Thanks for your ongoing help Dan. My computer has been running much better the past few days. I havent had any popups but occasionally McAfee will find a PUP. I followed all your instructions from the previous post and here are my logs:
Logfile of HijackThis v1.99.1
Scan saved at 8:55:33 PM, on 9/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dextroman\Desktop\Dustin's Stuff\Programs\Spyware Removal\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINDOWS\system32\hvjkt.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\system32\hvjkt.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINDOWS\system32\hvjkt.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = actsvr.comcastonline.com:8100
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = cdn
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV Media\TvmBho.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [zango] c:\program files\zango\zango.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [VBundleOuterDL] C:\Program Files\VBouncer\BundleOuter.EXE
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKCU\..\Run: [Fmzmojx] C:\WINDOWS\System32\w?nspool.exe
O4 - HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher-free\FreeScanner.exe -FastScan
O4 - HKCU\..\Run: [gBt6RfNtQ] imjlv.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - Global Startup: Wireless-B PCI Adapter Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe
O8 - Extra context menu item: &AIM Search -
res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Help - {1EF19158-E131-41ED-ACA3-A93CA4F121FE} -
http://www.comcast.net/memberservices/ (file missing) (HKCU)
O9 - Extra button: Support - {D03B89FA-397C-49D2-97C2-469C4331180A} -
http://www.comcastsupport.com (file missing) (HKCU)
O9 - Extra button: ComcastHSI - {F637BADC-39B6-485A-896D-553EA2E0A160} -
http://www.comcast.net (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.05p.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.my-internet.info (HKLM)
O15 - Trusted Zone: *.scoobidoo.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted IP range: 206.161.125.149
O15 - Trusted IP range: 206.161.124.130 (HKLM)
O16 - DPF: {10000000-1000-0000-1000-000000000000} -
file://C:\Program Files\Internet Explorer\nwa.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/share ... insctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftup ... 8506398186
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -
http://download.websearch.com/Dnl/T_50020/QDow_AS2.cab
O16 - DPF: {99410CDE-6F16-42CE-9D49-3807F78F0287} (ZangoInstaller Class) -
http://www.zango.com/getzango/download/ ... taller.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com/ewfrf-JAVA/S ... anager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://download.mcafee.com/molbin/share ... cgdmgr.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} -
http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4} (IObjSafety.DemoCtl) -
http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX/kdx.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: NICSer_WMP11 - Unknown owner - C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 8:10:20 PM 9/25/2006
+ Scan result:
C:\Documents and Settings\Dextroman\Cookies\dextroman@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Dextroman\Cookies\dextroman@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
::Report end
AboutBuster 6.05
Scan started on [9/25/2006] at [8:58:34 PM]
-------------------------------------------------------------
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
-------------------------------------------------------------
Removed Stream! C:\WINDOWS\aamqv.log:ielxd
Removed Stream! C:\WINDOWS\bootstat.dat:bhfel
Removed Stream! C:\WINDOWS\cyfqb.log:niiny
Removed Stream! C:\WINDOWS\DIIUnin.exe:uqdnj
Removed Stream! C:\WINDOWS\DtcInstall.log:mzhon
Removed Stream! C:\WINDOWS\DtcInstall.log:qiqwg
Removed Stream! C:\WINDOWS\FeatherTexture.bmp:faztp
Removed Stream! C:\WINDOWS\Gone Fishing.bmp:awqza
Removed Stream! C:\WINDOWS\iun6002.exe:fnopy
Removed Stream! C:\WINDOWS\iun6002.exe:zexni
Removed Stream! C:\WINDOWS\KB828741.log:reisc
Removed Stream! C:\WINDOWS\KB840987.log:kfaye
Removed Stream! C:\WINDOWS\msgsocm.log:fplnd
Removed Stream! C:\WINDOWS\msgsocm.log:trqgj
Removed Stream! C:\WINDOWS\npudt.dat:twvgj
Removed Stream! C:\WINDOWS\ntdtcsetup.log:xqesx
Removed Stream! C:\WINDOWS\n_exhfbl.txt:dfhnxd
Removed Stream! C:\WINDOWS\ocgen.log:agjuf
Removed Stream! C:\WINDOWS\ocgen.log:mgsyl
Removed Stream! C:\WINDOWS\OEWABLog.txt:fhldf
Removed Stream! C:\WINDOWS\ofdbz.log:shcza
Removed Stream! C:\WINDOWS\oibxn.txt:lfjox
Removed Stream! C:\WINDOWS\Q323255.log:rhytd
Removed Stream! C:\WINDOWS\Q329170.log:ghfmo
Removed Stream! C:\WINDOWS\Q329170.log:kzrzf
Removed Stream! C:\WINDOWS\Q810577.log:cabez
Removed Stream! C:\WINDOWS\Q817606.log:ilzzp
Removed Stream! C:\WINDOWS\regopt.log:teckl
Removed Stream! C:\WINDOWS\regopt.log:wvjvf
Removed Stream! C:\WINDOWS\River Sumida.bmp:pwcji
Removed Stream! C:\WINDOWS\SchedLgU.Txt:hxmoc
Removed Stream! C:\WINDOWS\setupapi.log:rzflz
Removed Stream! C:\WINDOWS\Soap Bubbles.bmp:kayqb
Removed Stream! C:\WINDOWS\SYMEVENT.LOG:cbjvv
Removed Stream! C:\WINDOWS\SYMEVENT.LOG:lpivb
Removed Stream! C:\WINDOWS\system.ini:dqbiv
Removed Stream! C:\WINDOWS\system.tmp:dqbiv
Removed Stream! C:\WINDOWS\tempf.txt:uzyqmn
Removed Stream! C:\WINDOWS\twain.dll:oodyl
Removed Stream! C:\WINDOWS\twain.dll:qjbij
Removed Stream! C:\WINDOWS\twain.dll:wqlnp
Removed Stream! C:\WINDOWS\twunk_16.exe:hpndn
Removed Stream! C:\WINDOWS\twunk_16.exe:jcunl
Removed Stream! C:\WINDOWS\unvise32qt.exe:bdmsf
Removed Stream! C:\WINDOWS\uqnvu.log:majdgy
Removed Stream! C:\WINDOWS\usta32.ini:rqyoj
Removed Stream! C:\WINDOWS\vb.ini:zxjyqo
Removed Stream! C:\WINDOWS\vjuvs.txt:rxcdsq
Removed Stream! C:\WINDOWS\vmmreg32.dll:fttic
Removed Stream! C:\WINDOWS\win.ini:exvyp
Removed Stream! C:\WINDOWS\win.ini:xumve
Removed Stream! C:\WINDOWS\win.tmp:exvyp
Removed Stream! C:\WINDOWS\win.tmp:xumve
Removed Stream! C:\WINDOWS\winamp.ini:cqujmb
Removed Stream! C:\WINDOWS\Windows Update.log:wyolr
Removed Stream! C:\WINDOWS\winhelp.exe:pzhql
Removed Stream! C:\WINDOWS\wininit.ini:bruot
Removed Stream! C:\WINDOWS\wininit.ini:scllg
Removed Stream! C:\WINDOWS\wininit.sd:bruot
Removed Stream! C:\WINDOWS\wininit.sd:scllg
Removed Stream! C:\WINDOWS\winnt256.bmp:sophi
Removed Stream! C:\WINDOWS\winnt256.bmp:usmbv
Removed Stream! C:\WINDOWS\Zapotec.bmp:wqgmz
Removed Stream! C:\WINDOWS\Zapotec.bmp:wwhbw
Removed Stream! C:\WINDOWS\_default.pif:ggwjds
Removed Stream! C:\WINDOWS\_default.pif:ofdeih
Removed Stream! C:\WINDOWS\_default.pif:zhopfc
-------------------------------------------------------------
Removed File! : C:\WINDOWS\aamqv.log
Removed File! : C:\WINDOWS\apofy.dat
Removed File! : C:\WINDOWS\blyjb.log
Removed File! : C:\WINDOWS\cbgep.txt
Removed File! : C:\WINDOWS\cyfqb.log
Removed File! : C:\WINDOWS\ffcwm.txt
Removed File! : C:\WINDOWS\gvomh.dat
Removed File! : C:\WINDOWS\hgnxi.txt
Removed File! : C:\WINDOWS\hpeky.txt
Removed File! : C:\WINDOWS\hzpre.txt
Removed File! : C:\WINDOWS\imhds.log
Removed File! : C:\WINDOWS\inume.log
Removed File! : C:\WINDOWS\jkfeh.log
Removed File! : C:\WINDOWS\jvufs.log
Removed File! : C:\WINDOWS\khchv.txt
Removed File! : C:\WINDOWS\khpcf.dat
Removed File! : C:\WINDOWS\kqyxq.txt
Removed File! : C:\WINDOWS\naics.txt
Removed File! : C:\WINDOWS\npudt.dat
Removed File! : C:\WINDOWS\n_axmjjk.log
Removed File! : C:\WINDOWS\n_bdnrcx.dat
Removed File! : C:\WINDOWS\n_bvwkvg.txt
Removed File! : C:\WINDOWS\n_cqlavy.dat
Removed File! : C:\WINDOWS\n_exhfbl.txt
Removed File! : C:\WINDOWS\n_fxgkci.dat
Removed File! : C:\WINDOWS\n_gfdaub.dat
Removed File! : C:\WINDOWS\n_ghjlja.log
Removed File! : C:\WINDOWS\n_grkxfx.dat
Removed File! : C:\WINDOWS\n_hjryfa.txt
Removed File! : C:\WINDOWS\n_hjsbuh.log
Removed File! : C:\WINDOWS\n_jawddv.txt
Removed File! : C:\WINDOWS\n_jybotj.txt
Removed File! : C:\WINDOWS\n_mazjhi.log
Removed File! : C:\WINDOWS\n_mhfthg.txt
Removed File! : C:\WINDOWS\n_ncesxz.dat
Removed File! : C:\WINDOWS\n_ngxfgz.log
Removed File! : C:\WINDOWS\n_nkdspc.log
Removed File! : C:\WINDOWS\n_nnbfot.dat
Removed File! : C:\WINDOWS\n_nsxbio.log
Removed File! : C:\WINDOWS\n_oiofvn.txt
Removed File! : C:\WINDOWS\n_ovgftt.txt
Removed File! : C:\WINDOWS\n_pqskkf.txt
Removed File! : C:\WINDOWS\n_pyepup.log
Removed File! : C:\WINDOWS\n_qtrynl.dat
Removed File! : C:\WINDOWS\n_qvcavf.log
Removed File! : C:\WINDOWS\n_qxfzed.log
Removed File! : C:\WINDOWS\n_stowod.log
Removed File! : C:\WINDOWS\n_uliiuh.txt
Removed File! : C:\WINDOWS\n_xleemi.log
Removed File! : C:\WINDOWS\n_xmfknd.txt
Removed File! : C:\WINDOWS\n_ybfaxx.log
Removed File! : C:\WINDOWS\n_zpyhtx.txt
Removed File! : C:\WINDOWS\n_zrrbom.log
Removed File! : C:\WINDOWS\n_zsogka.log
Removed File! : C:\WINDOWS\ofdbz.log
Removed File! : C:\WINDOWS\oibxn.txt
Removed File! : C:\WINDOWS\onsmx.log
Removed File! : C:\WINDOWS\oqykc.log
Removed File! : C:\WINDOWS\qnekj.log
Removed File! : C:\WINDOWS\qygza.dat
Removed File! : C:\WINDOWS\rkosb.log
Removed File! : C:\WINDOWS\sabpn.log
Removed File! : C:\WINDOWS\soqpy.log
Removed File! : C:\WINDOWS\tbmut.dat
Removed File! : C:\WINDOWS\uoxpp.dat
Removed File! : C:\WINDOWS\uqnvu.log
Removed File! : C:\WINDOWS\vbgss.dat
Removed File! : C:\WINDOWS\vjuvs.txt
Removed File! : C:\WINDOWS\wsccq.txt
Removed File! : C:\WINDOWS\xuuri.dat
Removed File! : C:\WINDOWS\ywexb.dat
Removed File! : C:\WINDOWS\zejsk.dat
Removed File! : C:\WINDOWS\zfrih.dat
Removed File! : C:\WINDOWS\zpxxa.log
Removed File! : C:\WINDOWS\zxrzd.log
Removed File! : C:\WINDOWS\zzijl.dat
Removed File! : C:\WINDOWS\system32\anzqu.txt
Removed File! : C:\WINDOWS\system32\aszxg.dat
Removed File! : C:\WINDOWS\system32\avekr.dat
Removed File! : C:\WINDOWS\system32\bebkp.txt
Removed File! : C:\WINDOWS\system32\bnnah.log
Removed File! : C:\WINDOWS\system32\cdrlp.log
Removed File! : C:\WINDOWS\system32\dichq.log
Removed File! : C:\WINDOWS\system32\dinnq.dat
Removed File! : C:\WINDOWS\system32\dizhh.log
Removed File! : C:\WINDOWS\system32\dkllt.txt
Removed File! : C:\WINDOWS\system32\emzhv.dat
Removed File! : C:\WINDOWS\system32\etukt.log
Removed File! : C:\WINDOWS\system32\fimjv.dat
Removed File! : C:\WINDOWS\system32\gdxfo.txt
Removed File! : C:\WINDOWS\system32\gfwht.txt
Removed File! : C:\WINDOWS\system32\gomtq.txt
Removed File! : C:\WINDOWS\system32\hvlfp.txt
Removed File! : C:\WINDOWS\system32\iopyd.dat
Removed File! : C:\WINDOWS\system32\ipeaw.txt
Removed File! : C:\WINDOWS\system32\jaicw.txt
Removed File! : C:\WINDOWS\system32\kanrn.txt
Removed File! : C:\WINDOWS\system32\kqqcv.txt
Removed File! : C:\WINDOWS\system32\kzusa.txt
Removed File! : C:\WINDOWS\system32\ljkcw.log
Removed File! : C:\WINDOWS\system32\lqqsu.log
Removed File! : C:\WINDOWS\system32\mcean.txt
Removed File! : C:\WINDOWS\system32\mpqkd.log
Removed File! : C:\WINDOWS\system32\nsgta.log
Removed File! : C:\WINDOWS\system32\ofuro.txt
Removed File! : C:\WINDOWS\system32\okmik.txt
Removed File! : C:\WINDOWS\system32\olodp.txt
Removed File! : C:\WINDOWS\system32\qdyra.log
Removed File! : C:\WINDOWS\system32\qvnxc.log
Removed File! : C:\WINDOWS\system32\rgcvc.dat
Removed File! : C:\WINDOWS\system32\ruyln.log
Removed File! : C:\WINDOWS\system32\rxpcd.dat
Removed File! : C:\WINDOWS\system32\shqpe.txt
Removed File! : C:\WINDOWS\system32\sjzwc.dat
Removed File! : C:\WINDOWS\system32\stxwp.txt
Removed File! : C:\WINDOWS\system32\sxcxe.dat
Removed File! : C:\WINDOWS\system32\tpaia.txt
Removed File! : C:\WINDOWS\system32\trsfr.log
Removed File! : C:\WINDOWS\system32\uarrn.txt
Removed File! : C:\WINDOWS\system32\ufupr.txt
Removed File! : C:\WINDOWS\system32\uingy.dat
Removed File! : C:\WINDOWS\system32\umixd.log
Removed File! : C:\WINDOWS\system32\vmtox.dat
Removed File! : C:\WINDOWS\system32\vsfdw.dat
Removed File! : C:\WINDOWS\system32\vzppy.log
Removed File! : C:\WINDOWS\system32\whjrl.txt
Removed File! : C:\WINDOWS\system32\wpnxi.log
Removed File! : C:\WINDOWS\system32\wufqv.txt
Removed File! : C:\WINDOWS\system32\xlesv.log
Removed File! : C:\WINDOWS\system32\xnthz.txt
Removed File! : C:\WINDOWS\system32\xywek.txt
Removed File! : C:\WINDOWS\system32\zfqsj.txt
Removed File! : C:\WINDOWS\system32\znzsb.dat
Removed File! : C:\WINDOWS\system32\zsjvz.log
-------------------------------------------------------------
Removed Temp Files
Internet Explorer Settings Reset!
-------------------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 9:00:41 PM