Dear Neal,
Thanks for your help once again.
After scanning my computer with Dr. webcureit, I couldn't find any next icon.
But here is my cureit log, combofix log and hijackthis log.
Dr.webcureit Log:
cnsstd.sys;c:\windows\system32\drivers;Trojan.NtRo otKit.442;Deleted.;
12850812.FIL;C:\$VAULT$.AVG;Trojan.PWS.Banker.6520 ;Deleted.;
12851531.FIL;C:\$VAULT$.AVG;Trojan.DownLoader.1493 7;Deleted.;
12852265.FIL;C:\$VAULT$.AVG;Trojan.DownLoader.1446 2;Deleted.;
12852875.FIL;C:\$VAULT$.AVG;Trojan.Spambot.2398;De leted.;
12853796.FIL;C:\$VAULT$.AVG;Adware.Cdn;Deleted.;
12854421.FIL;C:\$VAULT$.AVG;Trojan.StartPage.1672; Deleted.;
RegUBP2b-user.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Snapshots2;Trojan.StartPage.1505;Deleted.;
backup-20071212-193237-716.dll;C:\Program Files\HijackThis\backups;Adware.Baidu.origin;Delet ed.;
alliveex.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721;Adware.Cdn;Deleted.;
alrex.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721;Adware.Cdn;Deleted.;
autolive.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721;Adware.Newweb.origin;Deleted.;
cnsm.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721;Adware.Cdn.origin;Deleted.;
scrblock.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721;Adware.Cdn;Deleted.;
AutoLive.dll.vir;C:\qoobox\Quarantine\C\Program Files\3721\3721;Adware.Newweb.origin;Deleted.;
MFC32DLL.dll.vbs.vir;C:\qoobox\Quarantine\C\WINDOW S;VBS.Generic.544;Deleted.;
CnsMinEx.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\Do wnloaded Program Files;Adware.Cdn;Deleted.;
A0090372.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Adware.Newweb.origin;Invalid path to file ;
A0090381.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Trojan.PWS.Banker.6520;Deleted .;
A0090386.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Adware.Newweb.origin;Invalid path to file ;
A0091404.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Trojan.PWS.Banker.6520;Deleted .;
A0091409.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Adware.Newweb.origin;Invalid path to file ;
A0091425.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Trojan.PWS.Banker.6520;Deleted .;
A0091430.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP645;Adware.Newweb.origin;Invalid path to file ;
A0091452.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP646;Trojan.PWS.Banker.6520;Deleted .;
A0091457.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP646;Adware.Newweb.origin;Invalid path to file ;
A0091473.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP646;Trojan.PWS.Banker.6520;Deleted .;
A0091478.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP646;Adware.Newweb.origin;Invalid path to file ;
A0091498.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP646;Adware.Newweb.origin;Invalid path to file ;
A0091513.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091518.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Adware.Newweb.origin;Invalid path to file ;
A0091519.sys;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.NtRootKit.377;Deleted.;
A0091536.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091540.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Adware.Newweb.origin;Invalid path to file ;
A0091555.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091559.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Adware.Newweb.origin;Invalid path to file ;
A0091574.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091579.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Adware.Newweb.origin;Invalid path to file ;
A0091595.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091613.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Trojan.PWS.Banker.6520;Deleted .;
A0091618.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP647;Adware.Newweb.origin;Invalid path to file ;
A0091636.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP648;Trojan.PWS.Banker.6520;Deleted .;
A0091641.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP648;Adware.Newweb.origin;Invalid path to file ;
A0091653.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Adware.Newweb.origin;Invalid path to file ;
A0091659.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Trojan.PWS.Banker.6520;Deleted .;
A0091664.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Adware.Newweb.origin;Invalid path to file ;
A0092659.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Trojan.PWS.Banker.6520;Deleted .;
A0092668.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Trojan.PWS.Banker.6520;Deleted .;
A0092687.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Trojan.PWS.Banker.6520;Deleted .;
A0092692.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Adware.Newweb.origin;Invalid path to file ;
A0092708.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP649;Trojan.PWS.Banker.6520;Deleted .;
A0092726.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Trojan.PWS.Banker.6520;Deleted .;
A0092731.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Adware.Newweb.origin;Invalid path to file ;
A0092749.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Trojan.PWS.Banker.6520;Deleted .;
A0092754.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Adware.Newweb.origin;Invalid path to file ;
A0092770.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Trojan.PWS.Banker.6520;Deleted .;
A0092775.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Adware.Newweb.origin;Invalid path to file ;
A0092792.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Trojan.PWS.Banker.6520;Deleted .;
A0092797.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Adware.Newweb.origin;Invalid path to file ;
A0092815.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Trojan.PWS.Banker.6520;Deleted .;
A0092819.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP650;Adware.Newweb.origin;Invalid path to file ;
A0092834.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP651;Trojan.PWS.Banker.6520;Deleted .;
A0092850.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP651;Adware.Newweb.origin;Invalid path to file ;
A0092854.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP652;Adware.Newweb.origin;Invalid path to file ;
A0092924.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP653;Adware.Newweb.origin;Invalid path to file ;
A0092973.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP653;Trojan.PWS.Banker.6520;Deleted .;
A0092978.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP653;Adware.Newweb.origin;Invalid path to file ;
A0092993.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP653;Trojan.PWS.Banker.6520;Deleted .;
A0092998.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP653;Adware.Newweb.origin;Invalid path to file ;
A0093030.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093046.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093055.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093060.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093077.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093082.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093100.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093114.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093121.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093126.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093146.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093163.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093169.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093186.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093201.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093209.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093213.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093252.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093268.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093273.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093290.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Trojan.PWS.Banker.6520;Deleted .;
A0093295.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP654;Adware.Newweb.origin;Invalid path to file ;
A0093322.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093340.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093345.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093362.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093381.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093386.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093402.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093406.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093423.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093428.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093445.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Trojan.PWS.Banker.6520;Deleted .;
A0093450.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP655;Adware.Newweb.origin;Invalid path to file ;
A0093485.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP656;Adware.Newweb.origin;Invalid path to file ;
A0093493.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP656;Trojan.PWS.Banker.6520;Deleted .;
A0093498.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP656;Adware.Newweb.origin;Invalid path to file ;
A0093522.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP657;Trojan.PWS.Banker.6520;Deleted .;
A0093547.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP658;Trojan.PWS.Banker.6520;Deleted .;
A0093565.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP658;Trojan.PWS.Banker.6520;Deleted .;
A0093570.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP658;Adware.Newweb.origin;Invalid path to file ;
A0093665.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP660;Adware.Newweb.origin;Invalid path to file ;
A0093683.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP660;Trojan.PWS.Banker.6520;Deleted .;
A0093688.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP660;Adware.Newweb.origin;Invalid path to file ;
A0093710.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Trojan.PWS.Banker.6520;Deleted .;
A0093724.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Adware.Newweb.origin;Invalid path to file ;
A0093731.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Trojan.PWS.Banker.6520;Deleted .;
A0093735.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Adware.Newweb.origin;Invalid path to file ;
A0094731.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Trojan.PWS.Banker.6520;Deleted .;
A0094735.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Adware.Newweb.origin;Invalid path to file ;
A0094759.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Trojan.PWS.Banker.6520;Deleted .;
A0094764.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP661;Adware.Newweb.origin;Invalid path to file ;
A0094784.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP662;Adware.Newweb.origin;Invalid path to file ;
A0094794.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP662;Trojan.PWS.Banker.6520;Deleted .;
A0094799.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP662;Adware.Newweb.origin;Invalid path to file ;
A0094845.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP663;Trojan.PWS.Banker.6520;Deleted .;
A0094884.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP663;Trojan.PWS.Banker.6520;Deleted .;
A0094900.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP663;Adware.Newweb.origin;Invalid path to file ;
A0095884.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0095889.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0096884.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0096889.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0096918.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0097906.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0097909.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0098904.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0098909.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0098919.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0098934.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0098938.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0098957.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0098962.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0099957.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0099961.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0099979.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0099988.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0099993.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0100011.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Cdn;Invalid path to file ;
A0100016.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0100021.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0101015.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0101020.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0102015.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0102020.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0102037.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Trojan.PWS.Banker.6520;Deleted .;
A0102042.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP664;Adware.Newweb.origin;Invalid path to file ;
A0102059.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0102064.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103059.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0103063.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103085.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103101.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0103106.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103124.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0103129.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103147.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0103152.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103169.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Trojan.PWS.Banker.6520;Deleted .;
A0103174.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP665;Adware.Newweb.origin;Invalid path to file ;
A0103191.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0103196.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0103214.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0103219.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0103237.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0103242.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0103259.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0103264.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0103287.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0103290.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0104285.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0104290.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0104311.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0104327.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0104332.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0105327.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0105332.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0105347.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Trojan.PWS.Banker.6520;Deleted .;
A0105352.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP666;Adware.Newweb.origin;Invalid path to file ;
A0105367.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP667;Trojan.PWS.Banker.6520;Deleted .;
A0105372.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP667;Adware.Newweb.origin;Invalid path to file ;
A0106379.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP667;Adware.Newweb.origin;Invalid path to file ;
A0106382.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Adware.Newweb.origin;Invalid path to file ;
A0107367.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Trojan.PWS.Banker.6520;Deleted .;
A0107371.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Adware.Newweb.origin;Invalid path to file ;
A0107391.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Adware.Newweb.origin;Invalid path to file ;
A0107413.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Adware.Newweb.origin;Invalid path to file ;
A0107431.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Trojan.PWS.Banker.6520;Deleted .;
A0107436.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP668;Adware.Newweb.origin;Invalid path to file ;
A0107456.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP670;Trojan.PWS.Banker.6520;Deleted .;
A0107457.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP670;Trojan.PWS.Banker.6520;Deleted .;
A0107473.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP670;Adware.Newweb.origin;Invalid path to file ;
A0107485.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP671;Adware.Newweb.origin;Invalid path to file ;
A0107496.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP671;Adware.Newweb.origin;Invalid path to file ;
A0108495.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP671;Adware.Newweb.origin;Invalid path to file ;
A0108514.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP672;Adware.Newweb.origin;Invalid path to file ;
A0109514.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP672;Adware.Newweb.origin;Invalid path to file ;
A0110514.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP672;Adware.Newweb.origin;Invalid path to file ;
A0110532.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP672;Adware.Newweb.origin;Invalid path to file ;
A0110551.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0110571.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0111571.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0111580.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0112580.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0112589.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP673;Adware.Newweb.origin;Invalid path to file ;
A0112611.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP674;Adware.Newweb.origin;Invalid path to file ;
A0113610.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP674;Adware.Newweb.origin;Invalid path to file ;
A0113650.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP674;Adware.Newweb.origin;Invalid path to file ;
A0113659.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP674;Adware.Newweb.origin;Invalid path to file ;
A0113681.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP675;Adware.Newweb.origin;Invalid path to file ;
A0114659.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP675;Adware.Newweb.origin;Invalid path to file ;
A0114784.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114804.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114822.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114841.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114862.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114882.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP676;Adware.Newweb.origin;Invalid path to file ;
A0114902.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0114915.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0114948.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0114969.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0114987.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0115019.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0115037.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0115076.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP677;Adware.Newweb.origin;Invalid path to file ;
A0115079.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115125.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115149.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115170.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115189.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115215.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP678;Adware.Newweb.origin;Invalid path to file ;
A0115230.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0115245.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0115264.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0116265.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0116295.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0116318.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;VBS.Generic.544;Deleted.;
A0116319.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;VBS.Generic.544;Deleted.;
A0116321.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0116338.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;VBS.Generic.544;Deleted.;
A0116339.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;VBS.Generic.544;Deleted.;
A0116342.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP679;Adware.Newweb.origin;Invalid path to file ;
A0116354.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP680;VBS.Generic.544;Deleted.;
A0116355.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP680;VBS.Generic.544;Deleted.;
A0116360.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP680;Adware.Newweb.origin;Invalid path to file ;
A0116365.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP681;VBS.Generic.544;Deleted.;
A0116366.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP681;VBS.Generic.544;Deleted.;
A0116368.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP681;Adware.Newweb.origin;Invalid path to file ;
A0116438.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP683;VBS.Generic.544;Deleted.;
A0116440.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP683;VBS.Generic.544;Deleted.;
A0116454.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP683;Adware.Newweb.origin;Invalid path to file ;
A0116456.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP684;VBS.Generic.544;Deleted.;
A0116457.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP684;VBS.Generic.544;Deleted.;
A0116461.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP685;VBS.Generic.544;Deleted.;
A0116462.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP685;VBS.Generic.544;Deleted.;
A0116522.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP685;Adware.Newweb.origin;Invalid path to file ;
A0116523.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;VBS.Generic.544;Deleted.;
A0116524.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;VBS.Generic.544;Deleted.;
A0116527.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0116529.exe;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.PWS.Banker.6520;Deleted .;
A0116530.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.DownLoader.14937;Delete d.;
A0116531.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.DownLoader.14462;Delete d.;
A0116532.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.Spambot.2398;Deleted.;
A0116533.sys;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Cdn;Invalid path to file ;
A0116534.sys;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.StartPage.1672;Deleted. ;
A0116535.sys;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Trojan.Starter.108;Deleted.;
A0117338.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0117363.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0117382.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0117397.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;VBS.Generic.544;Deleted.;
A0117406.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0117429.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP686;Adware.Newweb.origin;Invalid path to file ;
A0117451.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP687;Adware.Newweb.origin;Invalid path to file ;
A0117464.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP687;Adware.Newweb.origin;Invalid path to file ;
A0117482.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP687;Adware.Newweb.origin;Invalid path to file ;
A0117496.vbs;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;VBS.Generic.544;Deleted.;
A0117498.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Cdn;Invalid path to file ;
A0117499.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Cdn;Invalid path to file ;
A0117500.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Newweb.origin;Invalid path to file ;
A0117503.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Cdn.origin;Invalid path to file ;
A0117508.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Cdn;Invalid path to file ;
A0117509.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP688;Adware.Newweb.origin;Invalid path to file ;
A0117630.dll;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP689;Adware.Baidu.origin;Deleted.;
A0117650.sys;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP689;Trojan.NtRootKit.442;Deleted.;
A0117651.reg;C:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP689;Trojan.StartPage.1505;Deleted. ;
CnsMinKP.sys;C:\WINDOWS\system32\drivers;Adware.Cd n;Deleted.;
homereg111.reg;E:\WINDOWS;Trojan.Seeker.151;Delete d.;
American Babes-uninstall.exe;E:\WINDOWS\SYSTEM;Dialer.Ezdial;Dele ted.;
EGGCEngine.dll;E:\Program Files\Common Files\GMT;Adware.Gator;Deleted.;
EGIEProcess.dll;E:\Program Files\Common Files\GMT;Adware.Gator;Deleted.;
EGNSEngine.dll;E:\Program Files\Common Files\GMT;Adware.Gator;Deleted.;
GatorRes.dll;E:\Program Files\Common Files\GMT;Adware.Gator - read error;;
GMT.exe;E:\Program Files\Common Files\GMT;Adware.Gator.origin;Deleted.;
GatorStubSetup.exe;E:\Program Files\Common Files\GMT;Adware.Gator;Deleted.;
GUninstaller.exe;E:\Program Files\Common Files\GMT;Adware.Gator;Deleted.;
CMEIIAPI.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
CMESys.exe;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GAppMgr.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GController.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GDwldEng.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GIocl.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GIoclClient.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GMTProxy.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GObjs.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GStore.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
GStoreServer.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
Gtools.dll;E:\Program Files\Common Files\CMEII;Adware.Gator;Deleted.;
SaveNow.exe;E:\Program Files\SaveNow;Adware.SaveNow;Deleted.;
Uninst.exe;E:\Program Files\SaveNow;Adware.SaveNow;Deleted.;
email_update.exe;E:\Program Files\Acceleration Software\Anti-Virus;Probably DLOADER.Trojan;Deleted.;
eanth_update.exe;E:\Program Files\Acceleration Software\Anti-Virus;Probably DLOADER.Trojan;Deleted.;
PrecisionTime.exe;E:\Program Files\PrecisionTime;Adware.Gator;Deleted.;
DateManager.exe;E:\Program Files\Date Manager;Adware.Gator;Deleted.;
American Babes.EXE;E:\Dialers;Dialer.Ezdial;Deleted.;
04045281.FIL;E:\$VAULT$.AVG;Trojan.PWS.LDPinch;Del eted.;
04045500.FIL;E:\$VAULT$.AVG;Win32.HLLM.Reteras;Del eted.;
04045687.FIL;E:\$VAULT$.AVG;Adware.Gator;Deleted.;
04045796.FIL;E:\$VAULT$.AVG;Adware.Gator;Deleted.;
04045953.FIL;E:\$VAULT$.AVG;Adware.Gator;Deleted.;
04046296.FIL;E:\$VAULT$.AVG;Probably DLOADER.Trojan;Deleted.;
05421656.FIL;E:\$VAULT$.AVG;Trojan.PWS.LDPinch;Del eted.;
05422015.FIL;E:\$VAULT$.AVG;Win32.HLLM.Reteras;Del eted.;
05422046.FIL;E:\$VAULT$.AVG;Adware.Gator;Deleted.;
05422062.FIL;E:\$VAULT$.AVG;Adware.Gator;Deleted.;
A0117658.reg;E:\System Volume Information\_restore{F7C43BAA-9F0B-4DB5-A500-C808BEDF3C9E}\RP689;Trojan.Seeker.151;Deleted.;
Combofix Log:
ComboFix 07-12-09.1 - user 2007-12-12 22:06:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.183 [GMT 13:00]
Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-12 to 2007-12-12 )))))))))))))))))))))))))))))))
.
2007-12-12 20:06 . 2007-12-12 20:06 <DIR> d-------- C:\Documents and Settings\user\DoctorWeb
2007-12-10 13:10 . 2007-12-12 13:57 <DIR> d-------- C:\Documents and Settings\user\Application Data\AVG7
2007-12-10 13:10 . 2007-12-10 13:10 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2007-12-10 13:09 . 2007-12-10 13:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-10 13:09 . 2007-12-10 20:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2007-12-10 13:07 . 2007-12-10 20:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-09 22:21 . 2007-12-09 22:21 <DIR> d-------- C:\Documents and Settings\user\Incomplete
2007-12-09 22:21 . 2007-12-10 00:05 <DIR> d-------- C:\Documents and Settings\user\Application Data\LimeWire
2007-12-09 22:20 . 2007-12-09 22:20 <DIR> d-------- C:\Program Files\Java
2007-12-09 22:20 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-09 22:19 . 2007-12-09 22:19 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-09 17:52 . 2007-12-09 17:52 244 --ah----- C:\sqmnoopt02.sqm
2007-12-09 17:52 . 2007-12-09 17:52 232 --ah----- C:\sqmdata02.sqm
2007-12-09 09:44 . 2007-12-09 09:44 62,464 --a------ C:\WINDOWS\system32\drivers\phldn.sys
2007-12-01 16:47 . 2007-12-01 16:47 <DIR> d-------- C:\Program Files\Windows Live Favorites
2007-11-16 15:22 . 2007-11-16 15:22 118 --a------ C:\WINDOWS\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-12-01 03:48 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-15 21:37 --------- d-----w C:\Program Files\Lexmark X1100 Series
2007-11-15 21:09 155 ----a-w C:\start.bat
2004-10-11 07:46 205,312 ----a-w C:\Program Files\ltefx13n.dll
2004-01-19 02:31 153,600 ----a-w C:\Program Files\ltfil13n.DLL
2004-01-19 01:31 27,648 ----a-w C:\Program Files\lfiff13n.dll
2004-01-19 01:31 20,480 ----a-w C:\Program Files\lfCUT13n.dll
2004-01-19 00:31 453,120 ----a-w C:\Program Files\ltkrn13n.dll
2004-01-19 00:12 89,600 ----a-w C:\Program Files\Lfcgm13n.dll
2004-01-18 23:49 278,016 ----a-w C:\Program Files\LFJ2K13n.dll
2004-01-18 23:49 180,736 ----a-w C:\Program Files\Lfpng13n.dll
2004-01-18 23:47 76,800 ----a-w C:\Program Files\Lfwmf13n.dll
2004-01-18 23:47 509,440 ----a-w C:\Program Files\LFCMW13n.dll
2004-01-18 23:45 420,352 ----a-w C:\Program Files\LFCMP13n.DLL
2004-01-18 23:44 143,872 ----a-w C:\Program Files\lftif13n.dll
2004-01-18 23:36 65,536 ----a-w C:\Program Files\Lfpct13n.dll
2004-01-18 23:36 56,832 ----a-w C:\Program Files\lfpsd13n.dll
2004-01-18 23:36 26,624 ----a-w C:\Program Files\lfpcx13n.dll
2004-01-18 23:36 19,968 ----a-w C:\Program Files\lfpcd13n.dll
2004-01-18 23:36 18,944 ----a-w C:\Program Files\lfmsp13n.dll
2004-01-18 23:35 20,992 ----a-w C:\Program Files\lfimg13n.dll
2004-01-18 23:35 18,944 ----a-w C:\Program Files\lfmac13n.dll
2004-01-18 23:34 31,744 ----a-w C:\Program Files\lfclp13n.dll
2004-01-18 23:34 30,208 ----a-w C:\Program Files\lfbmp13n.dll
2004-01-18 23:33 444,928 ----a-w C:\Program Files\ltimg13n.dll
2004-01-18 23:32 265,216 ----a-w C:\Program Files\LTDIS13n.dll
2000-05-01 16:17 212,480 ----a-w C:\Program Files\PCDLIB32.DLL
1999-11-18 11:00 284,032 ----a-w C:\Program Files\XceedZip.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54]
"ILO_Office_Manager"="IntEdReg.exe" [2002-10-15 12:30 C:\WINDOWS\system32\intedreg.exe]
"eMuleAutoStart"="C:\emule\eMule.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 20:56]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 21:31 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 21:10]
"SMSERIAL"="sm56hlpr.exe" [2004-01-28 23:42 C:\WINDOWS\sm56hlpr.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.e xe" [2001-07-10 15:50]
"SNPMI03"="C:\WINDOWS\vsnpmi03.exe" [2003-08-08 14:58]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-20 03:43]
"Intense Registry Service"="IntEdReg.exe" [2002-10-15 12:30 C:\WINDOWS\system32\intedreg.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 10:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 13:45]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-09-23 12:52]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-12-10 13:09]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2007-12-10 13:09]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~ 1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
R3 snpmi03;VideoCAM NB 300;C:\WINDOWS\system32\DRIVERS\snpmi03.sys
S3 baxevr36;baxevr36;\??\C:\WINDOWS\system32\drivers\ baxevr36.sys
S3 krdpdre;krdpdre;\??\C:\DOCUME~1\user\LOCALS~1\Temp \krdpdre.sys
S3 nowpuk95;nowpuk95;\??\C:\WINDOWS\system32\drivers\ nowpuk95.sys
S3 SetupNTGLM7X;SetupNTGLM7X;\??\D:\NTGLM7X.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-06-04 01:23:25 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-12 08:49:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\user\LOCALS~1\Temp\ojdgeqmmCFEBM77.dll
.
************************************************** ************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-12 22:12:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2007-12-12 22:13:23 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-11 18:07
.
--- E O F ---
HiJackThis Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:01 p.m., on 12/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\sm56hlpr.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\vsnpmi03.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Intense Language Office\COMMON\Offman.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?linkid=677
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.yahoo.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SNPMI03] C:\WINDOWS\vsnpmi03.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [Intense Registry Service] IntEdReg.exe /CHECK
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ILO_Office_Manager] IntEdReg.exe /OFFMAN
O4 - HKCU\..\Run: [eMuleAutoStart] C:\emule\eMule.exe -AutoStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.qmb.co.nz
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
O16 - DPF: {C7E002D6-324B-4500-883D-84B620FD8640} (Bridge Installer) -
http://cdn2.zone.msn.com/Bingame/BRD.../heartbeat.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
--
End of file - 7527 bytes