This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Computer Adware Spyware Can You Take a Look At My HJT Log

68 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 12:53:48 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [bppoxa] C:\WINDOWS\system32\bxlwxc.exe reg_run
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
I reviewed the log after i posted it… and i noticed the 3 Deluxe Communications are still on there… They won't delete from the HJt when i click on the Fix Checked Button… ???
Download Qoofix by RubbeR DuckY from http://www.malwarebytes.org/Qoofix.zip

1. Unzip all files to a convenient location such as C:\Qoofix.
2. Go to the folder you unzipped all files and run Qoofix.exe.
3. Click Begin Removal and wait for the scan to finish.
4. If an infection has been found, select yes to restart your computer.


Finally post a new Hijack This log and the contents of the Qoofix logfile.
Qoofix v1.04 by http://www.malwarebytes.org
Scan started on [2/13/2007] at [2:18:08 PM]
————————————————————-
No malicious modules found!
————————————————————-
No Qoologic infected files found!
————————————————————-
Scan COMPLETED SUCCESSFULLY on [2/13/2007] at [2:19:16 PM]

Note: Some registry keys may have been removed.




Logfile of HijackThis v1.99.1
Scan saved at 2:35:34 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Download The Avenger Copyright © Swandog46
You must extract avenger.exe to your desktop, before you run it.
The Avenger must be run from a user account with administrator privileges,
and ONLY works on Windows 2000 and XP, and only on 32-bit versions!

Copy all the text contained in the code box below to your Clipboard.

Files to delete:
C:\Program Files\DeluxeCommunications\Dxc.exe
C:\Program Files\Common Files\wmif\wmifm.exe
C:\WINDOWS\system32\dxclib303562752.dll
Folders to delete:
C:\Program Files\DeluxeCommunications
C:\Program Files\Common Files\wmif
Registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | DeluxeCommunications
HKCU\Software\Microsoft\Windows\CurrentVersion\Run | wmif
HKCU\Software\Microsoft\Windows\CurrentVersion\Run | DeluxeCommunications



The above script is for this user only, if you need help please start your own thread.


Start the Avenger.
Under "Script file to execute" choose "Input Script Manually".
Click on the Magnifying Glass icon which will open a new window titled "View/edit script".
Paste the entire text in into this window.
Click done, now click on the Green Light
Answer "Yes" twice when prompted.
Your computer shoud reboot, and briefly open a black command window on your desktop, this is normal.

After the restart, it will create a log file that should open.
This log file will be located at C:\avenger.txt
Paste the contents of the file into your reply along with a fresh HJT log.

Also: Avenger has made backups of all the files, etc., that you asked it to delete, located at C:\avenger\backup.zip.
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Syntax error in line — does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run | wmif


Syntax error in line — does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run | DeluxeCommunications


Error: could not execute export batch.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\audcierr

*******************

Script file located at: \??\C:\WINDOWS\vdlnvmfh.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Program Files\DeluxeCommunications deleted successfully.
Folder C:\Program Files\Common Files\wmif deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DeluxeCommunications deleted successfully.

Completed script processing.

*******************

Finished! Terminate.



Logfile of HijackThis v1.99.1
Scan saved at 5:03:14 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Syntax error in line — does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run | wmif


Syntax error in line — does not appear to be a valid registry path. Line will be ignored.
Error code: 0
Line: HKCU\Software\Microsoft\Windows\CurrentVersion\Run | DeluxeCommunications


Error: could not execute export batch.
Error code: 0


//////////////////////////////////////////


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\audcierr

*******************

Script file located at: \??\C:\WINDOWS\vdlnvmfh.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Folder C:\Program Files\DeluxeCommunications deleted successfully.
Folder C:\Program Files\Common Files\wmif deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DeluxeCommunications deleted successfully.

Completed script processing.

*******************

Finished! Terminate.



Logfile of HijackThis v1.99.1
Scan saved at 5:03:14 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CMIntex\CMIntex.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CMIntex] "C:\Program Files\CMIntex\CMIntex.exe"
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll (file missing)
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [wmif] C:\PROGRA~1\COMMON~1\wmif\wmifm.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O20 - AppInit_DLLs: dxclib303562752.dll


Reboot in safe mode, instructions here.
Some of these files my have hidden atributes.
Click Here Should you need instructions for Showing hidden files and folders in Windows.
Once in safe mode, Click start / then my computer / local disk then follow the process tree.
Or using Windows Explorer, locate the first file right click then select delete.

Delete the following file(s) listed in bold.
(do a search for this one. It'll probably be in c:\windows or c:\windows\system32.)
p2pnetworking.exe

Delete the following folder(s) listed in bold.
C:\PROGRA~1\COMMON~1\wmif\
C:\Program Files\DeluxeCommunications


Run avg anti-spyware. post the log here.
The HJT is not fixing some of the things that i check off. And i cant delete the
files it says they are being used by another person or program. Its the Deluxe communications programs.

And im having trouble finding this file…

C:\PROGRA~1\COMMON~1\wmif\


Logfile of HijackThis v1.99.1
Scan saved at 9:35:43 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe



———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 9:00:46 PM 2/13/2007

+ Scan result:



C:\Documents and Settings\Cory\Local Settings\Temp\stdrun13.exe -> Adware.180Solutions : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stdrun8.exe -> Adware.180Solutions : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003705.exe -> Adware.Agent : Ignored.
C:\WINDOWS\system32\flcjdfji.dll -> Adware.Agent : Ignored.
C:\WINDOWS\system32\ofpopmlp.dll -> Adware.Agent : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/thiselt.exe -> Adware.Agent : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stdrun15.exe/AutoSearch.dll -> Adware.AutoSearch : Ignored.
C:\WINDOWS\offun.exe -> Adware.Bagon : Ignored.
C:\WINDOWS\srvzmjrogl.exe -> Adware.BHO : Ignored.
C:\WINDOWS\system32\nodeipproc.dll -> Adware.BHO : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stub_sca4.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\bbnsjlip.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\cagiosbe.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\ixleoeju.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\lkzxvejy.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\lyhbjuuj.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\pgitraxj.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\qyppkcsu.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\sqvgpqki.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\stub_mm6.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\uewjfugp.exe -> Adware.BookedSpace : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\cmfibula.exe -> Adware.CASClient : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\exolon.exe -> Adware.CASClient : Ignored.
C:\Program Files\CMFibula\equpd.exe -> Adware.CASClient : Ignored.
C:\Program Files\CMIntex\CMIntex.exe -> Adware.CASClient : Ignored.
C:\Program Files\Exolon\Exolon.dll -> Adware.CASClient : Ignored.
C:\Program Files\Exolon\Exolon.exe -> Adware.CASClient : Ignored.
C:\Program Files\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\Dxc.exe -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\DxcBho.dll -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\DxcCore.dll -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\.DEFAULT\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\.DEFAULT\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-18\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-18\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
C:\Documents and Settings\Cory\Start Menu\Play Poker Online!.lnk -> Adware.Generic : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003563.exe -> Adware.IWantSearch : Ignored.
C:\WINDOWS\system32\AMIDDC.DLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\MTCTF.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\PzSFS.DLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\auicap.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\azaq03h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cayptdlg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cffview.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cqypt32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\csprops.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dSdramp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dlnet.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dmj8011ue.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dn4q01h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dnj8011ue.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dnn6015se.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dumclien.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e420lefm1h2a.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e8202ifmg82a2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e820lifm182a.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\en6sl1j71.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp8l17u1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enpol1731.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fp4q03h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fp8403lqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fpj2031oe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\g6lm0g31e6.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\h2n00c5mef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\h8j40i1qe8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hpetcfg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hr2q05f5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrp0057me.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrru0599e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hz0605dse.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i206lcds1f06.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i2nmlc511f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ilfgnt5.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ilxwan.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir0ml5d11.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir4sl5h71.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir4ul5h91.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir8ml5l11.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\irn8l55u1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\itxrtmgr.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j2j6lc1s1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j2l40c3qef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j86mlij118o.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\jt4407hqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\jtlm0731e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k226lcfs1f26.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k4js0e17eh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k4jsle171h.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdbu.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdvntc.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kvdmaori.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kxdintel.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kyddiv2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kydno1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l2p20c7oef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l8p2li7o18.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lbrmonui.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lqasrv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv2209foe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv4u09h9e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv8q09l5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lvjo0913e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lvnq0955e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mbrdim.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhbsync.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhutilse.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\moc42.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mugina.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mvn0l95m1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mvnol9531.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\n2n60c5sef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\n68olgl316q.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nqdsapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nrptools.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o0840alqedqe0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o248lchu1f48.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o284lclq1fqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o8nsli5718.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ofbccr32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\omjsel.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p2n8lc5u1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pnnppagn.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q4860elsehq60.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q486lels1hq6.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q8680ijue8o80.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r2p8lc7u1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r8r60i9se8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r8r6li9s18.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rXsauto.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sgredir.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\shns.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\skbiop.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\slardssp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\t08u0al9edq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\txpmon.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wKvemsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wT583cfd.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wbpasf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\winotify.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005787.ocx -> Adware.MediaMotor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit8.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit8.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit9.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit9.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\WINDOWS\876057.exe -> Adware.Mirar : Ignored.
C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003355.dll -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003694.exe -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003696.exe -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003697.dll -> Adware.NewDotNet : Ignored.
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Ignored.
C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/NewDotNet/uninstall6_38.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/NewDotNet/uninstall7_48.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/newdotnet7_48.dll -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink.1 -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink\CLSID -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink\CurVer -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\New.net -> Adware.NewDotNet : Ignored.
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Ignored.
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\New.net -> Adware.NewDotNet : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b124.exe -> Adware.PrintView : Ignored.
C:\Program Files\PrintView\printhook030.dll -> Adware.PrintView : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\BundleInstall.exe -> Adware.Relevant : Ignored.
C:\WINDOWS\rk.exe -> Adware.Relevant : Ignored.
C:\WINDOWS\876056.exe -> Adware.SaveNow : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/cvn0.exe -> Adware.SearchAssistant : Ignored.
C:\WINDOWS\Uninstall.exe -> Adware.SearchClickAds : Ignored.
C:\Documents and Settings\Cory\Desktop\hijackthis\backups\backup-20070208-174506-381.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Desktop\hijackthis\backups\backup-20070212-134807-573.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b116.exe -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{3001F81E-0703-1033-0102-060503310001}\Bar888.dll -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\system.dll -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{6001F81E-0703-1033-0102-060503310001}\system.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003336.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003337.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003340.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003341.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003342.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003343.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003423.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003435.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003436.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003562.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003602.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003672.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003675.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003716.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003722.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005825.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005832.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005901.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\E5C18.tmp/rnnypbw.exe -> Adware.Suggestor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/wfxqhv.exe -> Adware.Suggestor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/zqskw.exe -> Adware.Suggestor : Ignored.
C:\WINDOWS\system32\rnnypbw.exe -> Adware.Suggestor : Ignored.
C:\!KillBox\dxc.exe -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\i18.tmp -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\i220.tmp -> Adware.SurfSide : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DK1CDKV\DXC_vlert1205[1].exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003690.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003691.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003692.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005889.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005890.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005891.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006137.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006140.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006141.dll -> Adware.SurfSide : Ignored.
C:\WINDOWS\lhrnh0578.exe -> Adware.SurfSide : Ignored.
C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
[1044] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
[796] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\INSTALL.0XE -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003595.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003627.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003713.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005823.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006100.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006102.exe -> Adware.Toolbar888 : Ignored.
C:\WINDOWS\system32\INSTALL.0XE -> Adware.Toolbar888 : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{894F4911-02E8-4CDA-8A8D-BD7C0501E015}\teqe.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{B4ED9FDB-D6D1-46EF-96B9-C49FB34DDDEA}\kagaja.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{DE53ACA1-3744-4BC1-8AC8-50D867F3B9C2}\xutu.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\dexece.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\hudugu.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\loho.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000002.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000019.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000024.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000042.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000051.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000188.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000193.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000211.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001193.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001207.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001213.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001231.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001255.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001271.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002255.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002274.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002304.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002322.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003321.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003322.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003354.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003370.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003372.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003389.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003391.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003407.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003424.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003460.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003487.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003494.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003520.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003539.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003559.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003573.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\TTC.dll -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\GLB19.tmp/empty_00000001 -> Adware.Ucmore : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b129.exe -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001258.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001259.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003462.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003464.exe -> Adware.WebHancer : Ignored.
C:\WINDOWS\itpb_6.exe -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001257.exe -> Adware.Webhancer.a : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar -> Adware.WebSearch : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar\all -> Adware.WebSearch : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar\all\History -> Adware.WebSearch : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003634.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\ZICORN003.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpes.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpex.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpez.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\opdsregn.exe -> Adware.ZenoSearch : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005925.exe -> Downloader.Agent.aaf : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\9.tmp -> Downloader.Agent.aox : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F.tmp -> Downloader.Agent.aox : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000020.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000041.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000187.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000210.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001229.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001270.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002276.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002321.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003324.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003485.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003517.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003561.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005941.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005942.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005943.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005944.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005945.exe -> Downloader.Dyfuca.ey : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\cln51.tmp -> Downloader.Dyfuca.ez : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\1.dlb -> Downloader.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\5.dlb -> Downloader.Small.cwj : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\MIGCONF2.0XE -> Downloader.Small.cyh : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005936.exe -> Downloader.Small.cyh : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\A3584.0XE -> Downloader.Small.dcj : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\WIN32.0XE -> Downloader.Tibs.if : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\6.dlb -> Downloader.Tibs.im : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\7.dlb -> Downloader.Tibs.im : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b103.exe -> Downloader.TSUpdate.o : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b111.exe -> Downloader.VB.afa : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\1005_110.0XE -> Downloader.Zlob.avo : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\163.0XE -> Downloader.Zlob.avo : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN17.0XE -> Dropper.Agent.asr : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN14.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN18.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN2.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN3.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN4.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN19.0XE -> Dropper.Agent.mu : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\2.dlb -> Hijacker.Spywad.o : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005940.exe -> Hijacker.VB.ij : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DK1CDKV\ErrorSafeNewReleaseInstall[1].cab/UERS_9999_N91S2507NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\13.tmp -> Proxy.Agent.hd : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\B.tmp -> Proxy.Agent.hd : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@scrippshgtv.112.2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@atdmt[1].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@fastclick[2].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@pro-market[2].txt -> TrackingCookie.Pro-market : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@tacoda[1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@trafficmp[2].txt -> TrackingCookie.Trafficmp : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\TUQUSUPU.0XE -> Trojan.BHO.ab : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/321Studios/quhar.dll -> Trojan.BHO.ab : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\maxdd1.game -> Trojan.Dialer.ay : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\BUNDLEINSTALLER.0XE -> Trojan.LdPinch.atp : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\E5C18.tmp/t07grnpv.exe -> Trojan.Runner.j : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005946.exe -> Trojan.Runner.j : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\qvxt2.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\qvxt4.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\vx2.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\vx3.game -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005937.vbs -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005938.exe -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005939.vbs -> Trojan.Small : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/Ohrqm.exe -> Trojan.Small.cy : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\Setup100.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005926.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005927.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005928.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005929.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005930.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005931.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005932.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005933.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005934.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005935.exe -> Trojan.VB.tg : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\ZGO.0XE -> Worm.Agent.v : Ignored.


::Report end
The HJT is not fixing some of the things that i check off. And i cant delete the
files it says they are being used by another person or program. Its the Deluxe communications programs.

And im having trouble finding this file…

C:\PROGRA~1\COMMON~1\wmif\


Logfile of HijackThis v1.99.1
Scan saved at 9:35:43 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe



———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 9:00:46 PM 2/13/2007

+ Scan result:



C:\Documents and Settings\Cory\Local Settings\Temp\stdrun13.exe -> Adware.180Solutions : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stdrun8.exe -> Adware.180Solutions : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003705.exe -> Adware.Agent : Ignored.
C:\WINDOWS\system32\flcjdfji.dll -> Adware.Agent : Ignored.
C:\WINDOWS\system32\ofpopmlp.dll -> Adware.Agent : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/thiselt.exe -> Adware.Agent : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stdrun15.exe/AutoSearch.dll -> Adware.AutoSearch : Ignored.
C:\WINDOWS\offun.exe -> Adware.Bagon : Ignored.
C:\WINDOWS\srvzmjrogl.exe -> Adware.BHO : Ignored.
C:\WINDOWS\system32\nodeipproc.dll -> Adware.BHO : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\stub_sca4.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\bbnsjlip.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\cagiosbe.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\ixleoeju.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\lkzxvejy.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\lyhbjuuj.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\pgitraxj.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\qyppkcsu.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\sqvgpqki.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\stub_mm6.exe -> Adware.BookedSpace : Ignored.
C:\WINDOWS\uewjfugp.exe -> Adware.BookedSpace : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\cmfibula.exe -> Adware.CASClient : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\exolon.exe -> Adware.CASClient : Ignored.
C:\Program Files\CMFibula\equpd.exe -> Adware.CASClient : Ignored.
C:\Program Files\CMIntex\CMIntex.exe -> Adware.CASClient : Ignored.
C:\Program Files\Exolon\Exolon.dll -> Adware.CASClient : Ignored.
C:\Program Files\Exolon\Exolon.exe -> Adware.CASClient : Ignored.
C:\Program Files\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\Dxc.exe -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\DxcBho.dll -> Adware.DeluxeCommunications : Ignored.
C:\Program Files\DeluxeCommunications\DxcCore.dll -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\.DEFAULT\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\.DEFAULT\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-18\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-18\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Ignored.
C:\Documents and Settings\Cory\Start Menu\Play Poker Online!.lnk -> Adware.Generic : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003563.exe -> Adware.IWantSearch : Ignored.
C:\WINDOWS\system32\AMIDDC.DLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\MTCTF.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\PzSFS.DLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\auicap.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\azaq03h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cayptdlg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cffview.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\cqypt32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\csprops.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dSdramp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dlnet.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dmj8011ue.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dn4q01h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dnj8011ue.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dnn6015se.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dumclien.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e420lefm1h2a.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e8202ifmg82a2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\e820lifm182a.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\en6sl1j71.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp8l17u1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enpol1731.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fp4q03h5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fp8403lqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\fpj2031oe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\g6lm0g31e6.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\h2n00c5mef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\h8j40i1qe8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hpetcfg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hr2q05f5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrp0057me.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hrru0599e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\hz0605dse.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i206lcds1f06.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i2nmlc511f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ilfgnt5.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ilxwan.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir0ml5d11.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir4sl5h71.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir4ul5h91.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ir8ml5l11.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\irn8l55u1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\itxrtmgr.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j2j6lc1s1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j2l40c3qef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j86mlij118o.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\jt4407hqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\jtlm0731e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k226lcfs1f26.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k4js0e17eh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k4jsle171h.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdbu.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdvntc.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kvdmaori.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kxdintel.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kyddiv2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kydno1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l2p20c7oef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l8p2li7o18.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lbrmonui.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lqasrv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv2209foe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv4u09h9e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lv8q09l5e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lvjo0913e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\lvnq0955e.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mbrdim.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhbsync.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhutilse.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\moc42.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mugina.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mvn0l95m1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mvnol9531.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\n2n60c5sef.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\n68olgl316q.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nqdsapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nrptools.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o0840alqedqe0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o248lchu1f48.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o284lclq1fqe.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o8nsli5718.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ofbccr32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\omjsel.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p2n8lc5u1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pnnppagn.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q4860elsehq60.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q486lels1hq6.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q8680ijue8o80.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r2p8lc7u1f.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r8r60i9se8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\r8r6li9s18.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rXsauto.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sgredir.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\shns.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\skbiop.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\slardssp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\t08u0al9edq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\txpmon.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wKvemsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wT583cfd.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wbpasf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\winotify.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP5\A0005787.ocx -> Adware.MediaMotor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit8.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit8.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit9.tmp.cab/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\mit9.tmp/NNBar_VCSetup_876056.exe -> Adware.Mirar : Ignored.
C:\WINDOWS\876057.exe -> Adware.Mirar : Ignored.
C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003355.dll -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003694.exe -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003696.exe -> Adware.NewDotNet : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003697.dll -> Adware.NewDotNet : Ignored.
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Ignored.
C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/NewDotNet/uninstall6_38.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/NewDotNet/uninstall7_48.exe -> Adware.NewDotNet : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/newdotnet7_48.dll -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink.1 -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink\CLSID -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Classes\Tldctl2.URLLink\CurVer -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net -> Adware.NewDotNet : Ignored.
HKLM\SOFTWARE\New.net -> Adware.NewDotNet : Ignored.
HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Ignored.
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\New.net -> Adware.NewDotNet : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b124.exe -> Adware.PrintView : Ignored.
C:\Program Files\PrintView\printhook030.dll -> Adware.PrintView : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\BundleInstall.exe -> Adware.Relevant : Ignored.
C:\WINDOWS\rk.exe -> Adware.Relevant : Ignored.
C:\WINDOWS\876056.exe -> Adware.SaveNow : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/cvn0.exe -> Adware.SearchAssistant : Ignored.
C:\WINDOWS\Uninstall.exe -> Adware.SearchClickAds : Ignored.
C:\Documents and Settings\Cory\Desktop\hijackthis\backups\backup-20070208-174506-381.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Desktop\hijackthis\backups\backup-20070212-134807-573.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b116.exe -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{3001F81E-0703-1033-0102-060503310001}\Bar888.dll -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{6001F81E-0702-1033-0102-060503310001}\system.dll -> Adware.Softomate : Ignored.
C:\Program Files\Common Files\{6001F81E-0703-1033-0102-060503310001}\system.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003336.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003337.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003340.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003341.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003342.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003343.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003423.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003435.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003436.exe -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003562.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003602.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003672.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003675.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003716.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003722.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005825.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005832.dll -> Adware.Softomate : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005901.dll -> Adware.Softomate : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\E5C18.tmp/rnnypbw.exe -> Adware.Suggestor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/wfxqhv.exe -> Adware.Suggestor : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F7F1B1.tmp/zqskw.exe -> Adware.Suggestor : Ignored.
C:\WINDOWS\system32\rnnypbw.exe -> Adware.Suggestor : Ignored.
C:\!KillBox\dxc.exe -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\i18.tmp -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\i220.tmp -> Adware.SurfSide : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DK1CDKV\DXC_vlert1205[1].exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003690.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003691.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003692.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005889.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005890.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005891.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006137.exe -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006140.dll -> Adware.SurfSide : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006141.dll -> Adware.SurfSide : Ignored.
C:\WINDOWS\lhrnh0578.exe -> Adware.SurfSide : Ignored.
C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/Dxc.exe -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/DxcBho.dll -> Adware.SurfSide : Ignored.
C:\avenger\backup.zip/avenger/DeluxeCommunications/DxcCore.dll -> Adware.SurfSide : Ignored.
[1044] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
[796] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Ignored.
C:\Documents and Settings\Cory\INSTALL.0XE -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003595.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003627.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003713.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005823.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006100.exe -> Adware.Toolbar888 : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP8\A0006102.exe -> Adware.Toolbar888 : Ignored.
C:\WINDOWS\system32\INSTALL.0XE -> Adware.Toolbar888 : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{894F4911-02E8-4CDA-8A8D-BD7C0501E015}\teqe.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{B4ED9FDB-D6D1-46EF-96B9-C49FB34DDDEA}\kagaja.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{DE53ACA1-3744-4BC1-8AC8-50D867F3B9C2}\xutu.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\dexece.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\hudugu.exe -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\loho.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000002.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000019.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000024.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000042.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP2\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000051.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000188.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000193.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000211.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001193.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001207.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001213.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001231.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001255.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001271.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002255.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002274.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002304.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002322.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003321.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003322.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003354.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003370.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003372.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003389.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003391.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003407.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003424.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003460.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003487.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003494.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003520.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003539.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003559.exe -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003573.dll -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-1.DAT -> Adware.TTC : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\snapshot\MFEX-2.DAT -> Adware.TTC : Ignored.
C:\TTC.dll -> Adware.TTC : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\GLB19.tmp/empty_00000001 -> Adware.Ucmore : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b129.exe -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001258.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001259.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003462.dll -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003464.exe -> Adware.WebHancer : Ignored.
C:\WINDOWS\itpb_6.exe -> Adware.WebHancer : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001257.exe -> Adware.Webhancer.a : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar -> Adware.WebSearch : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar\all -> Adware.WebSearch : Ignored.
HKU\S-1-5-21-1214440339-261478967-725345543-1004\Software\ToolBar\all\History -> Adware.WebSearch : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003634.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\ZICORN003.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpes.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpex.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\kwinqpez.exe -> Adware.ZenoSearch : Ignored.
C:\WINDOWS\system32\opdsregn.exe -> Adware.ZenoSearch : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005925.exe -> Downloader.Agent.aaf : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\9.tmp -> Downloader.Agent.aox : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\F.tmp -> Downloader.Agent.aox : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000020.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP1\A0000041.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000187.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0000210.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001229.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0001270.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002276.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0002321.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003324.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003485.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP3\A0003517.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP4\A0003561.exe -> Downloader.Agent.bca : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005941.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005942.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005943.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005944.exe -> Downloader.Dyfuca.ey : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005945.exe -> Downloader.Dyfuca.ey : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\cln51.tmp -> Downloader.Dyfuca.ez : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\1.dlb -> Downloader.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\5.dlb -> Downloader.Small.cwj : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\MIGCONF2.0XE -> Downloader.Small.cyh : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005936.exe -> Downloader.Small.cyh : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\A3584.0XE -> Downloader.Small.dcj : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\WIN32.0XE -> Downloader.Tibs.if : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\6.dlb -> Downloader.Tibs.im : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\7.dlb -> Downloader.Tibs.im : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b103.exe -> Downloader.TSUpdate.o : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\b111.exe -> Downloader.VB.afa : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\1005_110.0XE -> Downloader.Zlob.avo : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\163.0XE -> Downloader.Zlob.avo : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN17.0XE -> Dropper.Agent.asr : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN14.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN18.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN2.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN3.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN4.0XE -> Dropper.Agent.atm : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\STDRUN19.0XE -> Dropper.Agent.mu : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\2.dlb -> Hijacker.Spywad.o : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005940.exe -> Hijacker.VB.ij : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\0DK1CDKV\ErrorSafeNewReleaseInstall[1].cab/UERS_9999_N91S2507NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\13.tmp -> Proxy.Agent.hd : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\B.tmp -> Proxy.Agent.hd : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@scrippshgtv.112.2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@atdmt[1].txt -> TrackingCookie.Atdmt : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@fastclick[2].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@pro-market[2].txt -> TrackingCookie.Pro-market : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@tacoda[1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Cory\Cookies\cory@trafficmp[2].txt -> TrackingCookie.Trafficmp : Ignored.
C:\Documents and Settings\Cory\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\{F79D750E-403F-4692-8E80-28EA35B87BA6}\TUQUSUPU.0XE -> Trojan.BHO.ab : Ignored.
C:\avenger\backup-Tue 02.13.2007-16.08.09.96.zip/avenger/321Studios/quhar.dll -> Trojan.BHO.ab : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\maxdd1.game -> Trojan.Dialer.ay : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\BUNDLEINSTALLER.0XE -> Trojan.LdPinch.atp : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\E5C18.tmp/t07grnpv.exe -> Trojan.Runner.j : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005946.exe -> Trojan.Runner.j : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\qvxt2.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\qvxt4.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\vx2.game -> Trojan.Small : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\vx3.game -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005937.vbs -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005938.exe -> Trojan.Small : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005939.vbs -> Trojan.Small : Ignored.
C:\avenger\backup-Mon 02.12.2007-13.32.53.23.zip/avenger/Ohrqm.exe -> Trojan.Small.cy : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\Setup100.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005926.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005927.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005928.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005929.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005930.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005931.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005932.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005933.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005934.exe -> Trojan.VB.tg : Ignored.
C:\System Volume Information\_restore{90284DB4-A71A-4FCD-8D5C-902C131B409E}\RP6\A0005935.exe -> Trojan.VB.tg : Ignored.
C:\Documents and Settings\Cory\Local Settings\Temp\ZGO.0XE -> Worm.Agent.v : Ignored.


::Report end
Download Look2Me-Destroyer.exe to your desktop.

* Close all windows before continuing.
* Double-click Look2Me-Destroyer.exe to run it.
* Put a check next to Run this program as a task.
* You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OK
* When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
* Once it's done scanning, click the Remove L2M button.
* You will receive a Done Scanning message, click OK.
* When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
* Your computer will then shutdown.
* Turn your computer back on.
* Please post the contents of Look2Me-Destroyer.txt and a new HiJackThis log. And the log from AVG
*use a new post for every log.

Run AVG-antispyware delete everything it finds then save the log.
I did everything you said to do on the look2me program the popup comes on saying that it will restart after 1 minute and then nothing happens… it doesnt restart???
Look2Me-Destroyer V1.0.12 Scanning for infected files….. Scan started at 2/14/2007 3:14:03 PM Infected! C:\WINDOWS\system32\auicap.dll Infected! C:\WINDOWS\system32\azaq03h5e.dll Infected! C:\WINDOWS\system32\cayptdlg.dll Infected! C:\WINDOWS\system32\cffview.dll Infected! C:\WINDOWS\system32\cqypt32.dll Infected! C:\WINDOWS\system32\csprops.dll Infected! C:\WINDOWS\system32\dlnet.dll Infected! C:\WINDOWS\system32\dmj8011ue.dll Infected! C:\WINDOWS\system32\dn4q01h5e.dll Infected! C:\WINDOWS\system32\dnj8011ue.dll Infected! C:\WINDOWS\system32\dnn6015se.dll Infected! C:\WINDOWS\system32\dSdramp.dll Infected! C:\WINDOWS\system32\dumclien.dll Infected! C:\WINDOWS\system32\e420lefm1h2a.dll Infected! C:\WINDOWS\system32\e8202ifmg82a2.dll Infected! C:\WINDOWS\system32\e820lifm182a.dll Infected! C:\WINDOWS\system32\en6sl1j71.dll Infected! C:\WINDOWS\system32\enp8l17u1.dll Infected! C:\WINDOWS\system32\enpol1731.dll Infected! C:\WINDOWS\system32\fp4q03h5e.dll Infected! C:\WINDOWS\system32\fp8403lqe.dll Infected! C:\WINDOWS\system32\fpj2031oe.dll Infected! C:\WINDOWS\system32\g6lm0g31e6.dll Infected! C:\WINDOWS\system32\h2n00c5mef.dll Infected! C:\WINDOWS\system32\h8j40i1qe8.dll Infected! C:\WINDOWS\system32\hpetcfg.dll Infected! C:\WINDOWS\system32\hr2q05f5e.dll Infected! C:\WINDOWS\system32\hrp0057me.dll Infected! C:\WINDOWS\system32\hrru0599e.dll Infected! C:\WINDOWS\system32\hz0605dse.dll Infected! C:\WINDOWS\system32\i206lcds1f06.dll Infected! C:\WINDOWS\system32\i2nmlc511f.dll Infected! C:\WINDOWS\system32\ilfgnt5.dll Infected! C:\WINDOWS\system32\ilxwan.dll Infected! C:\WINDOWS\system32\ir0ml5d11.dll Infected! C:\WINDOWS\system32\ir4sl5h71.dll Infected! C:\WINDOWS\system32\ir4ul5h91.dll Infected! C:\WINDOWS\system32\ir8ml5l11.dll Infected! C:\WINDOWS\system32\irn8l55u1.dll Infected! C:\WINDOWS\system32\itxrtmgr.dll Infected! C:\WINDOWS\system32\j2j6lc1s1f.dll Infected! C:\WINDOWS\system32\j2l40c3qef.dll Infected! C:\WINDOWS\system32\j86mlij118o.dll Infected! C:\WINDOWS\system32\jt4407hqe.dll Infected! C:\WINDOWS\system32\jtlm0731e.dll Infected! C:\WINDOWS\system32\k226lcfs1f26.dll Infected! C:\WINDOWS\system32\k4js0e17eh.dll Infected! C:\WINDOWS\system32\k4jsle171h.dll Infected! C:\WINDOWS\system32\kfdbu.dll Infected! C:\WINDOWS\system32\kfdvntc.dll Infected! C:\WINDOWS\system32\kvdmaori.dll Infected! C:\WINDOWS\system32\kxdintel.dll Infected! C:\WINDOWS\system32\kyddiv2.dll Infected! C:\WINDOWS\system32\kydno1.dll Infected! C:\WINDOWS\system32\l2p20c7oef.dll Infected! C:\WINDOWS\system32\l8p2li7o18.dll Infected! C:\WINDOWS\system32\lbrmonui.dll Infected! C:\WINDOWS\system32\lqasrv.dll Infected! C:\WINDOWS\system32\lv2209foe.dll Infected! C:\WINDOWS\system32\lv4u09h9e.dll Infected! C:\WINDOWS\system32\lv8q09l5e.dll Infected! C:\WINDOWS\system32\lvjo0913e.dll Infected! C:\WINDOWS\system32\lvnq0955e.dll Infected! C:\WINDOWS\system32\mbrdim.dll Infected! C:\WINDOWS\system32\mhbsync.dll Infected! C:\WINDOWS\system32\mhutilse.dll Infected! C:\WINDOWS\system32\moc42.dll Infected! C:\WINDOWS\system32\MTCTF.dll Infected! C:\WINDOWS\system32\mugina.dll Infected! C:\WINDOWS\system32\mvn0l95m1.dll Infected! C:\WINDOWS\system32\mvnol9531.dll Infected! C:\WINDOWS\system32\n2n60c5sef.dll Infected! C:\WINDOWS\system32\n68olgl316q.dll Infected! C:\WINDOWS\system32\nqdsapi.dll Infected! C:\WINDOWS\system32\nrptools.dll Infected! C:\WINDOWS\system32\o0840alqedqe0.dll Infected! C:\WINDOWS\system32\o248lchu1f48.dll Infected! C:\WINDOWS\system32\o284lclq1fqe.dll Infected! C:\WINDOWS\system32\o8nsli5718.dll Infected! C:\WINDOWS\system32\ofbccr32.dll Infected! C:\WINDOWS\system32\omjsel.dll Infected! C:\WINDOWS\system32\p2n8lc5u1f.dll Infected! C:\WINDOWS\system32\pnnppagn.dll Infected! C:\WINDOWS\system32\q0rq0a95ed.dll Infected! C:\WINDOWS\system32\q4860elsehq60.dll Infected! C:\WINDOWS\system32\q486lels1hq6.dll Infected! C:\WINDOWS\system32\q8680ijue8o80.dll Infected! C:\WINDOWS\system32\r2p8lc7u1f.dll Infected! C:\WINDOWS\system32\r8r60i9se8.dll Infected! C:\WINDOWS\system32\r8r6li9s18.dll Infected! C:\WINDOWS\system32\rXsauto.dll Infected! C:\WINDOWS\system32\sgredir.dll Infected! C:\WINDOWS\system32\shns.dll Infected! C:\WINDOWS\system32\skbiop.dll Infected! C:\WINDOWS\system32\slardssp.dll Infected! C:\WINDOWS\system32\t08u0al9edq.dll Infected! C:\WINDOWS\system32\txpmon.dll Infected! C:\WINDOWS\system32\wbpasf.dll Infected! C:\WINDOWS\system32\winotify.dll Infected! C:\WINDOWS\system32\wKvemsp.dll Infected! C:\WINDOWS\system32\wT583cfd.dll Attempting to delete infected files… Attempting to delete: C:\WINDOWS\system32\auicap.dll C:\WINDOWS\system32\auicap.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\azaq03h5e.dll C:\WINDOWS\system32\azaq03h5e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\cayptdlg.dll C:\WINDOWS\system32\cayptdlg.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\cffview.dll C:\WINDOWS\system32\cffview.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\cqypt32.dll C:\WINDOWS\system32\cqypt32.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\csprops.dll C:\WINDOWS\system32\csprops.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dlnet.dll C:\WINDOWS\system32\dlnet.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dmj8011ue.dll C:\WINDOWS\system32\dmj8011ue.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dn4q01h5e.dll C:\WINDOWS\system32\dn4q01h5e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dnj8011ue.dll C:\WINDOWS\system32\dnj8011ue.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dnn6015se.dll C:\WINDOWS\system32\dnn6015se.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dSdramp.dll C:\WINDOWS\system32\dSdramp.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\dumclien.dll C:\WINDOWS\system32\dumclien.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\e420lefm1h2a.dll C:\WINDOWS\system32\e420lefm1h2a.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\e8202ifmg82a2.dll C:\WINDOWS\system32\e8202ifmg82a2.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\e820lifm182a.dll C:\WINDOWS\system32\e820lifm182a.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\en6sl1j71.dll C:\WINDOWS\system32\en6sl1j71.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\enp8l17u1.dll C:\WINDOWS\system32\enp8l17u1.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\enpol1731.dll C:\WINDOWS\system32\enpol1731.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\fp4q03h5e.dll C:\WINDOWS\system32\fp4q03h5e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\fp8403lqe.dll C:\WINDOWS\system32\fp8403lqe.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\fpj2031oe.dll C:\WINDOWS\system32\fpj2031oe.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\g6lm0g31e6.dll C:\WINDOWS\system32\g6lm0g31e6.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\h2n00c5mef.dll C:\WINDOWS\system32\h2n00c5mef.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\h8j40i1qe8.dll C:\WINDOWS\system32\h8j40i1qe8.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\hpetcfg.dll C:\WINDOWS\system32\hpetcfg.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\hr2q05f5e.dll C:\WINDOWS\system32\hr2q05f5e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\hrp0057me.dll C:\WINDOWS\system32\hrp0057me.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\hrru0599e.dll C:\WINDOWS\system32\hrru0599e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\hz0605dse.dll C:\WINDOWS\system32\hz0605dse.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\i206lcds1f06.dll C:\WINDOWS\system32\i206lcds1f06.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\i2nmlc511f.dll C:\WINDOWS\system32\i2nmlc511f.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ilfgnt5.dll C:\WINDOWS\system32\ilfgnt5.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ilxwan.dll C:\WINDOWS\system32\ilxwan.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ir0ml5d11.dll C:\WINDOWS\system32\ir0ml5d11.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ir4sl5h71.dll C:\WINDOWS\system32\ir4sl5h71.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ir4ul5h91.dll C:\WINDOWS\system32\ir4ul5h91.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ir8ml5l11.dll C:\WINDOWS\system32\ir8ml5l11.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\irn8l55u1.dll C:\WINDOWS\system32\irn8l55u1.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\itxrtmgr.dll C:\WINDOWS\system32\itxrtmgr.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\j2j6lc1s1f.dll C:\WINDOWS\system32\j2j6lc1s1f.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\j2l40c3qef.dll C:\WINDOWS\system32\j2l40c3qef.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\j86mlij118o.dll C:\WINDOWS\system32\j86mlij118o.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\jt4407hqe.dll C:\WINDOWS\system32\jt4407hqe.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\jtlm0731e.dll C:\WINDOWS\system32\jtlm0731e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\k226lcfs1f26.dll C:\WINDOWS\system32\k226lcfs1f26.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\k4js0e17eh.dll C:\WINDOWS\system32\k4js0e17eh.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\k4jsle171h.dll C:\WINDOWS\system32\k4jsle171h.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kfdbu.dll C:\WINDOWS\system32\kfdbu.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kfdvntc.dll C:\WINDOWS\system32\kfdvntc.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kvdmaori.dll C:\WINDOWS\system32\kvdmaori.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kxdintel.dll C:\WINDOWS\system32\kxdintel.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kyddiv2.dll C:\WINDOWS\system32\kyddiv2.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\kydno1.dll C:\WINDOWS\system32\kydno1.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\l2p20c7oef.dll C:\WINDOWS\system32\l2p20c7oef.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\l8p2li7o18.dll C:\WINDOWS\system32\l8p2li7o18.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lbrmonui.dll C:\WINDOWS\system32\lbrmonui.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lqasrv.dll C:\WINDOWS\system32\lqasrv.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lv2209foe.dll C:\WINDOWS\system32\lv2209foe.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lv4u09h9e.dll C:\WINDOWS\system32\lv4u09h9e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lv8q09l5e.dll C:\WINDOWS\system32\lv8q09l5e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lvjo0913e.dll C:\WINDOWS\system32\lvjo0913e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\lvnq0955e.dll C:\WINDOWS\system32\lvnq0955e.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mbrdim.dll C:\WINDOWS\system32\mbrdim.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mhbsync.dll C:\WINDOWS\system32\mhbsync.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mhutilse.dll C:\WINDOWS\system32\mhutilse.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\moc42.dll C:\WINDOWS\system32\moc42.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\MTCTF.dll C:\WINDOWS\system32\MTCTF.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mugina.dll C:\WINDOWS\system32\mugina.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mvn0l95m1.dll C:\WINDOWS\system32\mvn0l95m1.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\mvnol9531.dll C:\WINDOWS\system32\mvnol9531.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\n2n60c5sef.dll C:\WINDOWS\system32\n2n60c5sef.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\n68olgl316q.dll C:\WINDOWS\system32\n68olgl316q.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\nqdsapi.dll C:\WINDOWS\system32\nqdsapi.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\nrptools.dll C:\WINDOWS\system32\nrptools.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\o0840alqedqe0.dll C:\WINDOWS\system32\o0840alqedqe0.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\o248lchu1f48.dll C:\WINDOWS\system32\o248lchu1f48.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\o284lclq1fqe.dll C:\WINDOWS\system32\o284lclq1fqe.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\o8nsli5718.dll C:\WINDOWS\system32\o8nsli5718.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\ofbccr32.dll C:\WINDOWS\system32\ofbccr32.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\omjsel.dll C:\WINDOWS\system32\omjsel.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\p2n8lc5u1f.dll C:\WINDOWS\system32\p2n8lc5u1f.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\pnnppagn.dll C:\WINDOWS\system32\pnnppagn.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\q0rq0a95ed.dll C:\WINDOWS\system32\q0rq0a95ed.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\q4860elsehq60.dll C:\WINDOWS\system32\q4860elsehq60.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\q486lels1hq6.dll C:\WINDOWS\system32\q486lels1hq6.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\q8680ijue8o80.dll C:\WINDOWS\system32\q8680ijue8o80.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\r2p8lc7u1f.dll C:\WINDOWS\system32\r2p8lc7u1f.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\r8r60i9se8.dll C:\WINDOWS\system32\r8r60i9se8.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\r8r6li9s18.dll C:\WINDOWS\system32\r8r6li9s18.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\rXsauto.dll C:\WINDOWS\system32\rXsauto.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\sgredir.dll C:\WINDOWS\system32\sgredir.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\shns.dll C:\WINDOWS\system32\shns.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\skbiop.dll C:\WINDOWS\system32\skbiop.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\slardssp.dll C:\WINDOWS\system32\slardssp.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\t08u0al9edq.dll C:\WINDOWS\system32\t08u0al9edq.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\txpmon.dll C:\WINDOWS\system32\txpmon.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\wbpasf.dll C:\WINDOWS\system32\wbpasf.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\winotify.dll C:\WINDOWS\system32\winotify.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\wKvemsp.dll C:\WINDOWS\system32\wKvemsp.dll Deleted successfully! Attempting to delete: C:\WINDOWS\system32\wT583cfd.dll C:\WINDOWS\system32\wT583cfd.dll Deleted successfully! Making registry repairs. Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E2C1BF0D-4235-43A4-BA6B-B29A5EEE7F2E}" HKCR\Clsid\{E2C1BF0D-4235-43A4-BA6B-B29A5EEE7F2E} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{791375A5-856B-4090-8BC5-ED50574AA820}" HKCR\Clsid\{791375A5-856B-4090-8BC5-ED50574AA820} Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3955C536-27B9-4F95-A660-FB913DEBCFDE}" HKCR\Clsid\{3955C536-27B9-4F95-A660-FB913DEBCFDE} Restoring Windows certificates. Replaced hosts file with default windows hosts file Restoring SeDebugPrivilege for Administrators - Succeeded
Logfile of HijackThis v1.99.1
Scan saved at 3:45:03 PM, on 2/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Cory\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…o&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.1.6
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NwCplMonitor] C:\WINDOWS\system32\redistributor.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\kwinqpem.exe CORN003
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Global Startup: dllhost.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra 'Tools' menuitem: Vegas Poker 247 - {E913D28B-4327-4f36-B303-D08ADF847142} - C:\Documents and Settings\Cory\Start Menu\Programs\Vegas Poker 247\Vegas Poker 247.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O20 - AppInit_DLLs: dxclib303562752.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Ok lets try this again click on Start, then Run and typecopy and paste the following in the Open: field:

C:\Program Files\DeluxeCommunications\Dxc.exe /u

and press the OK button

The DeluxeCommunications uninstall program will load and you will be asked to enter a security code. Enter the security code in the file and then press the OK button.

The uninstall process will then tell you that all browser windows will be closed if you continue. Press the Yes button to continue uninstalling DeluxeCommunications as shown in the figure below.

Finally, when it asks if you would to reboot, as shown in the image below, press the Yes button so that your computer reboots.

Download the FixDXC.reg from the following link and save it on your desktop.
FixDXC.reg Download Link

When the FixDCX.reg file has finished downloading double-click on the file. When it asks if you would like to add the information into the Registry, click on the Yes button and then on the OK button at next prompt..

Finally search for the following files. Make sure to search in hidden folders.

Dxcknwrd.dll
Dxccwrd.dll
dxclib303562752.dll


Scan with AVG anti-spyware. post the log from it and a new hijackthis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI