Phil -
Thanks. Everything seemed to go as you decribed. As you can see, Ewido found a lot of junk. After completing everything, there are three things you may find interesting:
1) At startup, Ewido flags "Downloader.Qoologic.bj", pointing to various EXE and DLL files (e.g. WINDOWS\System32\kfyqthe.dll). It does not seem able to clean them.
2) Upon startup, I get a Windows error box: RUNDLL: Error loading w003e4b4.dll. Specified module could not be found.
3) At startup, a Windows explorer window pops, displaying WINDOWS\System32. This has been happening for a while.
Logs below.
Scott
===================
Logfile of HijackThis v1.99.1
Scan saved at 1:57:33 PM, on 8/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\exyqdy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\uhqud.exe
C:\WINDOWS\system32\uhqud.exe
C:\WINDOWS\system32\uhqud.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.milwpc.com
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\uhqud.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,fcwxnes.exe
O1 - Hosts: 255.255.255.255 www.casinoxo.com
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: (no name) - {5C3E6596-C64F-48E0-AC1E-B9C6EB3A5915} - (no file)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [{E0-0E-EF-F3-ZN}] C:\windows\system32\pldsregs.exe GID003
O4 - HKLM\..\Run: [dodhdw] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKLM\..\Run: [w003e4b4.dll] RUNDLL32.EXE w003e4b4.dll,I2 001533820003e4b4
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sysmon.exe] ""
O4 - HKCU\..\Run: [test] C:\WINDOWS\system32\test.exe
O4 - HKCU\..\Run: [alkje] C:\WINDOWS\system32\exyqdy.exe reg_run
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: vflrj.exe
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: RemindU - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: RemindU - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.milwpc.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) -
http://www.dotphoto.com/DPImageUploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747} -
http://pak01.pictures.aol.com/ygp/aol/plug…US.9.1.6.18.cab
O18 - Filter: text/html - {624A3CDB-8C0A-4902-8480-191582C8498E} - (no file)
O20 - Winlogon Notify: BITS - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: dnsapi - Unknown owner - C:\WINDOWS\system32\dnsapi.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: inetpp.exe - Unknown owner - C:\WINDOWS\system32\inetpp.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
=======================================
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 1:07:40 PM 8/26/2006
+ Scan result:
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043824.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044821.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046073.exe -> Adware.Agent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044828.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044850.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044874.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044999.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045039.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045040.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045045.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047101.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048249.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32o.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32p.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32r.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32s.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension.5 -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\C9UF4DY3\!update-3945[1].0000 -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Тasks\Тasks\!update-3945.0000 -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046093.exe -> Adware.ClickSpring : Cleaned with backup (quarantined).
C:\WINDOWS\U2NvdHQ\asappsrv.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\WINDOWS\U2NvdHQ\command.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043808.exe -> Adware.Enbrow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044875.exe -> Adware.Enbrow : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044852.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044859.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044988.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044995.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044997.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045003.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045007.exe -> Adware.Linkmaker : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0008.CHK -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044836.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044879.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044888.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044951.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044967.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045012.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045017.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045034.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045047.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045053.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045068.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046071.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046088.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046092.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047120.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047124.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047145.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047156.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047159.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047169.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047175.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047189.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047194.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047197.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047201.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0048200.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048219.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048230.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\LBMSP80N.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WCWIZDLL.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WRNSSPI.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cbrtmgr.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dPnim.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\damsrpcn.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dgcpcsvc.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\diutil.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\e220lcfm1f2a.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ejts.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fp2603fse.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\i6jq0g15e6.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixxwan.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jt6007jme.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kmdfc.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ktl0l73m1.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lv6009jme.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mhdadiag.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mkjter40.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\o2480chuef480.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\owbccr32.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sbhannel.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\uwrrtosa.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wdhnetbs.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wnv8dmoe.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044982.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\876056.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\WinNB57.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043811.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044835.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044851.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044866.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044867.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044943.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045002.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047096.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047106.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047118.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047158.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047184.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048236.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand.1 -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CLSID -> Adware.PowerStrip : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CurVer -> Adware.PowerStrip : Cleaned with backup (quarantined).
C:\Program Files\aѕsembly\rеgsvr32.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046095.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047165.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\logonui.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Program Files\UpromiseRemindU\UpromiseRemindU1.exe -> Adware.Rebates : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/mptft.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044854.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044971.EXE -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044987.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044994.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045001.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045008.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048242.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048246.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048247.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048250.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048251.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048262.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048263.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048265.dll -> Adware.SearchAssistant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046072.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048261.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SpySheriff -> Adware.SpySheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/wfxqhv.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\A2B3C.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/nr1rnqm8.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\F4E35.tmp/ssn6tuu.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044860.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044990.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044998.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045005.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045041.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045042.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045043.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045044.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047091.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047109.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048239.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048240.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048244.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048252.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gbe90qs.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nr1rnqm8.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ssn6tuu.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\x3cqp0.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\i30.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\i7D.tmp -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044883.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044884.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044885.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044887.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047185.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047186.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047187.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047188.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined).
HKU\S-1-5-21-808743801-1487682723-3042452539-1005\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046086.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\Program Files\Toolbar888 -> Adware.ToolBar888 : Cleaned with backup (quarantined).
C:\Program Files\UpromiseRemindU\UpromiseRemindU.exe -> Adware.TopMoxie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043812.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043813.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043814.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044825.exe/whAgent.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044958.EXE -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044963.EXE -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044964.DLL -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044965.DLL -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0044966.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044842.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044858.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044863.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044872.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044873.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043810.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046080.exe -> Backdoor.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044846.exe -> Downloader.Adload.bo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044826.exe -> Downloader.Adload.bv : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0004.CHK -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\FOUND.003\FILE0005.CHK -> Downloader.Adload.ck : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047123.exe -> Downloader.Adload.cn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048255.exe -> Downloader.Adload.dv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmonwv.dll -> Downloader.Agent.agw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003dfc2.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003e4b4.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w00416ef.dll -> Downloader.Agent.ahv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044838.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047125.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048253.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\WINDOWS\system32\MSAgentXP.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\WINDOWS\system32\msdadiag.exe -> Downloader.Agent.am : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045011.DLL -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047138.dll -> Downloader.Dyfuca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044848.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044871.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047108.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047128.exe -> Downloader.Dyfuca.ei : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\F7Z91BLM\!update-3895[1].0000 -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Тasks\services.exe -> Downloader.PurityScan.co : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\F7Z91BLM\!update-4120[1].0000 -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048235.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP765\A0048286.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temp\!update.exe -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\Documents and Settings\Scott\Local Settings\Temporary Internet Files\Content.IE5\6YW01EIM\!update-4220[1].0000 -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\WINDOWS\sуmbols\winspool.exe -> Downloader.PurityScan.da : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043809.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047084.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\WINDOWS\system32\juoto.dat -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\uhqud.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
[688] C:\WINDOWS\system32\kfyqthe.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dnsapi.exe -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\WINDOWS\system32\test.bmp -> Downloader.Reqlook.d : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w003bad5.dll -> Downloader.Small : Cleaned with backup (quarantined).
C:\Program Files\MSN Gaming Zone\auxe.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042810.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042811.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042812.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046097.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047206.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044841.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047095.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047126.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044833.exe -> Downloader.Small.cpu : Cleaned with backup (quarantined).
C:\Program Files\MSN Gaming Zone\wogexisu.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046096.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047205.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\VSL.dl_ -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047093.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046075.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046083.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046082.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044840.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047100.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046074.exe -> Downloader.TSUpdate.p : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044845.exe -> Downloader.VB.abm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047131.exe -> Downloader.VB.afv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046081.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047080.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047081.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047130.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047122.exe -> Downloader.VB.agi : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047094.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048260.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043806.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0043807.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047082.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047083.exe -> Downloader.VB.tw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044839.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047103.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044830.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044831.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044832.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047097.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047092.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044834.exe -> Dropper.Mudrop.bq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044837.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047099.exe -> Dropper.Small.qn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044864.exe -> Dropper.VB.mz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047115.exe -> Dropper.VB.mz : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0042816.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046100.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047129.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047143.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048270.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Program Files\Microsoft Works\zynela.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\Online Services\wolyjuju.html -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047119.exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044827.exe -> Hijacker.StartPage.aju : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0047098.exe -> Hijacker.VB.fc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP763\A0046098.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\WINDOWS\fzhtelx.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP761\A0044847.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048259.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP762\A0045010.exe -> Not-A-Virus.Downloader.Win32.FunWeb : Ignored.
C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\IGBFYK9V\WinAntiVirusPro2006ScannerInstall[1].cab/UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048258.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048269.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048248.exe -> Not-A-Virus.Hoax.Win32.Renos.dc : Ignored.
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\FOUND.004\FILE0002.CHK -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\FOUND.004\FILE0003.CHK -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{779966AB-1067-4D8F-AB44-5EB5C904C0FA}\RP764\A0048256.exe -> Proxy.Agent.km : Cleaned with backup (quarantined).
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Grace\Local Settings\Temp\Cookies\grace@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\jessi@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@112.2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\scott@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@7search[1].txt -> TrackingCookie.7search : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@ad-flow[2].txt -> TrackingCookie.Ad-flow : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@ad-logics[2].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed]-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@ad-logics[1].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\kiersten@ad-logics[2].txt -> TrackingCookie.Ad-logics : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\jessi@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\scott@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\WINDOWS\Temp\Cookies\grace@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Kiersten\Cookies\[removed][2].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Jessi\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Scott\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\jessi@advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Jessi\Cookies\[removed][2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings