C:\Documents and Settings\User1\Application Data\ShopperReports\cs\report\ag_ShopperReports.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\cs\report\ag_ShopperReports.xml.db -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\cs\report\send_ShopperReports.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\cs\report\send_ShopperReports.xml.db -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\cs\res1\WhiteList.dbs -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Application Data\ShopperReports\shprrprt_1137637426.log -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Adocean : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@cliks[2].txt -> TrackingCookie.Cliks : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@cliks[3].txt -> TrackingCookie.Cliks : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@goldenpalace[1].txt -> TrackingCookie.Goldenpalace : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@need2find[2].txt -> TrackingCookie.Need2find : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Wegcash : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\User1\Cookies\user1@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Abcsearch : Cleaned with backup
C:\Documents and Settings\User1\Cookies\
[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\User1\Desktop\Incomplete\Preview-T-187450-_HonkyTonk_ deamon tools.rar/Setup_toolBar.exe -> Downloader.IstBar.nj : Cleaned with backup
C:\Documents and Settings\User1\Local Settings\Temp\lf_B78.tmp -> Downloader.Agent.wp : Cleaned with backup
C:\Documents and Settings\User1\Local Settings\Temp\temp.fr041D -> Adware.Altnet : Cleaned with backup
C:\Downloads\FamilyFeudSetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtGuard.exe -> Adware.HotBar : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtHostIE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtHostOE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtInstIE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtOEAddOn.exe -> Adware.HotBar : Cleaned with backup
C:\Program Files\HbTools\Bin\4.7.7.0\HbtSrv.exe -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\Cml.exe -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\Contact.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbAds.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbCoreSrv.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbGuard.exe -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbHostIE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbHostOE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbInstIE.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbOEAddOn.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbToolbar.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\SpamBlockerUtility\bin\4.7.1.0\SbWallpaper.dll -> Adware.HotBar : Cleaned with backup
C:\Program Files\TBONBin -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\TBONBin\tbon.exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\TBONBin\tboninst.cfg -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\TBONBin\TBONWnd.EXE -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\YourSiteBar -> Adware.YourSiteBar : Cleaned with backup
C:\Program Files\YourSiteBar\imagemap_normal.bmp -> Adware.YourSiteBar : Cleaned with backup
C:\Program Files\YourSiteBar\imagemap_over.bmp -> Adware.YourSiteBar : Cleaned with backup
C:\Program Files\YourSiteBar\version.txt -> Adware.YourSiteBar : Cleaned with backup
C:\Program Files\YourSiteBar\yoursitebar.xml -> Adware.YourSiteBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HbInstIE.dll -> Adware.HotBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5_0001_N53L1025NetInstaller.exe -> Not-A-Virus.Downloader.Win32.Agent.f : Cleaned with backup
C:\WINDOWS\system32\gaallwtc.exe -> Adware.HotBar : Cleaned with backup
::Report End
--------------------------------------------------------------------------------------------
HJT Log
Logfile of HijackThis v1.99.1
Scan saved at 6:11:01 PM, on 4/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\D-Tools\daemon.exe
C:\program files\common files\system\mplay64.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HiJack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://resultsmaster...omeLeftPane.htmR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://bbmedic.ntlwo...tour/bbdemo.htmR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: HbTools - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.7.7.0\HbtHostIE.dll (file missing)
O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.7.7.0\HbtHostIE.dll (file missing)
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MediaPipe P2P Loader] "C:\Program Files\p2pnetworks\mpp2pl.exe" /H
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [Ldjja] C:\Program Files\Iuhbb\Amnst.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Emurayden PSX Emulator] C:\GAMES\Emurayden PSX AutoLauncher.exe
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [MPlay64] c:\program files\common files\system\mplay64.exe /noerrorinfo
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search -
http://kl.bar.need2f...earch.html?p=KLO8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2F003D51-39FD-4D18-9016-95CF70B92ABE} -
http://download.movi.../altpmtscab.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.c...nst20040510.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1145815044623O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1145814874618O16 - DPF: {8C875948-9C60-4381-9248-0DF180542D53} (HbtInstObj) -
http://installs.spam...ckerutility.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
http://locator1.cdn....FreeInstall.cabO16 - DPF: {FAF10F23-0AC1-1213-A139-0F032B2112CA} -
http://uk.global-acc...dpower/nat2.exeO16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} -
http://download.spys...rcabinstall.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe