalid object "{4982D40A-C53B-4615-B15B-B5B5E98D167C}". Action Taken: No Action Taken. Entry "HKCR\CDDBControlRoxio.CddbFullName.1" refers to invalid object "{1c6e0e46-4e5f-492d-b946-44291b931361}". Action Taken: No Action Taken. Entry "HKCR\CDDBControlRoxio.FullName" refers to invalid object "{1c6e0e46-4e5f-492d-b946-44291b931361}". Action Taken: No Action Taken. Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\System32\CMMGR32.EXE "%1"". Action Taken: No Action Taken. Entry "HKCR\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\aol.exe "%1" ". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\msbackupfile\shell\open\command" refers to invalid object "%SystemRoot%\system32\ntbackup.exe". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\ppifile\shell\open\command" refers to invalid object "%SystemRoot%\System32\msppcnfg.exe /Config %1". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\SpybotSD.DisabledFile\shell\open\command" refers to invalid object ""C:\Program Files\Spybot - Search & Destroy\blindman.exe" %1". Action Taken: No Action Taken. Entry "HKCR\SpybotSD.TInfoFile\shell\open\command" refers to invalid object ""C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" %1". Action Taken: No Action Taken. Entry "HKCR\ToolbarAOLToolbar" refers to invalid object "{4982D40A-C53B-4615-B15B-B5B5E98D167C}". Action Taken: No Action Taken. Entry &
2nd part of virus log and the findjobs.txt file…… File C:\Documents and Settings\sharon\Local Settings\Temp\wqlwrmbs.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wrcyeelt.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wvqfcrle.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\xzvofipw.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\yrvenxoq.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\zjvuocfr.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temporary Internet Files\Content.IE5\G9270P2J\upAYB[1].int infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\45F.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\47.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\52.tmp infected by "Trojan.Win32.Harnig.a" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\58B.tmp tagged as "not-a-virus:AdWare.Win32.PurityScan.b". Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\78.tmp infected by "Trojan-Dropper.DOS.Rute" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7A.tmp infected by "Trojan-Spy.Win32.Tofger.s" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A6.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485783.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485787.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485789.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485790.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492786.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492787.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492791.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492795.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499817.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499818.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499819.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499821.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499824.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499826.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP272\A0506806.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532828.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532829.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532830.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532832.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532836.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536819.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536820.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536821.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536823.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536826.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536827.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536830.exe infected by "Trojan-Downloader.Win32.Swizzor.dj" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536831.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537813.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537814.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537815.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537816.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537818.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537819.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537822.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537825.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550818.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550819.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550820.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550821.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550822.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550824.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550825.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550828.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550829.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550831.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553818.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553819.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553820.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553822.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553826.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553827.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553828.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553830.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553832.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553833.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564824.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564825.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564826.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570827.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570828.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570830.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570831.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570832.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570835.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570836.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570837.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570840.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570841.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572817.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572818.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572819.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572820.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572822.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572824.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572825.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572826.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572829.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572830.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593869.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593870.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593872.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593873.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593874.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593875.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593876.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593879.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593880.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593881.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593884.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593885.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602857.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602872.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602873.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602874.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602876.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602877.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602878.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602879.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602880.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602881.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602884.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602885.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602886.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606079.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606080.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606081.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606082.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606084.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606085.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606086.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606087.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606088.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606089.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606090.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606093.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606094.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606095.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0610382.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP302\A0622838.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP305\A0627011.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637427.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637458.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP309\A0637459.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648079.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648080.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648081.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648082.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648084.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648085.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648086.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648087.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648088.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648089.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648090.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648093.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648094.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648095.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648096.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648097.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648099.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648100.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648101.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648102.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648103.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648104.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648105.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648107.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP313\A0648108.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651317.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651318.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651319.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651320.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651321.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651323.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651324.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651325.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651326.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651327.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651329.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651331.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651332.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651333.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651334.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651335.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651339.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651341.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651343.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651344.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651350.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651351.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651356.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651357.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651359.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651361.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651362.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651363.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651364.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651366.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651369.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651370.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651371.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651372.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651373.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651376.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP314\A0651377.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\addgr32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\addjv32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\addtu.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\apifl.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\apptd32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\d3al32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\d3dx.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\javagi32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\javagw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\mfcaz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\mfcen.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\mfcvx.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\msfp.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\mshj32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\netbu.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\netdw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\ntdg.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\ntpo32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\n_foysiy.txt infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\n_vhzbep.log infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\sdkai.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\sdkvi32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\Install_All.DLL.tobedeleted tagged as "not-a-virus:AdWare.Win32.IGetNet.d". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6bO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6kO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6lO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6mO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6pO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\6sO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\addgl.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\addkr.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\AfMPARSE.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\AmCTRES.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\apibm.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\apigd.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\appez32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\appkt32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\appqb32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\apprw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\appxq.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\atluh32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\atlyr32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\ayd.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\AzCTRES.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\AzMPARSE.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\crli32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\d3dc.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\iebc.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\iepe.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\ieph.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\iepw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\iexg.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\ipvl32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\javaly32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\javaou.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\javaug32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\msg120.cpy.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\msg120.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\msg121.cpy.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\msnt32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\msvy32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\netnf32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\netzs.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\sdkde.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\sdkyj32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\surte.exe infected by "Trojan-Dropper.Win32.Small.dv" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\sysky32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\sysld32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\sysuz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winkv.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winst32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\sysuy.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\Temp\cidrules.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.g". Action Taken: No Action Taken. File C:\WINDOWS\Temp\GLB51.tmp tagged as "not-a-virus:AdWare.Win32.VirtualBouncer.j". Action Taken: No Action Taken. File C:\WINDOWS\Temp\GLB58.tmp tagged as "not-a-virus:AdWare.Win32.VirtualBouncer.j". Action Taken: No Action Taken. File C:\WINDOWS\Temp\upd122.exe tagged as "not-a-virus:AdWare.Win32.Look2Me.g". Action Taken: No Action Taken. File C:\WINDOWS\Temp\~compoundinst0\apropos_install.exe infected by "Trojan-Downloader.Win32.Apropo.b" Virus! Action Taken: No Action Taken. File C:\WINDOWS\winbz32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\winqu32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\winxf32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. FINDJOBS results… Volume in drive C has no label. Volume Serial Number is FC56-1593 Directory of C:\WINDOWS\tasks 10/09/2005 05:34 PM . 10/09/2005 05:34 PM .. 08/29/2002 05:00 AM 65 DESKTOP.INI 06/08/2003 02:37 PM 258 ISP signup reminder 1.job 10/09/2005 05:30 PM 6 SA.DAT 3 File(s) 329 bytes Directory of C:\Documents and Settings\ed\Desktop Thanks for staying with me on this…. Kristin
Quite a bit of the mwavscan log was missed in that first post as the email notification showed more than the actual post did. There is quite a bit of files that still need cleaning out. I am shocked that Ewido missed this many in its scans. :(

Click here to download Killbox by Option^Explicit.
Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program and click on Tools < Delete Temp Files.
Still in the killbox program, select the Delete on Reboot option.
Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\addgr32.exe
C:\WINDOWS\addjv32.exe
C:\WINDOWS\addtu.exe
C:\WINDOWS\apifl.exe
C:\WINDOWS\apptd32.exe
C:\WINDOWS\crpu.exe
C:\WINDOWS\d3al32.exe
C:\WINDOWS\d3dx.exe
C:\WINDOWS\dlm.html
C:\WINDOWS\javagi32.dll
C:\WINDOWS\javagw32.exe
C:\WINDOWS\mfcaz.exe
C:\WINDOWS\mfcen.exe
C:\WINDOWS\mfcvx.exe
C:\WINDOWS\msfp.exe
C:\WINDOWS\mshj32.dll
C:\WINDOWS\mssys.com
C:\WINDOWS\netbu.exe
C:\WINDOWS\netdw32.exe
C:\WINDOWS\ntdg.exe
C:\WINDOWS\ntpo32.exe
C:\WINDOWS\n_foysiy.txt
C:\WINDOWS\n_vhzbep.log
C:\WINDOWS\sdkai.exe
C:\WINDOWS\sdkvi32.exe
C:\WINDOWS\sysmj.exe
C:\WINDOWS\sysuy.exe
C:\WINDOWS\winbz32.exe
C:\WINDOWS\winqu32.exe
C:\WINDOWS\winxf32.exe
C:\WINDOWS\system32\6bO4SVC.DLL
C:\WINDOWS\system32\6kO4SVC.DLL
C:\WINDOWS\SYSTEM32\6lO4SVC.DLL
C:\WINDOWS\system32\6mO4SVC.DLL
C:\WINDOWS\system32\6pO4SVC.DLL
C:\WINDOWS\system32\6sO4SVC.DLL
C:\WINDOWS\system32\addgl.exe
C:\WINDOWS\system32\addkr.exe
C:\WINDOWS\system32\AfMPARSE.DLL
C:\WINDOWS\system32\AmCTRES.DLL
C:\WINDOWS\system32\apibm.dll
C:\WINDOWS\system32\apigd.dll
C:\WINDOWS\system32\appez32.exe
C:\WINDOWS\system32\appkt32.exe
C:\WINDOWS\system32\appqb32.exe
C:\WINDOWS\system32\apprw32.exe
C:\WINDOWS\system32\appxq.dll
C:\WINDOWS\system32\atluh32.exe
C:\WINDOWS\system32\atlyr32.exe
C:\WINDOWS\system32\ayd.dll
C:\WINDOWS\system32\AzCTRES.DLL
C:\WINDOWS\system32\AzMPARSE.DLL
C:\WINDOWS\system32\crli32.exe
C:\WINDOWS\system32\d3dc.exe
C:\WINDOWS\system32\iebc.exe
C:\WINDOWS\system32\iepe.exe
C:\WINDOWS\system32\ieph.exe
C:\WINDOWS\system32\iepw32.exe
C:\WINDOWS\system32\iexg.exe
C:\WINDOWS\system32\ipvl32.exe
C:\WINDOWS\system32\javaly32.exe
C:\WINDOWS\system32\javaou.exe
C:\WINDOWS\system32\javaug32.exe
C:\WINDOWS\system32\msg120.cpy.dll
C:\WINDOWS\system32\msg120.dll
C:\WINDOWS\system32\msg121.cpy.dll
C:\WINDOWS\system32\msnt32.exe
C:\WINDOWS\system32\msvy32.exe
C:\WINDOWS\system32\netnf32.exe
C:\WINDOWS\system32\netzs.exe
C:\WINDOWS\system32\sdkde.exe
C:\WINDOWS\system32\sdkyj32.exe
C:\WINDOWS\system32\surte.exe
C:\WINDOWS\system32\sysky32.exe
C:\WINDOWS\system32\sysld32.dll
C:\WINDOWS\system32\sysuz.exe
C:\WINDOWS\system32\winkv.exe
C:\WINDOWS\system32\winst32.exe
C:\bpc_bundleware.exe
C:\Documents and Settings\Administrator.D2SDZV21\My Documents\Data\Data\MemWatcher2.exe
C:\Documents and Settings\Administrator.D2SDZV21\My Documents\Data\MemWatcher2.exe
C:\Documents and Settings\Default User\My Documents\Data\Data\MemWatcher2.exe
C:\Documents and Settings\Default User\My Documents\Data\MemWatcher2.exe
C:\WINDOWS\SYSTEM\Install_All.DLL.tobedeleted


Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.


After the computer reboots, Restore Deleted System Files

Now we need to see if we need to restore some deleted files : Please check for the following files using the Windows Search Engine:
  • control.exe
  • rundll32.exe
  • wmplayer.exe
  • msconfig.exe
  • notepad.exe
  • shell.dll
  • SDHelper.dll
If any are missing or not working properly then you can download new copies from
Merijn's Files and following the instructions at that site to have them where they belong for your OS.
  • If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
  • Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
  • This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in XP. In XP there are two copies of this file, one in Windows and one in Windows\System32. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows and Windows\System32 .
  • The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not, please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website.
  • If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
Scan again with mwavscan and post the new log along with a fresh HijackThis log.
When posting the mwavscan log, please remove all entries that begin with Entry such as
Entry "HKCR\CDDBControlRoxio.CddbFullName.1" refers to invalid object "{1c6e0e46-4e5f-492d-b946-44291b931361}". Action Taken: No Action Taken.
as these are not needed and will make the log much easier to post. :)
Alan, Ok - Followed your instructions - the only file that was missing was the SDhelper.exe - but i couldn't find a program directory for SpyBot, so I didn't do anything about it…. Heres the new virus scan - without the "Entry…" entries. Object "srchasst Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "virtumonde Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "spediabar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "spediabar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "browseraid Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.savenow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "startsurfing Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "clipgenie Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cydoor Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\DOCUME~1\ed\LOCALS~1\Temp\9709c57e.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken. File C:\!KillBox\6bO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\6kO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\6lO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\6mO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\6pO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\6sO4SVC.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\addgl.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\addgr32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\addjv32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\addkr.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\addtu.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\AfMPARSE.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\AmCTRES.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\apibm.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\apifl.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\apigd.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\appez32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\appkt32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\appqb32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\apprw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\apptd32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\appxq.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\atluh32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\atlyr32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\ayd.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\AzCTRES.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\AzMPARSE.DLL tagged as "not-a-virus:AdWare.Win32.Look2Me.z". Action Taken: No Action Taken. File C:\!KillBox\bpc_bundleware.exe tagged as "not-a-virus:AdWare.Win32.Broadcap.c". Action Taken: No Action Taken. File C:\!KillBox\crli32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\d3al32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\d3dc.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\d3dx.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\iebc.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\iepe.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\ieph.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\iepw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\iexg.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\Install_All.DLL.tobedeleted tagged as "not-a-virus:AdWare.Win32.IGetNet.d". Action Taken: No Action Taken. File C:\!KillBox\ipvl32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\javagi32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\javagw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\javaly32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\javaou.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\javaug32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\MemWatcher2.exe infected by "Backdoor.Win32.VB.nb" Virus! Action Taken: No Action Taken. File C:\!KillBox\mfcaz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\mfcen.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\mfcvx.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\msfp.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\msg120.cpy.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\!KillBox\msg120.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\!KillBox\msg121.cpy.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.e". Action Taken: No Action Taken. File C:\!KillBox\mshj32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\msnt32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\msvy32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\netbu.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\netdw32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\netnf32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\netzs.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\ntdg.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\ntpo32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\n_foysiy.txt infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\n_vhzbep.log infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sdkai.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sdkde.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sdkvi32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sdkyj32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\surte.exe infected by "Trojan-Dropper.Win32.Small.dv" Virus! Action Taken: No Action Taken. File C:\!KillBox\sysky32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sysld32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\!KillBox\sysuy.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\sysuz.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\winbz32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\winkv.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\winqu32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\winst32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\!KillBox\winxf32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\ed\Local Settings\Temp\9709c57e.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Application Data\Browse dale sign\bold soft less.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Application Data\Browse dale sign\rgzqvngw.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\Documents and Settings\jack\Application Data\Browse dale sign\wait trans.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Application Data\chindumbdate\For owns.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\ekoiizzb.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\frfynghq.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\gljlotta.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\kxpqyhlo.exe tagged as "not-a-virus:AdWare.Win32.Lop". Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\mkjtiayy.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\nzgfhdai.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\ocaxpoft.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\pfvrhxfu.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\rbfdfmmy.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\sta5.exe infected by "Trojan-Downloader.Win32.Swizzor.br" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\sta9.exe infected by "Trojan-Downloader.Win32.Swizzor.br" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\staD.exe tagged as "not-a-virus:AdWare.Win32.Lop". Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\ulynubuu.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\vfctqpcf.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\xijlhyge.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\ymapujoo.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\zhmqapdq.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\jack\Local Settings\Temp\zooswhmo.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Application Data\Browse dale sign\bold soft less.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Application Data\Browse dale sign\cugfbhkw.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Application Data\Browse dale sign\wait trans.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Application Data\chindumbdate\For owns.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\blrchhcg.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\cupzjrtd.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\dcrxonez.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\ffpehgid.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\fsxivlyi.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\Inside Program.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\jqukxpgq.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\krszahsq.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\njbyizqv.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\oczpudsj.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\ooknfcks.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\rzhtkzcg.exe tagged as "not-a-virus:AdWare.Win32.Lop". Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\sbeopjfq.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\snnvxpjg.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\staD2.exe infected by "Trojan-Downloader.Win32.Swizzor.br" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\staE9.exe tagged as "not-a-virus:AdWare.Win32.Lop". Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\tinoabyk.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\tvbzjxzf.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wazkxzli.exe tagged as "not-a-virus:AdWare.Win32.Lop". Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wqlwrmbs.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wrcyeelt.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\wvqfcrle.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\xzvofipw.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\yrvenxoq.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temp\zjvuocfr.exe infected by "Trojan-Downloader.Win32.Swizzor.ch" Virus! Action Taken: No Action Taken. File C:\Documents and Settings\sharon\Local Settings\Temporary Internet Files\Content.IE5\G9270P2J\upAYB[1].int infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\45F.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\47.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\52.tmp infected by "Trojan.Win32.Harnig.a" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\58B.tmp tagged as "not-a-virus:AdWare.Win32.PurityScan.b". Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\78.tmp infected by "Trojan-Dropper.DOS.Rute" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7A.tmp infected by "Trojan-Spy.Win32.Tofger.s" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A6.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C20.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C22.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C24.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C29.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C37.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C39.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C3B.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C40.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C42.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C44.tmp infected by "Trojan-Downloader.Win32.Swizzor.di" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C54.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C59.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C5B.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C60.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C71.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C76.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C78.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C7A.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C88.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C8D.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C8F.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C97.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C99.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CAD.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CB5.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CB7.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CBF.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CD3.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CDB.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CDD.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CE5.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CF3.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CFB.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\CFD.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D08.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D0D.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D26.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D31.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D33.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D3E.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D40.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D54.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D65.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D67.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D6F.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D79.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D8A.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D8C.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D97.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D99.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DB5.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DC9.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DCB.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DD6.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DE4.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DFB.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\DFD.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E08.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E47.tmp infected by "Trojan.Win32.Harnig.a" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E5D.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E74.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E76.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E87.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E9E.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F73.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F75.tmp infected by "Trojan-Dropper.DOS.Rute" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F77.tmp infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F79.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F7B.tmp infected by "Trojan-Downloader.Win32.Small.ct" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F7D.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F7F.tmp infected by "Trojan-Downloader.Win32.Swizzor.bz" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F81.tmp infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. File C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F83.tmp tagged as "not-a-virus:AdWare.Win32.PurityScan.b". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485783.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485787.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485789.exe infected by "Trojan-Downloader.Win32.Swizzor.ca" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0485790.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492786.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492787.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492791.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP268\A0492795.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499817.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499818.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499819.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499821.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499824.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP271\A0499826.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP272\A0506806.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532828.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532829.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532830.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532832.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP281\A0532836.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536819.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536820.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536821.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536823.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536826.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536827.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536830.exe infected by "Trojan-Downloader.Win32.Swizzor.dj" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0536831.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537813.exe infected by "Trojan-Downloader.Win32.Swizzor.dp" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537814.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537815.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537816.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537818.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537819.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537822.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP282\A0537825.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550818.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550819.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550820.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550821.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550822.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550824.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550825.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550828.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550829.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0550831.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553818.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553819.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553820.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553822.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553826.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553827.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553828.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553830.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553832.exe infected by "Trojan-Downloader.Win32.Swizzor.dr" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP284\A0553833.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564824.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564825.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0564826.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570827.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570828.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570830.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570831.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570832.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570835.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570836.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570837.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570840.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP285\A0570841.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572817.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572818.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572819.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572820.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572822.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572823.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572824.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572825.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572826.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572829.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP286\A0572830.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593869.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593870.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593872.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593873.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593874.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593875.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593876.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593879.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593880.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593881.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593884.exe infected by "Trojan-Downloader.Win32.Swizzor.dh" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP290\A0593885.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602857.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602872.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602873.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602874.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602876.exe infected by "Trojan-Downloader.Win32.Swizzor.de" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602877.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602878.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602879.exe tagged as "not-a-virus:AdWare.Win32.Lop.ab". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602880.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602881.exe tagged as "not-a-virus:AdWare.Win32.Lop.ad". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602884.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602885.exe tagged as "not-a-virus:AdWare.Win32.Lop.p". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP295\A0602886.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606079.exe infected by "Trojan-Downloader.Win32.Swizzor.co" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606080.exe infected by "Trojan-Downloader.Win32.Swizzor.cb" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP297\A0606081.exe tagged as "not-a-virus:AdWare.Win32.Lop.z". Action Taken: No Action Taken. File C:\System Volume Information&

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI