This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Awaiting Assistance

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

damnit no matter how safe you try to be. they always get you

here's my HJT log:



Logfile of HijackThis v1.99.1
Scan saved at 11:33:02 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: 0 - {03CAEAA9-1EF9-49F9-D488-A405D751EDF3} - C:\Program Files\Messenger\qulazu.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\qlmodrfo.dll (file missing)
O2 - BHO: (no name) - {3F9D0C61-737D-44D1-BD80-91AF857061CC} - C:\WINDOWS\system32\yayabay.dll
O2 - BHO: (no name) - {48D4E1E3-9FD7-4653-B757-CC33078E3D14} - C:\Program Files\Windows Media Player\mezo.dll
O2 - BHO: (no name) - {67D6CCC9-42B9-4D1A-B437-E0508625B31A} - C:\WINDOWS\system32\ssqpm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: ssqpm - C:\WINDOWS\system32\ssqpm.dll
O20 - Winlogon Notify: yayabay - C:\WINDOWS\SYSTEM32\yayabay.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Hi YoungBruce,

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • A log file will be created at C:\vundofix.txt, please post the contents of this in your next response.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Next, move HijackThis from the desktop to it's own folder:
  • Open My Computer, navigate to C:\ and make a new folder named HJT
  • Move the HijackThis.exe program file from your desktop to C:\HJT
  • If you wish to place a shortcut to HijackThis on your desktop, then right-click hijackthis.exe, select Send To and choose Desktop (create shortcut)
Once complete, please post the VundoFix log along with a new HijackThis log.
here is the HJT log:




Logfile of HijackThis v1.99.1
Scan saved at 1:18:07 AM, on 4/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\HJT\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: 0 - {03CAEAA9-1EF9-49F9-D488-A405D751EDF3} - C:\Program Files\Messenger\qulazu.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\qlmodrfo.dll (file missing)
O2 - BHO: (no name) - {48D4E1E3-9FD7-4653-B757-CC33078E3D14} - C:\Program Files\Windows Media Player\mezo.dll
O2 - BHO: (no name) - {6DFEB79F-6BE4-48A2-B6F5-DF7FA605E46F} - C:\WINDOWS\system32\ssqpm.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sxload.net (HKLM)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe




and here is the VundoFix log:



VundoFix V6.3.20

Checking Java version…

Java version is 1.5.0.10

Scan started at 1:04:38 AM 4/25/2007

Listing files found while scanning….

C:\WINDOWS\system32\awttsss.dll
C:\WINDOWS\system32\awvvu.dll
C:\WINDOWS\system32\criwflux.dll
C:\WINDOWS\system32\ddcabxw.dll
C:\WINDOWS\system32\jkkjiih.dll
C:\WINDOWS\system32\khfddef.dll
C:\WINDOWS\system32\mkvkndgj.dll
C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\nnnklkk.dll
C:\WINDOWS\system32\pgsnbvej.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\tuvvttr.dll
C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\yayabay.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\awttsss.dll
C:\WINDOWS\system32\awttsss.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awvvu.dll
C:\WINDOWS\system32\awvvu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\criwflux.dll
C:\WINDOWS\system32\criwflux.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddcabxw.dll
C:\WINDOWS\system32\ddcabxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\jkkjiih.dll
C:\WINDOWS\system32\jkkjiih.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\khfddef.dll
C:\WINDOWS\system32\khfddef.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mkvkndgj.dll
C:\WINDOWS\system32\mkvkndgj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\mpqss.bak1
C:\WINDOWS\system32\mpqss.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnklkk.dll
C:\WINDOWS\system32\nnnklkk.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pgsnbvej.dll
C:\WINDOWS\system32\pgsnbvej.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqpm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvvttr.dll
C:\WINDOWS\system32\tuvvttr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\vtsqn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayabay.dll
C:\WINDOWS\system32\yayabay.dll Has been deleted!

Performing Repairs to the registry.
Done!
Hi YoungBruce,

I note you now have a program called New.net in your HijackThis log. Did you know this was installed and did you do it purposefully? This program is not malware, but has been linked with instability and is considered very undesirable. Unless you are sure you want it, I recommend you remove it. To do so, please follow the instructions colored olive.

Please download LSPFix.exe from here:
http://www.cexx.org/lspfix.htm
Do NOT run this program. This is only to be used if you lose Internet Access after removing NewDotNet.

Next, press Start > Control Panel > Add or Remove Programs, and remove the following:

New.Net Applications, New.Net Domains or any entry with the word New.Net

If you don't see anything listed that says New.Net, then we have to use a different method of removal:
open the following link: http://www.newdotnet.com/removal.html, and follow Procedure 4: NewDotNet
Caution: If you removed New.Net in Add/Remove Programs then you do not need to use this link

Removal of ~New.Net by either method can in some cases cause a loss in internet access. In the event that this has now happened, please double-click LSPFix.exe that you downloaded earlier. You will see 2 panels. If there is any file listed in the Remove panel on the right-side, leave it as is and just click Finish>> then reboot your computer and you should now have access to the Internet.. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. You will need to use another computer to come back here for further instructions on what to do.


You also have Viewpoint Media Player installed on your system. This program is not malware but it is foistware in that it is usually installed without the user's knowledge or approval, and for this reason I recommend you remove it. If you actually use this program, I recommend you try using alternatives such as VLC Player or Media Player Classic.
To remove, open Start->Control Panel->Add/Remove Programs find Viewpoint Media Player and select Uninstall

Temporarily disable Windows Defender:
  • Right-click on the Windows Defender icon in the system tray [it's the one with the red and yellow bulls-eye]
  • Click on Security Agents Status
  • Click on Disable real-time protection.
  • Next right-click on the Windows Defender icon in the system tray again to open the program
  • Click on the Options menu and choose Settings
  • In the left pane column click on Real Time Protection
  • Under Startup Options, uncheck Enable Security Agents on startup (recommended)
  • Under Real-time spyware threat protection, uncheck Enable real-time spyware threat protection (recommended)
  • Click the Save button and close Microsoft AntiSpyware
  • Finally, right-click on the Windows Defender icon in the system tray and select Shutdown Windows Defender
Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines (if present):
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\qlmodrfo.dll (file missing)
O2 - BHO: (no name) - {6DFEB79F-6BE4-48A2-B6F5-DF7FA605E46F} - C:\WINDOWS\system32\ssqpm.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


IP addresses for auto.search.msn.com and auto.search.msn.es have been manually added to your hosts file, unless you or the administrator of this machine knowingly made these changes, then also place checkmarks next to these lines:
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es


You have a website called sxload.net in your Internet Explorer Trusted Zone. Websites in your Trusted Zone have much lower security settings than normal, so unless you are sure you completely trust this site, then also place a checkmark next to this line:
O15 - Trusted Zone: *.sxload.net (HKLM)

Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Next, please upload some suspect files for testing:
Open http://virusscan.jotti.org/
Copy/paste this file and path into the white box at the top:
C:\Program Files\Messenger\qulazu.dll
Press Submit - this will submit the file for testing.
Please copy and paste the results in your next response.
Then repeat the process for:
C:\Program Files\Windows Media Player\mezo.dll

Next, please do an online scan with Kaspersky:

Open Kaspersky Online Scanner in Internet Explorer

You will be prompted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT and then Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • The program will start to scan your system.
  • Once the scan is complete, click on the Save as Text button and save the file to your desktop
Now open HijackThis, select Open the Misc Tools section
Press the Open Uninstall Manager… button, then press Save list…
Save the Uninstall log to your deskop and include a copy in your next response.
Now press Back and Scan and then Save log to create and save a new HijackThis log.

Once complete, please post the Jotti results, the Kaspersky log and the uninstall log along with a new HijackThis log. Also, let me know if you had any difficulty with the uninstalls.
here are the online file results

mezo.dll results:

Scan taken on 26 Apr 2007 04:11:45 (GMT)
A-Squared
Found nothing
AntiVir
Found ADSPY/TTC.A.2
ArcaVir
Found Adware.Ttc.A
Avast
Found nothing
AVG Antivirus
Found Generic2.GG
BitDefender
Found Adware.TTC.A
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found not-a-virus:AdWare.Win32.TTC.a (4, 1, 400)
Fortinet
Found nothing
Kaspersky Anti-Virus
Found not-a-virus:AdWare.Win32.TTC.a
NOD32
Found nothing
Norman Virus Control
Found W32/TTC.C
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing



qulazu.dll results:

A-Squared
Found nothing
AntiVir
Found HEUR/Malware
ArcaVir
Found Trojan.Bho.Ab
Avast
Found Win32:Small-AHY
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found Trojan.Clicker-79
Dr.Web
Found Trojan.StartPage.19992
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found Trojan.Win32.BHO.ab
Fortinet
Found nothing
Kaspersky Anti-Virus
Found Trojan.Win32.BHO.ab
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found Trojan.StartPage.117 (paranoid heuristics) (probable variant)




here are the uninstall results

4U WMA MP3 Converter 5.9.2
Ad-Aware SE Professional
Adobe Acrobat 6.0 Professional
Adobe Flash Player 9 ActiveX
Adobe Illustrator CS2
Adobe Photoshop CS2
Adobe Shockwave Player
Adobe SVG Viewer 3.0
AIM 6.0
Apple Software Update
ArcSoft Media Card Companion
ArcSoft MediaConverter
ArcSoft PhotoImpression 5
AVG 7.5
Azureus
BodyTrans
BodyTrans Tablet PC Support Files
BSPlayer
CDisplay 1.8
ConvertXtoDVD 2.0.12
DC++ 0.699
DV Ts
Fantastic Flame Screensaver
Gaim (remove only)
GTK+ Runtime 2.6.9 rev a (remove only)
Hamachi 1.0.1.5
HighMAT Extension to Microsoft Windows XP CD Writing Wizard
HijackThis 1.99.1
Hotfix for MSXML 2 (KB887606)
Hotfix for Windows XP (KB319740)
Hotfix for Windows XP (KB889527)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB897338)
Hotfix for Windows XP (KB898900)
Hotfix for Windows XP (KB903234)
Hotfix for Windows XP (KB904412)
Hotfix for Windows XP (KB906569)
Hotfix for Windows XP (KB907865)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB912461)
Hotfix for Windows XP (KB912817)
Hotfix for Windows XP (KB913538)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB917021)
Hotfix for Windows XP (KB918005)
Hotfix for Windows XP (KB918093)
Hotfix for Windows XP (KB918766)
Hotfix for Windows XP (KB918997)
Hotfix for Windows XP (KB919071)
Hotfix for Windows XP (KB924867)
Hotfix for Windows XP (KB924941)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB927544)
Hotfix for Windows XP (KB928388)
ICopyDVDs2 3.2.2
ID3-TagIT 3
Image Resizer Powertoy for Windows XP
Intel Application Accelerator
Intel® Extreme Graphics Driver
Intel® PRO Network Adapters and Drivers
Intel® PROSet
InterActual Player
iTunes
J2SE Runtime Environment 5.0 Update 10
Kaspersky Online Scanner
LimeWire PRO 4.13.0
MaxBlast 4
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Windows Journal Viewer
mIRC
Mozilla Firefox (2.0.0.3)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 6.0 Parser (KB927977)
muvee autoProducer 4.1
Nero 7 Ultra Edition
PowerDVD
QuickTime
RealPlayer
Realtek AC'97 Audio
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917537)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB929969)
SHOUTcast Source DSP 1.9.0 (remove only)
SoulSeek Client 156c
Sunbelt Kerio Personal Firewall
Ultra soft
Update for Windows XP (KB896256)
Update for Windows XP (KB897663)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB907265)
Update for Windows XP (KB908521)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB916846)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922120)
Update for Windows XP (KB922582)
Update for Windows XP (KB925876)
Verizon Online
Verizon Online DSL
VideoLAN VLC media player 0.8.6
Virtual DJ - Atomix Productions
Western Australian Time Zone Update
Winamp (remove only)
Windows Communication Foundation
Windows Defender
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Hotfix - KB895181
Windows Media Player 11
Windows Media Player 11
Windows PowerShell™ 1.0
Windows Presentation Foundation
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB884020
Windows XP Hotfix - KB884883
Windows XP Hotfix - KB885222
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB886677
Windows XP Hotfix - KB886716
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB889673
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB894395
Windows XP Hotfix - KB896626
WinRAR archiver
XP Codec Pack



and here is the HJT log

Logfile of HijackThis v1.99.1
Scan saved at 12:45:52 AM, on 4/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\program files\aim6\anotify.exe
C:\HJT\HijackThis.exe

O2 - BHO: 0 - {03CAEAA9-1EF9-49F9-D488-A405D751EDF3} - C:\Program Files\Messenger\qulazu.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {48D4E1E3-9FD7-4653-B757-CC33078E3D14} - C:\Program Files\Windows Media Player\mezo.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
i forgot to add the kaspersky results, here they go: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Friday, April 27, 2007 5:10:59 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 27/04/2007 Kaspersky Anti-Virus database records: 304177 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 78309 Number of viruses found: 22 Number of infected objects: 347 / 0 Number of suspicious objects: 0 Duration of the scan process: 02:45:12 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator\Application Data\Azureus\ipfilter.cache Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3433.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3434.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3435.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3436.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3437.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU3438.tmp Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\cert8.db Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\history.dat Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\key3.db Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\parent.lock Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\search.sqlite Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip/BaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip/VaaaaaaaBaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip/Baaaaa.class Infected: Trojan.Java.ClassLoader.ao skipped C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip ZIP: infected - 3 skipped C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Desktop\NNuninstall.exe Infected: not-a-virus:AdWare.Win32.NewDotNet.e skipped C:\Documents and Settings\Administrator\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Administrator\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\81guvdl7.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\MSHist012007042720070428\index.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temp\hsperfdata_Administrator\552 Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temp\NeroDemo12065\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped C:\Documents and Settings\Administrator\Local Settings\Temp\Perflib_Perfdata_6d0.dat Object is locked skipped C:\Documents and Settings\Administrator\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe/Stream/data0005 Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\Documents and Settings\Administrator\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe/Stream Infected: not-a-virus:Downloader.Win32.WinFixer.t skipped C:\Documents and Settings\Administrator\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe Inno: infected - 2 skipped C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Azureus Downloads\SuperFoot Bill Wallace Pro Stretching\Superfoot Bill Wallace Pro Stretching.avi Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Azureus Downloads\Thundercats\Season 0147 - Good And Ugly.m4v Object is locked skipped C:\Documents and Settings\Administrator\My Documents\Azureus Downloads\Thundercats\Season 0279 - Mad Bubbler.m4v Object is locked skipped C:\Documents and Settings\Administrator\ntuser.dat Object is locked skipped C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-04222007-030817.log Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\Messenger\qulazu.dll Infected: Trojan.Win32.BHO.ab skipped C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped C:\Program Files\Windows Media Player\mezo.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\Program Files\Windows Media Player\TTC.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\A0063523.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\A0063525.dll Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\A0063724.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\A0063724.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot\MFEX-4.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot\MFEX-5.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot\MFEX-6.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot\MFEX-7.DAT Infected: Trojan.Win32.BHO.g skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP233\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP234\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP235\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP236\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP237\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP238\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP239\A0064027.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP239\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064222.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064242.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064242.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064255.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064282.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064297.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064297.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064309.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064348.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064348.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064358.exe Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064384.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064398.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064398.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064399.exe Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064401.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064416.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP244\A0064416.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064430.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064431.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064444.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064444.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064445.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064452.exe Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064453.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064455.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064456.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064457.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064458.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064459.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064460.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064461.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064462.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064464.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064465.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064488.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\A0064488.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP246\A0064568.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP246\A0064568.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP247\A0064588.dll Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP247\A0064603.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP247\A0064603.exe NSIS: infected - 1 skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP247\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP248\change.log Object is locked skipped C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP248\snapshot\MFEX-1.DAT Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\VundoFix Backups\awttsss.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\criwflux.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped C:\VundoFix Backups\ddcabxw.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\jkkjiih.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\khfddef.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\mkvkndgj.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped C:\VundoFix Backups\nnnklkk.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\pgsnbvej.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.hb skipped C:\VundoFix Backups\ssqpm.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\VundoFix Backups\tuvvttr.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\VundoFix Backups\yayabay.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.il skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{573D79BC-B145-4C9C-8B33-2A39FFE59C97}.crmlog Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\awtqo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\awtsp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\WINDOWS\system32\awtsr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\awvtt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\awvtu.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fl skipped C:\WINDOWS\system32\awvvt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ig skipped C:\WINDOWS\system32\bund1\ClientBundle1.exe/data0002 Infected: not-a-virus:AdWare.Win32.NewDotNet skipped C:\WINDOWS\system32\bund1\ClientBundle1.exe/data0003 Infected: Trojan.Win32.BHO.ab skipped C:\WINDOWS\system32\bund1\ClientBundle1.exe/data0004 Infected: not-a-virus:AdWare.Win32.SurfSide.ax skipped C:\WINDOWS\system32\bund1\ClientBundle1.exe/data0005 Infected: Trojan-Dropper.Win32.Agent.bfr skipped C:\WINDOWS\system32\bund1\ClientBundle1.exe NSIS: infected - 4 skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\WindowsPowerShell.evt Object is locked skipped C:\WINDOWS\system32\ddaba.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ddabb.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ddabc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ddayw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ddccd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ddcya.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\gebcc.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\gebcy.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\gebyw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\gebyx.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\WINDOWS\system32\geeba.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ig skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\jkhfd.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\jkhhh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped C:\WINDOWS\system32\jkkjk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\jkkll.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\micro1\f4.exe Infected: not-a-virus:AdWare.Win32.SurfSide.ax skipped C:\WINDOWS\system32\mljgg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\mljjh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\mljjj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\mllmm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped C:\WINDOWS\system32\pmkhg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\pmkjg.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\pmkji.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\pmnlm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ig skipped C:\WINDOWS\system32\pmnnl.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\pmnnm.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ssqpq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ssqro.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ssqrq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\sstqo.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\sstqp.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\ssttt.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\vtstq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ig skipped C:\WINDOWS\system32\vtutq.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\vtutr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.iu skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\xlibgfl254.dll Infected: Trojan-Downloader.Win32.Agent.bfj skipped C:\WINDOWS\VTTC.exe/data0004 Infected: not-a-virus:AdWare.Win32.TTC.a skipped C:\WINDOWS\VTTC.exe NSIS: infected - 1 skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped F:\urcrazyclone\Programs & Apps\Scripts\DS\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\DS.zip/DS/mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\DS.zip ZIP: infected - 1 skipped F:\urcrazyclone\Programs & Apps\Scripts\GuarDDog\mirc_GuarDDogv.4.4.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\GuarDDog4-1.4LITE.zip/GuarDDog/mirc_GuarDDogv.4.4.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\GuarDDog4-1.4LITE.zip ZIP: infected - 1 skipped F:\urcrazyclone\Programs & Apps\Scripts\setup.exe/ci-temp0.cab/PCStats/DLL/Procs.dll Infected: not-a-virus:RiskTool.Win32.PsKill.b skipped F:\urcrazyclone\Programs & Apps\Scripts\setup.exe/ci-temp0.cab/mIRC.EXE Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\setup.exe/ci-temp0.cab Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\setup.exe CreateInstall: infected - 3 skipped F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip/setup.exe/ci-temp0.cab/PCStats/DLL/Procs.dll Infected: not-a-virus:RiskTool.Win32.PsKill.b skipped F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip/setup.exe/ci-temp0.cab/mIRC.EXE Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip/setup.exe/ci-temp0.cab Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip/setup.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip ZIP: infected - 4 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/idents.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/channel.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/events.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/dialog1.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/dialog3.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip/sys/events2.ini Infected: Flooder.IRC.Extreme.821 skipped F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip ZIP: infected - 6 skipped Scan process completed.
Hi YoungBruce,

There's quite a lot in this post, so I recommend you have a read through before starting and if anything is unclear or you have any trouble with the instructions, please stop and let me know.

First please open Start->Control Panel->Add/Remove Programs once more, we have some more uninstalls to consider:

Please remove BSPlayer because this program comes bundled with adware. If you use it, I recommend you try the safe alternatives to Viewpoint player which were VLC Player and Media Player Classic.

There are a couple of programs I couldn't find out anything much about - DV Ts and Ultra soft. Do you know what these programs are and did you willingly install them?

You have several peer-to-peer programs installed on your computer. The programs you have do not come bundled with malware as some similar programs do, but P2P file sharing networks are one of the biggest sources of malware we see. Anything downloaded from them cannot be trusted to be clean, because even if the file appears to be what it claims to be, it can have malware embedded in it.
I recommend you remove it, but of course the choice is yours. You can remove Azureus, Limewire and SoulSeek via Add/Remove Programs.

Then, open HijackThis, choose Do a system scan only and place a checkmark next to the following lines (if present):
O2 - BHO: 0 - {03CAEAA9-1EF9-49F9-D488-A405D751EDF3} - C:\Program Files\Messenger\qulazu.dll
O2 - BHO: (no name) - {48D4E1E3-9FD7-4653-B757-CC33078E3D14} - C:\Program Files\Windows Media Player\mezo.dll


Then close all open windows apart from HijackThis, press Fix checked, OK the prompt and close HijackThis.

Download OTMoveIt to your desktop. and double-click the program to start it.
Select the contents of the below file list, then press Ctrl+C to copy it to the clipboard
In OTMoveIt, click in the left-hand pane and press Ctrl+V to paste the file-list into the program
Then, press MoveIt!
Copy the Results output and paste it into a new notepad file so you can post it in your next response. Do this by clicking in the right-hand pane, press Ctrl-A then Ctrl-C to select all and copy. Then open Notepad, press Ctrl-V to paste in the text, and save this text file to your desktop.

OTMoveIt file list:
C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip
C:\Documents and Settings\Administrator\Desktop\NNuninstall.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\NeroDemo12065\Toolbar.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe
C:\Program Files\Messenger\qulazu.dll
C:\Program Files\Windows Media Player\mezo.dll
C:\Program Files\Windows Media Player\TTC.dll
C:\WINDOWS\system32\awtqo.dll 
C:\WINDOWS\system32\awtsp.dll 
C:\WINDOWS\system32\awtsr.dll
C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\awvtu.dll 
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\bund1\ClientBundle1.exe
C:\WINDOWS\system32\ddaba.dll 
C:\WINDOWS\system32\ddabb.dll 
C:\WINDOWS\system32\ddabc.dll 
C:\WINDOWS\system32\ddayw.dll 
C:\WINDOWS\system32\ddccd.dll 
C:\WINDOWS\system32\ddcya.dll 
C:\WINDOWS\system32\gebcc.dll 
C:\WINDOWS\system32\gebcy.dll 
C:\WINDOWS\system32\gebyw.dll 
C:\WINDOWS\system32\gebyx.dll 
C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\jkhfd.dll 
C:\WINDOWS\system32\jkhhh.dll 
C:\WINDOWS\system32\jkkjk.dll 
C:\WINDOWS\system32\jkkll.dll 
C:\WINDOWS\system32\micro1\f4.exe 
C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljjh.dll
C:\WINDOWS\system32\mljjj.dll 
C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\pmkhg.dll 
C:\WINDOWS\system32\pmkjg.dll 
C:\WINDOWS\system32\pmkji.dll 
C:\WINDOWS\system32\pmnlm.dll 
C:\WINDOWS\system32\pmnnl.dll 
C:\WINDOWS\system32\pmnnm.dll 
C:\WINDOWS\system32\qlmodrfo.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\ssqpq.dll 
C:\WINDOWS\system32\ssqro.dll 
C:\WINDOWS\system32\ssqrq.dll 
C:\WINDOWS\system32\sstqo.dll 
C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\ssttt.dll 
C:\WINDOWS\system32\vtstq.dll 
C:\WINDOWS\system32\vtutq.dll 
C:\WINDOWS\system32\vtutr.dll
C:\WINDOWS\system32\xlibgfl254.dll
C:\WINDOWS\system32\yayabay.dll
C:\WINDOWS\VTTC.exe
F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip
C:\Program Files\newdotnet
C:\Program Files\Viewpoint

Kaspersky also identified these files as being suspicious because they contain the MIRC executable which is sometimes used by malware:
F:\urcrazyclone\Programs & Apps\Scripts\DS\mirc.exe
F:\urcrazyclone\Programs & Apps\Scripts\DS.zip
F:\urcrazyclone\Programs & Apps\Scripts\GuarDDog\mirc_GuarDDogv.4.4.exe
F:\urcrazyclone\Programs & Apps\Scripts\GuarDDog4-1.4LITE.zip
F:\urcrazyclone\Programs & Apps\Scripts\setup.exe
F:\urcrazyclone\Programs & Apps\Scripts\tormentev_2b.zip
Do you know what these programs are for, and are you sure you want to keep them?
If not, use Windows Explorer to locate and delete them.

Next, please reboot your computer and do a couple further scans:

Please download F-Secure Blacklight (blbeta.exe):
https://europe.f-secure.com/blacklight/try.shtml
  • Click I ACCEPT and download the graphical user interface version to your Desktop
  • Double click the file to run it, choose I accept the agreement then press Scan
  • It will create the "fsbl-xxxxxxx.log" on your desktop.
  • The log will have a list of all items found.
  • Do not choose to rename any yet! I want to see the log first because legitimate items can also be present.
  • Exit Blacklight and post the contents of the log in your next reply.
Download Dr.WEB CureIt to your desktop from here:
ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe
  • Double-click cureit.exe to start the program.
  • Press Start and then OK to start the Express scan
  • The Express scan takes just a few moments to finish, if something is found, click Yes to cure it
  • Once the short scan has finished, Click Options->Change settings
  • Choose the Scan tab and remove the check mark from Heuristic analysis
  • Then choose the Actions tab and next to Infected objects select Move, then press OK to close the settings box.
  • Then select all hard drives to be scanned by clicking on them - choose all drives - a red dot confirms they will be scanned
  • Then click the green arrow on the right to start the scan
  • Click Yes to all if it asks if you want to move a file
  • Then click File-> Save report list and save the report to your desktop
  • Close Dr.Web Cureit and reboot your computer (this is important as files may be moved/deleted during reboot)
Once complete, please post the OTMoveIt output, the Blacklight log, the Dr Web log and a new HijackThis log.
Ok, first a few things. I chose not to download my p2p clients, because I do use them heavily and haven't had a problem with them. Also, I'm guessing that you did some research on BSplayer, i know you said it came bundled with adware. When I initially downloaded it I read that only the newer releases of it did. I have an older version that didn't seem to come with any adware. You may have come across some information that I didn't. if i am in error about BSplayer please let me know. Finally, the DV TS is software that came with my digital camera, I am not quite sure about ultrasoft though.



Now here is my DRweb log. I have two logs because when i scanned the first time, it said that the scan was interrupted by the user, so i saved the first incomplete log and have a second complete log. Here they are:


A0065874.exe;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.mIRC.616;;
A0065892.dll;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.MotherboardMonitor;;
A0065952.exe;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.mIRC.616;;
sysdoctor.exe;C:\Documents and Settings\Administrator\Application Data;Trojan.DownLoader.17013;Moved.;
Process.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.ShutDown.11;;
backup-20070430-011624-424.dll;C:\HJT\backups;Trojan.StartPage.19992;Moved.;
UnInstall.exe;C:\Program Files\Ipwindows;Trojan.Rond;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP194\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP195\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP196\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP197\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP198\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP199\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP200\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP201\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP202\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP203\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP204\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP205\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP206\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP207\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP208\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP209\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP210\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP211\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP212\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP213\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP214\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP215\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP216\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP217\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP218\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP219\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP220\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP221\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP222\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP223\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP224\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP225\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP226\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP227\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP228\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP229\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP230\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP231\snapshot;Trojan.Virtumod;Moved.;
MFEX-4.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot;Trojan.Virtumod;Moved.;
MFEX-5.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot;Trojan.Virtumod;Moved.;
MFEX-6.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot;Trojan.Virtumod;Moved.;
MFEX-7.DAT;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP232\snapshot;Trojan.Virtumod;Moved.;
A0064430.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064431.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064453.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064454.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064455.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064456.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064457.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064458.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064459.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064460.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064461.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064462.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064463.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0064464.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP245;Trojan.Virtumod;Moved.;
A0065845.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.StartPage.19992;Moved.;
A0065990.exe;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.DownLoader.17013;Moved.;
A0065991.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.StartPage.19992;Moved.;
A0065994.exe;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Rond;Moved.;
awttsss.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
awvvu.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
criwflux.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
ddcabxw.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
jkkjiih.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
khfddef.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
mkvkndgj.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
nnnklkk.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
pgsnbvej.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
ssqpm.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
tuvvttr.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
vtsqn.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
yayabay.dll.bad;C:\VundoFix Backups;Trojan.Virtumod;Moved.;
awtqn.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtqp.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtqq.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtqr.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtsq.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtss.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awvvv.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
awvvw.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddaya.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddayx.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddcca.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddccy.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebcb.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebcd.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebya.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
geebb.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
geebc.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
geeby.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
geedb.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkhhg.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkkji.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkklk.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkklm.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
mljge.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
mllji.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
mlljk.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
mllml.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmkjj.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmnnn.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
Process.exe;C:\WINDOWS\system32;Tool.Prockill;;
ssqrr.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssqrs.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssttr.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtsqq.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtstt.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtstu.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
vturp.dll;C:\WINDOWS\system32;Trojan.Virtumod;Moved.;
NNuninstall.exe;C:\_OTMoveIt\MovedFiles\Documents and Settings\Administrator\Desktop;Adware.NewDotNet;;
awtqo.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtsp.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
awtsr.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
awvtt.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
awvtu.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
awvvt.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddaba.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddabb.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddabc.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddayw.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddccd.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ddcya.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebcc.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebcy.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebyw.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
gebyx.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
geeba.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkhfd.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkhhh.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkkjk.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
jkkll.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
mljgg.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
mljjh.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
mljjj.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
mllmm.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmkhg.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmkjg.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmkji.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmnlm.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmnnl.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
pmnnm.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssqpq.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssqro.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssqrq.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
sstqo.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
sstqp.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
ssttt.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtstq.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtutq.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
vtutr.dll;C:\_OTMoveIt\MovedFiles\WINDOWS\system32;Trojan.Virtumod;Moved.;
f4.exe;C:\_OTMoveIt\MovedFiles\WINDOWS\system32\micro1;Adware.Surfside;;




and here is the second:


Process.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.Prockill;;
restart.exe;C:\Documents and Settings\Administrator\Desktop\SmitfraudFix;Tool.ShutDown.11;;
A0066003.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066004.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066005.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066006.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066007.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066008.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066009.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066010.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066011.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066012.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066013.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066014.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066015.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066016.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066017.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066018.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066019.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066020.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066021.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066022.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066023.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066024.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066025.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066026.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066027.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066028.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066029.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066030.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066031.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066032.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066033.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066034.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066035.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066036.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066037.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066038.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066039.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066040.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066041.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066042.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066043.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066044.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066045.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066046.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066047.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066048.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066049.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066050.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066051.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066052.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066053.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066054.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066055.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066056.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066057.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066058.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066059.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066060.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066061.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066062.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066063.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066064.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066065.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066066.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066067.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066068.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066069.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066070.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066071.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066072.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066073.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066074.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066075.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066076.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066077.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
A0066078.dll;C:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Trojan.Virtumod;Moved.;
Process.exe;C:\WINDOWS\system32;Tool.Prockill;;
NNuninstall.exe;C:\_OTMoveIt\MovedFiles\Documents and Settings\Administrator\Desktop;Adware.NewDotNet;;
f4.exe;C:\_OTMoveIt\MovedFiles\WINDOWS\system32\micro1;Adware.Surfside;;
A0065874.exe;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.mIRC.616;;
A0065892.dll;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.MotherboardMonitor;;
A0065952.exe;F:\System Volume Information\_restore{CE4B8214-1212-46E6-B242-43DBF9DD6465}\RP250;Program.mIRC.616;;






Here is my HJT log:


Logfile of HijackThis v1.99.1
Scan saved at 8:25:43 PM, on 4/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe




Here is my OTmoveit log:


C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\version.jar-759bdc60-7bf372c2.zip moved successfully.
C:\Documents and Settings\Administrator\Desktop\NNuninstall.exe moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\NeroDemo12065\Toolbar.exe moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Temp\USDR6_9999_N18M1603\installer.exe moved successfully.
File/Folder C:\Program Files\Messenger\qulazu.dll not found.
File/Folder C:\Program Files\Windows Media Player\mezo.dll not found.
File/Folder C:\Program Files\Windows Media Player\TTC.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awtqo.dll
C:\WINDOWS\system32\awtqo.dll NOT unregistered.
C:\WINDOWS\system32\awtqo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awtsp.dll
C:\WINDOWS\system32\awtsp.dll NOT unregistered.
C:\WINDOWS\system32\awtsp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awtsr.dll
C:\WINDOWS\system32\awtsr.dll NOT unregistered.
C:\WINDOWS\system32\awtsr.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\awvtt.dll NOT unregistered.
C:\WINDOWS\system32\awvtt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\awvtu.dll NOT unregistered.
C:\WINDOWS\system32\awvtu.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\awvvt.dll NOT unregistered.
C:\WINDOWS\system32\awvvt.dll moved successfully.
C:\WINDOWS\system32\bund1\ClientBundle1.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddaba.dll
C:\WINDOWS\system32\ddaba.dll NOT unregistered.
C:\WINDOWS\system32\ddaba.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddabb.dll
C:\WINDOWS\system32\ddabb.dll NOT unregistered.
C:\WINDOWS\system32\ddabb.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\ddabc.dll NOT unregistered.
C:\WINDOWS\system32\ddabc.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddayw.dll
C:\WINDOWS\system32\ddayw.dll NOT unregistered.
C:\WINDOWS\system32\ddayw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddccd.dll
C:\WINDOWS\system32\ddccd.dll NOT unregistered.
C:\WINDOWS\system32\ddccd.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ddcya.dll
C:\WINDOWS\system32\ddcya.dll NOT unregistered.
C:\WINDOWS\system32\ddcya.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gebcc.dll
C:\WINDOWS\system32\gebcc.dll NOT unregistered.
C:\WINDOWS\system32\gebcc.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gebcy.dll
C:\WINDOWS\system32\gebcy.dll NOT unregistered.
C:\WINDOWS\system32\gebcy.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gebyw.dll
C:\WINDOWS\system32\gebyw.dll NOT unregistered.
C:\WINDOWS\system32\gebyw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\gebyx.dll NOT unregistered.
C:\WINDOWS\system32\gebyx.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\geeba.dll
C:\WINDOWS\system32\geeba.dll NOT unregistered.
C:\WINDOWS\system32\geeba.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\jkhfd.dll
C:\WINDOWS\system32\jkhfd.dll NOT unregistered.
C:\WINDOWS\system32\jkhfd.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\jkhhh.dll
C:\WINDOWS\system32\jkhhh.dll NOT unregistered.
C:\WINDOWS\system32\jkhhh.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\jkkjk.dll
C:\WINDOWS\system32\jkkjk.dll NOT unregistered.
C:\WINDOWS\system32\jkkjk.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\jkkll.dll
C:\WINDOWS\system32\jkkll.dll NOT unregistered.
C:\WINDOWS\system32\jkkll.dll moved successfully.
C:\WINDOWS\system32\micro1\f4.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mljgg.dll
C:\WINDOWS\system32\mljgg.dll NOT unregistered.
C:\WINDOWS\system32\mljgg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mljjh.dll
C:\WINDOWS\system32\mljjh.dll NOT unregistered.
C:\WINDOWS\system32\mljjh.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mljjj.dll
C:\WINDOWS\system32\mljjj.dll NOT unregistered.
C:\WINDOWS\system32\mljjj.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mllmm.dll
C:\WINDOWS\system32\mllmm.dll NOT unregistered.
C:\WINDOWS\system32\mllmm.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmkhg.dll
C:\WINDOWS\system32\pmkhg.dll NOT unregistered.
C:\WINDOWS\system32\pmkhg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmkjg.dll
C:\WINDOWS\system32\pmkjg.dll NOT unregistered.
C:\WINDOWS\system32\pmkjg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmkji.dll
C:\WINDOWS\system32\pmkji.dll NOT unregistered.
C:\WINDOWS\system32\pmkji.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnlm.dll
C:\WINDOWS\system32\pmnlm.dll NOT unregistered.
C:\WINDOWS\system32\pmnlm.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnnl.dll
C:\WINDOWS\system32\pmnnl.dll NOT unregistered.
C:\WINDOWS\system32\pmnnl.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmnnm.dll
C:\WINDOWS\system32\pmnnm.dll NOT unregistered.
C:\WINDOWS\system32\pmnnm.dll moved successfully.
File/Folder C:\WINDOWS\system32\qlmodrfo.dll not found.
File/Folder C:\WINDOWS\system32\ssqpm.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqpq.dll
C:\WINDOWS\system32\ssqpq.dll NOT unregistered.
C:\WINDOWS\system32\ssqpq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqro.dll
C:\WINDOWS\system32\ssqro.dll NOT unregistered.
C:\WINDOWS\system32\ssqro.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssqrq.dll
C:\WINDOWS\system32\ssqrq.dll NOT unregistered.
C:\WINDOWS\system32\ssqrq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sstqo.dll
C:\WINDOWS\system32\sstqo.dll NOT unregistered.
C:\WINDOWS\system32\sstqo.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sstqp.dll
C:\WINDOWS\system32\sstqp.dll NOT unregistered.
C:\WINDOWS\system32\sstqp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ssttt.dll
C:\WINDOWS\system32\ssttt.dll NOT unregistered.
C:\WINDOWS\system32\ssttt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtstq.dll
C:\WINDOWS\system32\vtstq.dll NOT unregistered.
C:\WINDOWS\system32\vtstq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtutq.dll
C:\WINDOWS\system32\vtutq.dll NOT unregistered.
C:\WINDOWS\system32\vtutq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtutr.dll
C:\WINDOWS\system32\vtutr.dll NOT unregistered.
C:\WINDOWS\system32\vtutr.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\xlibgfl254.dll
C:\WINDOWS\system32\xlibgfl254.dll NOT unregistered.
C:\WINDOWS\system32\xlibgfl254.dll moved successfully.
File/Folder C:\WINDOWS\system32\yayabay.dll not found.
C:\WINDOWS\VTTC.exe moved successfully.
File/Folder F:\urcrazyclone\Programs & Apps\Scripts\xtreme_s[07-05].zip not found.
File/Folder C:\Program Files\newdotnet not found.
File/Folder C:\Program Files\Viewpoint not found.

Created on 04/30/2007 01:19:00




Here is my blacklight log:


04/30/07 01:31:51 [Info]: BlackLight Engine 1.0.61 initialized
04/30/07 01:31:51 [Info]: OS: 5.1 build 2600 (Service Pack 2)
04/30/07 01:31:51 [Note]: 7019 4
04/30/07 01:31:51 [Note]: 7005 0
04/30/07 01:31:54 [Note]: 7006 0
04/30/07 01:31:54 [Note]: 7011 1724
04/30/07 01:31:54 [Note]: 7026 0
04/30/07 01:31:54 [Note]: 7026 0
04/30/07 01:31:59 [Note]: FSRAW library version 1.7.1021
04/30/07 01:49:01 [Note]: 2000 1012
04/30/07 01:51:33 [Note]: 7007 0
Hi YoungBruce,

Wikipedia's article on BSPlayer says that it is bundled with adware since version 1.38, if you are using an older one then maybe it is clean. I would however reiterate that the players I linked to above are extremely popular and very fully featured as well as completely safe and free, so for those reasons I recommend them instead of this program.

Next please open OTMoveIt again by double-clicking the program to start it.
Select the contents of the below file list, then press Ctrl+C to copy it to the clipboard
In OTMoveIt, click in the left-hand pane and press Ctrl+V to paste the file-list into the program
Then, press MoveIt!
Copy the Results output and paste it into a new notepad file so you can post it in your next response. Do this by clicking in the right-hand pane, press Ctrl-A then Ctrl-C to select all and copy. Then open Notepad, press Ctrl-V to paste in the text, and save this text file to your desktop.

OTMoveIt file list:
C:\Program Files\Ipwindows
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine
Once you have saved the log information in a text file, use the CleanUp function:
  • Close all programs apart from OTMoveIt as this step will require a reboot
  • On the OTMoveIt main screen, press the CleanUp! button
  • Say Yes to the prompt and then allow the program to reboot your computer.
Re-enable Windows Defender real-time protection:
  • Right-click on the Windows Defender icon in the system tray [it's the one with the red and yellow bulls-eye].
  • Click on Security Agents Status
  • Click on Enable real-time protection
  • Next right-click on the Windows Defender icon in the system tray again to open the program
  • Click on the Options menu and choose Settings
  • In the left pane column click on Real Time Protection
  • Under Startup Options, check Enable Security Agents on startup (recommended)
  • Under Real-time spyware threat protection, check Enable real-time spyware threat protection (recommended)
  • Click the Save button and close Windows Defender
Once complete, please post the OTMoveIt log along with a new HijackThis log and let me know how your computer is running.
here is the OTmoveit log:


C:\Program Files\Ipwindows moved successfully.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine moved successfully.

Created on 05/01/2007 04:44:26



and here is the hjt log:


Logfile of HijackThis v1.99.1
Scan saved at 2:20:07 PM, on 5/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\HJT\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Monitor.lnk = C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - c:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe





My system is running well. I must ask you though, what tips would you give to keep my system protected and clean? Is it a good idea to install multiple antivirus and/or adware scanners?
Hi YoungBruce,

I'm glad to hear your machine is running better, your log looks good and I think your machine is now clean! If you still have cureit.exe or LSPFix.exe on your desktop they are no longer required and can be removed, as can any log files you have saved.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. You will lose all previous restore points which are likely to be infected.
Right-click My Computer (from the desktop or Start Menu)
Click Properties and choose the System Restore tab
Check Turn off System Restore
Click Apply, and then Yes to confirm, you may need to wait a moment while Windows deletes old System Restore Points
Then, UN-Check Turn off System Restore
Click OK

Your Java is outdated and is now a security risk
Go to Start » Control Panel » Add/Remove Programs
Search for all previous installed versions of Java. (J2SE Runtime Environment…. )
(It should have this icon next to it: [external image: Posted Image])
Click that entry and then click on the Change/Remove button and follow the instructions to remove Java.
Repeat to remove all versions of Java.
Download and install the newest version of Java Runtime Environment (JRE), from here:
http://java.sun.com/javase/downloads/index.jsp

You should have one antivirus and one antispyware program with real-time or active protection installed and running all the time. You should ideally have a two-way firewall installed also. Your log shows you have AVG antivirus, Windows Defender and Kerio firewall installed which gives you a good level of protection.

One antivirus program is sufficient. Installing multiple programs can cause system problems as they may conflict with one another, and it won't improve your security. Instead, I recommend you regularly scan using an online service, like Kaspersky's which we used in this thread. This will give you all the benefits of a '2nd opinion' without any system problems, and it's free too!

Antispyware/anti-adware programs cover a wide range of threats, and the key thing is to not double-up your protection. Windows Defender covers most bases, and if you are regularly scanning with it, your antivirus program and an online scanner then I'd say that's probably sufficient. If you wish to install another program, then I'd recommend the real-time protection is turned off and you use it only as an on-demand scanner.

IESPYADS helps protect you from malicious websites by placing a list of known bad websites in Internet Explorer's Restricted Zone. This Zone limits the capabilities of these websites including preventing them from installing software. This will compliment your security software and I recommend you install it:
http://www.spywarewarrior.com/uiuc/resource.htm

Please take care when downloading programs. One of the easiest ways to be infected is to download freeware/shareware programs which come laden with malware. Before downloading, it is crucial to check whether the source is reputable.
One way to check is to use McAfee SiteAdvisor. Copy the domain name into the space provided and SiteAdvisor will give you a report on the website which can help you decide if it is safe. They also have a toolbar for IE and Firefox which adds this functionality to your browser.

Find out how to prevent infection in the future
http://forum.malwareremoval.com/viewtopic.php?p=33687

Please post back to let me know how you got on, and if there are any further issues.
um there arent any other issues as far as my computer being infected, but maybe i can ask you this. my system doesnt seem to have usb support. there is no usb tree in the device manager. there isnt an option to enable it in the bios either. i tried updating my bios and it didnt help. i was able to use usb in the past, but when i had to format my computer and start fresh. there was no usb. maybe yo can help. other than that everything is fine. Thanks for the help

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI