1)look2me destroyer log
Look2Me-Destroyer V1.0.12
Scanning for infected files…..
Scan started at 4/22/2006 6:32:06 PM
Infected! C:\WINDOWS\system32\ir44l5hq1.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll
Infected! C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll
Infected! C:\WINDOWS\system32\aza4l9fq1.dll
Infected! C:\WINDOWS\system32\diquery.dll
Infected! C:\WINDOWS\system32\fp2203foe.dll
Infected! C:\WINDOWS\system32\hr8q05l5e.dll
Infected! C:\WINDOWS\system32\ir44l5hq1.dll
Infected! C:\WINDOWS\system32\j0p0la7m1d.dll
Infected! C:\WINDOWS\system32\jt6o07j3e.dll
Infected! C:\WINDOWS\system32\jtn2075oe.dll
Infected! C:\WINDOWS\system32\k0js0a17ed.dll
Infected! C:\WINDOWS\system32\kydest.dll
Infected! C:\WINDOWS\system32\m028lafu1d28.dll
Infected! C:\WINDOWS\system32\mtyuv.dll
Infected! C:\WINDOWS\system32\mvr0l99m1.dll
Infected! C:\WINDOWS\system32\o8ro0i93e8.dll
Infected! C:\WINDOWS\system32\p48qlel51hq.dll
Infected! C:\WINDOWS\system32\r06u0aj9edo.dll
Infected! C:\WINDOWS\system32\sfrialui.dll
Attempting to delete infected files…
Attempting to delete: C:\WINDOWS\system32\ir44l5hq1.dll
C:\WINDOWS\system32\ir44l5hq1.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014500.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP10\A0014562.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014798.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP11\A0014806.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP12\A0015791.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0015820.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016820.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016856.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP13\A0016857.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP15\A0017856.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018040.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0018073.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP16\A0019047.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020049.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020068.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0020072.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021082.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021084.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP17\A0021088.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0022105.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0023098.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0024093.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025110.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025126.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP18\A0025137.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025203.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP22\A0025226.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026221.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026242.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026266.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP26\A0026286.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0002360.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP4\A0003371.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0003545.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006610.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006726.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0006728.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP5\A0007726.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007762.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP6\A0007770.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007886.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007893.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007917.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0007931.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0008927.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009129.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009145.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP8\A0009963.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0009979.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0011961.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013966.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013974.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013977.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013978.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013980.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013981.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013982.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013990.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013991.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013992.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0013993.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014000.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014003.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014011.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014066.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014126.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll
C:\System Volume Information\_restore{10F140BD-AF29-4169-A291-956205C8F758}\RP9\A0014133.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\aza4l9fq1.dll
C:\WINDOWS\system32\aza4l9fq1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\diquery.dll
C:\WINDOWS\system32\diquery.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\fp2203foe.dll
C:\WINDOWS\system32\fp2203foe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\hr8q05l5e.dll
C:\WINDOWS\system32\hr8q05l5e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\ir44l5hq1.dll
C:\WINDOWS\system32\ir44l5hq1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\j0p0la7m1d.dll
C:\WINDOWS\system32\j0p0la7m1d.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\jt6o07j3e.dll
C:\WINDOWS\system32\jt6o07j3e.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\jtn2075oe.dll
C:\WINDOWS\system32\jtn2075oe.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\k0js0a17ed.dll
C:\WINDOWS\system32\k0js0a17ed.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\kydest.dll
C:\WINDOWS\system32\kydest.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\m028lafu1d28.dll
C:\WINDOWS\system32\m028lafu1d28.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mtyuv.dll
C:\WINDOWS\system32\mtyuv.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\mvr0l99m1.dll
C:\WINDOWS\system32\mvr0l99m1.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\o8ro0i93e8.dll
C:\WINDOWS\system32\o8ro0i93e8.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\p48qlel51hq.dll
C:\WINDOWS\system32\p48qlel51hq.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\r06u0aj9edo.dll
C:\WINDOWS\system32\r06u0aj9edo.dll Deleted successfully!
Attempting to delete: C:\WINDOWS\system32\sfrialui.dll
C:\WINDOWS\system32\sfrialui.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SMDEn
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{C3920E6C-CE19-4EF2-AAD3-62A5513FD10D}"
HKCR\Clsid\{C3920E6C-CE19-4EF2-AAD3-62A5513FD10D}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{045319BE-ECD4-451E-BAAD-73DA11AEE5FB}"
HKCR\Clsid\{045319BE-ECD4-451E-BAAD-73DA11AEE5FB}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AEF40B18-96C0-4150-87C3-4B91B1830D0F}"
HKCR\Clsid\{AEF40B18-96C0-4150-87C3-4B91B1830D0F}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{AE0FA138-A4C2-4152-B5D0-B42E922B6034}"
HKCR\Clsid\{AE0FA138-A4C2-4152-B5D0-B42E922B6034}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
_________________________________________________________________________________
2) ewido log
———————————————————
ewido anti-malware - Scan report
———————————————————
+ Created on: 7:02:09 PM, 4/22/2006
+ Report-Checksum: 65460EF
+ Scan result:
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6001CDF7-6F45-471b-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
HKLM\SOFTWARE\webhancer -> Adware.WebHancer : Cleaned with backup
HKLM\SOFTWARE\webhancer\CC -> Adware.WebHancer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup
HKU\S-1-5-21-448539723-1500820517-725345543-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup
[416] C:\Program Files\NewDotNet\newdotnet6_38.dll -> Adware.NewDotNet : Cleaned with backup
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe -> Dropper.VB.lu : Cleaned with backup
:mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\q1caj6u5.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@epilot[1].txt -> TrackingCookie.Epilot : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Desktop\aimfix_quarantine\10960_mousepad11.exe.bak -> Hijacker.VB.mo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\Cookies\owner@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\i24.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr8520 -> Adware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\temp.frE9B8 -> Adware.Look2Me : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u18.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u1D.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\u3B.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un17.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un1B.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\un22.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\unC6.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temp\unD.tmp -> Adware.SurfSide : Cleaned with backup
C:\iexplore.exe -> Dropper.VB.mn : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000137.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000140.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000137.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\mc-110-12-0000140.exe -> Dropper.Agent.aac : Cleaned with backup
C:\Program Files\Common Files\Windows\services32.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup
C:\Program Files\Internet Optimizer\optimize.exe -> Adware.InternetOptimizer : Cleaned with backup
C:\Program Files\Network\ipnetwork.exe -> Adware.Maxifiles : Cleaned with backup
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\newdotnet6_38.dll -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\readme.html -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\uninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\outlook\outlook.exe -> Worm.VB.dw : Cleaned with backup
C:\Program Files\outlook\v.tmp -> Worm.VB.dw : Cleaned with backup
C:\Program Files\Toolbar888\tbu02640\ToolBar888.dll -> Adware.Softomate : Cleaned with backup
C:\Program Files\Toolbar888\ToolBar888.dll -> Adware.Softomate : Cleaned with backup
C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\license.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\Sporder.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\webhdll.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whAgent.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whiehlpr.dll -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whInstaller.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whSurvey.exe -> Adware.Webhancer : Cleaned with backup
C:\Program Files\Yazzle Snowball Wars\OINSetup.exe -> Dropper.PurityScan.ad : Cleaned with backup
C:\Program Files\Yazzle Sudoku\Sudoku.exe -> Dropper.VB.kk : Cleaned with backup
C:\WINDOWS\b.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\DH.dll -> Hijacker.Small.jf : Cleaned with backup
C:\WINDOWS\keyboard13.exe -> Downloader.VB.abj : Cleaned with backup
C:\WINDOWS\mousepad13.e -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\mousepad13.exe -> Hijacker.VB.mo : Cleaned with backup
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup
C:\WINDOWS\newname13.exe -> Downloader.VB.aaf : Cleaned with backup
C:\WINDOWS\pf79.exe -> Downloader.Dyfuca.ei : Cleaned with backup
C:\WINDOWS\QWx0b24\asappsrv.dll -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\QWx0b24\command.exe -> Adware.CommAd : Cleaned with backup
C:\WINDOWS\SS1001.exe -> Dropper.Small.qn : Cleaned with backup
C:\WINDOWS\sys03495487738.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\SYSC00.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\system32\ad.html -> Hijacker.Agent.e : Cleaned with backup
C:\WINDOWS\system32\qzxz.dll -> Adware.PurityScan : Cleaned with backup
C:\WINDOWS\system32\rar.exe -> Dropper.VB.mn : Cleaned with backup
C:\WINDOWS\system32\setup.exe.tmp -> Downloader.VB.abh : Cleaned with backup
C:\WINDOWS\system32\w001e3e3.dll -> Downloader.Agent.ahv : Cleaned with backup
C:\WINDOWS\system32\winlog.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS\unin101.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\uni_eh.exe -> Trojan.VB.tg : Cleaned with backup
C:\WINDOWS\unwn.exe -> Trojan.Qoologic : Cleaned with backup
C:\WINDOWS\wallpap.exe -> Hijacker.Agent.gp : Cleaned with backup
C:\WINDOWS\wbyzdtv.exe -> Hijacker.VB.ij : Cleaned with backup
C:\WINDOWS\win3206487738495.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\win32097384954872006.exe -> Adware.Enbrow : Cleaned with backup
C:\WINDOWS\wnu_238.exe -> Trojan.Qoologic : Cleaned with backup
_______________________________________________________________________________
3) new HJT log
Logfile of HijackThis v1.99.1
Scan saved at 7:36:26 PM, on 4/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchIndexer.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearchFilter.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: (no name) - {C8F4C824-52BF-0631-B12A-2B17521976B7} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {A8B0BDED-64A5-495b-97DA-42C0301E229B} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?e4095aed42247d18d273a32562aff46
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?e4095aed42247d18d273a32562aff46
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QWx0b24\command.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe