This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Is Jacked!

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please help free my computer!

Logfile of HijackThis v1.99.1
Scan saved at 9:05:22 PM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Video ActiveX Object\isamonitor.exe
C:\Program Files\Video ActiveX Object\pmsngr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Video ActiveX Object\pmmon.exe
C:\Program Files\Video ActiveX Object\isamini.exe
C:\DOCUME~1\Tony\LOCALS~1\Temp\clclean.0001
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Tony\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.verizon.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1a1ddc19-5893-43ab-a73f-f41a0f34d115} - C:\Program Files\Video ActiveX Object\isaddon.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcdmon.exe] "C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 944\memcard.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer = 85.255.113.94,85.255.112.225
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225
O20 - AppInit_DLLs:
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
tonybagadonuts :D

Welcome to the forum, you have TWO Major Infections on this computer, I am scratching my head trying to figure out how it even starts up.

Your infected with Smitfraud and you got that by downloading a bogus codec. Your also infected with Wareout.

Lets attack Smitfraud first.


You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.


Make sure you follow these instructions correctly to Remove or Quarantine what it finds and also to save the report, without me seeing the report my hands are tied.
Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
  • A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt





Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start> Control Panel and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button.
  • Click Apply then OK.





  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:


Reboot normally.
  • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #3 - Delete Trusted zone by typing 3 and press Enter
  • Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.



I need to see the AVG Log, the Smitfraud log and a New HJT log please
I did my best to follow the instructions… it all seemed to follow accordingly. Here are the files I saved during the process and the new HJT scan. Thanks for you help with all this. SmitFraudFix v2.171 Scan done at 0:27:15.56, Fri 04/27/2007 Run from C:\Documents and Settings\Tony\Desktop\SmitfraudFix\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{af3fd9a8-1287-4159-9212-9a5b4494af70}"="ecosystems" [HKEY_CLASSES_ROOT\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32] @="C:\WINDOWS\system32\guxxa.dll" [HKEY_CURRENT_USER\Software\Classes\CLSID\{af3fd9a8-1287-4159-9212-9a5b4494af70}\InProcServer32] @="C:\WINDOWS\system32\guxxa.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{4fbbdfd6-2ca9-4bba-93e4-aadf75321bca}"="discriminable" [HKEY_CLASSES_ROOT\CLSID\{4fbbdfd6-2ca9-4bba-93e4-aadf75321bca}\InProcServer32] @="C:\WINDOWS\system32\kuhmk.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4fbbdfd6-2ca9-4bba-93e4-aadf75321bca}\InProcServer32] @="C:\WINDOWS\system32\kuhmk.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\ot.ico Deleted C:\WINDOWS\system32\stdole3.tlb Deleted C:\WINDOWS\system32\ts.ico Deleted C:\WINDOWS\system32\1024\ Deleted C:\Program Files\AntiVermins\ Deleted C:\Program Files\Media-Codec\ Deleted C:\Program Files\Security Toolbar\ Deleted C:\Program Files\Video ActiveX Object\ Deleted C:\Program Files\ZipCodec\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{29B39846-0902-49E5-B96A-2F1FC54E9A72}: DhcpNameServer=[removed],[removed] HKLM\SYSTEM\CCS\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer=85.255.113.94,85.255.112.225 HKLM\SYSTEM\CS1\Services\Tcpip\..\{29B39846-0902-49E5-B96A-2F1FC54E9A72}: DhcpNameServer=[removed],[removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer=85.255.113.94,85.255.112.225 HKLM\SYSTEM\CS3\Services\Tcpip\..\{29B39846-0902-49E5-B96A-2F1FC54E9A72}: DhcpNameServer=[removed],[removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CS3\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer=85.255.113.94,85.255.112.225 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=85.255.113.94 85.255.112.225 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=85.255.113.94 85.255.112.225 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254 192.168.1.254 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: NameServer=85.255.113.94 85.255.112.225 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="cslqd.exe" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 1:37:16 AM 4/27/2007 + Scan result: C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030497.exe -> Adware.AntiVermins : Cleaned with backup (quarantined). HKU\S-1-5-21-2251148007-3494182482-1353740021-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{736B5468-BDAD-41BE-92D0-22AE2DDF7BCB} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2251148007-3494182482-1353740021-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2251148007-3494182482-1353740021-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2251148007-3494182482-1353740021-1005\Software\SystemDoctor 2006 Free -> Adware.Systemdoctor : Cleaned with backup (quarantined). HKU\S-1-5-21-2251148007-3494182482-1353740021-1005\Software\SystemDoctor 2006 Free\Settings -> Adware.Systemdoctor : Cleaned with backup (quarantined). C:\Documents and Settings\Tony\Local Settings\Temp\USDR6_0001_D17M1107\installer.exe -> Adware.WinFixer : Cleaned with backup (quarantined). C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Creative\VoiceCenter\AndreaVC.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\DAEMON Tools\daemon.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Dell Photo AIO Printer 944\dlcdmon.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Dell Photo AIO Printer 944\memcard.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Dell Support\DSAgnt.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Dell\Media Experience\DMXLauncher.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\Agent\mcagent.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\Agent\mcupdate.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\Personal Firewall\MpfTray.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\VSO\mcmnhdlr.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\VSO\mcvsshld.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee.com\VSO\oasclnt.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee\SpamKiller\MSKDetct.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\McAfee\SpamKiller\MskAgent.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\QuickTime\qttask.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Real\RealPlayer\RealPlay.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\Program Files\Support.com\BellSouth\hcenter.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\WINDOWS\UpdReg.EXE -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\WINDOWS\ehome\ehtray.exe -> Downloader.Agent.ayy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030508.exe -> Downloader.Zlob.afq : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP288\A0022876.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP288\A0022877.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP289\A0022899.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP289\A0022900.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP290\A0022906.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP290\A0022907.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP291\A0022915.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP291\A0022916.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP292\A0022931.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP292\A0022932.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0022961.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0022962.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0022973.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0022974.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0022999.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP295\A0023000.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP296\A0023004.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP296\A0023005.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP296\A0023014.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP296\A0023015.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP297\A0023024.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP297\A0023025.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP298\A0023054.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP298\A0023055.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP298\A0024055.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP298\A0024056.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP299\A0024061.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP299\A0024062.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP299\A0024070.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP299\A0024071.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP300\A0024077.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP300\A0024078.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP302\A0024103.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP302\A0024104.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024108.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024109.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024128.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024129.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024136.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP303\A0024137.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP304\A0024242.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP304\A0024243.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP305\A0024257.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP305\A0024258.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP306\A0024274.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP306\A0024275.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP307\A0024288.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP307\A0024289.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP308\A0024303.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP308\A0024304.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP309\A0024338.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP309\A0024340.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP310\A0024362.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP310\A0024363.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP310\A0024377.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP310\A0024378.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP311\A0024387.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP311\A0024388.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP313\A0024392.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP313\A0024393.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP314\A0024430.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP314\A0024431.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP315\A0024436.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP315\A0024437.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP315\A0024455.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP315\A0024456.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP316\A0024464.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP316\A0024465.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP317\A0024474.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP317\A0024475.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP317\A0024490.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP317\A0024491.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP318\A0024514.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP318\A0024515.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP319\A0024542.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP319\A0024543.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP319\A0024551.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP319\A0024552.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP320\A0024564.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP320\A0024565.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP321\A0024575.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP321\A0024576.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP321\A0024583.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP321\A0024584.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP323\A0024597.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP323\A0024598.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP324\A0024619.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP324\A0024621.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP325\A0024633.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP325\A0024635.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP325\A0024642.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP325\A0024643.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP326\A0024650.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP326\A0024651.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP327\A0024661.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP327\A0024662.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP328\A0024687.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP328\A0024688.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP329\A0024705.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP329\A0024706.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP330\A0024715.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP330\A0024717.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP331\A0024722.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP331\A0024724.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP332\A0024754.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP332\A0024755.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP333\A0024760.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP333\A0024761.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP334\A0024781.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP334\A0024782.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP335\A0024785.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP335\A0024786.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP336\A0024789.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP336\A0024790.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP337\A0024795.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP337\A0024796.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP338\A0024814.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP338\A0024816.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP339\A0024827.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP339\A0024828.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP339\A0024837.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP339\A0024838.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP340\A0024852.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP340\A0024853.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP341\A0024860.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP341\A0024861.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP341\A0024869.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP341\A0024870.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP342\A0024875.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP342\A0024876.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP342\A0025870.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP342\A0025871.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0025897.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP343\A0025898.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0025912.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0025913.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0026895.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0026896.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0026906.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP344\A0026907.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP345\A0026924.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP345\A0026925.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0026938.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0026939.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0026949.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP346\A0026950.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0026988.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0026989.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0027007.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP347\A0027008.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP348\A0027012.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP348\A0027013.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP348\A0027027.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP348\A0027028.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP349\A0027048.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP349\A0027049.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP350\A0027054.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP350\A0027056.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP351\A0028057.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP351\A0028058.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP352\A0028083.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP352\A0028084.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP353\A0028087.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP353\A0028088.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP354\A0028106.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP354\A0028107.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP355\A0028111.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP355\A0028112.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP356\A0028139.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP356\A0028140.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP357\A0028147.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP357\A0028149.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP358\A0028197.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP358\A0028198.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP359\A0028202.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP359\A0028203.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP359\A0028228.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP359\A0028229.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP360\A0028239.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP360\A0028240.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP361\A0028258.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP361\A0028259.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP362\A0028264.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP362\A0028265.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP363\A0028276.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP363\A0028277.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP363\A0028304.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP363\A0028305.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP364\A0028308.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP364\A0028309.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP365\A0028322.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP365\A0028323.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP365\A0028345.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP365\A0028346.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP366\A0028349.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP366\A0028350.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP366\A0028370.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP366\A0028371.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP367\A0028382.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP367\A0028383.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0028907.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0028908.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029073.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029074.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029187.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029188.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029197.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029198.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029210.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP368\A0029211.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0029364.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0029365.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0029389.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0029390.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0030387.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP369\A0030388.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP370\A0030394.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP370\A0030395.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP371\A0030405.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP371\A0030406.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP372\A0030409.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP372\A0030410.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP373\A0030426.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP373\A0030427.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030451.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030452.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030483.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030484.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030503.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030504.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030505.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030507.exe -> Downloader.Zlob.bfj : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP374\A0030486.dll -> Dropper.WSO.a : Cleaned with backup (quarantined). C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined). C:\Documents and Settings\Ania\Cookies\ania@112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@geosign.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@nike.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@pch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@waterfrontmedia.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@advertising[1].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@bfast[2].txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Gemius : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@revsci[1].txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Sexcounter : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Tony\Local Settings\Temp\Cookies\tony@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned. C:\Documents and Settings\Ania\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Ania\Cookies\ania@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. ::Report end Logfile of HijackThis v1.99.1 Scan saved at 1:47:09 AM, on 4/27/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\stsystra.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Messenger\msmsgs.exe C:\DOCUME~1\Tony\LOCALS~1\Temp\clclean.0001 C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe C:\Program Files\Digital Line Detect\DLG.exe C:\WINDOWS\system32\dlcdcoms.exe C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\DOCUME~1\Tony\LOCALS~1\Temp\Temporary Directory 2 for hijackthis[1].zip\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16 O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer = 85.255.113.94,85.255.112.225 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225 O20 - AppInit_DLLs: O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
Good Morning Tony,

You did well, if you look at your original HJT log that you posted you will see a entry for C:\Program Files\Video ActiveX Object <– This was the Smitfraud Trojan, you have to be real careful what you download. Whenever you go into a website that says that you need to download and install this to view the page properly, be kind of leary about it..


On to the next one, this is the one giving you the redirects, before we run the tool, lets do a couple of things..

First open AVG Anti Spyware and go to the Quarantine folder and remove it all, nothing in there you want to keep.

Then move HJT to its own folder.
Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis



Your computer has been hijacked by the lovely people in the Ukraine, you are infected with Wareout.

85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine

You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
FixWareout Subratam
FixWareout Lonny
  • Save it to your desktop and run it.
  • Click Next, then Install,
  • Then make sure "Run fixit" is checked and click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
  • At the end of the fix, you may need to restart your computer again.
Save the contents of the logfile C:\fixwareout\report.txt and post it into your next reply.

Now lets check some settings on your system. For (2000/XP) Only)
  • Go to Start > control panel.
  • If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections.
  • Then right click on your default connection, usually local area connection for cable and dsl.
  • Left click on properties.
  • Click the Networking tab.
  • Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
  • Press OK twice to get out of the properties screen and reboot if it asks.
    That option might not be available on some systems

  • Next Go start> Run type cmd and hit OK
  • Type in ipconfig /flushdns then hit enter
    (that space between g and / is needed)
  • Type exit hit enter

These 017 entries are redirecting you to the Ukraine
Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O17 - HKLM\System\CCS\Services\Tcpip\..\{E8C95837-8DE3-47BD-9F36-E008936D3BFF}: NameServer = 85.255.113.94,85.255.112.225
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.94 85.255.112.225
O20 - AppInit_DLLs:




Download and Install CCleaner
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Let me see the FixWareout log and a New HJT log please.
I am on the last step with CCleanear. I ran the Issues Scan and saved the Registry. I have 222 selected issues… am I supposed to select Fix All Selected Issues or leave it for now? The last step in your post was to say Yes to saving the Registry. Again, thanks for you help. Tony
Yes, exactly. That program is free, I run mine about once a week to get rid of the temp files and such, I only like to use the issues scan after a bad infection which for me knock on wood I have never had. :weee:
Ok, here are the HJT and FixWareout logs. When all is said and done, what should I be doing to be proactive in keeping my computer clean? Pay for a program, or use some of the tools you provided at timely intervals? When I first got my computer the security program was so annoying because any action I did in explorer needed approval it seemed. Your advice is greatly appreciated. Thanks again.

Logfile of HijackThis v1.99.1
Scan saved at 11:36:14 AM, on 4/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\dlcdcoms.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\DOCUME~1\Tony\LOCALS~1\Temp\clclean.0001
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [DLCDCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCDtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: dlcd_device - - C:\WINDOWS\system32\dlcdcoms.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe


Fixwareout Last edited 4/5/2007
Post this report in the forums please
…
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="cslqd.exe"

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BB45131AA46D-9F78-40F4-D532-076F01BA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AE261164724F-78EB-83E4-5748-B134FE11{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}5D253672CCE8-2B58-3FC4-376D-738E3AAA{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}32A13DD6DD84-E1A9-81B4-71E9-383C5B78{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}AE7D2F85F915-C1C8-96E4-36D6-85B75BAD{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}F3BF6AE0678B-3178-5C14-4255-CB9344ED{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}93E62B3AEE5E-45F8-39C4-239F-89849912{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}7C5B78DAA3BD-941B-7EB4-A2FC-6D3061F4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}427792FDF56D-13C9-EC04-2536-8298F573{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}BCAF21E60893-1889-DF94-998A-2DC9A8A4{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}B0FBC223238D-1E89-DB84-6AB0-7B10EDB3{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "}0098C23615D2-A879-A1F4-AA3A-DEB5A1CE{" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ruins "mnmmd" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1trap" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "2trap" Deleted
C:\WINDOWS\System32\qqnpe.exe Deleted
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe"
"SigmatelSysTrayApp"="stsystra.exe"
"DMXLauncher"="C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r"
"MBMon"="Rundll32 CTMBHA.DLL,MBMon"
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"Corel Photo Downloader"="C:\\Program Files\\Corel\\Corel Photo Album 6\\MediaDetect.exe"
"DLCDCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCDtime.dll,_RunDLLEntry@16"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SetDefaultMIDI"="MIDIDef.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
….
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Tony,

You have a clean log :thumbup: :thumbup: :thumbup: I have been at this for a few years and the user names sometimes crack me up, the funniest I have seen was a guy going by LizardLips, how did you come by Tonybagodonuts??

The infections are gone, but if you look thru your AVG log you will see there is a ton of stuff backed up in your System Restore Program which means that if you ever use that program to revert your system to an earlier date you risk re infecting your self so lets flush it all out, I can't stress enough how important it is to create a new restore point, to use that feature you will have to switch to Catagory View in the Control Panel.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.


Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point <–You will have to be in Catagory View to see this.
    You can name the restore point anything you like, something that you can remember.
System Restore Tutorial <– If you need it


AVG Anti Spyware is one of the best programs on the market, its yours to keep, you will still be able to check for updates, run scans and remove what it finds, you will just lose the Background Guard feature after the trial so its your call to uninstall it, keep it or purchase the full version.


You also need to update your Java as its leaving holes in your system for this garbage to get in.
  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment Version 6 Update 1 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future



Let me know how your system is behaving now and if all is well I have some links to free programs for you to install to help keep you more secure.

Ken :D
Ken, This is great! Not only does my computer work, but I also don't have to listen to my wife complaining about it. It was like this for months. Tonybagadonuts was a nickname somebody called me working on a golf course years ago, and it stuck. I actually have an old laptop with similar issues that I wil try to play around with using your previous advice… but I may have to post that too. Anyway, thanks again for your help. Not only were you dead on fixing everything, but you so quick to respond. :thumbup: Tony
Thanks Tony for the kind words. Feel free to post back for your laptop anytime you wish. I may not get it but we have an excellent staff. If you want you can PM me with a heads up.


Malware Complaints
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI