This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Various Problems

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sorry, I should have known to post that…

Logfile of HijackThis v1.99.1
Scan saved at 10:12:18 PM, on 4/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\svehost.exe
C:\Program Files\Common Files\{54DAEEE3-0958-1033-1202-030512200001}\Update.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\DOCUME~1\Daren\MYDOCU~1\ASEMBL~1\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\svchost.exe
C:\program files\internet explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\clcl3.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SYSTEM32\??crosoft.NET\??xplore.exe
C:\Documents and Settings\Daren\Desktop\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070414.dll start
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {04564BE0-A9C1-55D2-38CE-083ACCD5584C} - C:\WINDOWS\system32\bewjocj.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0a720914-a097-48c6-8fd4-0f233464d15e} - C:\WINDOWS\system32\iaslug.dll (file missing)
O2 - BHO: 0 - {160DD5FB-D94E-44BC-3D92-8AE3190ED903} - C:\Program Files\Movie Maker\qufaqydit.dll
O2 - BHO: (no name) - {195FF362-78F4-42DD-95FB-3858E8D1EBC0} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
O2 - BHO: (no name) - {1EED04C6-3AC2-40D1-8DB0-084DE72FE44A} - C:\WINDOWS\system32\psyistc.dll (file missing)
O2 - BHO: Helper Class - {33161E98-0A6C-4d3c-BD62-3A7D56137F52} - C:\WINDOWS\system32\mac.dll
O2 - BHO: (no name) - {3728B359-CB24-4A81-8F8C-EFA4ADC639B1} - C:\WINDOWS\system32\ssqpq.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6391AA39-14F4-3F20-F048-67E34CE4FAE9} - C:\WINDOWS\system32\qyjlbgc.dll
O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp616.tmp.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7842CAD9-10B6-4F6D-A2AF-C6C89C33ED0b} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
O2 - BHO: (no name) - {B360F286-C903-4236-953F-234151C2E5B8} - C:\Program Files\MSN\mesowic.dll
O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\byxvwuu.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [VaCtrls] v7
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\updater.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\yaayvw.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Ben] C:\WINDOWS\?icrosoft\?canregw.exe
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [qwqm] C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe
O4 - HKCU\..\Run: [Rpan] "C:\DOCUME~1\Daren\MYDOCU~1\ASEMBL~1\dllhost.exe" -vt yazb
O4 - HKCU\..\Run: [Qzy] C:\WINDOWS\SYSTEM32\??crosoft.NET\??xplore.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168893765694
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hi rnjholley


I see you are using "Azureus" for the duration of the fix please down load files from this site.

Note! that as long as you're using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur.
Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current malware infestation.
Additional information on the safety of Peer to Peer Networks is here : http://www.spywareinfo.com/articles/p2p/
You can also catch a list of tested P2P programs here:
http://p2p.malwareremoval.com/
____________

You may want to print these instructions for reference

We have a few malware processes and files which we need to get rid of.
Please be patient, and follow all of the instructions as given. Please do not reboot unless it is part
of the fix, or you have no other choice. While you are following the fix, you will find it helpful to have
a pen and paper handy to take any notes, so you can let me know what happens.
Typical information that will be helpful will be:
  • Files or folders that will not delete properly
  • Any errors that occur when following a fix or during bootup
  • Notes on your system's operation (sluggish internet, popups, etc)
  • The more information we have, the better our chances to clean your system!
Download ATF Cleaner by Atribune and save it to your Desktop.
Do not use yet!

Ewido is now known as ( AVG Anti-Spyware.)

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!

_______________


Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field.

C:\Program Files\Movie Maker\qufaqydit.dll
C:\WINDOWS\system32\winsys16_070414.dll
C:\Program Files\MSN\mesowic.dll

Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
____________


Next we need to stop a couple of processes that are running on your computer

To do this…
Startup HJT and select the 4th button entitled
Open the misc tools section

Under where it says system tools click on
Open process manager

Now look for the following processes one by one in the list below, once you find them highlight them then click on the
killl process
button

C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svehost.exe
C:\Program Files\Common Files\{54DAEEE3-0958-1033-1202-030512200001}\Update.exe
C:\Program Files\Ipwindows\ipwins.exe
C:\DOCUME~1\Daren\MYDOCU~1\ASEMBL~1\dllhost.exe
C:\WINDOWS\system32\clcl3.exe
C:\WINDOWS\SYSTEM32\??crosoft.NET\??xplore.exe
________________


Delete these programs
It may show two Instances of this:Outerinfo
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present). It could be that they have a space or something between it , but it has to look like it:

  • Outerinfo
    Outerinfo
    Ipwindows
    DeluxeCommunications
**Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.



Open notepad and copy and paste this text in it:

if exist "C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe" del /q "C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe"
copy /y "C:\Program Files\BELKIN USB Wireless Monitor\bak\InfoMyCa.exe" "C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe"
if exist "C:\Program Files\Dell Support\DSAgnt.exe" del /q "C:\Program Files\Dell Support\DSAgnt.exe"
copy /y "C:\Program Files\Dell Support\bak\DSAgnt.exe" "C:\Program Files\Dell Support\DSAgnt.exe"
if exist "C:\Program Files\DIGStream\digstream.exe" del /q "C:\Program Files\DIGStream\digstream.exe"
copy /y "C:\Program Files\DIGStream\bak\digstream.exe" "C:\Program Files\DIGStream\digstream.exe"
if exist "C:\Program Files\ESPNRunTime\DIGServices.exe" del /q "C:\Program Files\ESPNRunTime\DIGServices.exe"
copy /y "C:\Program Files\ESPNRunTime\bak\DIGServices.exe" "C:\Program Files\ESPNRunTime\DIGServices.exe"
if exist "C:\Program Files\iTunes\iTunesHelper.exe" del /q "C:\Program Files\iTunes\iTunesHelper.exe"
copy /y "C:\Program Files\iTunes\bak\iTunesHelper.exe" "C:\Program Files\iTunes\iTunesHelper.exe"
if exist "C:\Program Files\Messenger\msmsgs.exe" del /q "C:\Program Files\Messenger\msmsgs.exe"
copy /y "C:\Program Files\Messenger\bak\msmsgs.exe" "C:\Program Files\Messenger\msmsgs.exe"
if exist "C:\Program Files\QuickTime\qttask.exe" del /q "C:\Program Files\QuickTime\qttask.exe"
copy /y "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\QuickTime\qttask.exe"
if exist "C:\WINDOWS\SYSTEM32\igfxtray.exe" del /q "C:\WINDOWS\SYSTEM32\igfxtray.exe"
copy /y "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" "C:\WINDOWS\SYSTEM32\igfxtray.exe"
if exist "C:\Program Files\Analog Devices\Core\smax4pnp.exe" del /q "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
copy /y "C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe" "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
if exist "C:\WINDOWS\SYSTEM32\hkcmd.exe" del /q "C:\WINDOWS\SYSTEM32\hkcmd.exe"
copy /y "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" "C:\WINDOWS\SYSTEM32\hkcmd.exe"
if exist "C:\Program Files\Common Files\qwqm\qwqmm.exe" del /q "C:\Program Files\Common Files\qwqm\qwqmm.exe"
copy /y "C:\Program Files\Common Files\qwqm\qwqmm.exe" "C:\Program Files\Common Files\qwqm\qwqmm.exe"
if exist "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" del /q "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe"
copy /y "C:\Program Files\McAfee\SpamKiller\bak\MSKDetct.exe" "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe"
if exist "C:\Program Files\Real\RealPlayer\RealPlay.exe" del /q "C:\Program Files\Real\RealPlayer\RealPlay.exe"
copy /y "C:\Program Files\Real\RealPlayer\bak\RealPlay.ex" "C:\Program Files\Real\RealPlayer\RealPlay.exe"
if exist "C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe" del /q "C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe"
copy /y "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" "C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe"
if exist "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" del /q "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
copy /y "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
if exist "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" del /q "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
copy /y "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe" "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "

Save this as fixme.bat , choose to save it as *all files and place it on your desktop.
Doubleclick fixme.bat and post the content of the txtfile you get in your next reply together with a new hijackthislog.
Note! you will briefly see a dos screen then it will go off, this is normal.
please post me a new awf log

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)

  • R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
    O2 - BHO: (no name) - {04564BE0-A9C1-55D2-38CE-083ACCD5584C} - C:\WINDOWS\system32\bewjocj.dll (file missing)
    O2 - BHO: (no name) - {0a720914-a097-48c6-8fd4-0f233464d15e} - C:\WINDOWS\system32\iaslug.dll (file missing)
    O2 - BHO: (no name) - {195FF362-78F4-42DD-95FB-3858E8D1EBC0} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
    O2 - BHO: (no name) - {1EED04C6-3AC2-40D1-8DB0-084DE72FE44A} - C:\WINDOWS\system32\psyistc.dll (file missing)
    O2 - BHO: Helper Class - {33161E98-0A6C-4d3c-BD62-3A7D56137F52} - C:\WINDOWS\system32\mac.dll
    O2 - BHO: (no name) - {3728B359-CB24-4A81-8F8C-EFA4ADC639B1} - C:\WINDOWS\system32\ssqpq.dll (file missing)
    O2 - BHO: (no name) - {6391AA39-14F4-3F20-F048-67E34CE4FAE9} - C:\WINDOWS\system32\qyjlbgc.dll
    O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\tmp616.tmp.dll
    O2 - BHO: (no name) - {7842CAD9-10B6-4F6D-A2AF-C6C89C33ED0b} - C:\WINDOWS\system32\jfsvdcqn.dll (file missing)
    O2 - BHO: (no name) - {B9697716-61E6-4FBC-89FD-EAC504D9EFE3} - C:\WINDOWS\system32\byxvwuu.dll (file missing)
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
    O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\system32\rpcc.exe
    O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
    O4 - HKLM\..\Run: [VaCtrls] v7
    O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
    O4 - HKLM\..\Run: [clcl3] C:\WINDOWS\system32\clcl3.exe
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\updater.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
    O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\yaayvw.dll",realset
    O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
    O4 - HKCU\..\Run: [Ben] C:\WINDOWS\?icrosoft\?canregw.exe
    O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
    O4 - HKCU\..\Run: [qwqm] C:\PROGRA~1\COMMON~1\qwqm\qwqmm.exe
    O4 - HKCU\..\Run: [Rpan] "C:\DOCUME~1\Daren\MYDOCU~1\ASEMBL~1\dllhost.exe" -vt yazb
    O4 - HKCU\..\Run: [Qzy] C:\WINDOWS\SYSTEM32\??crosoft.NET\??xplore.exe
    WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit

    We need to reveal system folders
    • Close all programs so that you are at your desktop.
    • Double-click on the My Computer icon.
    • Select the Tools menu and click Folder Options
    • After the new window appears select the View tab.
    • Place a checkmark in the checkbox labeled Display the contents of system folders
    • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
    • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
    • Remove the checkmark from the checkbox labeled Hide protected operating system files
    • Press the Apply and then the ok button and shut down my computer
    • Now your computer is configured to show all hidden files.
    • For you and the tools to be able to see appropriate files we need to Show Hidden Files
    Re-boot into safe mode

    • Next, please reboot your computer in Safe Mode by doing the following:
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
    • Select the first option, to run Windows in Safe Mode hit enter.
    • For additional help in booting into Safe Mode, see the following site: HERE
    _____________

    Note! before you start file deletions This folder will have each "?" in it's name replaced by another character so you will need to be a little careful.
    Be sure that there is only one option - don't guess.
    Do not delete microsoft folder or microsoft.net folder

    C:\WINDOWS\?icrosoft <========This folder
    C:\WINDOWS\SYSTEM32\??crosoft.NET <========This folder
    Now continue
    _______________

    File deletions

    Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

    C:\WINDOWS\yaayvw.dll << This file
    C:\WINDOWS\updater.exe << This file
    C:\WINDOWS\system32\clcl3.exe << This file
    C:\WINDOWS\system32\rpcc.exe << This file
    C:\WINDOWS\system32\lsasss.exe << This file
    C:\WINDOWS\system32\svehost.exe << This file
    C:\WINDOWS\system32\jfsvdcqn.dll << This file
    C:\WINDOWS\system32\tmp616.tmp.dll << This file
    C:\WINDOWS\system32\qyjlbgc.dll << This file
    C:\WINDOWS\system32\ssqpq.dll << This file
    C:\WINDOWS\system32\mac.dll << This file
    C:\WINDOWS\system32\psyistc.dll << This file
    C:\WINDOWS\system32\jfsvdcqn.dll << This file
    C:\WINDOWS\system32\iaslug.dll << This file
    C:\WINDOWS\system32\bewjocj.dll << This file
    C:\DOCUME~1\Daren\MYDOCU~1\ASEMBL~1\dllhost.exe << This file
    C:\Program Files\DeluxeCommunications <========This folder
    C:\WINDOWS\?icrosoft <========This folder
    C:\Program Files\Ipwindows <========This folder
    C:\PROGRA~1\COMMON~1\qwqm <========This folder
    C:\WINDOWS\SYSTEM32\??crosoft.NET <========This folder

    _______________________

    Run ATF cleaner
    • Double click ATF-Cleaner.exe to run the program.
    • Check the following boxes:
      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Prefetch
      • Recycle Bin
      • Java Cache
    • The rest are optional - if you want to remove the lot, check Select All.
    • Now click Empty Selected.
    • When you get the Done Cleaning message, click OK.
    • If you use Firefox browser.
      • Click Firefox at the top and choose: Select All
      • If you would like to keep your saved passwords, please click No at the prompt.
      • Click the Empty Selected button.
    • If you use Opera browser.
      • Click Opera at the top and choose: Select All
      • If you would like to keep your saved passwords, please click No at the prompt.
      • Click the Empty Selected button.

    Run AVG Anti-Spyware

    Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
    • Click on Scanner on the toolbar.
    • Click on the Settings tab.
      • Under How to act?
        • Click on Recommended Action and choose Quarantine from the popup menu.
      • Under How to scan?
        • All checkboxes should be ticked.
      • Under Possibly unwanted software:
        • All checkboxes should be ticked.
      • Under Reports:
        • Select Automatically generate report after every scan and uncheck Only if threats were found.
      • Under What to scan?
        • Select Scan every file.
    • Click on the Scan tab.
    • Click on Complete System Scan to start the scan process.
    • Let the program scan the machine.
    • When the scan has finished, follow the instructions below.
      IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
      • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
      • At the bottom of the window click on the Apply all Actions button. (3)

        [external image: Posted Image]
    • When done, click the Save Scan Report button. (4)
      • Click the Save Report as button.
      • Save the report to your Desktop.
    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
    Reboot in Normal Mode.

    Please include new HJT log, AVG Anti-Spyware log and a new awf log
    in your next post
    Thanks dan
There were several instances where it asked for a new HJT log, but I figured you only needed the logs at the very end of all the steps performed. So here they are.

Jotti log..

—–
C:\Program Files\Movie Maker\qufaqydit.dll

qufaqydit.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 aca538c6d18c5a697dde3d3a280435ca
Packers detected: -

Scanner results
Scan taken on 27 Apr 2007 02:15:43 (GMT)
A-Squared Found nothing
AntiVir Found TR/BHO.AB.5
ArcaVir Found Trojan.Agent.Virut
Avast Found Win32:Small-AHY
AVG Antivirus Found Generic.YWA
BitDefender Found Adware.Zquest.B
ClamAV Found Trojan.Clicker-79
Dr.Web Found Trojan.StartPage.19992
F-Prot Antivirus Found W32/Trojan.AFAT
F-Secure Anti-Virus Found Trojan.Win32.BHO.ab
Fortinet Found W32/BHO.AB!tr
Kaspersky Anti-Virus Found Trojan.Win32.BHO.ab
NOD32 Found Win32/Adware.ZQuest application
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
VirusBuster Found Trojan.BHO.FF
VBA32 Found Application.Win32.Adware.ZQuest


——

C:\WINDOWS\system32\winsys16_070414.dll

winsys16_070414.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 dcd80600f17b368228e8bab6c52e97e4
Packers detected: -

Scanner results
Scan taken on 27 Apr 2007 02:19:24 (GMT)
A-Squared Found nothing
AntiVir Found TR/Spy.Agent.PN.229
ArcaVir Found nothing
Avast Found Win32:Delf-ECW
AVG Antivirus Found PSW.Generic3.WAD
BitDefender Found nothing
ClamAV Found Trojan.Spy-4884
Dr.Web Found Trojan.Hitpop
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found Trojan-Spy.Win32.Agent.pn
Fortinet Found W32/Delf.NDZ!tr.spy
Kaspersky Anti-Virus Found Trojan-Spy.Win32.Agent.pn
NOD32 Found a variant of Win32/Spy.Delf.NEN
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found Trojan.Clicker.Pophot.dw
VirusBuster Found nothing
VBA32 Found nothing

—–

C:\Program Files\MSN\mesowic.dll

mesowic.dll
Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 5772663a5a4092c208f543baed9f2e75
Packers detected: -

Scanner results
Scan taken on 27 Apr 2007 02:21:21 (GMT)
A-Squared Found nothing
AntiVir Found ADSPY/TTC.A.2
ArcaVir Found Adware.Ttc.A
Avast Found nothing
AVG Antivirus Found Generic2.GG
BitDefender Found Adware.TTC.A
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found not-a-virus:AdWare.Win32.TTC.a (4, 1, 400)
Fortinet Found nothing
Kaspersky Anti-Virus Found not-a-virus:AdWare.Win32.TTC.a
NOD32 Found nothing
Norman Virus Control Found W32/TTC.C
Panda Antivirus Found nothing
Rising Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


HJT log…

Logfile of HijackThis v1.99.1
Scan saved at 4:16:17 PM, on 4/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
C:\Program Files\BELKIN USB Wireless Monitor\WLanCfgG.exe
C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
C:\WINDOWS\system32\svchost.exe
C:\program files\internet explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\{54DAEEE3-0958-1033-1202-030512200001}\Update.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Documents and Settings\Daren\Desktop\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_070425.dll start
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {0a720914-a097-48c6-8fd4-0f233464d15e} - C:\WINDOWS\system32\ksphts.dll
O2 - BHO: 0 - {160DD5FB-D94E-44BC-3D92-8AE3190ED903} - C:\Program Files\Movie Maker\qufaqydit.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {B360F286-C903-4236-953F-234151C2E5B8} - C:\Program Files\MSN\mesowic.dll
O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\tmp29D.tmp.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Getca] C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\hggfeb.dll",realset
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Lqsc] "C:\Documents and Settings\Daren\Application Data\A?pPatch\m?hta.exe"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168893765694
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ksphts - C:\WINDOWS\SYSTEM32\ksphts.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Belkin 54Mbps Wireless USB Network Service (Belkin 54Mbps Wireless USB) - Unknown owner - C:\Program Files\BELKIN USB Wireless Monitor\WLService.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGFyZW4gSG9sbGV5\command.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

AVG>..

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:06:02 PM 4/27/2007

+ Scan result:



C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP188\A0025571.exe -> Downloader.Age : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\svchosts.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp117.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp17E.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp184.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1C3.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1C7.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1E3.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1F1.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1FB.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp23A.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp23E.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp24C.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp251.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp261.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp26B.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp29.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp290.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp2D0.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp41F.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp511.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp57.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp620.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp758.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpB7C.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpBE.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpD2.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpE8.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpFD.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0027821.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP203\A0028840.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0028794.exe -> Downloader.Agent.es : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0028795.exe -> Downloader.Agent.es : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1162OinAdmin.exe -> Downloader.PurityScan.dc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP178\A0023445.exe -> Downloader.PurityScan.dt : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\sdexe.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP188\A0025570.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0027822.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028850.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028852.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022429.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\WINDOWS\b104.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\1.exe -> Downloader.Small.bve : Cleaned with backup (quarantined).
C:\WINDOWS\1.exe -> Downloader.Small.bve : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\wpdtmmyx.exe -> Downloader.Small.cpg : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\cgalyxbh.exe -> Downloader.Small.cpg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022405.dll -> Downloader.Small.dxm : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028936.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028931.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028939.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028933.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022390.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
C:\WINDOWS\lcass.exe -> Downloader.VB.att : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\simpole.tlb -> Downloader.Zlob.xo : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ld108.tmp -> Downloader.Zlob.xq : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\v7.exe -> Hijacker.Agent.jc : Cleaned with backup (quarantined).
C:\Program Files\Analog Devices\Core\smax4pnp.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\Program Files\Analog Devices\Core\smax4pnp.exe1175711255 -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021703.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021704.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021705.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021706.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021707.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021708.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021709.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021710.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021711.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021712.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021713.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021714.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021715.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021716.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021717.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024518.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024519.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024520.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024521.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024522.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024523.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024524.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024525.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024526.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024527.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024528.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024529.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024530.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024531.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024532.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP181\A0024533.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP186\A0025512.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0027816.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028896.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028897.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028898.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028899.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028900.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028901.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028902.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028903.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028904.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028905.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028906.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028907.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028908.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028909.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028910.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028927.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\bak\lsasss.exe -> Hijacker.Agent.jh : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\NetworkService\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022411.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022400.dll -> Hijacker.Small.ja : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022401.exe -> Hijacker.Small.ja : Cleaned with backup (quarantined).
C:\WINDOWS\svchost.exe -> Logger.Agent.or : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026724.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP194\A0027684.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0027773.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP195\A0027792.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0028792.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028876.exe -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028877.scr -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028878.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028879.dll -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028880.scr -> Logger.Agent.pn : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Desktop\hjt\backups\backup-20070426-215903-240.dll -> Logger.Banker.cnb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028923.dll -> Logger.Banker.cnb : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\bak\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022427.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026647.dll -> Proxy.Small : Cleaned with backup (quarantined).
C:\VundoFix Backups\instcat.dll.bad -> Proxy.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\netfilter.dll -> Proxy.Small : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined).
[472] C:\WINDOWS\system32\netfilter.dll -> Proxy.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\DRIVERS\core.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP176\A0021701.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP186\A0025499.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP190\A0026623.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026651.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026653.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026713.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026714.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026715.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026716.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026717.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP193\A0026718.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP194\A0027503.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP194\A0027652.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028866.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028924.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\qomnlj.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\wvvuss.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\xxyvvt.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\drvmug.dll -> Trojan.Agent.qt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022420.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp115.tmp.exe -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpBB7.tmp.exe -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022368.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\snapshot\MFEX-2.DAT -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\snapshot\MFEX-3.DAT -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp115.tmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp2B4.tmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp428.tmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmpBB7.tmp.dll -> Trojan.BHO.g : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp110.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp189.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp1C6.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp218.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp275.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp2CD.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp2F.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp45.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp505.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp616.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp66.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp74C.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpC3.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmpEA.tmp.exe -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026650.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028929.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\VundoFix Backups\tmp189.tmp.dll.bad -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp110.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp1C6.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp218.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp275.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp2CD.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp2F.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp45.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp505.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp66.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp74C.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmpC3.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmpEA.tmp.dll -> Trojan.BHO.o : Cleaned with backup (quarantined).
C:\svhost.exe -> Trojan.Crypt.y : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026648.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\VundoFix Backups\jfsvdcqn.dll.bad -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\emubfsfa.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\hqvuctrb.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mbwapprp.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\nxpocnvo.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\xjaacwib.dll -> Trojan.Klone.j : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026645.dll -> Trojan.Obfuscated.ev : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026649.dll -> Trojan.Obfuscated.ev : Cleaned with backup (quarantined).
C:\VundoFix Backups\bewjocj.dll.bad -> Trojan.Obfuscated.ev : Cleaned with backup (quarantined).
C:\VundoFix Backups\psyistc.dll.bad -> Trojan.Obfuscated.ev : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0027817.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP200\A0027836.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028855.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp187.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp19D.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp2A0.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp2B4.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp425.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Daren\Local Settings\Temp\tmp428.tmp.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP177\A0022428.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP183\A0024556.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP188\A0025573.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP191\A0026666.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP196\A0027810.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP203\A0028813.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP204\A0028845.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\RGFyZW4gSG9sbGV5\l3IVtqb0m36Pv3pc.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld1191.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld14B2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld14DD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld14EE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld18AB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld1AE9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld1CA3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld1E4B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld1F50.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld2012.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld208A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld215D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld21A8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld22E5.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld24F7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld25CE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld2634.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld2879.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld28F7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld2B08.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld2CDA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld31C7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld324E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld335F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld352C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld355A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3651.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld36A5.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld37E8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3892.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3A6C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3ABA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3BD6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3D2A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3D51.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3D58.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3E8F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld3F6D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld40A2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld41D7.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4277.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld43E3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld444.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld46C1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld47E6.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld48CC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld49D9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4B04.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4BF2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4D22.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4F34.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld4F99.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5020.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld502A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5095.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld50FF.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld51DD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5237.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld538F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld53B5.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld54ED.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5567.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5619.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld575F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5776.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5808.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5827.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld588D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5906.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5AA0.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5CEA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5EA8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld5FEB.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6007.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6030.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6117.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6171.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6228.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld62F2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld633D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld63EC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6452.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6497.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld65FD.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6B44.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6E22.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld6F5F.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld739E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld747E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7553.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7735.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7C8B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7D79.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7DCA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld7F5A.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld807.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8114.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8213.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld83F8.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8402.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8407.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8408.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8760.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8841.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8896.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld89CE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld89DA.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8A0E.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8AFC.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8B55.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8CFE.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld8F5C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld924C.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld956B.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld98B1.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld98D3.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld995D.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld9AF2.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld9B70.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\1024\ld9DA6.tmp -> Trojan.Small : Cleaned with backup (quarantined).

AWF log…

Find AWF report by noahdfear ©2006


bak folders found
~~~~~~~~~~~


Directory of C:\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\BELKIN~1\BAK

03/10/2004 08:57 PM 45,056 InfoMyCa.exe
1 File(s) 45,056 bytes

Directory of C:\PROGRA~1\DIGSTR~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\ESPNRU~1\BAK

05/19/2005 01:55 PM 101,888 DIGServices.exe
1 File(s) 101,888 bytes

Directory of C:\PROGRA~1\ITUNES\BAK

03/02/2007 04:24 PM 257,088 iTunesHelper.exe
1 File(s) 257,088 bytes

Directory of C:\PROGRA~1\MESSEN~1\BAK

10/13/2004 11:24 AM 1,694,208 msmsgs.exe
1 File(s) 1,694,208 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

02/16/2007 11:54 AM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\WINDOWS\SYSTEM32\BAK

08/20/2004 04:51 PM 118,784 hkcmd.exe
08/20/2004 04:55 PM 155,648 igfxtray.exe
2 File(s) 274,432 bytes

Directory of C:\PROGRA~1\ANALOG~1\CORE\BAK

10/14/2004 04:42 PM 1,404,928 smax4pnp.exe
1 File(s) 1,404,928 bytes

Directory of C:\PROGRA~1\MCAFEE\SPAMKI~1\BAK

08/03/2004 06:18 PM 1,083,392 MSKDetct.exe
1 File(s) 1,083,392 bytes

Directory of C:\PROGRA~1\REAL\REALPL~1\BAK

02/08/2005 11:59 PM 26,112 RealPlay.exe
1 File(s) 26,112 bytes

Directory of C:\WINDOWS\SYSTEM32\DLA\BAK

08/13/2004 02:05 AM 122,939 tfswctrl.exe
1 File(s) 122,939 bytes

Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK

01/07/2004 02:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK

12/15/2006 04:23 AM 75,520 jusched.exe
1 File(s) 75,520 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

45056 Mar 10 2004 "C:\Program Files\BELKIN USB Wireless Monitor\InfoMyCa.exe"
45056 Mar 10 2004 "C:\Program Files\BELKIN USB Wireless Monitor\bak\InfoMyCa.exe"
101888 May 19 2005 "C:\Program Files\ESPNRunTime\DIGServices.exe"
101888 May 19 2005 "C:\Program Files\ESPNRunTime\bak\DIGServices.exe"
257088 Mar 2 2007 "C:\Program Files\iTunes\iTunesHelper.exe"
257088 Mar 2 2007 "C:\Program Files\iTunes\bak\iTunesHelper.exe"
102400 Mar 14 2007 "C:\WINDOWS\Installer\{01B51908-02EF-453B-87A9-815182E8C2F2}\iTunesIco.exe"
116288 Mar 14 2007 "C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.1.0.59\iTunesSetupAdmin.exe"
1694208 Oct 13 2004 "C:\Program Files\Messenger\msmsgs.exe"
1694208 Oct 13 2004 "C:\Program Files\Messenger\bak\msmsgs.exe"
1694208 Oct 13 2004 "C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe"
282624 Feb 16 2007 "C:\Program Files\QuickTime\qttask.exe"
282624 Feb 16 2007 "C:\Program Files\QuickTime\bak\qttask.exe"
118784 Aug 20 2004 "C:\DRIVERS\VIDEO\HKCMD.EXE"
118784 Aug 20 2004 "C:\WINDOWS\SYSTEM32\hkcmd.exe"
118784 Aug 20 2004 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
155648 Aug 20 2004 "C:\DRIVERS\VIDEO\IGFXTRAY.EXE"
155648 Aug 20 2004 "C:\WINDOWS\SYSTEM32\igfxtray.exe"
155648 Aug 20 2004 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
1404928 Oct 14 2004 "C:\DRIVERS\AUDIO\SMAX4PNP.EXE"
1404928 Oct 14 2004 "C:\Program Files\Analog Devices\Core\bak\smax4pnp.exe"
1083392 Aug 3 2004 "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe"
1083392 Aug 3 2004 "C:\Program Files\McAfee\SpamKiller\bak\MSKDetct.exe"
26112 Feb 8 2005 "C:\Program Files\Real\RealPlayer\bak\RealPlay.exe"
122939 Aug 13 2004 "C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe"
122939 Aug 13 2004 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe"
122939 Aug 13 2004 "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe"
110592 Jan 7 2004 "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe"
110592 Jan 7 2004 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
32881 Nov 19 2003 "C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
75520 Dec 15 2006 "C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe"


end of report


Hope all of this is right. Please advise if it isn't. I REALLY owe you one.

There were several instances where it asked for a new HJT log, but I figured you only needed the logs at the very end of all the steps performed. So here they are.


Yes you did exactly right.
I try to get my posts out to users on a quick turn around If I'm able, and some times little things slip by me like that.

Will make a start on your returned logs then I have to put it by my tutor.
so would Imagine it will be at some point tomorrow when I get back to you.
Thanks dan
Hi, my apology I had a few net problems myself please let me know if you still need help. If so can I see a new HJT log as it's been a while since your last one. Thanks dan
Due to inactivity, this topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI