This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log..tagasaurus

47 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

depends on how many files are on your computer. but the number of files scanned should change as it starts scanning. it shouldn't stay at 0. let me know if you have any problems with it.
Hmm…well I downloaded the stuff I needed. I clicked on My Computer but I don't have like a progress bar or anything showing how many files have been scanned. The IE window says the scan has started…but..it sounds like something more should be happening.
Yea it's not doing anything after the files have finished downloading. The progress bar for the files is full but it is not moving to the next screen.
ok, looks like panda scan is not working for you. don't worry, lots of people have been having trouble with them lately, so its not your fault.

let's use kaspersky:

Please do an online scan with Kaspersky WebScanner

Note: This Scanner is for Internet Explorer Only!

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
ok, kaspersky scan might be a bit slower than most, so I wouldn't sit in front of your computer waiting for it to finish ;) thanks for keeping me updated on your situation.
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Monday, July 24, 2006 2:04:14 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 24/07/2006 Kaspersky Anti-Virus database records: 209586 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 46172 Number of viruses found: 50 Number of infected objects: 185 / 0 Number of suspicious objects: 0 Duration of the scan process: 02:15:03 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_6c9f3adf-e398-45fe-8fa8-ba59aaef5b4b Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cert8.db Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\formhistory.dat Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\history.dat Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\key3.db Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\parent.lock Object is locked skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-778fef39.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-778fef39.zip ZIP: infected - 1 skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-23da15e8.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-23da15e8.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-23da15e8.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-23da15e8.zip ZIP: infected - 3 skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-7c627de7.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-7c627de7.zip/Counter.class Infected: Trojan.Java.ClassLoader.h skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-7c627de7.zip/Parser.class Infected: Trojan.Java.ClassLoader.d skipped C:\Documents and Settings\Daniel\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv646.jar-4dc27cf4-7c627de7.zip ZIP: infected - 3 skipped C:\Documents and Settings\Daniel\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Daniel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Daniel\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Daniel\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Daniel\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Daniel\My Documents\My Music\iTunes\iTunes Library.itl Object is locked skipped C:\Documents and Settings\Daniel\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Daniel\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Guest\setup.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\fym9bvo.exe Infected: Trojan-Downloader.Win32.Agent.ala skipped C:\l2mfix\backup.zip/dlls/awstream.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/ayivvaxx.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/DillSys.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/dsrgsnap.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/dVvclnt.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/fp6s03j7e.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/guard.tmp Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/gwkcsp.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/h0n0la5m1d.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/hdfcisp2.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/HNZidr12.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip/dlls/ir02l5do1.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\l2mfix\backup.zip ZIP: infected - 12 skipped C:\Program Files\Messenger\kyzeqe.html Infected: Trojan-Clicker.Win32.Small.jf skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP422\A0115701.dll Infected: not-a-virus:AdWare.Win32.180Solutions.au skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0165098.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0165100.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0166083.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0166084.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0166087.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167210.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167211.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167212.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167213.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167222.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167235.dll Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167238.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167239.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167240.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167241.exe/data0002 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167241.exe/data0003 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167241.exe NSIS: infected - 2 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167242.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167244.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167259.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0167260.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168247.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168250.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168254.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168265.dll Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168271.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168272.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168273.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168274.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0168275.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0169250.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0172252.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0174259.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0174264.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0175263.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0175272.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0175277.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0176276.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0176280.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0176285.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177300.exe Infected: Trojan-Downloader.Win32.VB.aik skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177301.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177317.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177321.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.l skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177322.DLL Infected: not-a-virus:AdWare.Win32.MyWebSearch.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177324.dll Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177325.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177326.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177335.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177336.exe/InpB/Ssk.exe Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177336.exe/InpB Infected: not-a-virus:AdWare.Win32.SurfSide.av skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177336.exe CAB: infected - 2 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177338.dll Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177381.DLL Infected: not-a-virus:AdWare.Win32.MySearch.e skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177382.dll Infected: not-a-virus:AdWare.Win32.SurfSide.ap skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177383.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177384.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177385.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177386.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177387.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177389.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177390.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177391.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177406.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177407.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177413.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177417.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177427.dll Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177433.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177434.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177435.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177436.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177437.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177438.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177439.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177440.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177441.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177442.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177443.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177444.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177445.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177446.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177447.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177448.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177449.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177450.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177451.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177452.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177453.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177454.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177455.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177456.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177457.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177458.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177459.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177460.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177461.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177462.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177463.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177464.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177465.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177466.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177467.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177468.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177469.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177470.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177471.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177472.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177473.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177474.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177475.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177476.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177477.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177478.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177479.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177480.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177481.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177482.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177483.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177484.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177485.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177486.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177487.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177488.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177489.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177490.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177491.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177492.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177493.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177494.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177495.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177497.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177500.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177501.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177502.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177503.exe Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP440\A0177504.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177528.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177529.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177530.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177531.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177532.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177533.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177534.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177535.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177536.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177537.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177538.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0177539.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178517.dll Object is locked skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178702.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178703.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178705.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178706.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178708.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178709.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178711.dll Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178714.dll Infected: not-a-virus:AdWare.Win32.Softomate.q skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178716.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178717.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178718.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178721.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178722.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178723.dll Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178724.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178725.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178754.exe Infected: not-a-virus:AdWare.Win32.CommAd.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178755.dll Infected: not-a-virus:AdWare.Win32.CommAd.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178756.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.i skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178757.exe Infected: Trojan.Win32.Runner.j skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178758.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.i skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178767.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.i skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178769.exe Infected: Trojan-Downloader.Win32.Adload.cy skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178770.exe Infected: Trojan-Downloader.Win32.Adload.cu skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178771.exe Infected: Trojan-Clicker.Win32.VB.nh skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178772.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178774.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.q skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178775.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178776.exe Infected: not-a-virus:AdWare.Win32.ZenoSearch.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178777.exe Infected: not-a-virus:Monitor.Win32.NetMon.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178781.ocx Infected: not-a-virus:AdWare.Win32.MediaMotor.m skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178783.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178784.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178785.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178786.dll Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178787.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178788.exe Infected: not-a-virus:AdWare.Win32.BookedSpace.h skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178791.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178792.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178793.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178794.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178795.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178796.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178797.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178798.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178799.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178800.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178801.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178802.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178803.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178804.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178805.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178806.exe Infected: not-a-virus:AdWare.Win32.Look2Me.ab skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178807.EXE Infected: not-a-virus:AdWare.Win32.NewDotNet skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178809.exe Infected: not-a-virus:AdWare.Win32.CASClient.f skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178810.dll Infected: not-a-virus:AdWare.Win32.CASClient.d skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178811.dll Infected: not-a-virus:AdWare.Win32.WinAD.aw skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178812.exe Infected: not-a-virus:AdWare.Win32.PurityScan.ep skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178813.dll Infected: not-a-virus:AdWare.Win32.MySearch.e skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178814.exe Infected: not-a-virus:AdWare.Win32.AdURL.c skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178815.exe Infected: not-a-virus:AdWare.Win32.NetNucleus skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178816.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.l skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178817.exe Infected: not-a-virus:AdWare.Win32.MediaMotor.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178819.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178820.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178821.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178822.exe Infected: Trojan.Win32.Runner.j skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178823.exe Infected: Trojan.Win32.Runner.j skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178824.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178825.dll Infected: not-a-virus:AdWare.Win32.Agent.e skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178826.dll Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178827.dll Infected: not-a-virus:AdWare.Win32.Mirar.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178828.dll Infected: not-a-virus:AdWare.Win32.Mirar.a skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\A0178829.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.f skipped C:\System Volume Information\_restore{84CAE80A-C234-4828-B041-0F3E34D98DCD}\RP441\change.log Object is locked skipped C:\WINDOWS\$NtUninstallKB824141$\user32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB824141$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\accwiz.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\crypt32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\cryptsvc.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\hh.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\hhctrl.ocx Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\html32.cnv Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\locator.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\magnify.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\migwiz.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\mrxsmb.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\msconv97.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\narrator.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\newdev.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\ntdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\ntkrnlpa.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\osk.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\pchshell.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\raspptp.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\shmedia.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\srrstr.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\srv.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\user32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB826939$\zipfldr.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB839645$\sxs.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\media_motor_bundle.exe/data0002/stream/data0002 Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\media_motor_bundle.exe/data0002/stream Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\media_motor_bundle.exe/data0002 Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\media_motor_bundle.exe/data0003/stream/data0001 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\media_motor_bundle.exe/data0003/stream Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\media_motor_bundle.exe/data0003 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\media_motor_bundle.exe NSIS: infected - 6 skipped C:\WINDOWS\pf78.exe/data0002 Infected: Trojan-Downloader.Win32.VB.tw skipped C:\WINDOWS\pf78.exe/data0003 Infected: Trojan.Win32.VB.tg skipped C:\WINDOWS\pf78.exe/data0006 Infected: Trojan.Win32.VB.tg skipped C:\WINDOWS\pf78.exe/data0007 Infected: Trojan.Win32.VB.tg skipped C:\WINDOWS\pf78.exe NSIS: infected - 4 skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\srvdmpkadw.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.ep skipped C:\WINDOWS\srvdmpkadw.exe NSIS: infected - 1 skipped C:\WINDOWS\srvxztaxbu.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\srvxztaxbu.exe/stream Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\srvxztaxbu.exe NSIS: infected - 2 skipped C:\WINDOWS\ssqbn.exe/data0002 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\WINDOWS\ssqbn.exe/data0003 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\WINDOWS\ssqbn.exe NSIS: infected - 2 skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\8n93i290.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped C:\WINDOWS\system32\bez6n4r21.exe Infected: not-a-virus:AdWare.Win32.SearchAssistant.g skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\icon_mediamotor.exe/stream/data0001 Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\system32\icon_mediamotor.exe/stream Infected: not-a-virus:AdWare.Win32.BHO.ao skipped C:\WINDOWS\system32\icon_mediamotor.exe NSIS: infected - 2 skipped C:\WINDOWS\system32\iqqr.exe Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped C:\WINDOWS\system32\ts_mediamotor.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\system32\ts_mediamotor.exe/stream Infected: not-a-virus:AdWare.Win32.SideFind.a skipped C:\WINDOWS\system32\ts_mediamotor.exe NSIS: infected - 2 skipped C:\WINDOWS\system32\VSL03.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped C:\WINDOWS\system32\VSL03.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\WINDOWS\system32\VSL03.exe NSIS: infected - 2 skipped C:\WINDOWS\system32\VSL05.exe/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped C:\WINDOWS\system32\VSL05.exe/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped C:\WINDOWS\system32\VSL05.exe NSIS: infected - 2 skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\xeymi.dll Infected: not-a-virus:AdWare.Win32.Suggestor.o skipped C:\WINDOWS\Temp\hsperfdata_Guest\3780 Object is locked skipped C:\WINDOWS\whCC-GIANT.exe/data.rar/WhAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped C:\WINDOWS\whCC-GIANT.exe/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\WINDOWS\whCC-GIANT.exe/data.rar/WhSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\WINDOWS\whCC-GIANT.exe/data.rar/Webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\WINDOWS\whCC-GIANT.exe/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\WINDOWS\whCC-GIANT.exe/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped C:\WINDOWS\whCC-GIANT.exe RarSFX: infected - 6 skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is lock
Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
Save it to your desktop.

Please re-open HiJackThis and select Scan. Check the boxes next to all the entries listed below (if present).

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int408387.exe -auto
O4 - HKLM\..\Run: [blld06ee] "RUNDLL32.EXE" w0035e7d.dll,n 001d06ed000000030035e7d
O4 - HKLM\..\Run: [w00386be.dll] "RUNDLL32.EXE" w00386be.dll,I2 001d06ed000386be
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\ir6ml5j11.dll (file missing)

Now close all windows other than HiJackThis, then click Fix Checked. close HijackThis.

Open Killbox:
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


    C:\Documents and Settings\Guest\setup.exe
    C:\fym9bvo.exe
    C:\Program Files\Messenger\kyzeqe.html
    C:\WINDOWS\media_motor_bundle.exe
    C:\WINDOWS\pf78.exe
    C:\WINDOWS\srvdmpkadw.exe
    C:\WINDOWS\ssqbn.exe
    C:\WINDOWS\system32\8n93i290.ini
    C:\WINDOWS\system32\bez6n4r21.exe
    C:\WINDOWS\system32\icon_mediamotor.exe
    C:\WINDOWS\system32\iqqr.exe
    C:\WINDOWS\system32\ts_mediamotor.exe
    C:\WINDOWS\system32\VSL03.exe
    C:\WINDOWS\system32\VSL05.exe
    C:\WINDOWS\system32\xeymi.dll
    C:\WINDOWS\whCC-GIANT.exe
    C:\Program Files\websx\int408387.exe
    C:\Program Files\websx\
    C:\WINDOWS\system32\w0035e7d.dll
    C:\WINDOWS\system32\w00386be.dll
    C:\WINDOWS\system32\wfxqhv.exe
    C:\Program Files\TClock\tclock_install.exe
    C:\Program Files\TClock\

  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    NOTE: You must use the File menu–pasting by right-clicking the mouse will only enter one file.

  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

after reboot,

Go to start > control panel > Display properties > Desktop > Customize Desktop… > Web tab
Uncheck and delete everything you find in there. (except for "My current home page")

then, post a new hijackthis log.

Also let me know how your PC is behaving and if problems persist.
Things seem to be running nicely. Thank for your help. Here is the HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 10:39:00 PM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Some security programs with active monitoring processes are known to interfere with automatic scanners and can actually prevent HJT fixes from taking effect.

Please turn off or disable any of the following programs you may have,

If you have SpySweeper 4.5:

1. Open Spysweeper and click on Options > Program Options and uncheck "load at windows startup".
2. On the left click "shields" and then uncheck everything there.
3. Uncheck "home page shield".
4. Uncheck "automatically restore default without notification".
5. Exit the program.

If you have SpySweeper 5.0:

To disable SpySweeper Shields
  • Open SpySweeper.
  • Click Shield Settings on the right
    (or Shields on the left, depending what screen you're on).
  • Click Internet Explorer and uncheck all items.
  • Click Windows System and uncheck all items.
  • Click Hosts File and uncheck all items.
  • Click Startup Programs and uncheck all items.
  • Close SpySweeper.
Please re-open HiJackThis and select Scan. Check the boxes next to all the entries listed below (if present).

O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll (file missing)
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll

Now close all windows other than HiJackThis, then click Fix Checked. close HijackThis.

Next, we need to Reveal Hidden Files

1. Click Start.
2. Open My Computer.
3. Select Tools menu
4. Click Folder Options.
5. Select the View Tab.
6. Select Show hidden files and folders in the Hidden files and folders section.
7. Uncheck Hide protected operating system files (recommended) option.
8. Uncheck the Hide file extensions for known file types option.
9. Click Yes.
10. Click OK.

***************************************

Using Windows Explorer/My Computer, please delete the following files if still present:

C:\WINDOWS\system32\wfxqhv.exe
C:\WINDOWS\system32\xeymi.dll

If you get an error when deleting a file, <<right click>> on the file and check to see if the read only attribute is checked. If it is uncheck it and try again.

Please note any files you couldn't find or delete in your next post.

Then reboot, and post a new hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 11:01:08 PM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Seems to be running fine. It logs in as fast as it used to. It's a little slow loading everything up once I'm logged in but after that things seem to be fine. I have a question. Is it ok for me to delete the icons on my desktop for ring tones/poker installed by the malware?
yes you can do that!

Congratulations, your log looks clean! Are you having any other problems?

If not, we have just a couple of last steps to perform and then you're all set.

First, let's reset your hidden/system files and folders. System files are hidden for a reason and we don't want to have them openly available and susceptible to accidental deletion.
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View tab.
* Under the Hidden files and folders heading UNSELECT Show hidden files and folders.
* CHECK the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.
It's also a good idea to Flush your System Restore points after ridding yourself of malware:
  • Click Start | Help and Support | Undo changes to your computer with System Restore.
  • Click Create A Restore Point then click Next. Give it a name it and then click Create, then Close.
  • Close the Help and Support Center box.
  • Click Start | Run and type Cleanmgr
  • Select (C: ) then click OK.
  • Click the More Options tab.
  • Click Clean Up in the System Restore Section.
This will remove all previous restore points except the newly created one.

Let's renable your security programs:

If you have SpySweeper 4.5:

1. Open Spysweeper and click on Options > Program Options and Check "load at windows startup".
2. On the left click "shields" and then Check everything there.
3. Check "home page shield".
4. Check "automatically restore default without notification".
5. Exit the program.

If you have SpySweeper 5.0:

To enable SpySweeper Shields
  • Open SpySweeper.
  • Click Shield Settings on the right
    (or Shields on the left, depending what screen you're on).
  • Click Internet Explorer and Check all items.
  • Click Windows System and Check all items.
  • Click Hosts File and Check all items.
  • Click Startup Programs and Check all items.
  • Close SpySweeper.

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.

To keep your operating system up to date visit
  • Microsoft Windows Update
monthly. And to keep your system clean run these free malware scannersweekly, and be aware of what emails you open and websites you visit.

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

Have a safe and happy computing day!


(Please respond to this thread one more time so we can mark this thread as resolved.)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI