Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

OuterInfo HELP


  • This topic is locked This topic is locked

#1
commercialasreannoying

commercialasreannoying

    New Member

  • Member
  • Pip
  • 8 posts
SO i dont know how to block outerinfo ads and my dad has pretty safe stuff like AVG7.5

so im ready to start

p.s purity scan isnt on my comp


thx

MERRY CHRISTMAS!

need help asap

Logfile of HijackThis v1.99.1
Scan saved at 9:34:10 PM, on 12/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Toolbar\TBPSSvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\dvd43\dvd43_tray.exe
c:\PROGRA~1\Toolbar\radio.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\APPATC~1\chkdsk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
c:\PROGRA~1\Toolbar\WSG.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\l?[bleep].exe
C:\Program Files\PartyGaming\PartyGaming.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alan\Local Settings\Temporary Internet Files\Content.IE5\I1FCDGZ6\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50245
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {C1034046-8D87-DB56-8C3D-894D86857C97} - C:\WINDOWS\system32\wpfzj.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {A8A79C0C-5ACD-0B1D-931C-0BE52C1F4091} - C:\WINDOWS\system32\xpquut.dll (file missing)
R3 - URLSearchHook: (no name) - {A5A9CF0D-5C9F-0A49-C81C-0BE52C1C15CE} - C:\WINDOWS\system32\ymkkquuk.dll (file missing)
R3 - URLSearchHook: (no name) - {D0C3385F-A29E-A615-9EFC-F5FA4DAA6DCD} - C:\WINDOWS\system32\lxb.dll (file missing)
R3 - URLSearchHook: (no name) - {9AD69DBB-5070-06A2-23F7-0545060E2693} - C:\WINDOWS\system32\mcnttymz.dll
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: sPeerObj Class - {00000097-7C67-4BA6-8B42-05128941688A} - C:\WINDOWS\speeryox.dll (file missing)
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\Aprps\cxtpls.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {03C471EB-B576-BDA5-2857-BFCE1ECCE89A} - C:\WINDOWS\system32\mqolgopm.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SearchToolbarBHOObject - {12EE7A5E-0674-42f9-A76A-000000004D00} - C:\WINDOWS\system32\stlb2.dll (file missing)
O2 - BHO: (no name) - {2BD5498E-8E11-88C9-1E33-D938034D9590} - C:\WINDOWS\system32\vgrcrv.dll (file missing)
O2 - BHO: (no name) - {2DE70756-919A-9510-C19C-C649641FC4C3} - C:\WINDOWS\system32\abtdizri.dll (file missing)
O2 - BHO: My Global Search Bar BHO - {37B85A21-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O2 - BHO: (no name) - {3CE13C1B-A0DF-A801-8F59-AF7F676ED095} - C:\WINDOWS\system32\dbyuafij.dll (file missing)
O2 - BHO: (no name) - {446CDAA6-1A37-47B9-6906-4A31B1B6F6C5} - C:\WINDOWS\system32\wnvhhy.dll (file missing)
O2 - BHO: wb - {55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} - C:\WINDOWS\system32\nsv6DB.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll (file missing)
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {992A1812-DBD9-DF57-D608-8AADAACD259B} - C:\WINDOWS\system32\cps.dll (file missing)
O2 - BHO: (no name) - {9AD69DBB-5070-06A2-23F7-0545060E2693} - C:\WINDOWS\system32\mcnttymz.dll
O2 - BHO: ohb - {9ADE0443-2AB2-4B23-A3F8-AC520773DE12} - C:\WINDOWS\system32\nsl6CD.dll (file missing)
O2 - BHO: (no name) - {A5A9CF0D-5C9F-0A49-C81C-0BE52C1C15CE} - C:\WINDOWS\system32\ymkkquuk.dll (file missing)
O2 - BHO: (no name) - {A8A79C0C-5ACD-0B1D-931C-0BE52C1F4091} - C:\WINDOWS\system32\xpquut.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {C1034046-8D87-DB56-8C3D-894D86857C97} - C:\WINDOWS\system32\wpfzj.dll (file missing)
O2 - BHO: (no name) - {C554C20F-59C0-5242-CFAC-5050D78024CD} - C:\WINDOWS\system32\srnbfnax.dll (file missing)
O2 - BHO: (no name) - {CF05955D-079F-5519-98FD-5050D58B2DC8} - C:\WINDOWS\system32\vebxneen.dll (file missing)
O2 - BHO: (no name) - {D0C3385F-A29E-A615-9EFC-F5FA4DAA6DCD} - C:\WINDOWS\system32\lxb.dll (file missing)
O2 - BHO: (no name) - {D51E1E49-81DD-840F-D8A8-D02890043ACB} - C:\WINDOWS\system32\tljwcc.dll (file missing)
O2 - BHO: (no name) - {DBB903EF-917F-9AF1-7C02-CA896A2B3593} - C:\WINDOWS\system32\wedzrwae.dll (file missing)
O2 - BHO: (no name) - {DEEB50BC-9379-98AB-2902-CA896A2B60C1} - C:\WINDOWS\system32\ahodlvi.dll (file missing)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Search - {12EE7A5E-0674-42f9-A76B-000000004D00} - C:\WINDOWS\system32\stlb2.dll (file missing)
O3 - Toolbar: My Global Search Bar - {37B85A29-692B-4205-9CAD-2626E4993404} - C:\Program Files\MyGlobalSearch\bar\1.bin\MGSBAR.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\RunOnce: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe /boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Lrjfu] C:\WINDOWS\SYSTEM32\LASS~1.EXE
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\APPATC~1\chkdsk.exe" -vt mtx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Alan\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinn...rabblecubes.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/...UI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c9.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...tup1.0.0.15.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2A9146F3-E5DE-48D8-8B53-E1214450B778} (Generator Class) - http://users.rcn.com...s/MachineID.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://game1.pogo.co...erInstaller.CAB
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinn...8/pool/pool.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/...dy.cab32846.cab
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.co...ysb_regular.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23....es/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/...at.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...ck/bjattack.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/c...tallerProj1.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinn...jo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v45/sol/sol.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/...he.cab50108.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinn...luxor/luxor.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab53083.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinn...royal/royal.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/...xy.cab41227.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://207.81.91.42:...activex/AMC.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinn...es/wwspades.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...nnerInstall.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinn...ool/h2hpool.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O20 - AppInit_DLLs: dvdplay.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe (file missing)

Edited by commercialasreannoying, 20 December 2006 - 11:35 PM.

  • 0

Advertisements


#2
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Hmmm... do this first. Download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode.
Post the results of the AVG Anti-Spyware report.

Then this. Download SUPERAntiSpyware Home Edition (free version)
  • Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
    • Close browsers before scanning
    • Scan for tracking cookies
    • Terminate memory threats before quarantining.
    • Please leave the others unchecked.
    • Click the Close button to leave the control center screen.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
  • To retrieve the removal information for me please do the following:
    • After reboot, double-click the SUPERAntispyware icon on your desktop.
    • Click Preferences. Click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • It will open in your default text editor (such as Notepad/Wordpad).
    • Please highlight everything in the notepad, then right-click and choose copy.
  • Click close and close again to exit the program.
  • Please paste that information here for me with a new HijackThis log.

  • 0

#3
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:17:19 AM 12/21/2006

+ Scan result:



C:\Program Files\BearShare\BearShareZangoInstaller.exe/clientax.dll -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP575\A0094739.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\RCX159D.tmp -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\Program Files\Aprps -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_01-08-2005.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_02-08-2005.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_30-07-2005.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\AI_31-07-2005.log -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\Aprps\data.bin -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\AutoUpdate -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\AutoUpdate\libexpat.dll -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\AutoLoader -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\AutoLoader\tw3Z1MTQMNLd -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\AutoLoader\tw3v1MTQMNLd -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Envolo -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Envolo\AutoUpdate -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Envolo\AutoUpdate\State -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Envolo\AutoUpdate\Tasks -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AproposClient -> Adware.Apropos : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoUpdate -> Adware.Apropos : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Apropos -> Adware.Apropos : Cleaned with backup (quarantined).
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091605.vxd/C:/WINDOWS/system32/exdl.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091605.vxd/C:/WINDOWS/system32/exul.exe -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091605.vxd/C:/WINDOWS/system32/javexulm.vxd -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091605.vxd/C:/WINDOWS/system32/mqexdlm.srg -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADP.UrlCatcher -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADP.UrlCatcher.1 -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\ADP.UrlCatcher\CLSID -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\eXactUtil -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup (quarantined).
C:\WINDOWS\DrUninst.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\sPeerDll.sPeerDllObj -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\sPeerDll.sPeerDllObj.1 -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\sPeerDll.sPeerDllObj\CLSID -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\sPeerDll.sPeerDllObj\CurVer -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\speer -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\sPeer -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarBHO -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarBHO.1 -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarBHO\CLSID -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarBHO\CurVer -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarName -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarName.1 -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarName\CLSID -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\_ATL_GENERATED.SearchToolbarName\CurVer -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunWindowsUpdate -> Adware.BrowserAid : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunWindowsUpdate\Active -> Adware.BrowserAid : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091603.exe -> Adware.EZula : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091604.exe -> Adware.EZula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\eZulaBootExe.EXE -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Adware\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\BHO.Hider\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl.1 -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CLSID -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\EZulaBootExe.InstallCtrl\CurVer -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Netstat -> Adware.Ezula : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{55BE9F0D-6CAF-4c3e-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Hotbar\Bin -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\Hotbar\Bin\4.6.0.0 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports\Bin -> Adware.HotBar : Cleaned with backup (quarantined).
C:\Program Files\ShopperReports\Bin\1.3.0.0 -> Adware.HotBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091600.exe -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Hotbar -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Hotbar\Install -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Hotbar\PI -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Hotbar\PI\3.2 -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Install -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Hotbar\Install\CmpMap -> Adware.HotBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tpro -> Adware.IBIS : Cleaned with backup (quarantined).
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
C:\Program Files\Internet Optimizer\update -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Active Alert -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Active Alert\cf1 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Active Alert\cf3 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE\cf1 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE\cf2 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE\cf3 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE\cf4 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\WSE\cf5 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\anything -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\anything\cf1 -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\IST -> Adware.ISTBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj.1 -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CLSID -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\DyFuCA_BH.SinkObj\CurVer -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT -> Adware.NaviSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Enum -> Adware.NaviSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Security -> Adware.NaviSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087791.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087803.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP542\A0089011.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP543\A0089039.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP544\A0089085.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP544\A0089086.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP546\A0091083.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP547\A0091120.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091303.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091584.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091609.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP553\A0091614.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP554\A0092568.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP560\A0092829.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP572\A0094477.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP574\A0094635.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP578\A0094946.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP579\A0094953.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP584\A0095073.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP584\A0095074.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP585\A0095099.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP586\A0095137.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP586\A0095185.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP587\A0095236.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP593\A0096647.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\mcnttymz.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MEDIATICKETSINSTALLER.MediaTicketsInstallerCtrl.1 -> Adware.PurityScan : Cleaned with backup (quarantined).
[228] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[276] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[288] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[448] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[496] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[552] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[788] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[876] C:\WINDOWS\system32\dvdplay.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer Active Alert -> Adware.SafeSurfing : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091472.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091473.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Program Files\Toolbar\TBPSSvc.exe -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Program Files\Toolbar\WSG.exe -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Program Files\Toolbar\common.