ok here is my fresh hijack this log :
Logfile of HijackThis v1.99.1
Scan saved at 12:29:17 AM, on 3/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WIN\System32\smss.exe
C:\WIN\system32\csrss.exe
C:\WIN\system32\winlogon.exe
C:\WIN\system32\services.exe
C:\WIN\system32\lsass.exe
C:\WIN\system32\svchost.exe
C:\WIN\System32\svchost.exe
C:\WIN\System32\svchost.exe
C:\WIN\System32\svchost.exe
C:\WIN\system32\spoolsv.exe
C:\WIN\System32\alg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WIN\system32\cisvc.exe
C:\WIN\System32\CTSvcCDA.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WIN\system32\ZoneLabs\vsmon.exe
C:\WIN\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WIN\System32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\X-NetStat 5.0\xns5.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eugene Goh\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 69.10.139.104:8155
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WIN\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Iomega Product Registration.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: RunOnce- - C:\WIN\system32\i406leds1h06.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WIN\System32\CTSvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: rundll.exe - Unknown owner - C:\WIN\rundll.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WIN\system32\ZoneLabs\vsmon.exe
________________________________________________________________________
here is the look2me destroyer log:
Look2Me-Destroyer V1.0.7
Scanning for infected files.....
Scan started at 3/6/2006 12:01:55 AM
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP0\A0000004.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001031.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001203.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001204.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001213.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001228.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001272.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001274.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001280.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002287.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002314.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002324.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002338.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002641.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002651.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002654.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002664.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0003668.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0003712.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004722.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004728.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004737.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004744.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004752.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005004.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005008.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005011.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005012.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005013.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005014.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005015.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005016.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005017.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005018.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005019.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005020.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005021.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005022.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005023.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005025.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005034.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007960.dll
Infected! C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007975.dll
Infected! C:\WIN\system32\i406leds1h06.dll
Infected! C:\WIN\system32\l44q0eh5eh4.dll
Infected! C:\WIN\system32\t08u0al9edq.dll
Infected! C:\WIN\system32\utrfaxa.dll
Attempting to delete infected files...
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP0\A0000004.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP0\A0000004.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001031.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001031.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001203.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001203.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001204.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001204.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001213.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001213.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001228.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001228.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001272.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001272.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001274.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001274.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001280.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0001280.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002287.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002287.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002314.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002314.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002324.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002324.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002338.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002338.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002641.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002641.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002651.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002651.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002654.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002654.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002664.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0002664.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0003668.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP1\A0003668.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0003712.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0003712.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004722.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004722.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004728.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004728.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004737.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004737.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004744.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004744.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004752.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0004752.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005004.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005004.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005008.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005008.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005011.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005011.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005012.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005012.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005013.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005013.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005014.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005014.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005015.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005015.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005016.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005016.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005017.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005017.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005018.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005018.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005019.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005019.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005020.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005020.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005021.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005021.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005022.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005022.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005023.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005023.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005025.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005025.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005034.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP2\A0005034.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007960.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007960.dll Deleted successfully!
Attempting to delete: C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007975.dll
C:\System Volume Information\_restore{D8D91882-ABAF-4FDB-8C62-1F019B47410B}\RP3\A0007975.dll Deleted successfully!
Attempting to delete: C:\WIN\system32\i406leds1h06.dll
C:\WIN\system32\i406leds1h06.dll Deleted successfully!
Attempting to delete: C:\WIN\system32\l44q0eh5eh4.dll
C:\WIN\system32\l44q0eh5eh4.dll Deleted successfully!
Attempting to delete: C:\WIN\system32\t08u0al9edq.dll
C:\WIN\system32\t08u0al9edq.dll Deleted successfully!
Attempting to delete: C:\WIN\system32\utrfaxa.dll
C:\WIN\system32\utrfaxa.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{ECB9ECAB-8813-4F16-B8AF-AF39D69B9908}"
HKCR\Clsid\{ECB9ECAB-8813-4F16-B8AF-AF39D69B9908}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{5A2DF3B0-9AC2-4E48-ABB4-F4228AEB76BD}"
HKCR\Clsid\{5A2DF3B0-9AC2-4E48-ABB4-F4228AEB76BD}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{ADF036CC-097B-448D-9FCF-5FCAAE4A61EE}"
HKCR\Clsid\{ADF036CC-097B-448D-9FCF-5FCAAE4A61EE}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7989AE07-8EF7-4F55-85E9-76DB53F2A209}"
HKCR\Clsid\{7989AE07-8EF7-4F55-85E9-76DB53F2A209}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3F62F7F9-31A0-4472-BC29-E72B7D198FC1}"
HKCR\Clsid\{3F62F7F9-31A0-4472-BC29-E72B7D198FC1}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{490820D4-7E38-4E58-A0A8-544FF82CAFD4}"
HKCR\Clsid\{490820D4-7E38-4E58-A0A8-544FF82CAFD4}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{804209E5-569C-4397-ACF8-E59985355C3A}"
HKCR\Clsid\{804209E5-569C-4397-ACF8-E59985355C3A}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0F06FA5B-7E72-4D0C-A105-62164808AE81}"
HKCR\Clsid\{0F06FA5B-7E72-4D0C-A105-62164808AE81}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{36898428-3BB9-472F-85E3-E055120C9A98}"
HKCR\Clsid\{36898428-3BB9-472F-85E3-E055120C9A98}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
________________________________________________________________________
Hope everything is fine, no unwanted webpages load like before.