This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Browser's being hijacked !

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am at my wits end. I have run all the conventional stuff (Norton, Ad-Aware, SpyBot, and NoAdware) plus, I have downloaded and run smitfraudfix. However, I still have a hijacker that I can't get rid of. It launches my browser when ever it wants, changes my home page and seems to have taken over and turned off my Windows firewall. Below is my HijackThis log. Please help. THis is driving me nuts!!!

Logfile of HijackThis v1.99.1
Scan saved at 9:40:38 PM, on 7/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\RGVubmlz\command.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
C:\Documents and Settings\Dennis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [xmj] C:\WINDOWS\xmj.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [w37V35X] pidput.exe
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Itorkf.exe
O4 - HKLM\..\Run: [s8B] C:\documents and settings\emily\local settings\temp\s8B.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ohfpF] C:\WINDOWS\skcgp.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mgdpppws] c:\windows\system32\mgdpppws.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Morpheus] "C:\Program Files\StreamCast\Morpheus\Morpheus.exe" -min
O4 - HKCU\..\Run: [h0o9RRbnV] patutils.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\6.1.4.37-7288971L\Program\runner.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
O8 - Extra context menu item: &Search - http://km.bar.need2find.com/KM/menusearch.html?p=KM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\hr6005jme.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Siggyx,

I have done as you have requested. The following is my Look2Me-Destroyer.txt and my latest Hijackthis log:


Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 7/20/2006 6:12:13 AM

Infected! C:\WINDOWS\system32\en0ol1d31.dll
Infected! C:\RECYCLER\NPROTECT\01378362.dll
Infected! C:\RECYCLER\NPROTECT\01379526.dll
Infected! C:\RECYCLER\NPROTECT\01380223.dll
Infected! C:\RECYCLER\NPROTECT\01380301.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP963\A0425500.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426497.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426498.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426499.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426505.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426526.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426528.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426529.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426532.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426534.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426537.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426540.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426541.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426606.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426610.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426617.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426618.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426620.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426621.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426625.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426628.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426629.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426630.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426700.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP967\A0427745.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427793.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427804.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427809.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427816.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427817.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427824.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427825.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427826.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427836.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427886.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427887.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427893.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427900.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427908.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427912.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427919.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427923.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427942.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427950.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427957.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427963.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427964.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427966.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427984.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427996.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428010.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428011.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428014.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP972\A0429065.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP973\A0429100.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430106.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430110.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430116.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430145.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430148.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430150.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430151.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430152.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430154.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430155.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430156.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430169.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430181.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430191.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430226.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430230.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430285.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430289.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430384.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430409.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430423.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430461.dll
Infected! C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430471.dll
Infected! C:\WINDOWS\SYSTEM32\dJd9.dll
Infected! C:\WINDOWS\SYSTEM32\en0ol1d31.dll
Infected! C:\WINDOWS\SYSTEM32\gpp2l37o1.dll
Infected! C:\WINDOWS\SYSTEM32\iq41_qc.dll
Infected! C:\WINDOWS\SYSTEM32\jct.dll
Infected! C:\WINDOWS\SYSTEM32\mcjava.dll
Infected! C:\WINDOWS\SYSTEM32\mnastmib.dll
Infected! C:\WINDOWS\SYSTEM32\mqxoci.dll
Infected! C:\WINDOWS\SYSTEM32\sncbase.dll

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\en0ol1d31.dll
C:\WINDOWS\system32\en0ol1d31.dll Deleted successfully!

Attempting to delete: C:\RECYCLER\NPROTECT\01378362.dll
C:\RECYCLER\NPROTECT\01378362.dll Deleted successfully!

Attempting to delete: C:\RECYCLER\NPROTECT\01379526.dll
C:\RECYCLER\NPROTECT\01379526.dll Deleted successfully!

Attempting to delete: C:\RECYCLER\NPROTECT\01380223.dll
C:\RECYCLER\NPROTECT\01380223.dll Deleted successfully!

Attempting to delete: C:\RECYCLER\NPROTECT\01380301.dll
C:\RECYCLER\NPROTECT\01380301.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP963\A0425500.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP963\A0425500.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426497.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426497.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426498.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426498.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426499.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426499.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426505.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426505.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426526.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426526.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426528.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426528.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426529.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426529.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426532.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426532.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426534.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426534.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426537.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426537.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426540.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426540.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426541.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426541.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426606.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426606.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426610.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426610.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426617.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426617.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426618.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426618.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426620.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426620.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426621.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426621.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426625.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426625.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426628.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426628.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426629.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426629.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426630.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426630.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426700.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426700.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP967\A0427745.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP967\A0427745.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427793.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427793.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427804.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427804.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427809.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427809.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427816.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427816.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427817.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427817.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427824.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427824.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427825.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427825.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427826.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427826.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427836.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427836.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427886.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427886.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427887.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427887.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427893.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427893.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427900.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427900.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427908.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427908.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427912.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427912.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427919.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427919.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427923.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427923.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427942.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427942.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427950.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427950.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427957.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427957.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427963.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427963.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427964.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427964.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427966.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427966.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427984.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427984.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427996.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427996.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428010.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428010.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428011.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428011.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428014.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428014.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP972\A0429065.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP972\A0429065.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP973\A0429100.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP973\A0429100.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430106.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430106.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430110.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430110.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430116.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430116.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430145.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430145.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430148.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430148.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430150.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430150.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430151.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430151.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430152.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430152.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430154.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430154.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430155.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430155.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430156.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430156.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430169.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430169.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430181.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430181.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430191.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430191.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430226.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430226.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430230.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430230.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430285.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430285.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430289.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430289.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430384.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430384.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430409.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430409.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430423.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430423.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430461.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430461.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430471.dll
C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430471.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\dJd9.dll
C:\WINDOWS\SYSTEM32\dJd9.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\en0ol1d31.dll
C:\WINDOWS\SYSTEM32\en0ol1d31.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\gpp2l37o1.dll
C:\WINDOWS\SYSTEM32\gpp2l37o1.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\iq41_qc.dll
C:\WINDOWS\SYSTEM32\iq41_qc.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\jct.dll
C:\WINDOWS\SYSTEM32\jct.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\mcjava.dll
C:\WINDOWS\SYSTEM32\mcjava.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\mnastmib.dll
C:\WINDOWS\SYSTEM32\mnastmib.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\mqxoci.dll
C:\WINDOWS\SYSTEM32\mqxoci.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\SYSTEM32\sncbase.dll
C:\WINDOWS\SYSTEM32\sncbase.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Controls Folder

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{CBFA6F1D-2CF1-4294-9AB3-DEF9444BBEE3}"
HKCR\Clsid\{CBFA6F1D-2CF1-4294-9AB3-DEF9444BBEE3}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2DE88E38-CED6-445C-8E29-880AE7CD409A}"
HKCR\Clsid\{2DE88E38-CED6-445C-8E29-880AE7CD409A}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{469A344E-F1AC-476B-91D6-0A18FC985A43}"
HKCR\Clsid\{469A344E-F1AC-476B-91D6-0A18FC985A43}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2AAE875E-F3AE-48A2-896B-281769DF4200}"
HKCR\Clsid\{2AAE875E-F3AE-48A2-896B-281769DF4200}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{8985585C-A2BB-4627-B4B4-8659E36F5FA4}"
HKCR\Clsid\{8985585C-A2BB-4627-B4B4-8659E36F5FA4}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{6364009F-7E6D-4025-BAA3-25AB7DC40FFD}"
HKCR\Clsid\{6364009F-7E6D-4025-BAA3-25AB7DC40FFD}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{42380570-5AAF-4BEC-89E0-EC5BEA5A299C}"
HKCR\Clsid\{42380570-5AAF-4BEC-89E0-EC5BEA5A299C}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2A7AD193-D5D9-409D-ABD9-1C86CEFAA0B5}"
HKCR\Clsid\{2A7AD193-D5D9-409D-ABD9-1C86CEFAA0B5}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B45EBF5D-EEF7-46D4-8F1F-956B6ED38182}"
HKCR\Clsid\{B45EBF5D-EEF7-46D4-8F1F-956B6ED38182}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{DD08D7F1-7793-4E9D-85DB-71B4D0177F95}"
HKCR\Clsid\{DD08D7F1-7793-4E9D-85DB-71B4D0177F95}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{06970400-51D0-4C49-9E9F-351FE4C659F4}"
HKCR\Clsid\{06970400-51D0-4C49-9E9F-351FE4C659F4}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4B3689A8-142C-4F29-BC74-E91C5F1774FC}"
HKCR\Clsid\{4B3689A8-142C-4F29-BC74-E91C5F1774FC}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7EE22FC6-CBD6-4322-88BC-AD168AB2F8BF}"
HKCR\Clsid\{7EE22FC6-CBD6-4322-88BC-AD168AB2F8BF}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2372C8B6-34A4-4ACB-9931-6B52ECD4476F}"
HKCR\Clsid\{2372C8B6-34A4-4ACB-9931-6B52ECD4476F}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{99CADB0F-0007-4277-A305-FA0FA24415CB}"
HKCR\Clsid\{99CADB0F-0007-4277-A305-FA0FA24415CB}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{241DE2C7-33C7-4233-89A1-FB6BCA7AD931}"
HKCR\Clsid\{241DE2C7-33C7-4233-89A1-FB6BCA7AD931}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{29F4835E-84DD-4174-93C5-D0006350AF90}"
HKCR\Clsid\{29F4835E-84DD-4174-93C5-D0006350AF90}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{EF904C76-A0DE-4410-88A8-20E093E9A704}"
HKCR\Clsid\{EF904C76-A0DE-4410-88A8-20E093E9A704}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4788173C-BBC9-48BE-BCC5-B480C0C6B924}"
HKCR\Clsid\{4788173C-BBC9-48BE-BCC5-B480C0C6B924}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded





Logfile of HijackThis v1.99.1
Scan saved at 6:29:36 AM, on 7/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\RGVubmlz\command.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dennis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [xmj] C:\WINDOWS\xmj.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [w37V35X] pidput.exe
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Itorkf.exe
O4 - HKLM\..\Run: [s8B] C:\documents and settings\emily\local settings\temp\s8B.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ohfpF] C:\WINDOWS\skcgp.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mgdpppws] c:\windows\system32\mgdpppws.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Morpheus] "C:\Program Files\StreamCast\Morpheus\Morpheus.exe" -min
O4 - HKCU\..\Run: [h0o9RRbnV] patutils.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\6.1.4.37-7288971L\Program\runner.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
O8 - Extra context menu item: &Search - http://km.bar.need2find.com/KM/menusearch.html?p=KM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/downloadget.php?…7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot 1.4 & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Step # 4

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan and a new hijackthis log please.
I feel we may be making progress, but I don’t believe I am completely rid of this vile bug yet. I have done what you instructed and then some. The logs you requested are below, but please bear with me while I share some of the strange things I have observed through the process that may (or may not) be germane to this hunt. There are five family members on this home computer, each with their own user account. One of the first things I checked when all the craziness started was my Firewall settings. To my surprise, I found that it was turned off and could not be turned on because “my network administrator was using Group Policy to control it”. I got this same message no matter who I logged in as, including when I logged on as Administrator in Safe Mode. Since this is a home system, there is no “network” administrator. This was the first thing that tipped me off to the fact that my computer was being controlled by someone (or something) else. Interestingly, after all we have done so far, I am still not able to gain control over my firewall settings. Another curious thing has shown up when I’m running an Ad-Aware scan. I noticed that when it came to scanning thru the various user’s areas, it would display my name, then my wife’s, then my one daughter’s, but when it came to my second daughter, in place of her name I saw, “Local Service” followed by “Owner”, and then it went on to my son’s area. This same thing happened when I logged on as all the other users except for my second daughter. Only when I logged on as her, did her name show up in the scan order, but even then, this was followed by a brief appearance of “Local Service” and “Owner” before continuing on to my son. Does my computer think it’s owned by someone else and did that someone possibly come in thru my second daughter’s account? When I ran CWShredder, I found and removed CWS.Aff.Toolband. I ran Ad-Aware and Spybot and found nothing. However, I was unable to run the TrendMicro virus scan because my system kept hanging up during the download, and then I got a warning message from my 2Wire Gateway (i.e. DSL modem/router) that a device on my network, DJT9KY11, (which turns out to be the computer I’m working on) was suddenly sucking up an inordinate amount of bandwidth, likely due to a “blaster worm”. I got this same message when I tried to access the Internet with my laptop. I stopped trying to download and simply ran my Norton antivirus and did find and eliminate one infected file. I then downloaded and ran ewido and found, as the log shows, several Trojans, Downloaders, and Hijackers. These were quarantined and I immediately stopped getting the bandwidth message on both my desktop and my laptop. This ewido log is below and is titled “Pre Norton Fix”. Just out of curiosity, I also ran ewido when logged on as my second daughter and a few Trojan.Pakes and Downloaders. I saved this log and can send it if you like. And while I was at it, I also ran it logged on as Administrator and found another Trojan. I would run it for the other three users on this computer, but each one of these scans takes over an hour. But then I started to wonder about the integrity of my Norton program. I had also noticed that for a while now that when I began a scan, my Norton had shown messages saying that certain components (I believe 3031,6; 3031,9; and 3031,10) were missing, so I uninstalled and reinstalled Norton, did a full system scan, and found 7 Trojan.KillAV viruses. An example file name was A0430561.exe. All were in the C:\System Volume Information\restore… area. Had my previous ability to detect these with Norton been compromised? After eliminating these Trojans, I went back into Safe Mode and reran ewido again. The log for this is titled “Post Norton Fix”. The last log is the most recent HijackThis. Thanks for your help so far and PLEASE keep helping!!! Dennis Pre-Norton Fix ewido log ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 1:12:04 PM 7/20/2006 + Scan result: C:\Program Files\INSTAFINK -> Adware.404Search : Cleaned with backup (quarantined). C:\Program Files\INSTAFINK\Cache -> Adware.404Search : Cleaned with backup (quarantined). C:\Program Files\INSTAFINK\Cache\ErrorLog.txt -> Adware.404Search : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426508.exe -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426511.EXE -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426514.exe -> Adware.Agent : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426518.exe -> Adware.Agent : Cleaned with backup (quarantined). C:\Program Files\Altnet -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\ceva_emu.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.rvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cevakrnl.xmd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cran.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cran.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\cran.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\emalware.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\emalware.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\java.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\mdx_97.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\na.xmd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab (incomplete) -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\rup.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\sdx.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\sdx.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\unpack.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\unpack.ivd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\update.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\update.txt.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\ve.cvd.cab -> Adware.Altnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379648.DLL -> Adware.Altnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379987.exe -> Adware.Altnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380069.dll -> Adware.Altnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380070.dll -> Adware.Altnet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP934\A0420909.dll -> Adware.Altnet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430159.dll -> Adware.Altnet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430160.dll -> Adware.Altnet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430161.dll -> Adware.Altnet : Cleaned with backup (quarantined). HKLM\SOFTWARE\Altnet -> Adware.Altnet : Error during cleaning. HKLM\SOFTWARE\Altnet\Dashboard -> Adware.Altnet : Error during cleaning. HKLM\SOFTWARE\Altnet\Dashboard\Messages -> Adware.Altnet : Error during cleaning. HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Adware.Altnet : Error during cleaning. HKLM\SOFTWARE\Altnet\TopSearch -> Adware.Altnet : Cleaned with backup (quarantined). C:\Program Files\CxtPls -> Adware.Apropos : Cleaned with backup (quarantined). C:\Program Files\CxtPls\AI_22-05-2005.log -> Adware.Apropos : Cleaned with backup (quarantined). C:\Program Files\CxtPls\AI_23-05-2005.log -> Adware.Apropos : Cleaned with backup (quarantined). C:\Program Files\CxtPls\AI_28-05-2005.log -> Adware.Apropos : Cleaned with backup (quarantined). C:\Program Files\CxtPls\data.bin -> Adware.Apropos : Error during cleaning. C:\RECYCLER\NPROTECT\01379633.idf/C:/Program Files/BullsEye Network/bin/adv.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379633.idf/C:/Program Files/BullsEye Network/bin/adx.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379633.idf/C:/Program Files/BullsEye Network/bin/bargains.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379633.idf/C:/WINDOWS/system32/msbe.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/system32/exdl.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/system32/exul.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/system32/javexulm.vxd -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\netut80ex.vxd/C:/WINDOWS/system32/mqexdlm.srg -> Adware.BargainBuddy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP980\A0430629.dll -> Adware.CommAd : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP980\A0430630.exe -> Adware.CommAd : Cleaned with backup (quarantined). HKLM\SOFTWARE\dealhelper -> Adware.DealHelper : Cleaned with backup (quarantined). HKLM\SOFTWARE\dealhelper\KeyWord -> Adware.DealHelper : Cleaned with backup (quarantined). HKLM\SOFTWARE\DelFin -> Adware.Delfin : Cleaned with backup (quarantined). HKLM\SOFTWARE\DelFin\PromulGate -> Adware.Delfin : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DelFin Media Viewer -> Adware.Delfin : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP963\A0425479.exe -> Adware.DollarRevenue : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaLoads Enhanced -> Adware.Downloadware : Cleaned with backup (quarantined). C:\Program Files\Common Files\jddarbjd\hbrelhaf\nptfchel.exe -> Adware.Gator : Cleaned with backup (quarantined). C:\Program Files\Common Files\jddarbjd\janenpnbjj\ertdctlpc.exe -> Adware.Gator : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426516.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426517.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426527.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426542.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426543.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426544.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426605.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426611.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426612.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426619.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427794.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427795.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427796.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427797.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427798.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427799.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427800.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427801.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427802.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427803.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427805.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427806.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427807.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427808.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427818.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427820.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427821.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427827.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427828.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427829.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427852.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427853.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427854.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427855.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427856.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427857.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427858.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427859.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427866.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427871.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427872.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427873.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427955.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427956.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427958.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427959.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427960.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427961.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427962.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427965.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428003.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428004.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428005.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428006.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428007.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428008.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP969\A0428009.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP975\A0430103.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430141.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430142.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430143.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430144.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430146.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430149.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430153.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430163.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430283.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430284.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430484.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430487.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430488.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430489.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430490.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430517.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430536.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430563.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430564.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430565.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430566.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430567.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430568.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430569.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430570.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430571.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430572.DLL -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430573.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430574.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430575.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430576.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430577.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430578.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380074.DLL -> Adware.MediaPops : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380075.DLL -> Adware.MediaPops : Cleaned with backup (quarantined). HKLM\SOFTWARE\WildMedia -> Adware.MidAddle : Cleaned with backup (quarantined). HKLM\SOFTWARE\WildMedia\LicenseStores -> Adware.MidAddle : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall4_80.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall4_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall4_94.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall5_20.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall5_40.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall5_48.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall5_64.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_10.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\P2P Networking -> Adware.P2PNetworking : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\P2P Networking\Cache -> Adware.P2PNetworking : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database -> Adware.P2PNetworking : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\P2P Networking\Cache\Database\file-10001-105.sig -> Adware.P2PNetworking : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\P2P Networking\P2P Networking.LOG -> Adware.P2PNetworking : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380076.DLL -> Adware.PeerNet : Cleaned with backup (quarantined). C:\Program Files\PerfectNav -> Adware.PerfectNav : Cleaned with backup (quarantined). C:\Program Files\PerfectNav\BHO -> Adware.PerfectNav : Cleaned with backup (quarantined). C:\Program Files\PerfectNav\BHO\PerfectNav150.dll -> Adware.PerfectNav : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380093.dll -> Adware.RXBar : Cleaned with backup (quarantined). C:\Program Files\RXToolBar -> Adware.RXToolbar : Cleaned with backup (quarantined). C:\Program Files\RXToolBar\Cache -> Adware.RXToolbar : Cleaned with backup (quarantined). C:\Program Files\RXToolBar\Cache\CTwww_opelgtsource_com -> Adware.RXToolbar : Cleaned with backup (quarantined). C:\Program Files\RXToolBar\Cache\CTwww_playboy_com_ -> Adware.RXToolbar : Cleaned with backup (quarantined). HKU\S-1-5-21-1445258045-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427832.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP979\A0430580.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\WINDOWS\Temp\~27152.tmp -> Adware.Wintol : Error during cleaning. C:\WINDOWS\Temp\~290181.tmp -> Adware.Wintol : Error during cleaning. C:\WINDOWS\Temp\~714633.tmp -> Adware.Wintol : Error during cleaning. C:\WINDOWS\Temp\~914359.tmp -> Adware.Wintol : Error during cleaning. C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427840.exe -> Backdoor.SdBot.aad : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427847.exe -> Backdoor.VB.ary : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426520.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426521.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426522.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426523.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426524.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426525.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426602.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426603.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426604.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427810.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427811.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427812.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427813.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427814.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427815.exe -> Downloader.Adload.ck : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427849.exe -> Downloader.Adload.cm : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426539.exe -> Downloader.Adload.cn : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP967\A0427750.exe -> Downloader.Adload.ct : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427831.exe -> Downloader.Adload.ct : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427861.exe -> Downloader.Adload.ct : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427896.exe -> Downloader.Adload.cu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427897.exe -> Downloader.Adload.cu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427898.exe -> Downloader.Adload.cu : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427845.exe -> Downloader.Adload.cv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427846.exe -> Downloader.Adload.cv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427862.exe -> Downloader.Adload.cw : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427863.exe -> Downloader.Adload.cw : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427864.exe -> Downloader.Adload.cw : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427865.exe -> Downloader.Adload.cw : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380108.exe/g.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426535.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426536.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426608.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426609.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427822.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427823.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427869.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427870.exe -> Downloader.Small.buy : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9MQXG8UP\load67[1].zip -> Downloader.VB.afo : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\9MQXG8UP\load67[2].zip -> Downloader.VB.afo : Cleaned with backup (quarantined). C:\setup30.exe -> Downloader.VB.afo : Cleaned with backup (quarantined). C:\setup32.exe -> Downloader.VB.afo : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426504.exe -> Downloader.VB.afv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427844.exe -> Downloader.VB.afv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427860.exe -> Downloader.VB.afv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427848.exe -> Downloader.VB.agi : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427867.exe -> Downloader.VB.agi : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP963\A0425502.exe -> Downloader.VB.agk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426519.exe -> Downloader.VB.agk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426601.exe -> Downloader.VB.agk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426635.exe -> Downloader.VB.agk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP965\A0426704.exe -> Downloader.VB.agk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427851.exe -> Downloader.VB.agp : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426530.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP964\A0426538.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP968\A0427850.exe -> Hijacker.VB.nh : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP977\A0430147.exe -> Hijacker.VB.nh : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined). C:\System Volume Information\_restore{11B4CBB0-31B0-483C-A4FE-D6E9E8C1A928}\RP978\A0430383.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Cookies\dennis@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Local Settings\Temp\Cookies\ellen@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Cookies\dennis@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\Documents and Settings\Sam\Local Settings\Temp\Cookies\sam@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379393.TXT -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379394.TXT -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Emily\Cookies\emily@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\system@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379043.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379044.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379045.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379378.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379379.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379380.TXT -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\Documents and Settings\Sam\Local Settings\Temp\Cookies\sam@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379391.TXT -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379392.TXT -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). C:\Documents and Settings\Emily\Cookies\[removed][2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380209.TXT -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380211.TXT -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380212.TXT -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380213.TXT -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380214.TXT -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380899.TXT -> TrackingCookie.Goclick : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380900.TXT -> TrackingCookie.Goclick : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\dennis@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379382.TXT -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379383.TXT -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379384.TXT -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379385.TXT -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379387.TXT -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\Documents and Settings\Sam\Local Settings\Temp\Cookies\sam@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Cookies\dennis@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Dennis\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Emily\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Sam\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Sam\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379029.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379030.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379039.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379040.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379041.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379049.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379050.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379051.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379060.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379061.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379062.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379198.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379199.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379341.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379342.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379347.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379348.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379349.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379351.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379358.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379359.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379360.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379366.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379367.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379368.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379375.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379376.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379377.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379398.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379399.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379400.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379405.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379406.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379423.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379424.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379425.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379434.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379435.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379436.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380206.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380207.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380208.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01380215.TXT -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). C:\Documents and Settings\Ellen\Cookies\ellen@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379361.TXT -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379362.TXT -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379363.TXT -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379364.TXT -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\RECYCLER\NPROTECT\01379365.TXT -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\dennis@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\WINDOWS\Temp\Cookies\sam@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined). C:\Program Files\Common Files\{941261D3-0703-1033-0826-020409200001}\Update.exe -> Trojan.Starter.65 : Cleaned with backup (quarantined). ::Report end Post-Norton Fix ewido log —————————-
Oops, Looks like I ran out of room in my last post. To finish the story, the Post-Norton fix ewido log is as follows:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 9:45:05 PM 7/20/2006

+ Scan result:



C:\WINDOWS\Temp\~27152.tmp -> Adware.Wintol : Error during cleaning.
C:\WINDOWS\Temp\~290181.tmp -> Adware.Wintol : Error during cleaning.
C:\WINDOWS\Temp\~714633.tmp -> Adware.Wintol : Error during cleaning.
C:\WINDOWS\Temp\~914359.tmp -> Adware.Wintol : Error during cleaning.
C:\Documents and Settings\Dennis\Cookies\dennis@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).


::Report end


The latest Hijack this log is as follows:

Logfile of HijackThis v1.99.1
Scan saved at 9:53:24 PM, on 7/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dennis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myclassiccar.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



Thanks, Dennis
Lets eee if we can get the administrator clean then we can look at the other user account logs.

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download AproposFix from here:
http://swandog46.geekstogo.com/aproposfix.exe

Save it to your desktop but do NOT run it yet.

Then please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

When the tool is finished, please reboot back into normal mode, and post a new HijackThis log, along with the entire contents of the log.txt file in the aproposfix folder.

NEXT

Please download http://users.telenet.be/marcvn/tools/delcmdservice.zip (by Marckie), and save it to your Desktop.
Unzip the content to your Desktop (a folder named delcmdservice)
Double-click on the delcmdservice folder
Double-click on delreg.bat to launch the tool
When the tool has finished, please reboot your computer

After restarting, with only HijackThis running, scan and when complete, remove the following entries if still there by checking the box to the left and clicking 'fixed checked':

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)

O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe (file missing)
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)

Then reboot and a new log please.
Ok, here's the latest. I downloaded and ran AproposFix in Safe Mode as instructed, followed by another HijackTHis. The logs are below. However, I am having trouble downloading the delcmdservice.zip program. It only gets about 30K of the supposed 132K and then doesn't go any farther. Once I got an download interruption message saying something like "the server address has been reset". I suspect that my computer is trying to prevent me from getting this program. I am even having some difficulty accseeing your site and in fact am doing so right now from my office computer. I just downloaded the delcmsdservice.zip to a flash memory and will take it home and run the program off of this. I think we might have the RAT cornered, but it seems to be getting a bit more aggressive because of that. Here are the logs so far:

Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\Dennis\Desktop\aproposfix

************



Registry entries found:


************

No service found!

Removing hidden folder:
No folder found!

Deleting files:


Backing up files:
Done!

Removing registry entries:

REGEDIT4


Done!

Finished!

Logfile of HijackThis v1.99.1
Scan saved at 12:18:09 PM, on 7/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ipwins\ipwins.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Dennis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myclassiccar.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [xmj] C:\WINDOWS\xmj.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [w37V35X] pidput.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Itorkf.exe
O4 - HKLM\..\Run: [s8B] C:\documents and settings\emily\local settings\temp\s8B.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ohfpF] C:\WINDOWS\skcgp.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mgdpppws] c:\windows\system32\mgdpppws.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Morpheus] "C:\Program Files\StreamCast\Morpheus\Morpheus.exe" -min
O4 - HKCU\..\Run: [h0o9RRbnV] patutils.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\6.1.4.37-7288971L\Program\runner.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe (file missing)
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


Thanks, Dennis
Go to add/remove programs and look for New.Net or NewDot.Net and remove if present.

Next

Click Start > Run

In the box, type in services.msc then hit (or click OK)

In the Name column, look for Command Service

it.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled, then click Apply then OK.

Then do the same for Remote Procedure Call Service

Scan with hijackthis and put a check beside these lines and choose FIX

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O3 - Toolbar: (no name) - {0E677229-E309-4341-81BD-3CC3018BF5B3} - (no file)
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (file missing)

O4 - HKLM\..\Run: [xmj] C:\WINDOWS\xmj.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [w37V35X] pidput.exe
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINDOWS\Temp\WTuninst.exe /remove
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Itorkf.exe
O4 - HKLM\..\Run: [s8B] C:\documents and settings\emily\local settings\temp\s8B.exe
O4 - HKLM\..\Run: [ohfpF] C:\WINDOWS\skcgp.exe
O4 - HKLM\..\Run: [mgdpppws] c:\windows\system32\mgdpppws.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [h0o9RRbnV] patutils.exe

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGVubmlz\command.exe (file missing)
O23 - Service: Remote Procedure Call Service (RPCS) - Unknown owner - C:\WINDOWS\rcss.exe (file missing)


Next reboot to safe mode (tap f8 while bios loads) look for and delete these files/folders if present

C:\WINDOWS\xmj.exe C:\Program Files\WildTangent C:\WINDOWS\Temp\WTuninst.exe C:\WINDOWS\system32\Itorkf.exe C:\documents and settings\emily\local settings\temp\s8B.exe C:\WINDOWS\skcgp.exe c:\windows\system32\mgdpppws.exe C:\Program Files\ipwins\ipwins.exe C:\WINDOWS\system32\gah95on6.exe C:\PROGRA~1\AWS\WEATHE~
Then reboot and a new log please.
As if I’m not already having enough trouble, my home DLS modem/router went out this afternoon so I did end up uploading the delcmdservice program from a flash memory that I had created on my office computer. It appeared to work fine tho. I followed all instructions and the logs for aproposfix and HijackThis are below. I am accessing the Internet via dialup to send this.

The HijackThis log did not contain

023 – Service: Command Service (cmdService)-unknown owner-C:\\Windows\RGVubmiz\command.exe (file missing)

as your instructions indicated, but as you see, it does contain another “unknown owner” entry, namely:

023 – Service: ScsiAccess-Unknown owner- C:\\WINDOWS\System32\ScsiAccess.EXE

I was tempted check this too, but resisted the temptation until I heard from the guru.

I also searched for, found, and removed many of the items you listed in your instructions.

There are still some curious things going on with this system. I still don’t seem to have control over my firewall settings. Also, I get brief wallpaper flashes of a grassy green hill and blue sky when I boot up and when I switch between users. I didn’t used to get these before all this started. Lastly, I still see “Owner” show up instead of my daughter’s name when I’m doing Ad-Aware scans. Your thoughts on these things would be greatly appreciated.

And now the logs:

Log of AproposFix v1.1

************

Running from directory:
C:\Documents and Settings\Dennis\Desktop\aproposfix

************



Registry entries found:


************

No service found!

Removing hidden folder:
No folder found!

Deleting files:


Backing up files:
Done!

Removing registry entries:

REGEDIT4


Done!

Finished!



Logfile of HijackThis v1.99.1
Scan saved at 9:34:28 PM, on 7/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1129610569\ee\AOLServiceHost.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
C:\Documents and Settings\Dennis\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myclassiccar.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1129610569\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Morpheus] "C:\Program Files\StreamCast\Morpheus\Morpheus.exe" -min
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\6.1.4.37-7288971L\Program\runner.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\WINDOWS\TWAIN_32\ScanWiz5\SDII.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common


Thanks, Dennis
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE

Name ScsiAccess
Command ScsiAccess.EXE
Status Legitimate
Description Alcohol Software's CD/DVD writing application


Download the trial version of trojan hunter from the link below. Update it scan your system and allow it to clean what it finds.

http://www.trojanhunter.com/

Let me know if it finds something it can not remove.


I will be out of town for a few days and will not be able to respond.
Hope you had a good couple days away from all this madness. Per your instructions, I went to trojanhunter.com. I downloaded the trial version of pctool’s Spyware Doctor. I ran the scan and it found quite a lot of stuff. Unfortunately, I couldn’t remove these without purchasing the software, but that ended up being the best 30 bucks I’ve ever spent. The software found the following items: IncrediFind – Hijacker Transponder.Speer DollarRevenue – Trojan MediaLoads Enhancer Worm.WGAVIN Network Monitor (Command Webroot) IST Bar - Trojan Downloader It found tons of other stuff, but these were considered severe threats. The Worm (Backdoor.Win32.IRC Bot.st) is an instant messaging worm and was said to be capable of turning off the system firewall. I removed all these items and regained control over my firewall!!! I ran this program for all the users on my home computer, and found and removed tons of additional carp** from each. I have re-run every other virus and spyware program I have and the system appears to be clean. Everything seems to be working fine now. You are a god in my book! Thank you for all your help. I will definitely donate at the link below. You folks are the “good guys” in the fight against the sleaze bags that create vile things like Trojans and Hijackers. Us “regular folks” would be screwed without you Thanks again, Dennis
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI