WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionPC infected with Antivirus system pro EmptyPC infected with Antivirus system pro

more_horiz
Have picked up this nasty today. I've tried to download Malwarebytes Anti Malware, PC Doctor and Hijack This but it will not allow me to run them, it says they are infected files. I think the only reason I can get online at all is that I am using Firefox as a browser. It has blocked Explorer in the same way as the anti malware programs.
Any suggestions gratefully received.

Dave

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hello.
Did you try this renamed version of Hijack This?
http://www.sendspace.com/pro/dl/fpzz64

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hi

I just tried it but it tells me that this file is infected too! These things are damn scary.

Dave

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Lets try this instead.

Please download SilentRunners from here:
http://www.silentrunners.org/Silent%20Runners.zip
Unzip it to the desktop and double-click on it. If you get any kind of warning message about scripts, please choose to allow the script to run. When the scan is finished, a message will pop up and a logfile will have been created on the desktop. Please post the entire contents of this logfile for me to see.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
"Silent Runners.vbs", revision 59, http://www.silentrunners.org/
Operating System: Windows XP
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"MsnMsgr" = ""C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background" [MS]
"ErrorFix" = "C:\Program Files\ErrorFix\ErrorFix.exe -boot" [file not found]
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"system tool" = "C:\Program Files\mlfauc\jclqsysguard.exe" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SoundMAXPnP" = "C:\Program Files\Analog Devices\Core\smax4pnp.exe" ["Analog Devices, Inc."]
"IntelMeM" = "C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" ["Intel Corporation"]
"DVDLauncher" = ""C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"" ["CyberLink Corp."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"dla" = "C:\WINDOWS\system32\dla\tfswctrl.exe" ["Sonic Solutions"]
"ISUSScheduler" = ""C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start" ["InstallShield Software Corporation"]
"igfxtray" = "C:\WINDOWS\system32\igfxtray.exe" ["Intel Corporation"]
"igfxhkcmd" = "C:\WINDOWS\system32\hkcmd.exe" ["Intel Corporation"]
"igfxpers" = "C:\WINDOWS\system32\igfxpers.exe" ["Intel Corporation"]
"Lexmark 1200 Series" = ""C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"" ["Lexmark International, Inc."]
"avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" ["ALWIL Software"]
"btbb_McciTrayApp" = ""C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe"" ["Motive Communications, Inc."]
"btbb_wcm_McciTrayApp" = ""C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe"" ["Motive Communications, Inc."]
"EPGServiceTool" = "C:\PROGRA~1\WinTV\EPG Services\System\EPGClient.exe" ["Hauppauge Inc."]
"system tool" = "C:\Program Files\mlfauc\jclqsysguard.exe" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
-> {HKLM...CLSID} = "&Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{22E1EFF7-D8DD-4bbc-9CE8-87EDBE8C1A40}\(Default) = (no title provided)
-> {HKLM...CLSID} = "BHO"
\InProcServer32\(Default) = "C:\WINDOWS\system32\iehelper.dll" [null data]
{3049C3E9-B461-4BC5-8870-4C09146192CA}\(Default) = (no title provided)
-> {HKLM...CLSID} = "RealPlayer Download and Record Plugin for Internet Explorer"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll" ["RealPlayer"]
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll" ["Yahoo! Inc."]
{5CA3D70E-1895-11CF-8E15-001234567890}\(Default) = (no title provided)
-> {HKLM...CLSID} = "DriveLetterAccess"
\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["Sonic Solutions"]
{9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Sign-in Helper"
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll" ["Google Inc."]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Notifier BHO"
\InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll" ["Google Inc."]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Windows Live Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]
{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}\(Default) = "Google Dictionary Compression sdch"
-> {HKLM...CLSID} = "Google Dictionary Compression sdch"
\InProcServer32\(Default) = "C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll" ["Google Inc."]
{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\(Default) = "JQSIEStartDetectorImpl"
-> {HKLM...CLSID} = "JQSIEStartDetectorImpl Class"
\InProcServer32\(Default) = "C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
-> {HKLM...CLSID} = "DriveLetterAccess"
\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["Sonic Solutions"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "My Sharing Folders"
\InProcServer32\(Default) = "C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {HKLM...CLSID} = "Yahoo! Mail Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\Ymmapi.dll" ["Yahoo! Inc."]
"{11016101-E366-4D22-BC06-4ADA335C892B}" = "IE History and Feeds Shell Data Source for Windows Search"
-> {HKLM...CLSID} = "IE History and Feeds Shell Data Source for Windows Search"
\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<> GoToAssist\DLLName = "C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll" ["Citrix Online, a ~[Filtered HTML]~ of Citrix Systems, Inc."]
<> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {HKLM...CLSID} = "Yahoo! Mail Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Common\Ymmapi.dll" ["Yahoo! Inc."]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations\

"LowRiskFileTypes" = (REG_SZ) .exe
{unrecognized setting}

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments\

"SaveZoneInformation" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\

"NoCDBurning" = (REG_DWORD) dword:0x00000000
{unrecognized setting}

"HonorAutoRunSetting" = (REG_DWORD) dword:0x00000001
{unrecognized setting}

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

dȋsplay if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

dȋsplay if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Dave\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

DMXPlayCD\
"Provider" = "Dell Media Experience"
"InvokeProgID" = "DMX.PLAYCD"
"InvokeVerb" = "Play"
HKLM\SOFTWARE\Classes\DMX.PLAYCD\shell\Play\Command\(Default) = "C:\Program Files\Dell\Media Experience\DMX.exe Music "Play %1"" [null data]

DMXPlayDVD\
"Provider" = "Dell Media Experience"
"InvokeProgID" = "DMX.PLAYDVD"
"InvokeVerb" = "Play"
HKLM\SOFTWARE\Classes\DMX.PLAYDVD\shell\Play\Command\(Default) = "C:\Program Files\Dell\Media Experience\DMX.exe DVD "Play %1"" [null data]

Jasc Paint Shop Photo Album 5HandleCDBurningOnArrival\
"Provider" = "Jasc Paint Shop Photo Album 5"
"InvokeProgID" = "JascPaintShopPhotoAlbumFolder"
"InvokeVerb" = "BurnCD"
HKLM\SOFTWARE\Classes\JascPaintShopPhotoAlbumFolder\shell\BurnCD\command\(Default) = "C:\PROGRA~1\JASCSO~1\PAINTS~1\pspa.exe -burncdlaunch" ["Jasc Software"]

Jasc Paint Shop Photo Album 5ShowPicturesOnArrivalHandler\
"Provider" = "Jasc Paint Shop Photo Album 5"
"InvokeProgID" = "JascPaintShopPhotoAlbumFolder"
"InvokeVerb" = "open"
HKLM\SOFTWARE\Classes\JascPaintShopPhotoAlbumFolder\shell\open\command\(Default) = "C:\PROGRA~1\JASCSO~1\PAINTS~1\pspa.exe "%1"" ["Jasc Software"]

MSWPDShellNamespaceHandler\
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = " "
-> {HKLM...CLSID} = "WPDShextAutoplay"
\LocalServer32\(Default) = "C:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]

PDVDPlayDVDMovieOnArrival\
"Provider" = "PowerDVD"
"InvokeProgID" = "DVD"
"InvokeVerb" = "PlayWithPowerDVD"
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithPowerDVD\Command\(Default) = ""C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe" MOVIE "%L"" ["CyberLink Corp."]

RPCDBurningOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.CDBurn.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.CDBurn.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /burn "%1"" ["RealNetworks, Inc."]

RPDeviceOnArrival\
"Provider" = "RealPlayer"
"ProgID" = "RealPlayer.HWEventHandler"
HKLM\SOFTWARE\Classes\RealPlayer.HWEventHandler\CLSID\(Default) = "{67E76F1D-BDE2-4052-913C-2752366192D2}"
-> {HKLM...CLSID} = "RealNetworks Scheduler"
\LocalServer32\(Default) = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -autoplay" ["RealNetworks, Inc."]

RPPlayCDAudioOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AudioCD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.AudioCD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /play %1 " ["RealNetworks, Inc."]

RPPlayDVDMovieOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.DVD.6"
"InvokeVerb" = "play"
HKCU\Software\Classes\RealPlayer.DVD.6\shell\play\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1 " ["RealNetworks, Inc."]

RPPlayMediaOnArrival\
"Provider" = "RealPlayer"
"InvokeProgID" = "RealPlayer.AutoPlay.6"
"InvokeVerb" = "open"
HKCU\Software\Classes\RealPlayer.AutoPlay.6\shell\open\command\(Default) = ""C:\Program Files\Real\RealPlayer\RealPlay.exe" /autoplay "%1"" ["RealNetworks, Inc."]

SonicSCAudioCDTask\
"Provider" = "Sonic RecordNow Audio"
"InvokeProgID" = "Sonic.SonicCentral"
"InvokeVerb" = "AudioCDTask"
HKLM\SOFTWARE\Classes\Sonic.SonicCentral\shell\AudioCDTask\Command\(Default) = ""C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe" /Launch {EBD22732-1CC3-4CD7-9A45-B8D98DA0E784}" [null data]

SonicSCCopyCD\
"Provider" = "Sonic RecordNow Copy"
"InvokeProgID" = "Sonic.SonicCentral"
"InvokeVerb" = "ExactCopyJob"
HKLM\SOFTWARE\Classes\Sonic.SonicCentral\shell\ExactCopyJob\Command\(Default) = ""C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe" /Launch {49B235A3-1C3E-4802-9B5C-BAFBE69A3C85}" [null data]

SonicSCCopyDisc\
"Provider" = "Sonic RecordNow Copy"
"InvokeProgID" = "Sonic.SonicCentral"
"InvokeVerb" = "ExactCopyJob"
HKLM\SOFTWARE\Classes\Sonic.SonicCentral\shell\ExactCopyJob\Command\(Default) = ""C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe" /Launch {49B235A3-1C3E-4802-9B5C-BAFBE69A3C85}" [null data]

SonicSCDataProject\
"Provider" = "Sonic RecordNow Data"
"InvokeProgID" = "Sonic.SonicCentral"
"InvokeVerb" = "DataGuide"
HKLM\SOFTWARE\Classes\Sonic.SonicCentral\shell\DataGuide\Command\(Default) = ""C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe" /Launch Data" [null data]

SonicSCDataTask\
"Provider" = "Sonic RecordNow Data"
"InvokeProgID" = "Sonic.SonicCentral"
"InvokeVerb" = "DataTask"
HKLM\SOFTWARE\Classes\Sonic.SonicCentral\shell\DataTask\Command\(Default) = ""C:\Program Files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe" /Launch {0BAC5C34-DF45-4C0F-8D64-8E92DCCF007D}" [null data]


Startup items in "Dave" & "All Users" startup folders:
------------------------------------------------------

C:\Documents and Settings\Dave\Start Menu\Programs\Startup
"Dreamspell Calendar (2)" -> shortcut to: "C:\DREAMSP\dreamsp.exe" [null data]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"AutoStart IR" -> shortcut to: "C:\Program Files\WinTV\Ir.exe /QUIET" ["Hauppauge Computer Works"]
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]


Enabled Scheduled Tasks:
------------------------

"Antispyware Scheduled Scan" -> launches: "C:\Program Files\AntiSpywareApp\AntiSpyware.exe scheduled" [file not found]
"Check Updates for Windows Live Toolbar" -> launches: "C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE" [MS]
"ErrorFix Scan" -> launches: "C:\Program Files\ErrorFix\ErrorFix.exe scheduled" [file not found]
"Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDetect.exe" [file not found]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "Google Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll" ["Google Inc."]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
-> {HKLM...CLSID} = "Windows Live Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "Google Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll" ["Google Inc."]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
-> {HKLM...CLSID} = "Windows Live Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = (no title provided)
-> {HKLM...CLSID} = "Windows Live Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Windows Live Toolbar\msntb.dll" [MS]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]
"{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}" = "ALOT Toolbar"
-> {HKLM...CLSID} = "ALOT Toolbar"
\InProcServer32\(Default) = "C:\Program Files\alot\bin\alot.dll" ["Miva"]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll" ["Google Inc."]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\
"ButtonText" = "BT Yahoo! Services"
"CLSIDExtension" = "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}"
-> {HKLM...CLSID} = "Yahoo! IE Services Button"
\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll" ["Yahoo! Inc."]

{9034A523-D068-4BE8-A284-9DF278BE776E}\
"MenuText" = "IE Anti-Spyware"
"Exec" = "http://www.safeiegate.com/redirect.php" [file not found]

{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\

{E2E2DD38-D088-4134-82B7-F2BA38496583}\
"MenuText" = "@xpsp3res.dll,-20001"
"Exec" = "%windir%\Network Diagnostic\xpnetdiag.exe" [MS]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[Strings]: MS_START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

Missing lines (compared with English-language version):
[Strings]: 2 lines

HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
<> "{4D25F926-B9FE-4682-BF72-8AB8210D6D75}" = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll" ["MyWay.com"]
<> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll" ["Yahoo! Inc."]

HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\
<> "InPrivate" = "res://ieframe.dll/inprivate.htm" [MS]


HOSTS file
----------

C:\WINDOWS\System32\drivers\etc\HOSTS

maps: 5 domain names to IP addresses,
3 of the IP addresses are *not* localhost!


Running Services (dȋsplay Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" ["ALWIL Software"]
avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
EPGService, EPGService, "C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe" ["Hauppauge Computer Works"]
Java Quick Starter, JavaQuickStarterService, ""C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"" ["Sun Microsystems, Inc."]
LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]
McciCMService, McciCMService, ""C:\Program Files\Common Files\Motive\McciCMService.exe"" ["Motive Communications, Inc."]
Messenger Sharing Folders USN Journal Reader service, usnjsvc, ""C:\Program Files\Windows Live\Messenger\usnsvc.exe"" [MS]

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hello.

Please download the OTMoveIt by OldTimer.

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :files
    C:\Program Files\alot
    C:\Program Files\MyWaySA
    C:\Program Files\mlfauc
    C:\Program Files\ErrorFix

    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ErrorFix"=-
    "system tool"=-
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "system tool"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22E1EFF7-D8DD-4bbc-9CE8-87EDBE8C1A40}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"=-
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{4D25F926-B9FE-4682-BF72-8AB8210D6D75}"=-


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
========== FILES ==========
C:\Program Files\alot\bin moved successfully.
C:\Program Files\alot moved successfully.
C:\Program Files\MyWaySA\SrchAsDe\1.bin moved successfully.
C:\Program Files\MyWaySA\SrchAsDe moved successfully.
C:\Program Files\MyWaySA moved successfully.
C:\Program Files\mlfauc moved successfully.
File/Folder C:\Program Files\ErrorFix not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\ErrorFix not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\system tool deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\system tool deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{22E1EFF7-D8DD-4bbc-9CE8-87EDBE8C1A40}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22E1EFF7-D8DD-4bbc-9CE8-87EDBE8C1A40}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks\\{4D25F926-B9FE-4682-BF72-8AB8210D6D75} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\ deleted successfully.

OTM by OldTimer - Version 3.0.0.6 log created on 09262009_200654

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Malwarebytes' Anti-Malware 1.41
Database version: 2863
Windows 5.1.2600 Service Pack 3

26/09/2009 20:56:50
mbam-log-2009-09-26 (20-56-50).txt

Scan type: Quick Scan
Objects scanned: 124041
Time elapsed: 11 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 26
Registry Values Infected: 5
Registry Data Items Infected: 0
Folders Infected: 4
Files Infected: 321

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{0ec085a8-9818-43b7-b975-ec7555eda4d2} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1a74c41c-0837-4fbe-ba50-621eb70f01ce} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{25297614-1b76-4c2c-82c6-62738aa0e8f0} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{37f89457-1208-4670-9245-58c62bd6d870} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{45477032-abd0-454d-9ce4-ea34c10322f8} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{69e34747-0b27-4b30-ae20-1023bf29e246} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{79be5b3b-80b2-4b77-a042-efc90f6e0de7} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7c0ec6bf-81b9-4fe0-9447-4ed29a36bf5d} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7ebb34cf-1728-4136-a968-48f231dad1b4} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{88daa291-b413-4c46-b378-3be66f65369e} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{936a2f4a-53f8-4d2f-92aa-2f9de889841c} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{afcc3fa7-82a9-42d5-a405-78711e97a5d6} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cc05a4a3-7b28-488f-ab02-6aaedb86accf} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e80114aa-6653-4952-9e97-5f1dc63bee0f} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f9109a2a-432b-4add-a6fa-06ba22dcd2d9} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fca3958a-8d38-4d14-8b81-ccd7f68a8a01} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{cbd02e9b-37ef-47d2-96b0-3abbb2eb92bf} (Rogue.VirusHeat) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijacker) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\multimediaControls.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\videoPl.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NetProject (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\Dave\Application Data\ErrorFix (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\Logs (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460 (Rogue.ErrorFix) -> Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\iehelper.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\resultsw.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\Logs\2009-03-16 19-12-030.log (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\filelist.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-0.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-1.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-10.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-100.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-101.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-102.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-103.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-104.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-105.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-106.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-107.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-108.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-109.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-11.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-110.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-111.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-112.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-113.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-114.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-115.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-116.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-117.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-118.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-119.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-12.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-120.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-121.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-122.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-123.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-124.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-125.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-126.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-127.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-128.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-129.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-13.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-130.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-131.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-132.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-133.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-134.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-135.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-136.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-137.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-138.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-139.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-14.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-140.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-141.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-142.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-143.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-144.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-145.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-146.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-147.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-148.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-149.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-15.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-150.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-151.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-152.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-153.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-154.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-155.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-156.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-157.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-158.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-159.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-16.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-160.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-161.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-162.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-163.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-164.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-165.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-166.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-167.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-168.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-169.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-17.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-170.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-171.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-172.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-173.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-174.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-175.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-176.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-177.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-178.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-179.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-18.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-180.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-181.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-182.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-183.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-184.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-185.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-186.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-187.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-188.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-189.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-19.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-190.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-191.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-192.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-193.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-194.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-195.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-196.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-197.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-198.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-199.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-2.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-20.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-200.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-201.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-202.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-203.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-204.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-205.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-206.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-207.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-208.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-209.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-21.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-210.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-211.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-212.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-213.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-214.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-215.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-216.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-217.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-218.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-219.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-22.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-220.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-221.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-222.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-223.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-224.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-225.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-226.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-227.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-228.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-229.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-23.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-230.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-231.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-232.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-233.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-234.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-235.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-236.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-237.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-238.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-239.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-24.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-240.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-241.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-242.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-243.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-244.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-245.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-246.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-247.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-248.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-249.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-25.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-250.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-251.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-252.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-253.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-254.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-255.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-256.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-257.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-258.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-259.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-26.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-260.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-261.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-262.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-263.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-264.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-265.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-266.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-267.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-268.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-269.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-27.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-270.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-271.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-272.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-273.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-274.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-275.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-276.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-277.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-278.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-279.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-28.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-280.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-281.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-282.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-283.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-284.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-285.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-286.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-287.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-288.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-289.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-29.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-290.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-291.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-292.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-293.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-294.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-295.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-296.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-297.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-298.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-299.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-3.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-30.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-300.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-301.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-302.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-303.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-304.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-305.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-306.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-307.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-308.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-309.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-31.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-310.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-311.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-312.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-313.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-32.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-33.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-34.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-35.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-36.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-37.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-38.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-39.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-4.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-40.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-41.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-42.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-43.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-44.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-45.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-46.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-47.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-48.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-49.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-5.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-50.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-51.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-52.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-53.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-54.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-55.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-56.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-57.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-58.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-59.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-6.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-60.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-61.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-62.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-63.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-64.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-65.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-66.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-67.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-68.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-69.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-7.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-70.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-71.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-72.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-73.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-74.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-75.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-76.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-77.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-78.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-79.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-8.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-80.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-81.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-82.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-83.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-84.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-85.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-86.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-87.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-88.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-89.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-9.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-90.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-91.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-92.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-93.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-94.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-95.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-96.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-97.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-98.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\Application Data\ErrorFix\QuarantineW\2009-03-16 19-15-460\regb-99.db (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\Antispyware Scheduled Scan.job (Rogue.AntiSpyware) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\ErrorFix Scan.job (Rogue.ErrorFix) -> Quarantined and deleted successfully.
C:\Documents and Settings\Dave\My Documents\downloads\winlogon.scr (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    Link 1
    Link 2
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt just yet.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
DDS (Ver_09-09-24.01) - NTFSx86
Run by Dave at 21:16:11.79 on 26/09/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.205 [GMT 1:00]

AV: avast! antivirus 4.8.1351 [VPS 090926-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
C:\Program Files\BT Broadband Desktop Help\btbb_wcm\McciTrayApp.exe
C:\PROGRA~1\WinTV\EPG Services\System\EPGClient.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\WinTV\EPG Services\System\EPGService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Documents and Settings\Dave\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://bt.yahoo.com/
uSearch Page =
uDefault_Page_URL = hxxp://bt.yahoo.com
uWindow Title = Windows Internet Explorer provided by Yahoo!
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant =
mSearchAssistant =
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Lexmark 1200 Series] "c:\program files\lexmark 1200 series\lxczbmgr.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [btbb_McciTrayApp] "c:\program files\bt broadband desktop help\btbb\BTHelpNotifier.exe"
mRun: [btbb_wcm_McciTrayApp] "c:\program files\bt broadband desktop help\btbb_wcm\McciTrayApp.exe"
mRun: [EPGServiceTool] c:\progra~1\wintv\epg services\system\EPGClient.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\dave\startm~1\programs\startup\dreams~2.lnk - c:\dreamsp\dreamsp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autost~1.lnk - c:\program files\wintv\Ir.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
Trusted Zone: 1and1.co.uk\www
Trusted Zone: microsoft.com\office
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.1.4.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} - hxxps://register.btinternet.com/templates/btmailcontrol013.cab
DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} - hxxp://esupport.epson-europe.com/selftest/en/Prg/ESTPTest.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} - hxxps://register.btinternet.com/templates/btwebcontrol028.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\570\G2AWinLogon.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\dave\applic~1\mozilla\firefox\profiles\5aw4ifi3.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-GB:official
FF - plugin: c:\program files\common files\motive\npMotive.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - hȋdden: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-9-25 206256]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-2 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-2 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-12-2 138680]
R2 EPGService;EPGService;c:\progra~1\wintv\epg services\system\EPGService.exe [2009-6-18 437248]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-12-2 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-12-2 352920]
S3 aswArKrn;aswArKrn;\??\c:\docume~1\dave\locals~1\temp\aswarkrn.sys --> c:\docume~1\dave\locals~1\temp\aswArKrn.sys [?]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2009-6-18 823296]
S3 hcw95bda;Hauppauge MOD7700 Tuner Driver;c:\windows\system32\drivers\hcw95bda.sys [2009-6-18 560640]
S3 hcw95rc;Hauppauge MOD7700 IR Driver;c:\windows\system32\drivers\hcw95rc.sys [2009-6-18 15616]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2009-3-25 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2009-3-25 12672]

=============== Created Last 30 ================

2009-09-26 20:42 --d----- c:\docume~1\dave\applic~1\Malwarebytes
2009-09-26 20:06 --d----- C:\_OTM
2009-09-25 21:05 --d----- c:\program files\Trend Micro
2009-09-25 20:05 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-25 20:05 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-25 20:05 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-25 20:05 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-09-25 15:14 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
2009-09-25 15:14 206,256 a------- c:\windows\system32\drivers\PCTCore.sys
2009-09-25 15:14 86,888 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-09-25 15:14 7,396 a------- c:\windows\system32\drivers\pctcore.cat
2009-09-25 15:14 --d----- c:\program files\common files\PC Tools
2009-09-25 15:14 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
2009-09-25 15:13 --d----- c:\program files\Spyware Doctor
2009-09-25 15:13 --d----- c:\docume~1\dave\applic~1\PC Tools
2009-09-25 15:13 --d----- c:\docume~1\alluse~1\applic~1\PC Tools
2009-09-09 07:26 153,088 -------- c:\windows\system32\dllcache\triedit.dll
2009-09-04 13:34 501 a------- c:\windows\cdplayer.ini
2009-08-29 13:11 54,156 a---h--- c:\windows\QTFont.qfn
2009-08-29 13:11 1,409 a------- c:\windows\QTFont.for

==================== Find3M ====================

2009-08-05 10:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 10:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-19 18:48 11,067,392 -------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 14:18 5,937,152 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-17 20:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 20:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 10,841,088 -------- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-10 14:27 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-07-03 18:09 915,456 a------- c:\windows\system32\wininet.dll
2009-07-03 18:09 915,456 -------- c:\windows\system32\dllcache\wininet.dll
2009-07-03 18:09 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-07-03 18:09 1,208,832 -------- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 18:09 206,848 -------- c:\windows\system32\dllcache\occache.dll
2009-07-03 18:09 594,432 -------- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 18:09 55,296 -------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 18:09 1,985,536 -------- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 18:09 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 18:09 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-07-03 18:09 184,320 -------- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 18:09 386,048 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 12:01 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-02-16 09:28 37,016 a------- c:\docume~1\dave\applic~1\GDIPFONTCACHEV1.DAT
2005-10-23 19:01 97 a------- c:\program files\INSTALL.LOG

============= FINISH: 21:16:47.92 ===============

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hello.
Please post attach.txt. Smile...

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-09-24.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 25/08/2005 20:28:36
System Uptime: 26/09/2009 20:58:20 (1 hours ago)

Motherboard: Dell Computer Corp. | | 0TC666
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | Microprocessor | 2793/533mhz

==== Disk Partitions =========================

C: is fȋxed (NTFS) - 146 GiB total, 121.505 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP404: 28/06/2009 11:32:28 - System Checkpoint
RP405: 29/06/2009 12:08:17 - System Checkpoint
RP406: 30/06/2009 12:30:19 - System Checkpoint
RP407: 01/07/2009 14:50:21 - System Checkpoint
RP408: 02/07/2009 15:25:53 - System Checkpoint
RP409: 03/07/2009 15:30:46 - System Checkpoint
RP410: 04/07/2009 15:56:14 - System Checkpoint
RP411: 05/07/2009 16:27:09 - System Checkpoint
RP412: 06/07/2009 17:29:33 - System Checkpoint
RP413: 07/07/2009 18:20:03 - System Checkpoint
RP414: 08/07/2009 19:05:59 - System Checkpoint
RP415: 09/07/2009 19:42:24 - System Checkpoint
RP416: 10/07/2009 20:02:52 - System Checkpoint
RP417: 11/07/2009 20:54:45 - System Checkpoint
RP418: 12/07/2009 21:32:35 - System Checkpoint
RP419: 14/07/2009 07:13:08 - System Checkpoint
RP420: 14/07/2009 19:24:03 - Software Distribution Service 3.0
RP421: 14/07/2009 19:28:49 - Installed Windows Internet Explorer 8.
RP422: 14/07/2009 19:29:57 - Software Distribution Service 3.0
RP423: 15/07/2009 19:36:02 - System Checkpoint
RP424: 15/07/2009 22:50:27 - Software Distribution Service 3.0
RP425: 17/07/2009 08:31:01 - System Checkpoint
RP426: 18/07/2009 08:52:54 - System Checkpoint
RP427: 18/07/2009 16:03:18 - Installed Java(TM) 6 Update 14
RP428: 19/07/2009 16:29:12 - System Checkpoint
RP429: 20/07/2009 16:42:09 - System Checkpoint
RP430: 21/07/2009 17:40:57 - System Checkpoint
RP431: 22/07/2009 17:50:44 - System Checkpoint
RP432: 23/07/2009 18:38:17 - System Checkpoint
RP433: 24/07/2009 19:18:11 - System Checkpoint
RP434: 25/07/2009 20:06:35 - System Checkpoint
RP435: 26/07/2009 20:59:24 - System Checkpoint
RP436: 27/07/2009 21:51:15 - System Checkpoint
RP437: 29/07/2009 08:04:10 - System Checkpoint
RP438: 29/07/2009 22:13:01 - Software Distribution Service 3.0
RP439: 31/07/2009 14:00:17 - System Checkpoint
RP440: 01/08/2009 14:50:07 - System Checkpoint
RP441: 02/08/2009 15:55:45 - System Checkpoint
RP442: 03/08/2009 16:22:46 - System Checkpoint
RP443: 04/08/2009 16:33:02 - System Checkpoint
RP444: 05/08/2009 17:01:39 - System Checkpoint
RP445: 06/08/2009 17:12:33 - System Checkpoint
RP446: 07/08/2009 17:59:20 - System Checkpoint
RP447: 08/08/2009 18:57:52 - System Checkpoint
RP448: 09/08/2009 11:52:06 - Installed Java(TM) 6 Update 15
RP449: 09/08/2009 11:52:45 - Installed Java Runtime Environment
RP450: 10/08/2009 12:43:41 - System Checkpoint
RP451: 11/08/2009 13:05:27 - System Checkpoint
RP452: 12/08/2009 13:50:02 - System Checkpoint
RP453: 12/08/2009 23:11:15 - Software Distribution Service 3.0
RP454: 14/08/2009 09:08:52 - System Checkpoint
RP455: 15/08/2009 09:20:47 - System Checkpoint
RP456: 16/08/2009 10:12:45 - System Checkpoint
RP457: 16/08/2009 23:52:31 - Software Distribution Service 3.0
RP458: 18/08/2009 11:52:00 - System Checkpoint
RP459: 19/08/2009 12:06:12 - System Checkpoint
RP460: 20/08/2009 12:14:38 - System Checkpoint
RP461: 21/08/2009 12:25:02 - System Checkpoint
RP462: 22/08/2009 12:27:25 - System Checkpoint
RP463: 23/08/2009 12:42:28 - System Checkpoint
RP464: 24/08/2009 12:45:32 - System Checkpoint
RP465: 25/08/2009 12:55:24 - System Checkpoint
RP466: 26/08/2009 13:03:42 - System Checkpoint
RP467: 26/08/2009 22:35:16 - Software Distribution Service 3.0
RP468: 28/08/2009 08:43:37 - System Checkpoint
RP469: 29/08/2009 09:53:01 - System Checkpoint
RP470: 30/08/2009 10:58:13 - System Checkpoint
RP471: 31/08/2009 11:25:33 - System Checkpoint
RP472: 01/09/2009 11:35:35 - System Checkpoint
RP473: 02/09/2009 15:52:44 - System Checkpoint
RP474: 03/09/2009 16:42:46 - System Checkpoint
RP475: 04/09/2009 16:46:04 - System Checkpoint
RP476: 05/09/2009 16:49:36 - System Checkpoint
RP477: 06/09/2009 16:52:39 - System Checkpoint
RP478: 07/09/2009 17:24:12 - System Checkpoint
RP479: 08/09/2009 18:03:06 - System Checkpoint
RP480: 09/09/2009 18:26:10 - System Checkpoint
RP481: 09/09/2009 22:23:40 - Software Distribution Service 3.0
RP482: 11/09/2009 09:22:46 - System Checkpoint
RP483: 12/09/2009 09:39:49 - System Checkpoint
RP484: 13/09/2009 10:17:43 - System Checkpoint
RP485: 14/09/2009 11:08:41 - System Checkpoint
RP486: 15/09/2009 11:23:57 - System Checkpoint
RP487: 16/09/2009 12:08:42 - System Checkpoint
RP488: 17/09/2009 12:09:48 - System Checkpoint
RP489: 18/09/2009 12:24:08 - System Checkpoint
RP490: 19/09/2009 13:08:46 - System Checkpoint
RP491: 20/09/2009 14:08:47 - System Checkpoint
RP492: 21/09/2009 15:34:54 - System Checkpoint
RP493: 22/09/2009 15:55:37 - System Checkpoint
RP494: 23/09/2009 15:57:45 - System Checkpoint
RP495: 24/09/2009 16:52:05 - System Checkpoint

==== Installed Programs ======================

ABBYY FineReader 5.0 Sprint
Adobe Acrobat - Reader 6.0.2 Update
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0.1
ALOT Toolbar
AOL You've Got Pictures Screensaver
ARTEuro
avast! Antivirus
Azureus Vuze
BT Broadband Desktop Help
BT Broadband Support Tools
BT reƖ Connection Manager
BT Yahoo! Applications
BTHomeHub
CCleaner (remove only)
Critical Update for Windows Media Player 11 (KB959772)
Crown My Rooms in Colour 1.1
Dell Driver Reset Tool
Dell Media Experience
Dell Picture Studio v3.0
Dell System Restore
FaxTools
Google Earth
Google Toolbar for Internet Explorer
GoToAssist Corporate
Hauppauge English Help Files and Resources
Hauppauge WinTV
Hauppauge WinTV DVB-T EPG Service
Hauppauge WinTV Infrared Remote
Hauppauge WinTV Scheduler
Hauppauge WinTV TV Services
Highlight Viewer (Windows Live Toolbar)
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics 2 Driver
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet for Wired Connections
Internet Explorer Default Page
InterVideo FilterSDK for Hauppauge
J2SE Runtime Environment 5.0 Update 5
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
Java(TM) 6 Update 15
Learn2 Player (Uninstall Only)
Lexmark 1200 Series
Malwarebytes' Anti-Malware
Map Button (Windows Live Toolbar)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office PowerPoint Viewer 2003
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 7.0
Modem Event Monitor
Modem Helper
Modem On Hold
Moon
Mozilla Firefox (3.5.3)
MSN
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
My Way Search Assistant
Polaroid Digital Cam
PowerDVD 5.5
QuickTime
RealPlayer
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Serif PagePlus 4.0
Smart Menus (Windows Live Toolbar)
Sonic DLA
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spyware Doctor 6.1
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB973815)
Viewpoint Media Player
Wanadoo Europe Installer
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows Live Favorites for Windows Live Toolbar
Windows Live installer
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3

==== Event Viewer Messages From Past Week ========

25/09/2009 21:14:49, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
25/09/2009 21:11:53, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
25/09/2009 21:11:53, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
25/09/2009 21:11:53, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
25/09/2009 21:11:53, error: Service Control Manager [7001] - The Fax service depends on the Print Spooler service which failed to start because of the following error: The dependency service or group failed to start.
25/09/2009 21:11:53, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
25/09/2009 21:11:53, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
25/09/2009 21:11:14, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
25/09/2009 21:11:08, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

==== End Of File ===========================

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hello.

I see that you are running Azureus.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    ALOT Toolbar
    Azureus Vuze
    J2SE Runtime Environment 5.0 Update 5
    Jasc Paint Shop Photo Album 5
    Jasc Paint Shop Pro Studio, Dell Editon
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 15
    My Way Search Assistant
    Viewpoint Media Player

How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hi

I have deleted all the programs that you suggested with the exception of My Way Search Assistant. When I tried to delete this I got an error message "RUNDLL Specified module could not be found". Do I need to worry about this one or does the error message suggest that it is already gone?
Apart from that all seems to be well. I was amazed that traces of My Way and Virus Heat were still in there as I thought they had gone long ago!

If that is all I need to do then thank you SO much! I will be sending a donation to GeekPolice.

While I have you here, can you suggest an affordable Anti Virus we could install. As you will have seen we have the free version of Avast! Is this sufficient, and would anything have stopped Antivirus System Pro?

Regards

Dave

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Hello.
Yes, it's gone, just not gone from the uninstall list. We can use this uninstaller to delete it from the list though.

Please download Revo Uninstall from here: Revo Uinstaller

  1. Download and run the setup file for Revo Uninstaller.
  2. Once setup, run Revo Uninstaller.
  3. Select the following item for removal by clicking on it once.

    My Way Search Assistant


  4. Then hit the "Uninstall" button at the top. PC infected with Antivirus system pro Jph4lw
  5. Close Revo Uninstaller.

Free version of Avast! is good.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
PC infected with Antivirus system pro DXwU4
PC infected with Antivirus system pro VvYDg

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
Thank you Belahzur

That shifted it. Thank you for your help and patience with so many problems that I would never have fȋxed on my own. This is an incredible service and I will recommend it to any friends who have virus problems.

Going now to donate!

Kindest Regards

Dave

descriptionPC infected with Antivirus system pro EmptyRe: PC infected with Antivirus system pro

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum