Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Please Help...my computers being attacked

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Please Help...my computers being attacked

Unread postby PamelaJG » October 29th, 2008, 4:25 pm

Hi, I keep getting this pop up from the bottom of my screen that says "you have a security problem" and then Personal AntiSpy in a blue box pops up, but I know better now and I close out the program. I went too far with this program when it first poped up because I didn't know and now my computer is being attacked CONSTANTLY. Please help me. I don't know what to do and I don't know what this thing is capable of doing to my computer. I scanned my computer and there is over 1000 things that came up, but I am clueless what these viruses/spyware mean and what they do. Please help guide me through this. I have been trying to do this by myself for almost a week now, but it keeps getting worse and I don't think I am helping anything. I am desparately in need of your help. I have many personal files on my computer that would just kill me if anyone got into them.
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm
Advertisement
Register to Remove

Re: Please Help...my computers being attacked

Unread postby Dakeyras » October 29th, 2008, 7:06 pm

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hi PamelaJG and welcome to Malware Removal :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:

  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe.

Extra note: Please be aware as I am still in training all of my fixes/posts require prior checking by a Expert. So some delays may be inevitable, please be patient and I will reply again asap.

Next:

Please download HijackThis from Here .

  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • The program will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
  • Click Do a system scan and save a log file. A Notepad file will open.
  • To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
  • Now paste the log into this thread using the (Ctrl + V) buttons.

Note: Do not be tempted to make any changes or click on Fix Checked until I Have checked your log. As Most of the files may/will be legitimate and vital to the function of your computer.

Next:

I would like to view a list of currently installed software applications on you're PC. How to provide as follows:

Run HijackThis and click on Open the Misc Tools section.

  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

When completed the above, please post back the following:

  • Uninstall list.
  • A HijackThis Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby PamelaJG » October 30th, 2008, 4:04 pm

Here is the uninstall list you requested: The HiJackThis Log is below. Thank You for the fast reply!! It is greatly appreciated!!

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player ActiveX
Adobe Reader 9
Adobe Shockwave Player
Broadcom Management Programs
Candy Land - Dora the Explorer Edition
ccCommon
CCHelp
CCScore
Compatibility Pack for the 2007 Office system
DSC Driver
ESSAdpt
ESSANUP
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSvpaht
ESSvpot
GamingSquared Console
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
HLPIndex
HLPRFO
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
IEBrowse Tool
IExplorer Bar
Intel(R) Extreme Graphics Driver
Java(TM) 6 Update 5
Java(TM) 6 Update 7
JohnQ TV Remote Toolbar
Kodak EasyShare software
KSU
LimeWire 4.16.7
LiveUpdate Notice (Symantec Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB936181)
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Parent MSI
Notifier
OpenOffice.org Installer 1.0
OTtBP
OTtBPSDK
PCDADDIN
PCDHELP
PCDLNCH
PDF Complete
QuickTime
SecureIT
Security Advisor
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB958644)
Seekmo Browser and Wowpapers Tools
SFR
SFR2
ShopperReports
Software Setup
SoundMAX
Symantec
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Verizon Online Help and Support
Verizon Servicepoint 1.5.20
Virtools 3D Life Player
VPRINTOL
Warning Center
WeatherBug
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Safety Alert
Windows XP Service Pack 3
Zango

And here is the HiJackThisLog:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:48:46 PM, on 10/30/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\SecureIT\scmonitor\SCMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\PDF Complete\pdfsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\GamingSquared\Gaming2\G2.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\SecureIT\SCControlPanel.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Zango\bin\10.3.75.0\Weather.exe
C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\xxx1550.exe
C:\Documents and Settings\Valued Person\My Documents\My Pictures\PAMS PICS\Kodak EasyShare software\bin\EasyShare.exe
C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\~tmpb.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
R3 - URLSearchHook: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {3B7AAEB1-9F3D-4491-9C06-C7165CA8D058} - C:\Program Files\Applications\iebt.dll
O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
O2 - BHO: 512686 helper - {51B15F5A-E98B-4658-B9CB-9307B74773A7} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O2 - BHO: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll
O2 - BHO: (Gaming)2 - {971F630E-AD68-4d6e-B0C3-1C627AAC80F1} - C:\Program Files\GamingSquared\Gaming2\G2IE_v1042.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: VResLabWarningBHO Class - {B494E7BB-1E33-4922-A947-F74EFF4E714F} - C:\Program Files\VResLab\VResLabWarning.dll (file missing)
O2 - BHO: SecurityCoverage Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\SecureIT\PopupBlocker.dll
O3 - Toolbar: Zango - {90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll
O3 - Toolbar: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O3 - Toolbar: Internet Service - {144A6B24-0EBC-4D89-BF09-A06A718E57B5} - C:\Program Files\Applications\iebr.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Clock knob fast okay] C:\Documents and Settings\All Users\Application Data\Idle Skip Clock Knob\joy hold.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.406.0\OEAddOn.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [G2] "C:\Program Files\GamingSquared\Gaming2\G2.exe"
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.3.75.0\OEAddOn.exe
O4 - HKLM\..\Run: [ZangoSA] "C:\Program Files\Zango\bin\10.3.75.0\ZangoSA.exe"
O4 - HKLM\..\Run: [UPAS] C:\WINDOWS\Downloaded Program Files\UPAS_0001_N93M1306NetInstaller.exe
O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\UAV\uav.exe
O4 - HKLM\..\Run: [SCControlPanel] C:\Program Files\SecureIT\SCControlPanel.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [sect book] C:\DOCUME~1\VALUED~1\APPLIC~1\ONLINE~1\linkinfomess.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Zango\bin\10.3.75.0\Weather.exe" -auto
O4 - HKCU\..\Run: [MSFox] C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\xxx1550.exe
O4 - HKCU\..\Run: [VResLab] "C:\Program Files\VResLab\VResLab.exe"
O4 - HKCU\..\Run: [wblogon] C:\WINDOWS\system32\algg.exe
O4 - HKCU\..\Run: [ANTIVIRUS] C:\Program Files\UAV\uav.exe
O4 - HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Applications\iebtm.exe
O4 - HKUS\S-1-5-18\..\Run: [89394842963136077095918817033455] C:\Program Files\Antivirus 2009\av2009.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ieupdate] "C:\WINDOWS\system32\ieexplorer32.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [89394842963136077095918817033455] C:\Program Files\Antivirus 2009\av2009.exe (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Documents and Settings\Valued Person\My Documents\My Pictures\PAMS PICS\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.onlyiesettings.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.onlyiesettings.com/redirect.php (file missing)
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Fun Web Products Installer Start) - http://ak.exe.imgfarm.com/images/nocach ... 0.15-3.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4556153187
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player ... taller.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/active ... anager.CAB
O22 - SharedTaskScheduler: gey - {ba934431-76af-4c99-93c2-c3d21944a72e} - C:\WINDOWS\system32\gcqltg.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: SecureIT Monitor (SCMonitor) - Security Coverage Inc. - C:\Program Files\SecureIT\scmonitor\SCMonitorService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 12433 bytes
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 1st, 2008, 4:53 pm

Hi :)

I apologies for the delay with myself responding. I will provide the next course of action as soon as possible, thank you.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 4th, 2008, 6:59 am

Hi :)

Before commencing with any of the below please make sure you are logged into the Computer Administrator account for this machine.

I notice you have installed a Peer to Peer file sharing application.

Please read this: P2P (peer to peer) file sharing programmes must be removed

This is forum policy, Now please go to Start >> Control Panel >> Add/Remove Programs and remove the following:

LimeWire 4.16.7

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post that log in your next reply.
The log can also be found here:
  1. Launch Malwarebytes' Anti-Malware
  2. Click on the Logs radio tab.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediatly.

Next:

I would like to view a new list of currently installed software applications on you're PC. How to provide as follows:

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

When completed the above, please post back the following:

  • How is you computer running now?
  • Malwarebytes Anti-Malware Log.
  • Uninstall List.
  • A new HijackThis Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby PamelaJG » November 5th, 2008, 5:08 pm

Hi...Thank You for all your help. Unfortunately, I am having problems getting to my computer right now. Is it possible that I can respond to you Friday or Saturday with out my post being cancelled (I read the terms for this website and they said after 3 days of no action, they cancel and have to repost. Please don't cancel this for me. I will respond with the info you requested by Saturday morning. Thank You AGAIN!! Much appreciation.
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 5th, 2008, 5:40 pm

Hi :)
PamelaJG wrote:Hi...Thank You for all your help. Unfortunately, I am having problems getting to my computer right now. Is it possible that I can respond to you Friday or Saturday with out my post being cancelled (I read the terms for this website and they said after 3 days of no action, they cancel and have to repost. Please don't cancel this for me. I will respond with the info you requested by Saturday morning. Thank You AGAIN!! Much appreciation.

That is absolutely fine and thank you for the courtesy of informing myself. My pleasure to be of assistance and you are very welcome!

One point however while I do not mind what you asked I would prefer for the computer in question not to be actively used in a on-line capacity as this will cause further infection during the malware removal process, thank you.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 10th, 2008, 8:46 am

Hi :)

Do you still need help with your machine?

If the instructions are unclear or something isn't working, please let me know before proceeding.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby PamelaJG » November 10th, 2008, 2:52 pm

Hello...I did everything you told me to & my computer is working GREAT now...THANK YOU!!! That pop up stopped...there was 700 & something infections & some Trojans. Here is the Anti-Malware Log:

Malwarebytes' Anti-Malware 1.30
Database version: 1380
Windows 5.1.2600 Service Pack 3

11/10/2008 1:35:14 PM
mbam-log-2008-11-10 (13-35-14).txt

Scan type: Full Scan (A:\|C:\|D:\|)
Objects scanned: 120211
Time elapsed: 50 minute(s), 55 second(s)

Memory Processes Infected: 2
Memory Modules Infected: 9
Registry Keys Infected: 204
Registry Values Infected: 22
Registry Data Items Infected: 15
Folders Infected: 70
Files Infected: 430

Memory Processes Infected:
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpq.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\Program Files\Zango\bin\10.3.75.0\Weather.exe (Adware.180Solutions) -> Unloaded process successfully.

Memory Modules Infected:
C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (Adware.Shopper) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\CoreSrv.dll (Adware.Zango) -> Delete on reboot.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Program Files\Applications\iebr.dll (Trojan.Zlob) -> Delete on reboot.
C:\WINDOWS\system32\gcqltg.dll (Trojan.Zlob) -> Delete on reboot.
C:\Program Files\Applications\iebt.dll (Trojan.Zlob) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\Toolbar.dll (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\WeSkin.dll (Adware.180Solutions) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{ba934431-76af-4c99-93c2-c3d21944a72e} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{100eb1fd-d03e-47fd-81f3-ee91287f9465} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.Shopper) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.lfgax (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0729f461-8054-47dc-8d39-a31b61cc0119} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{40ca90f3-4098-4877-ae87-23eb612b18c7} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{4c3b62af-ca25-4fba-8405-32e44f83bb6f} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{5a635a91-c303-45c9-8db9-f759d98a3b9d} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7e335d04-2e6e-4d0e-a921-c3d9192e7121} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{99ccfb8c-6380-4a14-8fdd-ef3e7e95335d} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b20d7add-989c-4bc0-a797-f6fe7998efd7} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bfc20a15-b0ac-44cc-a25a-a7039014ba9f} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f019aec4-4c95-46de-a107-e302473e3b9a} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2d00aa2a-69ef-487a-8a40-b3e27f07c91e} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{86c5840b-80c4-4c30-a655-37344a542009} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b0cb585f-3271-4e42-88d9-ae5c9330d554} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.lfgax.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproductsinstaller.start (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproductsinstaller.start.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmo.desktopflash (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmo.desktopflash.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.clientdetector (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.clientdetector.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.userprofiles (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\seekmoax.userprofiles.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1d4db7d1-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1d4db7d3-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{967a494a-6aec-4555-9caf-fa6eb00acf91} (Rogue.PestPatrol) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9692be2f-eb8f-49d9-a11c-c24c1ef734d5} (Rogue.PestPatrol) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bd5258af-20ae-4bd3-b748-b2851aca7335} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3b7aaeb1-9f3d-4491-9c06-c7165ca8d058} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3b7aaeb1-9f3d-4491-9c06-c7165ca8d058} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3b7aaeb1-9f3d-4491-9c06-c7165ca8d058} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{F5734812-E6A1-8833-ECA9-949B5B8A88BF} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e313f5dc-cfe7-4568-84a4-c76653547571} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{a8954909-1f0f-41a5-a7fa-3b376d69e226} (Rogue.PestPatrol) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{9233c3c0-1472-4091-a505-5580a23bb4ac} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{1d4db7d0-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{995e885e-3ff5-4f66-a107-8bfb3a0f8f12} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{fbb40fdf-b715-4342-ab82-244ecc66e979} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\{4a40e8fc-c7e4-4f57-9fa4-85dd77402897} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bfc08cff-c737-4433-bd5a-0ee7efcfee54} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{51b15f5a-e98b-4658-b9cb-9307b74773a7} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1f158a1e-a687-4a11-9679-b3ac64b86a1c} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e313f5dc-cfe7-4568-84a4-c76653547571} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{914a8f99-38e4-47ec-b875-2b0653516030} (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Products\568267acfc5644dab06f058006ddbae3 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Installer\Features\9ee2330ae5f4470cac801baac83818c9 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{a57470de-14c7-4fcd-9d4c-e5711f24f0ed} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2557dd3f-23a0-477c-bcd8-90fd0aecc4b8} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2893116c-a176-42b1-8794-da8c9fc45564} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{99fdca0c-7380-4e9c-8d99-5dc4750334ef} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b1d9f4b1-b9ff-463f-bf15-ab9cb26160f7} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2aa2fbf8-9c76-4e97-a226-25c5f4ab6358} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{2aa2fbf8-9c76-4e97-a226-25c5f4ab6358} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{2aa2fbf8-9c76-4e97-a226-25c5f4ab6358} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{71f731b3-008b-4052-9ea4-4145acce40c3} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c62a9e79-2b52-439b-af57-2e60bb06e86c} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{15fd8424-d12a-4c51-8c6c-d5d57b80f781} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{67b3becf-7b6f-42b2-99f0-f7656f89cffa} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{715ffd42-4e05-4eab-9513-c8daa5395ae2} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{759d6f7c-8d30-45b6-abea-fa51c190eed5} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{9a4a64a4-a2fb-48fa-9bba-1ac50267695d} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{62906e60-bce2-4e1b-9ed0-8b9042ee15e4} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{f9bfa98d-9935-4ea4-a05a-72c7f0778f02} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{a56fe01c-77c4-4f5e-8198-e4b72207890a} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{af55160d-cde1-4a8b-8001-66da06bee740} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{89085678-632d-4deb-bda0-cd912c63203e} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{30b15818-e110-4527-9c05-46ace5a3460d} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{618aad04-921f-44c2-be38-c0818af69861} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b5d2ed96-62f9-4c2c-956d-e425b1f67337} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d3a412e8-1e4b-47d2-9b12-f88291f5afbb} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3788e535-897b-463d-b6d6-fee5b86ec144} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3788e535-897b-463d-b6d6-fee5b86ec144} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3788e535-897b-463d-b6d6-fee5b86ec144} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d3f940ea-4e87-423b-9091-934e1e4fceae} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d3f940ea-4e87-423b-9091-934e1e4fceae} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d3f940ea-4e87-423b-9091-934e1e4fceae} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\win a v (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\BitDownload (Trojan.Lop) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\VResLab (Rogue.AntiVirusLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\vreslabwarning.warningbho (Rogue.AntiVirusLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\vreslabwarning.warningbho.1 (Rogue.AntiVirusLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\UAV (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmo.desktopflash (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmo.desktopflash.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.clientdetector (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.clientdetector.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.userprofiles (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\seekmoax.userprofiles.1 (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\seekmosa (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\seekmosa (Adware.Seekmo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Alert Popup (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEBrowse Tool (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer Bar (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Warning Center (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Zango (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.clientdetector (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.clientdetector.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.userprofiles (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\zangoax.userprofiles.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\wallpaper.wallpapermanager (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\wallpaper.wallpapermanager.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.toolbarctl.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\toolbar.htmlmenuui.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\srv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\srv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.webmailsend.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostol.mailanim.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hostie.bho.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbr.hbmain.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\hbmain.commband.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\coresrv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\zango (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ba934431-76af-4c99-93c2-c3d21944a72e} (Trojan.Zlob.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cognac (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\upas (Rogue.Installer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{144a6b24-0ebc-4d89-bf09-a06a718e57b5} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\89394842963136077095918817033455 (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{90b8b761-df2b-48ac-bbe0-bcc03a819b3b} (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\weatherdpa (Adware.180Solutions) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.Antivirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSFox (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wblogon (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\start (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\smile (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\Zango@Zango.com (Adware.Zango) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\zango 10.3.75.0 (Adware.Zango) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\Local Page (Hijack.Search) -> Bad: (http://www.iesearch.com/) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://windiwsfsearch.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://windiwsfsearch.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
C:\Program Files\Zango (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0 (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\firefox (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\components (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\plugins (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> Delete on reboot.
C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> Delete on reboot.
C:\Program Files\ShoppingReport\Bin\2.5.0 (Adware.Shopping.Report) -> Delete on reboot.
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Installr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Installr\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WAV (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\UAV (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\512686 (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\res1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\res1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\res1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\eskin (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\IESkins (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0 (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOI (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOI\dynamic (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOI\static (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOL (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOL\dynamic (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\HostOL\static (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\344stat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\TooltipXML (Adware.Agent) -> Files: 1179 -> Delete on reboot.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2 (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\PersonalAntiSpy (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\PersonalAntiSpy\Data (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\VirusRemover2008 (Rogue.VirusRemover) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\VirusRemover2008\Logs (Rogue.VirusRemover) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\gcqltg.dll (Trojan.Zlob.H) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll (Adware.Shopper) -> Delete on reboot.
C:\WINDOWS\Downloaded Program Files\UPAS_0001_N93M1306NetInstaller.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\CoreSrv.dll (Adware.Zango) -> Delete on reboot.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Program Files\Applications\iebr.dll (Trojan.Zlob) -> Delete on reboot.
C:\Program Files\Applications\iebt.dll (Trojan.Zlob) -> Delete on reboot.
C:\WINDOWS\system32\512686\512686.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\brF.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpb.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmph.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpj.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Program Files\SecureIT\SCMonitor\quarantine\~tmps.exe.scavm (Trojan.Agent) -> Delete on reboot.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP129\A0044368.exe (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP129\A0044370.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP129\A0044371.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP129\A0045049.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP131\A0046640.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0049170.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0049202.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0050272.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0050420.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0050422.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP134\A0050424.dll (Rogue.PersonalAntiSpy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP135\A0050628.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{FAF3A79F-981E-49D5-8191-87F38A83E320}\RP141\A0053820.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\scui.cpl (Rogue.XPantivirus) -> Quarantined and deleted successfully.
C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\arrow.ico (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\copyright.txt (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\HostIE.dll (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\link.ico (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\Toolbar.dll (Adware.180Solutions) -> Delete on reboot.
C:\Program Files\Zango\bin\10.3.75.0\Weather.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\WeSkin.dll (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\ZangoSAAX.dll (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\ZangoSAHook.dll (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\chrome.manifest (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\install.rdf (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\Zango\bin\10.3.75.0\firefox\extensions\components\npclntax.xpt (Adware.180Solutions) -> Quarantined and deleted successfully.
C:\Program Files\ShoppingReport\Uninst.exe (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History\search2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images\07754512.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images\077C2AC1.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images\f3wallpp.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\ScreenSaver\Images\wrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\WAV\Uninstall.exe (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\WAV\WAV1.dat (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\Program Files\UAV\UAV.cpl (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\UAV\uav.ooo (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
C:\Program Files\UAV\UAV1.dat (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\NetworkService\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAau.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSAEula.mht (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\ZangoSA\ZangoSA_kyf.dat (Adware.Zango) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\eskin\empty_bg_st.htm (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\eskin\FileManager.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1022703.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1027908.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1050749.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1055540.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1055749.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1055791.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1055795.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1056077.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1056875.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1057182.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1057221.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1058230.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1059553.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1059772.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1060004.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1064782.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1065003.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1066272.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1066422.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1066750.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1067625.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1070198.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1097994.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1168802.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\118843.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1197683.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1281592.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1298431.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1320552.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1338673.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1383747.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1383771.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1385390.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1385751.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1386047.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1386551.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1387572.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1388487.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1388761.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1389151.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1389807.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1390361.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1391571.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1392559.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1393321.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1395796.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1396657.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1400106.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1400602.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1400879.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1402008.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1402414.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1405222.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1405982.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1406401.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1537613.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1562194.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\160699.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\169190.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\1840276.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\188485.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\205037.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2153895.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\216253.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2208948.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\221540.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2461570.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2590073.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\282540.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\286877.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2881352.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2883568.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2883915.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2884426.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2884484.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2884488.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2885069.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2893654.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2894792.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2896084.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2897171.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2899625.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2899627.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\2901962.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\293965.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\314276.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3240891.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3251993.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3277710.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3305670.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\330656.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3316271.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3320550.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\332144.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3332798.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3339582.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3340762.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3347275.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3351516.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3372080.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\338253.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3383342.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3384337.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3399375.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3426404.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3428586.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3429068.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\346907.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3471272.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3474772.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\350739.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\368333.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3720795.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3756134.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3756141.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\379000.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\380258.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852201.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852203.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852348.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3852706.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\385434.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3859864.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3862047.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3862708.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3863025.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3863038.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3864497.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3865689.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3866435.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3866547.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3874857.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893180.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893401.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893469.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893553.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893642.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3893972.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894020.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894066.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894095.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894099.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894272.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894488.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\3894699.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\401301.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\414482.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\420374.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\427607.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\465741.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\483647.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\48657.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\489874.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\506210.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\515176.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\516629.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\527853.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\575671.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\600583.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\612740.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\620184.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\625696.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\631547.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\632810.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\63804.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\648665.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\64961.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\651008.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\655531.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\667482.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\687752.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\693171.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\69361.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\698191.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\719189.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\738318.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\811121.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\830831.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\859800.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\86092.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\875951.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\890068.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\914376.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\920086.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\929314.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\935350.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\939832.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\965301.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\965522.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\971957.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\972052.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\987997.sdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\domains.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\dynamic\ustat\f8e3.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans.idx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\btntrans1.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\buttondir.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\components.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\cursors.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\default.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_511745-514279.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_categorize.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_comparison.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-Mails.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_explorer-people.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_favorites.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Games.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hide.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Hotmail.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_hsskin.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_Mails.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_new.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_premium.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchfor.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_searchgo.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_weather.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Default_yellowpages.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\d_icons_buttons_1000.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-548964.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\email-def-511724-9595.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\email-t1-bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_games_icon.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\ie_video.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords.idx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\keywords1.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\layout.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\linkpathlegal.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\sales_buttons.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\seekmo_ie_menu.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\s_icons_buttons.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\t2_bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\theweb.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\top7.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\Top7_theweb.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\1\tsd_bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans.idx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\btntrans1.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\buttondir.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\components.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\cursors.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\default.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_511745-514279.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_categorize.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_comparison.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-Mails.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_explorer-people.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_favorites.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Games.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hide.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Hotmail.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_hsskin.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_Mails.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_new.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_premium.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchfor.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_searchgo.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_weather.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Default_yellowpages.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\d_icons_buttons_1000.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-548964.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\email-def-511724-9595.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\email-t1-bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_games_icon.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\ie_video.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords.idx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\keywords1.dat (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\layout.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\linkpathlegal.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\sales_buttons.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\seekmo_ie_menu.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\s_icons_buttons.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\t2_bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\theweb.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\top7.cdf (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\Top7_theweb.mnu (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\2\tsd_bg.res (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\BtnTrans1.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\buttondir.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\cursors.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\default.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_1000.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_2000.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_3000.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\d_icons_buttons_bbar1.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\email-t1-bg.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_games_icon.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\ie_video.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.idx (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\keywords1.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\layout.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\linkpathlegal.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\sales_buttons.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.txt (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\samplegroups2.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\seekmo_ie_menu.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\t2_bg.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\top7.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\Seekmo\v3.0\Seekmo\static\DownLoad\tsd_bg.xip (Adware.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA.dat (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAAbout.mht (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAau.dat (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSAEULA.mht (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\SeekmoSA\SeekmoSA_kyf.dat (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Reset Cursor.lnk (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Customer Support Center.lnk (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Seekmo\Seekmo Uninstall Instructions.lnk (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\2ACA5CC3-0F83-453D-A079-1076FE1A8B65\ProfileReg.dat (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Application Data\VirusRemover2008\Logs\scns.log (Rogue.VirusRemover) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\UAV.cpl (Rogue.UltimateAntivirus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\WAV.cpl (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\e4asjEg0.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winsrc.dll (Adware.Toolbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\xxx1550.exe (Trojan.FakeAlert) -> Delete on reboot.
C:\Program Files\Applications\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Program Files\Applications\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpe.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpg.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpi.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpn.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpo.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmpr.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Local Settings\Temp\~tmps.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Antivirus Scan.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Online Spyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
C:\Documents and Settings\Valued Person\Favorites\Antivirus Scan.url (Rogue.Link) -> Quarantined and deleted successfully.


And here is the Uninstall List:

Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player ActiveX
Adobe Reader 9
Adobe Shockwave Player
Broadcom Management Programs
Candy Land - Dora the Explorer Edition
CCHelp
CCScore
Compatibility Pack for the 2007 Office system
DSC Driver
ESSAdpt
ESSANUP
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSvpaht
ESSvpot
GamingSquared Console
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
HLPIndex
HLPRFO
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Intel(R) Extreme Graphics Driver
Java(TM) 6 Update 5
Java(TM) 6 Update 7
JohnQ TV Remote Toolbar
Kodak EasyShare software
KSU
Malwarebytes' Anti-Malware
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSXML 4.0 SP2 (KB936181)
Notifier
OTtBP
OTtBPSDK
PCDADDIN
PCDHELP
PCDLNCH
PDF Complete
QuickTime
SecureIT
Security Advisor
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB958644)
SFR
SFR2
Software Setup
SoundMAX
Symantec Technical Support Web Controls
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Verizon Online Help and Support
Verizon Servicepoint 1.5.20
Virtools 3D Life Player
VPRINTOL
WeatherBug
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3

I will reply back with the HiJackThis Log.(I need to check into your notes on how to do this)
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm

Re: Please Help...my computers being attacked

Unread postby PamelaJG » November 10th, 2008, 2:54 pm

Here is the HiJackThis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:53:44 PM, on 11/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\SecureIT\scmonitor\SCMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\PDF Complete\pdfsty.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\GamingSquared\Gaming2\G2.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\SecureIT\SCControlPanel.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Valued Person\My Documents\My Pictures\PAMS PICS\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\PDF Complete\pdfsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O2 - BHO: (Gaming)2 - {971F630E-AD68-4d6e-B0C3-1C627AAC80F1} - C:\Program Files\GamingSquared\Gaming2\G2IE_v1042.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: VResLabWarningBHO Class - {B494E7BB-1E33-4922-A947-F74EFF4E714F} - C:\Program Files\VResLab\VResLabWarning.dll (file missing)
O2 - BHO: SecurityCoverage Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - C:\Program Files\SecureIT\PopupBlocker.dll
O3 - Toolbar: JohnQ TV Remote Toolbar - {7ae48414-1d85-44a1-8e46-5c3516c53584} - C:\Program Files\JohnQ_TV_Remote\tbJohn.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Clock knob fast okay] C:\Documents and Settings\All Users\Application Data\Idle Skip Clock Knob\joy hold.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.406.0\OEAddOn.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [G2] "C:\Program Files\GamingSquared\Gaming2\G2.exe"
O4 - HKLM\..\Run: [VerizonServicepoint.exe] "C:\Program Files\Verizon\VSP\VerizonServicepoint.exe" /AUTORUN
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.3.75.0\OEAddOn.exe
O4 - HKLM\..\Run: [ZangoSA] "C:\Program Files\Zango\bin\10.3.75.0\ZangoSA.exe"
O4 - HKLM\..\Run: [SCControlPanel] C:\Program Files\SecureIT\SCControlPanel.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [sect book] C:\DOCUME~1\VALUED~1\APPLIC~1\ONLINE~1\linkinfomess.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [VResLab] "C:\Program Files\VResLab\VResLab.exe"
O4 - HKUS\S-1-5-18\..\Run: [ieupdate] "C:\WINDOWS\system32\ieexplorer32.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ieupdate] "C:\WINDOWS\system32\ieexplorer32.exe" (User 'Default user')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Documents and Settings\Valued Person\My Documents\My Pictures\PAMS PICS\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 4556153187
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player ... taller.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/active ... anager.CAB
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files\PDF Complete\pdfsvc.exe
O23 - Service: SecureIT Monitor (SCMonitor) - Security Coverage Inc. - C:\Program Files\SecureIT\scmonitor\SCMonitorService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 7653 bytes


THANK YOU!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm

Re: Please Help...my computers being attacked

Unread postby PamelaJG » November 10th, 2008, 2:57 pm

Was it possible that any of these infections & viruses (Trojan) was capable of taking info & docs/pics from my computer?
PamelaJG
Active Member
 
Posts: 11
Joined: October 29th, 2008, 4:12 pm

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 12th, 2008, 3:24 pm

Hi :)

Here is the uninstall list you requested: The HiJackThis Log is below. Thank You for the fast reply!! It is greatly appreciated!!

THANK YOU!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Was it possible that any of these infections & viruses (Trojan) was capable of taking info & docs/pics from my computer?

I took the liberty of placing all in on quote, so I can answer/reply to all at once.

OK firstly you are very welcome!

The types of infections that were(are) present are not of the nature you inquired about I can assure you at this point in time. I hope this piece of news is what you wished to learn. We have made a good in-roads however to cleaning your computer.

Next:

There is indication from the Malwarebytes' Anti-Malware log you have not re-booted(re-started) your computer to continue the disinfection process. Do not be alarmed by this ok please. The aforementioned application has removed many malware infections from your computer and just needs this simple task to complete all ok :)

Now please Re-boot(re-start) your computer.

Malwarebytes' Anti-Malware should now produce a new log for you, if it does not however please carry out the following:

Launch Malwarebytes' Anti-Malware and click on the Logs radio tab.

Note: The newest log should be dated the appropiate dd/mm/yr time you carry this out.

Next:

Now please go to Start >> Control Panel >> Add/Remove Programs and remove the following (if present):

Java(TM) 6 Update 5
WeatherBug


When completed the above, please post back the following:

  • Malwarebytes Anti-malware Log.
  • A new HijackThis Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby Dakeyras » November 14th, 2008, 2:59 pm

Hi :)

Do you still need help with your machine?

If the instructions are unclear or something isn't working, please let me know before proceeding.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help...my computers being attacked

Unread postby NonSuch » November 17th, 2008, 7:17 pm

Due to lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 27300
Joined: February 23rd, 2005, 7:08 am
Location: California
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 50 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware