This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer Adware Spyware Can You Take a Look At My HJT Log

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 4:45:25 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {1928B50D-41F0-4521-8A0F-0147F0503B9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1DE869EE-B3F3-4F04-8E74-41826D6A92A4} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {2AA7921B-ACDF-4096-856D-532106FEE749} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {4BD36C81-10C7-45DD-BC10-654966734970} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {65802BB7-5B71-47F8-9617-5E56AB232B0C} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {92BB630D-67C4-459A-932D-CC39774DDC9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {BB528829-10C5-41F0-A9A5-2A583A4F8644} - C:\Program Files\321Studios\quhar.dll
O2 - BHO: (no name) - {CF969165-4EB9-4201-AD8B-9F2B5DF57575} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DB611A9A-9A6E-4679-9E08-DD5110D7228A} - C:\Program Files\Windows NT\mevoxuzak.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [wasa] C:\WINDOWS\$NtUninstallKB896358$\wasa.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HiJackThis log.
VundoFix V6.3.6

Checking Java version…

Java version is 1.5.0.2

Scan started at 3:36:00 PM 2/10/2007

Listing files found while scanning….

No infected files were found.


VundoFix V6.3.6

Checking Java version…

Java version is 1.5.0.2

Scan started at 3:52:52 PM 2/10/2007

Listing files found while scanning….

No infected files were found.


Beginning removal…




Logfile of HijackThis v1.99.1
Scan saved at 4:35:08 PM, on 2/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\p2pnetworking.exe
C:\WINDOWS\system32\stup9x.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {1928B50D-41F0-4521-8A0F-0147F0503B9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1DE869EE-B3F3-4F04-8E74-41826D6A92A4} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {2AA7921B-ACDF-4096-856D-532106FEE749} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {4BD36C81-10C7-45DD-BC10-654966734970} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {65802BB7-5B71-47F8-9617-5E56AB232B0C} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {8893E2B9-419C-4F40-A9C2-591851776865} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {92BB630D-67C4-459A-932D-CC39774DDC9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CF969165-4EB9-4201-AD8B-9F2B5DF57575} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DB611A9A-9A6E-4679-9E08-DD5110D7228A} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {EB27FBAE-1561-4261-5DB5-725EE4E075D3} - C:\Program Files\321Studios\quhar.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [xetewe] C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Click on Start, then Run and type the following in the Open: field:
C:\Program Files\DeluxeCommunications\Dxc.exe /u
and press the OK button.

The DeluxeCommunications uninstall program will load and you will be asked to enter a security code. Enter the security code in the file and then press the OK button.

The uninstall process will then tell you that all browser windows will be closed if you continue. Press the Yes button to continue uninstalling DeluxeCommunications as shown in the figure below.

Finally, when it asks if you would to reboot, as shown in the image below, press the Yes button so that your computer reboots.

Download the FixDXC.reg from the following link and save it on your desktop.


When the FixDCX.reg file has finished downloading double-click on the file. When it asks if you would like to add the information into the Registry, click on the Yes button and then on the OK button at next prompt..

Now search for the following files. If they exist, they will be in the C:\Documents and Settings\Your login name\Application Data folder. In order to see the Application Data folder may have to enable Windows to show hidden files. When you find these files, delete them.

Dxcknwrd.dll
Dxccwrd.dll

Reboot and rescan with hijackthis and post another log.
OK… the run c:\program files…… is saying that it cannot find the file… i tried to cut and paste the file exactly as you wrote it … still nothing . Also when i run the fixdxc program it says another program is using this file and won't allow me to finish running it.
I deleted those two things… here is the new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 12:56:08 AM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\Update.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {1928B50D-41F0-4521-8A0F-0147F0503B9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1DE869EE-B3F3-4F04-8E74-41826D6A92A4} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {2AA7921B-ACDF-4096-856D-532106FEE749} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {4BD36C81-10C7-45DD-BC10-654966734970} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {65802BB7-5B71-47F8-9617-5E56AB232B0C} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {8893E2B9-419C-4F40-A9C2-591851776865} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {92BB630D-67C4-459A-932D-CC39774DDC9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CF969165-4EB9-4201-AD8B-9F2B5DF57575} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DB611A9A-9A6E-4679-9E08-DD5110D7228A} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {EB27FBAE-1561-4261-5DB5-725EE4E075D3} - C:\Program Files\321Studios\quhar.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [xetewe] C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Copy all the text contained in the code box below to your Clipboard.

Files to delete:
C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
C:\Program Files\DeluxeCommunications\DxcBho.dll
C:\Program Files\Windows NT\mevoxuzak.dll
C:\Program Files\321Studios\quhar.dll
C:\Program Files\DeluxeCommunications\Dxc.exe
Folders to delete:
C:\Program Files\321Studios
C:\WINDOWS\$NtUninstallKB896422$
C:\Program Files\DeluxeCommunications


The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply.

—————————————————————
Reboot in safe mode:
Leaving only HijackThis running. Place a check against each of the following, making sure you get them all :

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: (no name) - {1928B50D-41F0-4521-8A0F-0147F0503B9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {1DE869EE-B3F3-4F04-8E74-41826D6A92A4} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {2AA7921B-ACDF-4096-856D-532106FEE749} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {4BD36C81-10C7-45DD-BC10-654966734970} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {65802BB7-5B71-47F8-9617-5E56AB232B0C} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {8893E2B9-419C-4F40-A9C2-591851776865} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {92BB630D-67C4-459A-932D-CC39774DDC9D} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O2 - BHO: (no name) - {CF969165-4EB9-4201-AD8B-9F2B5DF57575} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: (no name) - {DB611A9A-9A6E-4679-9E08-DD5110D7228A} - C:\Program Files\Windows NT\mevoxuzak.dll
O2 - BHO: 0 - {EB27FBAE-1561-4261-5DB5-725EE4E075D3} - C:\Program Files\321Studios\quhar.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{3001F~1\Bar888.dll
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [xetewe] C:\WINDOWS\$NtUninstallKB896422$\xetewe.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O20 - AppInit_DLLs: dxclib303562752.dll


Click on Fix Checked when finished and exit HijackThis.

Using Windows Explorer, locate the following files/folders, and delete them:

p2pnetworking.exe
dxclib303562752.dll

Exit Explorer, and reboot as normal afterwards.


Download and install AVG Anti-Spyware (ewido). Then scan and post the report here with avenger log and a new hijackthis log.
Instructions and download link can be found here.
I did the Avg Log before i quArantined everything… do you need the log after the quarantine or do you need a new avg log or is it ok??? AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:25:00 PM 2/12/2007 + Scan result: C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003705.exe -> Adware.Agent : No action taken. C:\WINDOWS\system32\flcjdfji.dll -> Adware.Agent : No action taken. C:\WINDOWS\system32\ofpopmlp.dll -> Adware.Agent : No action taken. C:\WINDOWS\offun.exe -> Adware.Bagon : No action taken. C:\WINDOWS\srvzmjrogl.exe -> Adware.BHO : No action taken. C:\WINDOWS\system32\nodeipproc.dll -> Adware.BHO : No action taken. C:\WINDOWS\bbnsjlip.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\cagiosbe.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\ixleoeju.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\lkzxvejy.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\lyhbjuuj.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\pgitraxj.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\qyppkcsu.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\sqvgpqki.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\stub_mm6.exe -> Adware.BookedSpace : No action taken. C:\WINDOWS\uewjfugp.exe -> Adware.BookedSpace : No action taken. C:\Program Files\CMFibula\equpd.exe -> Adware.CASClient : No action taken. C:\Program Files\CMIntex\CMIntex.exe -> Adware.CASClient : No action taken. C:\Program Files\Exolon\Exolon.dll -> Adware.CASClient : No action taken. C:\Program Files\Exolon\Exolon.exe -> Adware.CASClient : No action taken. C:\Program Files\DeluxeCommunications -> Adware.DeluxeCommunications : No action taken. C:\Program Files\DeluxeCommunications\Dxc.exe -> Adware.DeluxeCommunications : No action taken. C:\Program Files\DeluxeCommunications\DxcBho.dll -> Adware.DeluxeCommunications : No action taken. C:\Program Files\DeluxeCommunications\DxcCore.dll -> Adware.DeluxeCommunications : No action taken. C:\Documents and Settings\Cory\Start Menu\Play Poker Online!.lnk -> Adware.Generic : No action taken. C:\WINDOWS\system32\AMIDDC.DLL -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\MTCTF.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\PzSFS.DLL -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\auicap.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\azaq03h5e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\cayptdlg.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\cffview.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\cqypt32.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\csprops.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dSdramp.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dlnet.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dmj8011ue.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dn4q01h5e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dnj8011ue.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dnn6015se.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\dumclien.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\e420lefm1h2a.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\e8202ifmg82a2.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\e820lifm182a.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\en6sl1j71.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\enp8l17u1.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\enpol1731.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\fp4q03h5e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\fp8403lqe.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\fpj2031oe.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\g6lm0g31e6.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\h2n00c5mef.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\h8j40i1qe8.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\hpetcfg.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\hr2q05f5e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\hrp0057me.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\hrru0599e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\hz0605dse.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\i206lcds1f06.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\i2nmlc511f.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ilfgnt5.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ilxwan.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ir0ml5d11.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ir4sl5h71.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ir4ul5h91.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ir8ml5l11.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\irn8l55u1.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\itxrtmgr.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\j2j6lc1s1f.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\j2l40c3qef.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\j86mlij118o.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\jt4407hqe.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\jtlm0731e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\k226lcfs1f26.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\k4js0e17eh.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\k4jsle171h.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kfdbu.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kfdvntc.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kvdmaori.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kxdintel.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kyddiv2.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\kydno1.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\l2p20c7oef.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\l8p2li7o18.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lbrmonui.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lqasrv.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lv2209foe.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lv4u09h9e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lv8q09l5e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lvjo0913e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\lvnq0955e.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mbrdim.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mhbsync.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mhutilse.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\moc42.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mugina.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mvn0l95m1.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\mvnol9531.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\n2n60c5sef.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\n68olgl316q.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\nqdsapi.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\nrptools.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\o0840alqedqe0.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\o248lchu1f48.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\o284lclq1fqe.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\o8nsli5718.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\ofbccr32.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\omjsel.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\p2n8lc5u1f.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\pnnppagn.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\q4860elsehq60.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\q486lels1hq6.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\q8680ijue8o80.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\r2p8lc7u1f.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\r8r60i9se8.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\r8r6li9s18.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\rXsauto.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\sgredir.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\shns.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\skbiop.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\slardssp.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\t08u0al9edq.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\txpmon.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\wKvemsp.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\wT583cfd.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\wbpasf.dll -> Adware.Look2Me : No action taken. C:\WINDOWS\system32\winotify.dll -> Adware.Look2Me : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005787.ocx -> Adware.MediaMotor : No action taken. C:\WINDOWS\876057.exe -> Adware.Mirar : No action taken. C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003355.dll -> Adware.NewDotNet : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003694.exe -> Adware.NewDotNet : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003696.exe -> Adware.NewDotNet : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003697.dll -> Adware.NewDotNet : No action taken. C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : No action taken. C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : No action taken. C:\Program Files\PrintView\printhook030.dll -> Adware.PrintView : No action taken. C:\WINDOWS\rk.exe -> Adware.Relevant : No action taken. C:\WINDOWS\876056.exe -> Adware.SaveNow : No action taken. C:\WINDOWS\Uninstall.exe -> Adware.SearchClickAds : No action taken. C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\system.dll -> Adware.Softomate : No action taken. C:\Program Files\Common Files\{6001F81E-0703-1033-0102-060503310001}\system.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003336.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003337.exe -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003340.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003341.exe -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003342.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003343.exe -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003423.exe -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003435.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003436.exe -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003562.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003602.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003675.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003722.dll -> Adware.Softomate : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005832.dll -> Adware.Softomate : No action taken. C:\WINDOWS\system32\rnnypbw.exe -> Adware.Suggestor : No action taken. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DK1CDKV\DXC_vlert1205[1].exe -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003690.dll -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003691.exe -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003692.dll -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005889.exe -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005890.dll -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005891.dll -> Adware.SurfSide : No action taken. C:\WINDOWS\lhrnh0578.exe -> Adware.SurfSide : No action taken. C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003595.exe -> Adware.Toolbar888 : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003627.exe -> Adware.Toolbar888 : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003713.exe -> Adware.Toolbar888 : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005823.exe -> Adware.Toolbar888 : No action taken. C:\WINDOWS\system32\install.exe -> Adware.Toolbar888 : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000002.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000019.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000024.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000042.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\snapshot\MFEX-1.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-1.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-2.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000051.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000188.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000193.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000211.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001193.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001207.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001213.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001231.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001255.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001271.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002255.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002274.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002304.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002322.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003321.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003322.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003354.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003370.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003372.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003389.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003391.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003407.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003424.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003460.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003487.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003494.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003520.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-1.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-2.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003539.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003559.exe -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003573.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-1.DAT -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-2.DAT -> Adware.TTC : No action taken. C:\TTC.dll -> Adware.TTC : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001258.dll -> Adware.WebHancer : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001259.dll -> Adware.WebHancer : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003462.dll -> Adware.WebHancer : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003464.exe -> Adware.WebHancer : No action taken. C:\WINDOWS\itpb_6.exe -> Adware.WebHancer : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001257.exe -> Adware.Webhancer.a : No action taken. C:\SDFix\backups\backups.zip/backups/dwdsregt.exe -> Adware.ZenoSearch : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003634.exe -> Adware.ZenoSearch : No action taken. C:\WINDOWS\system32\ZICORN003.exe -> Adware.ZenoSearch : No action taken. C:\WINDOWS\system32\kwinqpes.exe -> Adware.ZenoSearch : No action taken. C:\WINDOWS\system32\kwinqpex.exe -> Adware.ZenoSearch : No action taken. C:\WINDOWS\system32\kwinqpez.exe -> Adware.ZenoSearch : No action taken. C:\WINDOWS\system32\opdsregn.exe -> Adware.ZenoSearch : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000016.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000038.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000207.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001227.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001265.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002267.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002272.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002317.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003314.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003325.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003383.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003387.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003421.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003481.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003505.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003510.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003548.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003584.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003617.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003636.exe -> Backdoor.Rbot.rc : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005796.exe -> Backdoor.Rbot.rc : No action taken. C:\Program Files\Cas2Stub\cas2stub.exe -> Downloader.Agent.aaf : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005792.dll -> Downloader.Agent.ahv : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005793.dll -> Downloader.Agent.ahv : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005794.dll -> Downloader.Agent.ahv : No action taken. C:\SDFix\backups\backups.zip/backups/aff_001.exe -> Downloader.Agent.aqx : No action taken. C:\SDFix\backups\backups.zip/backups/affiliate.exe -> Downloader.Agent.aqx : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002273.exe -> Downloader.Agent.bca : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003319.exe -> Downloader.Agent.bca : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003513.exe -> Downloader.Agent.bca : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003558.exe -> Downloader.Agent.bca : No action taken. C:\WINDOWS\srvepwxzjp.exe -> Downloader.Dyfuca.ey : No action taken. C:\WINDOWS\srvfxvusno.exe -> Downloader.Dyfuca.ey : No action taken. C:\WINDOWS\srvgdxwsfp.exe -> Downloader.Dyfuca.ey : No action taken. C:\WINDOWS\srvurgpodk.exe -> Downloader.Dyfuca.ey : No action taken. C:\WINDOWS\srvyilvoha.exe -> Downloader.Dyfuca.ey : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005788.exe -> Downloader.Small.ajc : No action taken. C:\WINDOWS\ac3_0002.exe -> Downloader.Small.cyh : No action taken. C:\SDFix\backups\backups.zip/backups/setup.exe -> Downloader.Tibs.if : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003529.exe -> Downloader.VB.apu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003701.exe -> Downloader.VB.apu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005789.exe -> Downloader.VB.nw : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003397.exe -> Dropper.Agent.bbp : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005786.exe -> Dropper.Agent.hl : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005396.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005397.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005398.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005399.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005400.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005401.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005402.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005403.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005404.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005405.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005406.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005407.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005408.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005409.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005410.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005411.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005412.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005413.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005414.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005415.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005416.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005417.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005418.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005419.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005420.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005421.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005422.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005423.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005424.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005425.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005426.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005427.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005428.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005429.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005430.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005431.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005432.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005433.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005434.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005435.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005436.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005437.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005438.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005439.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005440.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005441.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005442.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005443.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005444.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005445.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005446.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005447.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005448.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005449.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005450.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005451.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005452.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005453.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005454.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005455.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005456.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005457.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005458.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005459.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005460.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005461.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005462.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005463.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005464.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005465.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005466.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005467.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005468.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005469.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005470.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005471.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005472.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005473.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005474.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005475.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005476.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005477.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005478.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005479.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005480.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005481.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005482.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005483.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005484.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005485.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005486.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005487.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005488.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005489.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005490.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005491.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005492.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005493.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005494.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005495.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005496.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005497.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005498.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005499.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005500.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005501.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005502.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005503.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005504.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005505.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005506.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005507.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005508.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005509.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005510.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005511.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005512.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005513.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005514.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005515.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005516.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005517.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005518.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005519.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005520.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005521.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005522.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005523.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005524.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005525.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005526.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005527.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005528.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005529.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005530.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005531.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005532.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005533.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005534.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005535.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005536.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005537.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005538.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005539.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005540.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005541.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005542.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005543.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005544.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005545.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005546.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005547.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005548.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005549.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005550.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005551.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005552.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005553.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005554.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005555.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005556.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005557.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005558.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005559.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005560.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005561.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005562.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005563.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005564.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005565.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005566.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005567.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005568.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005569.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005570.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005571.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005572.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005573.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005574.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005575.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005576.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005577.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005578.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005579.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005580.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005581.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005582.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005583.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005584.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005585.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005586.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005587.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005588.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005589.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005590.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005591.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005592.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005593.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005594.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005595.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005596.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005597.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005598.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005599.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005600.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005601.exe -> Dropper.VB.lu : No action taken. C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5
Sorry about that i thought i posted this with the avg log…





Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\crncamfg

*******************

Script file located at: \??\C:\WINDOWS\ayaamowc.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Program Files\321Studios deleted successfully.
Folder C:\WINDOWS\$NtUninstallKB896422$ deleted successfully.
Folder C:\Program Files\DeluxeCommunications deleted successfully.

Completed script processing.

*******************

Finished! Terminate








Logfile of HijackThis v1.99.1
Scan saved at 5:34:06 PM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Three Rings Design\Bang Howdy\java_vm\bin\javaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Three Rings Design\Bang Howdy\java_vm\bin\java.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Be sure to keep SunJava, updated

In Add/Remove programs click on these and press *remove* if listed:
J2SE Runtime Environment 5.0 - 97.99Mb
J2SE Runtime Environment 5.0 Update 2 - 143.00Mb
J2SE Runtime Environment 5.0 Update 4 - 144.00Mb
J2SE Runtime Environment 5.0 Update 5- 151.00Mb
Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb
Or any other outdated J2SE


It is important to remove older versions as these are the ones with the holes in them. You will be surprised when you go to add/remove to see all of the versions sitting there.

Download Newest >>>> http://www.java.com/en/download/index.jsp

Once installed you can test to see that it is in fact installed >>>>

Sun Java Test


Then click HERE and do a online scan. Deleting every thing it finds.
Post the log here.
Monday, February 12, 2007 19:08:51 - 20:38:14 Computer name: TRIPLEC Scanning type: Scan system for viruses, rootkits, spyware Target: C:\ ——————————————————————————– Result: 112 malware found Adware.MyToolbar (spyware) System DLoader.BAUB (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\B111.EXE (Submitted) DeluxeCommunications (spyware) System Exploit.HTML.Mht (virus) C:\WINDOWS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\MBU789GZ\DELIVER46860[1].HTM (Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\JJD3UDU9\DELIVER46860[1].HTM (Submitted) JS/ForcePopup@troj (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\8VFJ6EQ8\POPUP[1].HTM (Submitted) Malware.AL (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\CMFIBULA.EXE (Submitted) Malware.CCP (virus) C:\PROGRAM FILES\CMFIBULA\EQUPD.EXE (Submitted) P2P-Worm.Win32.Agent.v (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\ZGO.EXE (Renamed & Submitted) PurityScan.ZW.dropper (virus) C:\WINDOWS\SRVCXDWHGD.EXE (Submitted) Smalltroj.HAP.dropper (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\SNF3QOX5\ACDT-PID27[1].EXE (Submitted) SurfSideKick (spyware) System Tracking Cookie (spyware) System (Disinfected) System System System System (Submitted) System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System System Trojan-Clicker.Win32.Small.ja (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN17.EXE (Renamed) Trojan-Downloader.Win32.Agent.bca (virus) C:\WINDOWS\SYSTEM32\SVCHOSTS.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Agent.bdr (virus) C:\WINDOWS\SYSTEM32\INSTALL.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\INSTALL.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Busky.gen (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\H91746.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Small.cyh (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\MIGCONF2.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Tibs.if (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\WIN32.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Tiny.cl (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\A3584.EXE (Renamed & Submitted) Trojan-Downloader.Win32.VB.anl (virus) C:\WINDOWS\SYS0161074179012006.EXE (Renamed & Submitted) Trojan-Downloader.Win32.Zlob.avo (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\1005_110.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\163.EXE (Renamed & Submitted) Trojan-Dropper.Win32.Agent.atm (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN14.EXE (Renamed) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN18.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN2.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN3.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN4.EXE (Renamed & Submitted) Trojan-Dropper.Win32.Agent.mu (virus) C:\WINDOWS\STEJUVA.EXE (Renamed & Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\STDRUN19.EXE (Renamed & Submitted) Trojan-PSW.Win32.LdPinch.atp (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\BUNDLEINSTALLER.EXE (Renamed & Submitted) Trojan.Win32.BHO.ab (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\{F79D750E-403F-4692-8E80-28EA35B87BA6}\TUQUSUPU.EXE (Renamed & Submitted) Virus.Win32.Fontra.c (virus) C:\WINDOWS\SYSTEM32\P2PNETWORKING.EXE (Submitted) C:\WINDOWS\SYSTEM32\SHARED.EXE (Submitted) C:\PROGRAM FILES\SETUP.EXE (Submitted) C:\PROGRAM FILES\TRACK_03.EXE (Submitted) C:\PROGRAM FILES\UY.EXE (Submitted) C:\PROGRAM FILES\VIDEO.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\CORY\HUI.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\CORY\SHARED.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\CORY\SHARED\DICKIN AROUND2 FELLATIO STUDY_43.WMV.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\DLLHOST.EXE (Submitted) W32/Agent.AMFZ (virus) C:\WINDOWS\SYSTEM32\KWINQPES.EXE (Submitted) W32/Agent.ANEI (virus) C:\PROGRAM FILES\PRINTVIEW\PRINTHOOK030.DLL (Submitted) W32/DLoader.AXTD (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\BUNDLEINSTALL.EXE (Submitted) W32/DLoader.BJUN (virus) C:\WINDOWS\OFFUN.EXE (Submitted) W32/DLoader.BJUN.dropper (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\188.EXE (Submitted) W32/DLoader.BKCW (virus) C:\WINDOWS\MS0541790161072006.EXE (Submitted) C:\WINDOWS\MS0617901610742006.EXE (Submitted) W32/DLoader.BXTM (virus) C:\RECYCLER\S-1-5-18\DC7\UPDATE.EXE (Submitted) W32/Mirar.J.dropper (virus) C:\WINDOWS\876057.EXE (Submitted) W32/Mirar.T.dropper (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\NNBAR_VCSETUP_876056.EXE (Submitted) W32/NetworkWorm.KB (virus) C:\PROGRAM FILES\EXOLON\UNINSTALL.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\EXOLON.EXE (Submitted) W32/PurityScan.AFM.dropper (virus) C:\WINDOWS\SRVVDYWMWT.EXE (Submitted) W32/PurityScan.ZW.dropper (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\AXSETUP1.EXE (Submitted) W32/Relevance.F.dropper (virus) C:\WINDOWS\ITPB_3.EXE (Submitted) W32/SaveNow.UF.dropper (virus) C:\WINDOWS\ITPB_4.EXE (Submitted) W32/Smalldrp.GOJ (virus) C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\SETUP100.EXE (Submitted) W32/SurfSide.EY.dropper (virus) C:\WINDOWS\LHRNH0578.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\0DK1CDKV\DXC_VLERT1205[1].EXE (Submitted) W32/SurfSide.FD.dropper (virus) C:\WINDOWS\DYTGK0578.EXE (Submitted) C:\WINDOWS\MKIJI0578.EXE (Submitted) C:\WINDOWS\PALCV0578.EXE (Submitted) C:\WINDOWS\UCHLD0578.EXE (Submitted) C:\WINDOWS\VKQLI0578.EXE (Submitted) C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\CTEL2B2J\B0104A[1].EXE (Submitted) WebHancer.CE.dropper (virus) C:\WINDOWS\ITPB_6.EXE (Submitted) C:\WINDOWS\WHCC-MTHREE.EXE (Submitted) Win32.P2P-Worm.Alcan.a (spyware) System ——————————————————————————– Statistics Scanned: Files: 45940 System: 5514 Not scanned: 5 Actions: Disinfected: 1 Renamed: 21 Deleted: 0 None: 90 Submitted: 65 Files not scanned: C:\HIBERFIL.SYS C:\PAGEFILE.SYS C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{D6905086-6E2B-49D7-81F5-5841B877CDB0}.BIN C:\DOCUMENTS AND SETTINGS\CORY\LOCAL SETTINGS\TEMP\HSPERFDATA_CORY\2940 ——————————————————————————– Options Scanning engines: F-Secure Libra: 2.4.2, 2007-02-01 F-Secure AVP: 7.0.171, 2007-02-12 F-Secure Orion: 1.2.37, 2007-02-12 F-Secure Blacklight: 1.0.53, 0000-00-00 F-Secure Draco: 1.0.35, 0260-02-44 F-Secure Pegasus: 1.19.0, 2007-01-07 Scanning options: Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX Use Advanced heuristics

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI