Hi again from Wisconsin ... we're nearing 100 today and it's humid. My husband is still thinking of mowing the lawn, and I'm trying to convince him it's a bad idea! Well, on to the computer ......
Ran Silent Runner (had to download WMI), and here's the log:
2005-07-23 13.25.05
"Silent Runners.vbs", revision 39,
http://www.silentrunners.org/Operating System: Windows 98
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
"ccRegVfy" = ""C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"" ["Symantec Corporation"]
"CriticalUpdate" = "c:\windows\SYSTEM\wucrtupd.exe -startup" [MS]
"QuickTime Task" = ""C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime" ["Apple Computer, Inc."]
"HP Software Update" = "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
"Zone Labs Client" = "C:\Program Files\ZoneAlarm Firewall\ZoneAlarm\zlclient.exe" ["Zone Labs, LLC"]
"Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer" ["Symantec Corporation"]
"RegistryMechanic" = (empty string)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ {++}
"ccEvtMgr" = ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
"ScriptBlocking" = ""C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg" ["Symantec Corporation"]
"Hidserv" = "Hidserv.exe run" [MS]
"SchedulingAgent" = "mstask.exe" [MS]
"TrueVector" = "C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service" ["Zone Labs, LLC"]
"KB891711" = "c:\windows\SYSTEM\KB891711\KB891711.EXE" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX" ["("]
{BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "CNavExtBho Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\DirectCD\shellex.dll" ["Adaptec"]
"{00020D75-0000-0000-C000-000000000046}" = "Microsoft Exchange"
-> {CLSID}\InProcServer32\(Default) = "c:\PROGRA~1\MICROS~4\OFFICE\MLSHEXT.DLL" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "c:\PROGRA~1\MICROS~4\OFFICE\OLKFSTUB.DLL" [MS]
"{506F4668-F13E-4AA1-BB04-B43203AB3CC0}" = "{506F4668-F13E-4AA1-BB04-B43203AB3CC0}"
-> {CLSID}\InProcServer32\(Default) = "c:\WINDOWS\SYSTEM\VisShe.dll" [null data]
"{D66DC78C-4F61-447F-942B-3FB6980118CF}" = "{D66DC78C-4F61-447F-942B-3FB6980118CF}"
-> {CLSID}\InProcServer32\(Default) = "c:\WINDOWS\SYSTEM\VisShe.dll" [null data]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMMON\YMMAPI.DLL" ["Yahoo! Inc."]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\REAL\REALPLAYER\RPSHELL.DLL" ["RealNetworks, Inc."]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{FA010552-4A27-4cb1-A1BB-3E2D697F1639}" = "SpySubtract Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\INTERMUTE\SPYSUBTRACT\SSHOOK.DLL" ["InterMute, Inc."]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\wzshlext.dll" [null data]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMMON\YMMAPI.DLL" ["Yahoo! Inc."]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\wzshlext.dll" [null data]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\wzshlext.dll" [null data]
Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "c:\windows\Clouds.bmp"
WIN.INI & SYSTEM.INI launch points:
-----------------------------------
SYSTEM.INI
[boot]
"SCRNSAVE.EXE=C:\WINDOWS\SYSTEM\MYSTIF~1.SCR" (Mystify Your Mind.scr) [MS]
Startup items in "Startup" & "All Users...Startup" folders:
-----------------------------------------------------------
C:\WINDOWS\Start Menu\Programs\StartUp
"SpySubtract" -> shortcut to: "C:\Program Files\interMute\SpySubtract\SpySub.exe -autostart" ["InterMute, Inc."]
Enabled Scheduled Tasks:
------------------------
"Norton AntiVirus - Scan my computer" -> launches: "C:\PROGRA~1\NORTON~1\NAVW32.exe /task:C:\WINDOWS\ALLUSE~1\APPLIC~1\SYMANTEC\NORTON~1\TASKS\MYCOMP.SCA" ["Symantec Corporation"]
"RUTASK" -> launches: "C:\WINDOWS\ru.exe" [file not found]
"Windows Critical Update Notification" -> launches: "C:\WINDOWS\SYSTEM\WUCRTUPD.EXE" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "c:\windows\SYSTEM\rnr20.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
c:\windows\SYSTEM\mswsosp.dll [MS], 1
c:\windows\SYSTEM\msafd.dll [MS], 2 - 4
c:\windows\SYSTEM\rsvpsp.dll [MS], 5 - 6
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{4D5C8C2A-D075-11D0-B416-00C04FB90376}" = "Microsoft CommBand" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\BROWSEUI.DLL" [MS]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
Explorer Bars
HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ = "&Yahoo! Messenger" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{4528BBE0-4E08-11D5-AD55-00010333D0AD}\ = "&Yahoo! Messenger" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL" ["Yahoo! Inc."]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{4528BBE0-4E08-11D5-AD55-00010333D0AD}\
"ButtonText" = "Messenger"
"MenuText" = "Yahoo! Messenger"
"CLSIDExtension" = "{4C171D40-8277-11D5-AD55-00010333D0AD}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES.DLL" ["Yahoo! Inc."]
{2499216C-4BA5-11D5-BD9C-000103C116D5}\
"ButtonText" = "Yahoo! Login"
"MenuText" = "Yahoo! Login"
"CLSIDExtension" = "{2499216C-4BA5-11D5-BD9C-000103C116D5}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMMON\YLOGIN.DLL" ["Yahoo! Inc."]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 31 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 21 seconds.
---------- (total run time: 89 seconds)
I then unchecked casstub.exe in the start-up tab of msconfig.
I also unchecked M190309 because I found it there, too.
As for the exact location of M190309, I find it using regedit in:
hkey_local_machine
software
microsoft
windows
current version
run- (folder)
Properties of M190309:
Application
Size: 76.0kb, 81,920 bytes used
MSDOS name: M190309.exe
Created: 7/20/05 8:24:07
Modified: 7/20/04 8:24:08
Accessed: Saturday, 7/23/05
Archive
Version 2.0.000
I have not deleted M190309 yet.
I deleted cass.tub while in safe mode, and also found "Install_Marketing 58", which I also deleted, and ran Clean-Up again.
Here are the three additional scans/logs you'd requested:
Panda Scan (reported 244 infections not fixed)PandaActivescan 072305 2200 hrs
Incident Status Location
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MKJET35.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RXCLTC3.DLL
Spyware:spyware/yoursitebar No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\ysbactivex.inf
Adware:adware/transponder No disinfected C:\WINDOWS\abiuninst.htm
Adware:adware/bookedspace No disinfected C:\WINDOWS\cfgmgr52.ini
Spyware:spyware/searchcentrix No disinfected HKEY_CURRENT_USER\SOFTWARE\DYNAMIC TOOLBAR
Adware:adware/consumeralertsystemNo disinfected HKEY_CURRENT_USER\SOFTWARE\CAS
Adware:adware/comet No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\USERKEYS\COMETKEY
Spyware:spyware/istbar No disinfected HKEY_CLASSES_ROOT\YSBACTIVEX.INSTALLER
Adware:adware/savenow No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MVU
Adware:adware/gator No disinfected HKEY_USERS\.DEFAULT\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\TRUSTEDPUBLISHER\CTLS
Adware:adware/powerscan No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\BANDREST
Adware:adware/ncase No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\SEARCH BAR_BAK
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MFFMIG32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MNJAVA.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\APIDIAG.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\FZAMEBUF.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MRDCTRL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IWMUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SAI_CI32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\LLRT.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\WMASPI32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\NMNDS.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\TGD32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DPKAPI32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RZANP.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MCXML3.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\VSHELPER.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RZGWIZC.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\SJVRTGUI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\TBP3216S.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OATLCOMM.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\OJPRT400.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\swkoy.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\DCSERIAL.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\GNI32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CAL3D32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MTHTMLER.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HQFCSA.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\VGB32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MGCUIA32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\aripk32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wcv8dmod.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\domap.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\pbbole32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ggcwb.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dWdref.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\HMFecp11.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ivoi.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mpvcp71.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ootext32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dzmsgnet.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\nytha32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\CJMPPL32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\Shorts.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\cptb.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\aapwv.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM\winxm.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mbcbh.dll
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\SYSTEM\craw32.exe
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\nztel.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mgay32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ovdbse32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\awpoy.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\aklpk.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\stsgw.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\irsg32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\aditz.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\nhtvg32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\nmtup.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\jhpl400.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\axdzh32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\nrttg.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dFil.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\ibbd.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\iwbd.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\RXCLTC3.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\TKAPI.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\IWM32.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\akibt.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\axikr.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\MKJET35.DLL
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wwnetmgr.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\sjsml.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\mpcxr.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\wanqg32.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\dknlobby.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\SYSTEM\menv.dll
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav9364.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav93A0.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav32E3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav3323.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav4020.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav4025.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav40D2.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav40F1.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav41F0.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav50F4.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav5104.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav52C3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav5301.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav5336.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav5384.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav60B2.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav6172.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav6182.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav62C3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7025.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7035.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7075.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7083.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7235.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7295.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav72D0.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav72E1.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav72F3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7303.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7331.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7343.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav7345.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8031.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8043.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8060.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8082.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav80A2.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8141.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8164.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8172.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8182.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8194.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav81A5.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav81B3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav81E1.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav81F3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8212.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8230.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8233.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8243.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav82A3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav82E4.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav82F3.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8302.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8315.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8322.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8325.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP\pav8331.TMP
Adware:Adware/Look2Me No disinfected C:\WINDOWS\TEMP