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Program Files\Toolbar\nzqlihv.wzg -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\Program Files\Toolbar\radio.exe -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Common.Buttons -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Common.Buttons\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res\WToolsB.ResProtocol -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res\toolbar.ResProtocol -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Radio.RadioPlayer -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Radio.RadioPlayer\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginConfig -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginConfig\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginDown -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginDown\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginEvents -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginEvents\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginInst -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginInst\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginServer -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.PluginServer\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WSG.WSGObj -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WSG.WSGObj\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WToolsB.ResProtocol -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WToolsB.ResProtocol\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\toolbar.ResProtocol -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\toolbar.ResProtocol\Clsid -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\APP -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\BBDE -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\BBDHE -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\BBDI -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\COMMON -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\MAJORSE -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\RADIO -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\SVC -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\TBR -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Files\WSG -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Install -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\PlugIns -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\PlugIns\COMMON -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\PlugIns\RADIO -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\PlugIns\WSG -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Toolbar\Server -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WinTools -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WinTools\kydmzylki -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WinTools\nlibjhin -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\WinTools\nlibx4m -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\btlink -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\btlink\btlink -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Enum -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Security -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Security -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\toolbar -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\toolbar -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar\PlugIns -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar\PlugIns\COMMON -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar\PlugIns\RADIO -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar\PlugIns\WSG -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Toolbar\Server -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\WinTools -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\WinTools\URLSearchHooks -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\btlink -> Adware.WebSearch : Cleaned with backup (quarantined).
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\btlink\btlink -> Adware.WebSearch : Cleaned with backup (quarantined).
[848] c:\PROGRA~1\Toolbar\common.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
[920] c:\PROGRA~1\Toolbar\radio.exe -> Adware.WebSearch : Cleaned with backup (quarantined).
[960] c:\PROGRA~1\Toolbar\WSG.exe -> Adware.WebSearch : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MediaAccX.Installer -> Adware.WinAd : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MediaAccX.Installer\CLSID -> Adware.WinAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP527\A0087425.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP527\A0087426.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087498.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087499.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087500.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087509.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087518.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087547.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087551.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087557.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP530\A0087577.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP532\A0087618.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP532\A0087619.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP532\A0087621.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP534\A0087706.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP534\A0087709.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP535\A0087739.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087794.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087795.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087804.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087811.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP537\A0087872.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP537\A0087875.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP537\A0087883.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP537\A0087906.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP537\A0087921.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP538\A0087947.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP538\A0087966.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP538\A0088010.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP538\A0088030.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP539\A0088098.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088601.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088622.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088643.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088683.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088800.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088825.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088845.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088865.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP541\A0088885.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP543\A0089054.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP544\A0090055.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP546\A0090099.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP546\A0091090.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP547\A0091137.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091187.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091210.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091228.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091261.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091290.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP550\A0091455.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091491.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091574.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP554\A0092586.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP554\A0092616.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP555\A0092648.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP556\A0092666.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP556\A0092708.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP558\A0092759.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP558\A0092760.exe -> Adware.Wintol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP558\A0092761.dll -> Adware.Wintol : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer -> Adware.YourSiteBar : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\YSBactivex.Installer\CLSID -> Adware.YourSiteBar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP575\A0094778.dll -> Adware.Zango : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091605.vxd/C:/WINDOWS/system32/msexreg.exe -> Dialer.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-5e55057-176d49c5.zip/Matrix.class -> Downloader.OpenStream.c : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\OMG.class-1540eca1-7221e56f.class -> Downloader.OpenStream.y : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP559\A0092814.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP564\A0094244.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP573\A0094576.exe -> Downloader.Purit.co : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP560\A0092899.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP566\A0094295.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-53cc4468-5d67d806.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-69b179b1.zip/NewSecurityClassLoader.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-69b179b1.zip/NewURLClassLoader.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv661.jar-5e55057-176d49c5.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
C:\Documents and Settings\Alan\Cookies\alan@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Belstat : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@bfast[1].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@paycounter[2].txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Alan\Cookies\alan@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091606.exe -> Trojan.Crypt.t : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP536\A0087792.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP542\A0089012.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP544\A0089089.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP546\A0090104.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP547\A0091118.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP549\A0091304.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP551\A0091585.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091610.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP559\A0092815.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP564\A0094245.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP572\A0094478.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP573\A0094577.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP577\A0094901.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP578\A0094947.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP582\A0095045.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP583\A0095067.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP584\A0095094.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP585\A0095123.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP586\A0095187.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP588\A0096228.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP594\A0096671.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP595\A0096951.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP596\A0096969.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wcptr.exe -> Trojan.Small : Cleaned with backup (quarantined).
  • 0

#4
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
SUPERAntiSpyware Scan Log
Generated 12/21/2006 at 02:26 AM

Application Version : 3.4.1000

Core Rules Database Version : 3151
Trace Rules Database Version: 1167

Scan type : Complete Scan
Total Scan Time : 00:54:04

Memory items scanned : 493
Memory threats detected : 8
Registry items scanned : 5992
Registry threats detected : 277
File items scanned : 75094
File threats detected : 228

Spyware.WebSearch (WinTools/HuntBar)
C:\PROGRA~1\TOOLBAR\TBPS.EXE
C:\PROGRA~1\TOOLBAR\TBPS.EXE
C:\PROGRA~1\TOOLBAR\PIB.EXE
C:\PROGRA~1\TOOLBAR\PIB.EXE
C:\PROGRA~1\TOOLBAR\RADIO.EXE
C:\PROGRA~1\TOOLBAR\RADIO.EXE
C:\PROGRA~1\TOOLBAR\WSG.EXE
C:\PROGRA~1\TOOLBAR\WSG.EXE
C:\PROGRA~1\TOOLBAR\TBPSSVC.EXE
C:\PROGRA~1\TOOLBAR\TBPSSVC.EXE
[TBPS] C:\PROGRA~1\TOOLBAR\TBPS.EXE
HKLM\System\ControlSet001\Services\TBPSSvc
HKLM\System\CurrentControlSet\Services\TBPSSvc
HKCR\CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}
HKCR\CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}\InprocServer32
HKCR\CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}\InprocServer32#ThreadingModel
HKCR\CLSID\{87766247-311C-43B4-8499-3D5FEC94A183}
HKCR\CLSID\{87766247-311C-43B4-8499-3D5FEC94A183}\InprocServer32
HKCR\CLSID\{87766247-311C-43B4-8499-3D5FEC94A183}\InprocServer32#ThreadingModel
HKCR\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}
HKCR\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}\InprocServer32
HKCR\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}\InprocServer32#ThreadingModel
HKCR\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}
HKCR\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\InprocServer32
HKCR\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\InprocServer32#ThreadingModel
C:\Program Files\Common Files\WinTools\iwuivj.wzg
C:\Program Files\Common Files\WinTools\rmhgxlmu.wzg
C:\Program Files\Common Files\WinTools\Update
C:\Program Files\Common Files\WinTools\WToolsC.cfg
C:\Program Files\Common Files\WinTools\WToolsD.cfg
C:\Program Files\Common Files\WinTools\WToolsP.cfg
C:\Program Files\Common Files\WinTools\WToolsR.cfg
C:\Program Files\Common Files\WinTools\WToolsT.dll
C:\Program Files\Common Files\WinTools\WToolsU.cfg
C:\Program Files\Common Files\WinTools
C:\Documents and Settings\All Users\Start Menu\Programs\Web Search Tools\Frequently Asked Questions.url
C:\Documents and Settings\All Users\Start Menu\Programs\Web Search Tools\Home.url
C:\Documents and Settings\All Users\Start Menu\Programs\Web Search Tools\Privacy Policy.url
C:\Documents and Settings\All Users\Start Menu\Programs\Web Search Tools\Terms of Use.url
C:\Documents and Settings\All Users\Start Menu\Programs\Web Search Tools
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL#DisplayIcon
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}\Implemented Categories
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}\LocalServer32
HKCR\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7}\LocalServer32#ThreadingModel
HKCR\CLSID\{A8DEB4A5-D9EF-4D21-B4F6-921475004E7D}
HKCR\CLSID\{A8DEB4A5-D9EF-4D21-B4F6-921475004E7D}\InprocServer32
HKCR\CLSID\{A8DEB4A5-D9EF-4D21-B4F6-921475004E7D}\InprocServer32#ThreadingModel
HKCR\CLSID\{A8DEB4A5-D9EF-4D21-B4F6-921475004E7D}\ProgID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC#NextInstance
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Service
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Legacy
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#ConfigFlags
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Class
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#ClassGUID
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#DeviceDesc
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools_ESIES
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools_ESIES#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools_ESIES#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools_ESIES#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools_ESIES#URLInfoAbout
C:\PROGRAM FILES\TOOLBAR\PIB.EXE
C:\PROGRAM FILES\TOOLBAR\RADIO.EXE
C:\PROGRAM FILES\TOOLBAR\TBPS.EXE
C:\PROGRAM FILES\TOOLBAR\TBPSSVC.EXE
C:\PROGRAM FILES\TOOLBAR\WSG.EXE
C:\WINDOWS\Prefetch\TBPS.EXE-2EE5A9EB.pf
C:\WINDOWS\Prefetch\TBPSSVC.EXE-14A5E98F.pf

BearShare File Sharing Client
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
[BearShare] C:\PROGRAM FILES\BEARSHARE\BEARSHARE.EXE
C:\WINDOWS\Prefetch\BEARSHARE.EXE-35739D34.pf

Adware.ClickSpring/Resident
C:\WINDOWS\SYSTEM32\LASS~1.EXE
C:\WINDOWS\SYSTEM32\LASS~1.EXE

Adware.ClickSpring-Variant
C:\PROGRA~1\APPATC~1\CHKDSK.EXE
C:\PROGRA~1\APPATC~1\CHKDSK.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP576\A0094872.EXE

Adware.ClickSpring
[Lrjfu] C:\WINDOWS\SYSTEM32\LASS~1.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP547\A0091117.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP577\A0094900.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP597\A0098048.DLL

Adware.MyGlobalSearchBar
HKLM\Software\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}\InprocServer32
C:\PROGRAM FILES\MYGLOBALSEARCH\BAR\1.BIN\MGSBAR.DLL
HKLM\Software\Classes\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\InprocServer32
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\Programmable
HKCR\CLSID\{37B85A21-692B-4205-9CAD-2626E4993404}\TypeLib
HKLM\Software\Classes\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\InprocServer32
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\Programmable
HKCR\CLSID\{37B85A29-692B-4205-9CAD-2626E4993404}\TypeLib
HKLM\Software\Classes\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Control
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\InprocServer32
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\InprocServer32#ThreadingModel
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\MiscStatus
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\MiscStatus\1
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\ProgID
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Programmable
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\TypeLib
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\Version
HKCR\CLSID\{37B85A2B-692B-4205-9CAD-2626E4993404}\VersionIndependentProgID
HKLM\Software\Classes\CLSID\{EF281620-A3A3-4f08-874F-D68CFC9B7945}
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\InprocServer32
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\InprocServer32#ThreadingModel
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\ProgID
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\Programmable
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\TypeLib
HKCR\CLSID\{EF281620-A3A3-4F08-874F-D68CFC9B7945}\VersionIndependentProgID
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{37B85A21-692B-4205-9CAD-2626E4993404}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{37B85A29-692B-4205-9CAD-2626E4993404}
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\0
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\0\win32
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\FLAGS
HKCR\TypeLib\{37B85A20-692B-4205-9CAD-2626E4993404}\1.0\HELPDIR
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{37B85A29-692B-4205-9CAD-2626E4993404}

Adware.Tracking Cookie
C:\Documents and Settings\Alan\Cookies\alan@tacoda[2].txt
C:\Documents and Settings\Alan\Cookies\alan@bluestreak[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@mywebsearch[1].txt
C:\Documents and Settings\Alan\Cookies\alan@hitbox[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@indiads[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@cgi-bin[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@winantispyware[2].txt
C:\Documents and Settings\Alan\Cookies\alan@adrevolver[3].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@belnk[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@mediaplex[1].txt
C:\Documents and Settings\Alan\Cookies\alan@partner2profit[2].txt
C:\Documents and Settings\Alan\Cookies\alan@adbrite[2].txt
C:\Documents and Settings\Alan\Cookies\alan@indexstats[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@a[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@trafficmp[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@realmedia[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@1067919435[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@valueclick[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@maxserving[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@zedo[2].txt
C:\Documents and Settings\Alan\Cookies\alan@atdmt[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@ad[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@cpvfeed[2].txt
C:\Documents and Settings\Alan\Cookies\alan@interclick[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@atwola[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@burstnet[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@nextag[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@questionmarket[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@1072598540[1].txt
C:\Documents and Settings\Alan\Cookies\alan@targetnet[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@mb[3].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@tribalfusion[2].txt
C:\Documents and Settings\Alan\Cookies\alan@adtech[2].txt
C:\Documents and Settings\Alan\Cookies\alan@directtrack[1].txt
C:\Documents and Settings\Alan\Cookies\alan@serving-sys[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@2o7[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@mb[2].txt
C:\Documents and Settings\Alan\Cookies\alan@casalemedia[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@paycounter[2].txt
C:\Documents and Settings\Alan\Cookies\alan@23844616[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@doubleclick[1].txt
C:\Documents and Settings\Alan\Cookies\alan@revsci[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@247realmedia[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@LPBofA1[1].txt
C:\Documents and Settings\Alan\Cookies\alan@fastclick[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@bizrate[2].txt
C:\Documents and Settings\Alan\Cookies\alan@43355559[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@1071868927[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@1068538250[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@87263826[1].txt
C:\Documents and Settings\Alan\Cookies\alan@tradedoubler[1].txt
C:\Documents and Settings\Alan\Cookies\alan@adrevolver[1].txt
C:\Documents and Settings\Alan\Cookies\alan@entrepreneur[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@sextracker[1].txt
C:\Documents and Settings\Alan\Cookies\alan@advertising[2].txt
C:\Documents and Settings\Alan\Cookies\alan@drivecleaner[2].txt
C:\Documents and Settings\Alan\Cookies\alan@spamblockerutility[1].txt
C:\Documents and Settings\Alan\Cookies\alan@linksynergy[2].txt
C:\Documents and Settings\Alan\Cookies\alan@mb[4].txt
C:\Documents and Settings\Alan\Cookies\alan@statcounter[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@mediaonenetwork[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@24292[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@mb[5].txt
C:\Documents and Settings\Alan\Cookies\alan@html[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@jamster[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@1072611828[1].txt
C:\Documents and Settings\Alan\Cookies\alan@S152628[1].txt
C:\Documents and Settings\Alan\Cookies\alan@24215[1].txt
C:\Documents and Settings\Alan\Cookies\alan@revenue[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@partypoker[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@onlinerewardcenter[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@stats[1].txt
C:\Documents and Settings\Alan\Cookies\alan@1066331376[2].txt
C:\Documents and Settings\Alan\Cookies\alan@40715998[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\alan@indextools[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@52168016[1].txt
C:\Documents and Settings\Alan\Cookies\alan@focalex[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@xiti[1].txt
C:\Documents and Settings\Alan\Cookies\alan@overture[2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@adserver[1].txt
C:\Documents and Settings\Alan\Cookies\alan@1072395179[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][1].txt
C:\Documents and Settings\Alan\Cookies\alan@66702201[1].txt
C:\Documents and Settings\Alan\Cookies\alan@tripod[1].txt
C:\Documents and Settings\Alan\Cookies\alan@1069095226[1].txt
C:\Documents and Settings\Alan\Cookies\[email protected][2].txt
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@atwola[1].txt
C:\Documents and Settings\Alan\Local Settings\Temp\Cookies\alan@revsci[2].txt

ADP UrlCatcher Class BHO
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}\InprocServer32
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}\InprocServer32#ThreadingModel
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}\ProgID
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}\Programmable
HKCR\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA}\VersionIndependentProgID

Adware.Avenue Media/Internet Optimizer
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\InprocServer32#ThreadingModel
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\ProgID
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\Programmable
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\TypeLib
HKCR\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8}\VersionIndependentProgID
HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}
HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\ProxyStubClsid
HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\ProxyStubClsid32
HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\TypeLib
HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\TypeLib#Version
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}\1.0
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}\1.0\0
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}\1.0\0\win32
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}\1.0\FLAGS
HKCR\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}\1.0\HELPDIR
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}

Adware.Apropos Media/CxtPls
HKCR\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}
HKCR\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}\InprocServer32
HKCR\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9}\InprocServer32#ThreadingModel

BHObj Class BHO
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\InprocServer32
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\InprocServer32#ThreadingModel
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\ProgID
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\Programmable
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\TypeLib
HKCR\CLSID\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4}\VersionIndependentProgID

SearchToolbarBHOObject BHO
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}#AppID
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\InprocServer32
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\InprocServer32#ThreadingModel
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\ProgID
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\Programmable
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\TypeLib
HKCR\CLSID\{12EE7A5E-0674-42F9-A76A-000000004D00}\VersionIndependentProgID

Search Explorer Bar/Toolbar
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}#AppID
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\Implemented Categories
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\InprocServer32
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\InprocServer32#ThreadingModel
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\ProgID
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\Programmable
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\TypeLib
HKCR\CLSID\{12EE7A5E-0674-42F9-A76B-000000004D00}\VersionIndependentProgID

Adware.Webext
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\InprocServer32
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\InprocServer32#ThreadingModel
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\ProgID
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\Programmable
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\TypeLib
HKCR\CLSID\{09D98DB3-217F-4A37-950F-7FA1B08CE2B6}\VersionIndependentProgID

Adware.Apropos Media
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Aprps
HKLM\Software\Aprps
HKLM\Software\Aprps\Client
HKLM\Software\Aprps\Client#InstallationId
HKLM\Software\Aprps\Client#ProxyStub
HKLM\Software\Aprps\Client#Plugin
HKLM\Software\Aprps\Client#ClientName
HKLM\Software\Aprps\Client#LegalNote
HKLM\Software\Aprps\Client#PartnerId
HKLM\Software\Aprps\Client#ServerAddress
C:\WINDOWS\system32\auto_update_uninstall.log

Adware.IST/ISTBar (Slotch Bar)
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\0
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\0\win32
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\FLAGS
HKCR\TypeLib\{67907B3C-A6EF-4A01-99AD-3FCD5F526429}\1.1\HELPDIR
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}\ProxyStubClsid
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}\ProxyStubClsid32
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}\TypeLib
HKCR\Interface\{0985C112-2562-46F2-8DA6-92648BA4630F}\TypeLib#Version
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main#BandRest [ Never ]
HKU\S-1-5-21-234976697-781374817-1698198236-1006\Software\Microsoft\Internet Explorer\Main#BandRest [ Never ]
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main#BandRest [ Never ]
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main#BandRest [ Never ]

Adware.Ezula
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}#AppID
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\LocalServer32
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\ProgID
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\Programmable
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\TypeLib
HKCR\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}\VersionIndependentProgID
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\0
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\0\win32
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\FLAGS
HKCR\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}\1.0\HELPDIR
HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}
HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\ProxyStubClsid
HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\ProxyStubClsid32
HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\TypeLib
HKCR\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}\TypeLib#Version
HKCR\AppId\{C0335198-6755-11D4-8A73-0050DA2EE1BE}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP552\A0091601.EXE

Trojan.SpySheriff
C:\WINDOWS\secure32.html

Adware.IST/YourSiteBar
HKCR\CLSID\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}
HKCR\CLSID\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}\InprocServer32
HKCR\CLSID\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}\InprocServer32#ThreadingModel
HKCR\CLSID\{42F2C9BA-614F-47c0-B3E3-ECFD34EED658}\ProgID
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll#.Owner
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/ysbactivex.dll#{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs#C:\WINDOWS\Downloaded Program Files\ysbactivex.dll [  ]

Adware.MediaMediatickets
HKCR\CLSID\{39DA2444-065F-47CB-B27C-CCB1A39C06B7}
HKCR\CLSID\{39DA2444-065F-47CB-B27C-CCB1A39C06B7}\InprocServer32
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\Control
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\Implemented Categories
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\InprocServer32
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\InprocServer32#ThreadingModel
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\MiscStatus
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\MiscStatus\1
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\ProgID
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\ToolboxBitmap32
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\TypeLib
HKCR\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}\Version

Trojan.Unknown Origin
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#SystemComponent
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}#Installer
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains\Files
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\Contains\Files#C:\WINDOWS\Downloaded Program Files\ysbactivex.dll
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\DownloadInformation#CODEBASE
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\InstalledVersion#LastModified
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP597\A0098047.EXE

Browser Hijacker.Begin2Search
HKCR\btnetw.amo
HKCR\btnetw.amo\CLSID
HKCR\btnetw.amo\CurVer
HKCR\btnetw.amo.1
HKCR\btnetw.amo.1\CLSID
HKCR\btnetw.iiittt
HKCR\btnetw.iiittt\CLSID
HKCR\btnetw.iiittt\CurVer
HKCR\btnetw.iiittt.1
HKCR\btnetw.iiittt.1\CLSID
HKCR\btnetw.momo
HKCR\btnetw.momo\CLSID
HKCR\btnetw.momo\CurVer
HKCR\btnetw.momo.1
HKCR\btnetw.momo.1\CLSID
HKCR\btnetw.ohb
HKCR\btnetw.ohb\CLSID
HKCR\btnetw.ohb\CurVer
HKCR\btnetw.ohb.1
HKCR\btnetw.ohb.1\CLSID

Adware.MyWay
HKLM\Software\MyWay
HKLM\Software\MyWay\myBar
HKLM\Software\MyWay\myBar#Dir
HKLM\Software\MyWay\myBar#pid
HKLM\Software\MyWay\myBar#CurInstall
HKLM\Software\MyWay\myBar#sr
HKLM\Software\MyWay\myBar#pl
HKLM\Software\MyWay\myBar#Id
HKLM\Software\MyWay\myBar#CacheDir
HKLM\Software\MyWay\myBar#HistoryDir
HKLM\Software\MyWay\myBar#Visible
HKLM\Software\MyWay\myBar#Maximized
HKLM\Software\MyWay\myBar#SettingsDir
HKLM\Software\MyWay\myBar#ConfigRevisionURL
HKLM\Software\MyWay\myBar#ConfigDateStamp
HKLM\Software\MyWay\SearchAssistant
HKLM\Software\MyWay\SearchAssistant#Dir
HKLM\Software\MyWay\SearchAssistant#pid
HKLM\Software\MyWay\SearchAssistant#CurInstall
HKLM\Software\MyWay\SearchAssistant#sr
HKLM\Software\MyWay\SearchAssistant#pl
HKLM\Software\MyWay\SearchAssistant#Id
HKLM\Software\MyWay\SearchAssistant#CacheDir
HKLM\Software\MyWay\SearchAssistant#ConfigDateStamp
C:\Program Files\MyWay\myBar\History\search
C:\Program Files\MyWay\myBar\History
C:\Program Files\MyWay\myBar\Settings\prevcfg.htm
C:\Program Files\MyWay\myBar\Settings
C:\Program Files\MyWay\myBar
C:\Program Files\MyWay\SrchAstt
C:\Program Files\MyWay

Trojan.Downloader-Gen/Update
C:\DOCUMENTS AND SETTINGS\ALAN\LOCAL SETTINGS\TEMP\!UPDATE.EXE

Adware.Casino Games (Golden Palace Casino)
C:\PROGRAM FILES\TITAN POKER\CASINO.EXE

Browser Hijacker.Favorites
C:\RECYCLER\S-1-5-21-234976697-781374817-1698198236-1006\DC1.URL

Adware.180solutions/Seekmo
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP565\A0094273.DLL

Trojan.Downloader-CSRSS/Fake
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP588\A0096227.EXE

Parasite.CoolWebSearch Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP597\A0098049.DLL

Adware.180solutions/ZangoSearch
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP597\A0098054.EXE

Unclassified.Unknown Origin
C:\WINDOWS\TEMP\QZTYT2H6.EXE
C:\WINDOWS\Prefetch\QZTYT2H6.EXE-2036BC8D.pf
  • 0

#5
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
if i uninstall any of the stuff i installed will it mess anythingup and my bearshares gone


Logfile of HijackThis v1.99.1
Scan saved at 2:43:08 AM, on 12/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Alan\Local Settings\Temporary Internet Files\Content.IE5\DKOBD1C5\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50245
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {C1034046-8D87-DB56-8C3D-894D86857C97} - C:\WINDOWS\system32\wpfzj.dll (file missing)
R3 - URLSearchHook: (no name) - {A8A79C0C-5ACD-0B1D-931C-0BE52C1F4091} - C:\WINDOWS\system32\xpquut.dll (file missing)
R3 - URLSearchHook: (no name) - {A5A9CF0D-5C9F-0A49-C81C-0BE52C1C15CE} - C:\WINDOWS\system32\ymkkquuk.dll (file missing)
R3 - URLSearchHook: (no name) - {D0C3385F-A29E-A615-9EFC-F5FA4DAA6DCD} - C:\WINDOWS\system32\lxb.dll (file missing)
R3 - URLSearchHook: (no name) - {9AD69DBB-5070-06A2-23F7-0545060E2693} - C:\WINDOWS\system32\mcnttymz.dll (file missing)
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O1 - Hosts: 66.38.215.115 kazza.com
O1 - Hosts: 66.38.215.115 www.kazza.com
O1 - Hosts: 66.38.215.115 kaza.com
O1 - Hosts: 66.38.215.115 www.kaza.com
O1 - Hosts: 66.38.215.115 kaaza.com
O1 - Hosts: 66.38.215.115 www.kaaza.com
O1 - Hosts: 66.38.215.115 kahza.com
O1 - Hosts: 66.38.215.115 www.kahza.com
O1 - Hosts: 66.38.215.115 edonkey.com
O1 - Hosts: 66.38.215.115 www.edonkey.com
O1 - Hosts: 66.38.215.115 emule.com
O1 - Hosts: 66.38.215.115 www.emule.com
O1 - Hosts: 66.38.215.115 suprnova.com
O1 - Hosts: 66.38.215.115 www.suprnova.com
O1 - Hosts: 64.124.166.37 klite.com
O1 - Hosts: 64.124.166.37 www.klite.com
O1 - Hosts: 64.124.166.37 k-lite.com
O1 - Hosts: 64.124.166.37 www.k-lite.com
O1 - Hosts: 64.124.166.37 kazaalite.com
O1 - Hosts: 64.124.166.37 www.kazzalite.com
O1 - Hosts: 64.124.166.37 kazalite.com
O1 - Hosts: 64.124.166.37 www.kazalite.com
O1 - Hosts: 64.124.166.37 kaazalite.com
O1 - Hosts: 64.124.166.37 www.kaazalite.com
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\APPATC~1\chkdsk.exe" -vt mtx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Alan\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinn...rabblecubes.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/...UI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c9.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...tup1.0.0.15.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2A9146F3-E5DE-48D8-8B53-E1214450B778} (Generator Class) - http://users.rcn.com...s/MachineID.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://game1.pogo.co...erInstaller.CAB
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinn...8/pool/pool.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/...dy.cab32846.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23....es/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/...at.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...ck/bjattack.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/c...tallerProj1.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinn...jo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v45/sol/sol.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/...he.cab50108.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinn...luxor/luxor.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab53083.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinn...royal/royal.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/...xy.cab41227.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://207.81.91.42:...activex/AMC.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinn...es/wwspades.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...nnerInstall.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinn...ool/h2hpool.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dvdplay.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0

#6
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
That's probably how you got so badly infected in the first place. You need to give me more of a clue as to what you are intending to uninstall for me to advise. Do this next. Click here to download the Hoster. Extract it from the zip file into a folder and doubleclick on hoster.exe. Press "Restore Original Hosts" and press "OK". Exit the program. Reboot and post a new HJT log.
  • 0

#7
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
nvm im not uninstalling anything and my popups seem to be gone :whistling:

ill get right on that hjl And bearshares back

Edited by commercialasreannoying, 21 December 2006 - 02:35 PM.

  • 0

#8
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
Logfile of HijackThis v1.99.1
Scan saved at 12:42:17 PM, on 12/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alan\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50245
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {C1034046-8D87-DB56-8C3D-894D86857C97} - C:\WINDOWS\system32\wpfzj.dll (file missing)
R3 - URLSearchHook: (no name) - {A8A79C0C-5ACD-0B1D-931C-0BE52C1F4091} - C:\WINDOWS\system32\xpquut.dll (file missing)
R3 - URLSearchHook: (no name) - {A5A9CF0D-5C9F-0A49-C81C-0BE52C1C15CE} - C:\WINDOWS\system32\ymkkquuk.dll (file missing)
R3 - URLSearchHook: (no name) - {D0C3385F-A29E-A615-9EFC-F5FA4DAA6DCD} - C:\WINDOWS\system32\lxb.dll (file missing)
R3 - URLSearchHook: (no name) - {9AD69DBB-5070-06A2-23F7-0545060E2693} - C:\WINDOWS\system32\mcnttymz.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\APPATC~1\chkdsk.exe" -vt mtx
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] C:\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyBingo.com - {B987E7E7-5997-4330-A5F9-9FFEFC1CCFD0} - C:\Program Files\PartyGaming\PartyBingo\RunBingo.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Alan\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinn...rabblecubes.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/...UI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c9.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft....204&clcid=0x409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...tup1.0.0.15.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2A9146F3-E5DE-48D8-8B53-E1214450B778} (Generator Class) - http://users.rcn.com...s/MachineID.dll
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC} (PogoWebLauncher Control) - http://game1.pogo.co...erInstaller.CAB
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinn...8/pool/pool.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplane...C_2.3.3.102.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/...dy.cab32846.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23....es/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/...at.cab32846.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinn...ck/bjattack.cab
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/c...tallerProj1.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinn...jo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v45/sol/sol.cab
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (ZPA_TexasHoldem Object) - http://zone.msn.com/...he.cab50108.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinn...luxor/luxor.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab53083.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinn...royal/royal.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinn...paint/paint.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/...xy.cab41227.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://207.81.91.42:...activex/AMC.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinn...es/wwspades.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...nnerInstall.cab
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinn...ool/h2hpool.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dvdplay.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
  • 0

#9
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
ok so everytime i reboot the computer bearshare goes away

is this because i terminated the memory on it in that scan we did???!??!?!?
  • 0

#10
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
I'm not sure what you are referring to. It has been removed because it's malware and caused you to get infected in the first place. If you are trying to reinstall it we are both wasting our time with this.
  • 0

#11
commercialasreannoying

commercialasreannoying

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts
ok fine ill take it off but now what do i do
  • 0

#12
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Make sure that you have no browser windows open as this could prevent the fix from working properly. Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch...spx?tb_id=50245
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch...spx?tb_id=50245
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch...spx?tb_id=50245
R3 - URLSearchHook: (no name) - {C1034046-8D87-DB56-8C3D-894D86857C97} - C:\WINDOWS\system32\wpfzj.dll (file missing)
R3 - URLSearchHook: (no name) - {A8A79C0C-5ACD-0B1D-931C-0BE52C1F4091} - C:\WINDOWS\system32\xpquut.dll (file missing)
R3 - URLSearchHook: (no name) - {A5A9CF0D-5C9F-0A49-C81C-0BE52C1C15CE} - C:\WINDOWS\system32\ymkkquuk.dll (file missing)
R3 - URLSearchHook: (no name) - {D0C3385F-A29E-A615-9EFC-F5FA4DAA6DCD} - C:\WINDOWS\system32\lxb.dll (file missing)
R3 - URLSearchHook: (no name) - {9AD69DBB-5070-06A2-23F7-0545060E2693} - C:\WINDOWS\system32\mcnttymz.dll (file missing)
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
O4 - HKCU\..\Run: [Sen] "C:\PROGRA~1\APPATC~1\chkdsk.exe" -vt mtx
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c9.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...tup1.0.0.15.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v6.cab
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://winfixer.com/...nnerInstall.cab


Exit HijackThis when done. Reboot, rescan with HijackThis and post a new log here.
  • 0

#13
Daemon

Daemon

    Security Expert

  • Retired Staff
  • 4,356 posts
  • MVP
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP