Here you go--one other note, the
http://info/ part of the HJT scan is harmless--the address is our internal company homepage. So ignore that one...
Here's a fresh HJT scan and the Trend Micro scan results.
Logfile of HijackThis v1.99.1
Scan saved at 12:32:38 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Belarc\BelMonitor\BANTMonitorSvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wintask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Omtool\GenifaxPrintToMail\GenifaxPTM.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\userinit.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\WINDOWS\system32\wuauclt.exe
\Hg-srv-fs1\Users\btketron\Personal\My Programs\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://info/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://info/O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [BelNotify] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Belarc\Advisor\System\NPBelv32.dll,RunDll32_BelNotify
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\system32\exp.exe
O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\system32\wintask.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Genifax Print to Mail.lnk = C:\Program Files\Omtool\GenifaxPrintToMail\GenifaxPTM.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120575933776O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) -
https://oracle.alpha...tor/oajinit.exeO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = alphanr.org
O17 - HKLM\Software\..\Telephony: DomainName = alphanr.org
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = alphanr.org
O20 - Winlogon Notify: Extensions - C:\WINDOWS\system32\pcintui.dll
O23 - Service: BelMonitor Service (BelMonitorService) - Belarc, Inc. - C:\PROGRA~1\Belarc\BelMonitor\BANTMonitorSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OracleClientCache80 - Unknown owner - C:\orant\BIN\ONRSD80.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Started Scanning
Internet Cookies
Found 'realmedia.com' in 'Internet Explorer Cache'
Found 'server.iad.liveperson.net' in 'Internet Explorer Cache'
Found 'master.mx-targeting.com' in 'Internet Explorer Cache'
Found 'imrworldwide.com' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Found 'adknowledge.com' in 'Internet Explorer Cache'
Found 'trafficmp.com' in 'Internet Explorer Cache'
Found 'questionmarket.com' in 'Internet Explorer Cache'
Found 'abetterinternet.com' in 'Internet Explorer Cache'
Found 'com.com' in 'Internet Explorer Cache'
Found 'a.websponsors.com' in 'Internet Explorer Cache'
Found 'offeroptimizer.com' in 'Internet Explorer Cache'
Found 'delfinproject.com' in 'Internet Explorer Cache'
Found 'dist.belnk.com' in 'Internet Explorer Cache'
Found 'cliks.org' in 'Internet Explorer Cache'
Found 'azjmp.com' in 'Internet Explorer Cache'
Found 'hits.clickandtrack.net' in 'Internet Explorer Cache'
Found 'citi.bridgetrack.com' in 'Internet Explorer Cache'
Found 'z1.adserver.com' in 'Internet Explorer Cache'
Found 'go.com' in 'Internet Explorer Cache'
Found 'insightexpressai.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'bluestreak.com' in 'Internet Explorer Cache'
Found 'centrport.net' in 'Internet Explorer Cache'
Found 'www.burstbeacon.com' in 'Internet Explorer Cache'
Found 'perf.overture.com' in 'Internet Explorer Cache'
Found 'server.iad.liveperson.net' in 'Internet Explorer Cache'
Found 'master.mx-targeting.com' in 'Internet Explorer Cache'
Found 'belnk.com' in 'Internet Explorer Cache'
Found 'revenue.net' in 'Internet Explorer Cache'
Found '2o7.net' in 'Internet Explorer Cache'
Found 'burstnet.com' in 'Internet Explorer Cache'
Found 'adopt.specificclick.net' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}'
Found '' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\VERSION'
Found '' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}'
Found '' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\VERSION'
Found '' in 'SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E}'
Found '' in 'SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{10D7DB96-56DC-4617-8EAB-EC506ABE6C7E}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE}'
Found '' in 'SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{6CDC3337-01F7-4A79-A4AF-0B19303CC0BE}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B}'
Found '' in 'SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{795398D0-DC2F-4118-A69C-592273BA9C2B}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06}'
Found '' in 'SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{B288F21C-A144-4CA2-9B70-8AFA1FAE4B06}\TypeLib'
Found '' in 'SOFTWARE\Classes\PopOops2.PopOops'
Found '' in 'SOFTWARE\Classes\PopOops2.PopOops\Clsid'
Found '' in 'SOFTWARE\Classes\SWLAD1.SWLAD'
Found '' in 'SOFTWARE\Classes\SWLAD1.SWLAD\Clsid'
Found '' in 'SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9}\7.0'
Found '' in 'SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9}\7.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9}\7.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{D0C29A75-7146-4737-98EE-BC4D7CF44AF9}\7.0\HELPDIR'
Found '' in 'SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52}\5.0'
Found '' in 'SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52}\5.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52}\5.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{E0D3B292-A0B0-4640-975C-2F882E039F52}\5.0\HELPDIR'
Found '' in 'Software\intexp'
Found '' in 'Software\intexp\Config'
Found '' in 'Software\intexp\MyFileSystem2'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.BottomFrame'
Found '' in 'SOFTWARE\Classes\IMIToolbar.BottomFrame.1'
Found '' in 'SOFTWARE\Classes\IMIToolbar.BottomFrame.1\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer'
Found '' in 'SOFTWARE\Classes\IMIToolbar.LeftFrame'
Found '' in 'SOFTWARE\Classes\IMIToolbar.LeftFrame.1'
Found '' in 'SOFTWARE\Classes\IMIToolbar.LeftFrame.1\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupBrowser'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupBrowser.1'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupBrowser.1\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupWindow'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupWindow.1'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupWindow.1\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID'
Found '' in 'SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer'
Found '' in 'SOFTWARE\Classes\Interface\{220959EA-B54C-4201-8DF2-1CFAC8B59FD7}'
Found '' in 'SOFTWARE\Classes\Interface\{220959EA-B54C-4201-8DF2-1CFAC8B59FD7}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{220959EA-B54C-4201-8DF2-1CFAC8B59FD7}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{220959EA-B54C-4201-8DF2-1CFAC8B59FD7}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}'
Found '' in 'SOFTWARE\Classes\Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{7371AD3F-C419-4DC0-8E8A-E21FAFAD53E0}'
Found '' in 'SOFTWARE\Classes\Interface\{7371AD3F-C419-4DC0-8E8A-E21FAFAD53E0}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{7371AD3F-C419-4DC0-8E8A-E21FAFAD53E0}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{7371AD3F-C419-4DC0-8E8A-E21FAFAD53E0}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{98B2DDBA-6DA2-4421-AF2B-814E98F53649}'
Found '' in 'SOFTWARE\Classes\Interface\{98B2DDBA-6DA2-4421-AF2B-814E98F53649}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{98B2DDBA-6DA2-4421-AF2B-814E98F53649}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{98B2DDBA-6DA2-4421-AF2B-814E98F53649}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\TypeLib'
Found 'ThreadingModel' in 'SOFTWARE\Classes\CLSID\{417386C3-8D4A-4611-9B91-E57E89D603AC}\InprocServer32'
Found 'ThreadingModel' in 'SOFTWARE\Classes\CLSID\{D52433A9-A44C-43AB-A013-24B3C756DD2B}\InprocServer32'
Found 'InstallDay' in 'Software\intexp\Config'
Found 'KeywordMatch' in 'Software\intexp\Config'
Found 'LogUrl' in 'Software\intexp\Config'
Found 'PostCGITime' in 'Software\intexp\Config'
Found 'SystemDate' in 'Software\intexp\Config'
Found 'SystemID' in 'Software\intexp\MyFileSystem2'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\HELPDIR'
Found '' in 'SOFTWARE\Classes\Wbho.Band'
Found '' in 'SOFTWARE\Classes\Wbho.Band.1'
Found '' in 'SOFTWARE\Classes\Wbho.Band.1\CLSID'
Found '' in 'SOFTWARE\Classes\Wbho.Band\CLSID'
Found '' in 'SOFTWARE\Classes\Wbho.Band\CurVer'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\LocalServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\NumMethods'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/VBouncer/INSTALL.LOG'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\HELPDIR'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj\CurVer'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj\CLSID'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj.1\CLSID'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj.1'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj'
Found '' in 'Software\Ceres'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000049-8F91-4D9C-9573-F016E7626484}'
Found '' in 'SOFTWARE\AutoLoader'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\0'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\Programmable'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\Implemented Categories\{00021494-0000-0000-C000-000000000046}'
Found '' in 'SOFTWARE\Classes\CLSID\{F3155057-4C2C-4078-8576-50486693FD49}\Implemented Categories'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\Programmable'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\Implemented Categories\{00021493-0000-0000-C000-000000000046}'
Found '' in 'SOFTWARE\Classes\CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}\Implemented Categories'
Found '' in 'SOFTWARE\Classes\CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}\Programmable'
Found '' in 'SOFTWARE\Classes\CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}\Programmable'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\TypeLib'
Found 'ThreadingModel' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32'
Found '' in 'SOFTWARE\Vendor\xml'
Found '' in 'SOFTWARE\Classes\Remove'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\0'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}'
Found '' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\Programmable'
Found 'Version' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\TypeLib'
Found 'ThreadingModel' in 'SOFTWARE\Classes\CLSID\{00000049-8F91-4D9C-9573-F016E7626484}\InprocServer32'
Found 'PluginLevel' in 'SYSTEM\CurrentControlSet\Control\Session Manager'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\Version'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\LocalServer32'
Found '' in 'TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}'
Found '' in 'Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}'
Found '' in 'CeresDll.CeresDllObj'
Found '' in 'CeresDll.CeresDllObj.1'
Found '' in 'CLSID\{00000049-8F91-4D9C-9573-F016E7626484}'
Found '' in 'Wbho.Band.1'
Found '' in 'Wbho.Band'
Found '' in 'CLSID\{1C896551-8B92-4907-8C06-15DB2D1F874A}'
Found '' in 'IMIToolbar.PopupBrowser'
Found '' in 'IMIToolbar.PopupBrowser.1'
Found '' in 'CLSID\{E2BF1BF3-1FDB-4C93-8874-0B09E71C594C}'
Found '' in 'IMIToolbar.LeftFrame'
Found '' in 'IMIToolbar.LeftFrame.1'
Found '' in 'IMIToolbar.BottomFrame'
Found '' in 'IMIToolbar.BottomFrame.1'
Found '' in 'CLSID\{F3155057-4C2C-4078-8576-50486693FD49}'
Found '' in 'IMIToolbar.PopupWindow'
Found '' in 'IMIToolbar.PopupWindow.1'
Found '' in 'CLSID\{D36F70B1-7DF5-4FD4-A765-70CCC8F72CD7}'
Found '' in 'Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}'
Found '' in 'TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}'
Found '' in 'Interface\{6A288140-3E1C-4CD9-AAC5-E20FDD4F5D64}'
Found '' in 'Interface\{7371AD3F-C419-4DC0-8E8A-E21FAFAD53E0}'
Found '' in 'Interface\{220959EA-B54C-4201-8DF2-1CFAC8B59FD7}'
Found '' in 'Interface\{98B2DDBA-6DA2-4421-AF2B-814E98F53649}'
Found '' in 'Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}'
Found '' in 'CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}'
Found '' in 'CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'CLSID\{F3155057-4C2C-4078-8576-50486693FD49}'
Internet URL Shortcuts
Files and Directories
Found '' in 'C:\Documents and Settings\btketron\Local Settings\Temp\drp1.tmp'
Found 'ceres.dll' in 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp'
Found 'ceres.inf' in 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp'
Found 'temp.fr7EA3' in 'C:\Documents and Settings\btketron\Local Settings\Temp'
Found 'temp.frD7E9' in 'C:\Documents and Settings\btketron\Local Settings\Temp'
Found 'data.bin' in 'C:\Program Files\Aprps'
Found 'RemoveDisplayUtility.exe' in 'C:\Program Files\Common Files\Uninstall Information'
Found '017F4365-3869-4D42-97B0-345ACB' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96'
Found '4F15276E-3F15-4B9D-A336-C818E3' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96'
Found 'ECAD3D2E-46D3-4087-BF0C-5A4190' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96'
Found '590AFC63-0FD6-4FDD-8D99-390BDB' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140'
Found '743BD699-A53C-470F-85B0-82AF73' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140'
Found '9DC5029C-8C53-422A-8448-EAFC92' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140'
Found 'C775AAA0-1CF1-40C9-ACA4-076828' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140'
Found '6B4705C7-C51D-4AAB-9102-4D5B1C' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\4F3E3EC6-594F-441E-BECF-7BB1B2'
Found 'B8D86C10-E689-4745-BE87-50C7EB' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0'
Found 'D602DF82-9741-41F3-9017-4C67B3' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0'
Found 'AC3E2621-EA81-4917-B565-DB0385' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C'
Found 'CFE569B0-0822-408D-BC9B-5D600C' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C'
Found '257175A4-B433-4786-93F4-10B8E0' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB'
Found '837CADEA-42A3-4D53-AEAA-37014F' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB'
Found 'EAC386A3-047F-453A-AB68-45B1A3' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB'
Found 'Dc13.dll' in 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652'
Found 'Dc5.exe' in 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652'
Found 'Buddy.exe' in 'C:\WINDOWS'
Found 'ceres.dll' in 'C:\WINDOWS'
Found 'ceres.inf' in 'C:\WINDOWS\inf'
Found 'AUNPS2.dll' in 'C:\WINDOWS\system32'
Found 'PopOops.dll' in 'C:\WINDOWS\system32'
Found 'SWLAD2.dll' in 'C:\WINDOWS\system32'
Found 'tdtb.exe' in 'C:\WINDOWS'
Found 'setup.inf' in 'C:\WINDOWS\Temp\AutoUpdate0'
Found 'AproposClientInstaller[1].exe' in 'C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\O9UBS9AJ'
Finished Scanning
Started Backup
Finished Backup
Started Cleaning
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\drp1.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\drp1.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\btketron\Local Settings\Temp\drp1.tmp'
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.dll' in shortcut areas.
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.dll' in startup areas.
Cleaning 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.dll'
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.inf' in shortcut areas.
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.inf' in startup areas.
Cleaning 'C:\Documents and Settings\btketron\Local Settings\Temp\DrTemp\ceres.inf'
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.fr7EA3' in shortcut areas.
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.fr7EA3' in startup areas.
Cleaning 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.fr7EA3'
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.frD7E9' in shortcut areas.
Checking for 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.frD7E9' in startup areas.
Cleaning 'C:\Documents and Settings\btketron\Local Settings\Temp\temp.frD7E9'
Checking for 'C:\Program Files\Aprps\data.bin' in shortcut areas.
Checking for 'C:\Program Files\Aprps\data.bin' in startup areas.
Cleaning 'C:\Program Files\Aprps\data.bin'
Checking for 'C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe' in shortcut areas.
Checking for 'C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe' in startup areas.
Cleaning 'C:\Program Files\Common Files\Uninstall Information\RemoveDisplayUtility.exe'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\017F4365-3869-4D42-97B0-345ACB' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\017F4365-3869-4D42-97B0-345ACB' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\017F4365-3869-4D42-97B0-345ACB'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\4F15276E-3F15-4B9D-A336-C818E3' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\4F15276E-3F15-4B9D-A336-C818E3' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\4F15276E-3F15-4B9D-A336-C818E3'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\ECAD3D2E-46D3-4087-BF0C-5A4190' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\ECAD3D2E-46D3-4087-BF0C-5A4190' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\1D3019C5-E425-4A2C-8057-491E96\ECAD3D2E-46D3-4087-BF0C-5A4190'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\590AFC63-0FD6-4FDD-8D99-390BDB' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\590AFC63-0FD6-4FDD-8D99-390BDB' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\590AFC63-0FD6-4FDD-8D99-390BDB'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\743BD699-A53C-470F-85B0-82AF73' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\743BD699-A53C-470F-85B0-82AF73' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\743BD699-A53C-470F-85B0-82AF73'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\9DC5029C-8C53-422A-8448-EAFC92' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\9DC5029C-8C53-422A-8448-EAFC92' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\9DC5029C-8C53-422A-8448-EAFC92'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\C775AAA0-1CF1-40C9-ACA4-076828' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\C775AAA0-1CF1-40C9-ACA4-076828' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\3535C531-7FA6-4E39-963D-1AE140\C775AAA0-1CF1-40C9-ACA4-076828'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\4F3E3EC6-594F-441E-BECF-7BB1B2\6B4705C7-C51D-4AAB-9102-4D5B1C' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\4F3E3EC6-594F-441E-BECF-7BB1B2\6B4705C7-C51D-4AAB-9102-4D5B1C' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\4F3E3EC6-594F-441E-BECF-7BB1B2\6B4705C7-C51D-4AAB-9102-4D5B1C'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\B8D86C10-E689-4745-BE87-50C7EB' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\B8D86C10-E689-4745-BE87-50C7EB' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\B8D86C10-E689-4745-BE87-50C7EB'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\D602DF82-9741-41F3-9017-4C67B3' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\D602DF82-9741-41F3-9017-4C67B3' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\61285762-D544-48BE-B90D-F2EFB0\D602DF82-9741-41F3-9017-4C67B3'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\AC3E2621-EA81-4917-B565-DB0385' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\AC3E2621-EA81-4917-B565-DB0385' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\AC3E2621-EA81-4917-B565-DB0385'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\CFE569B0-0822-408D-BC9B-5D600C' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\CFE569B0-0822-408D-BC9B-5D600C' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\8D9E19AD-E7C5-46EE-A345-C5778C\CFE569B0-0822-408D-BC9B-5D600C'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\257175A4-B433-4786-93F4-10B8E0' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\257175A4-B433-4786-93F4-10B8E0' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\257175A4-B433-4786-93F4-10B8E0'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\837CADEA-42A3-4D53-AEAA-37014F' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\837CADEA-42A3-4D53-AEAA-37014F' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\837CADEA-42A3-4D53-AEAA-37014F'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\EAC386A3-047F-453A-AB68-45B1A3' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\EAC386A3-047F-453A-AB68-45B1A3' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\FCC8A579-CBFF-4553-84D6-8346FB\EAC386A3-047F-453A-AB68-45B1A3'
Checking for 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc13.dll' in shortcut areas.
Checking for 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc13.dll' in startup areas.
Cleaning 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc13.dll'
Checking for 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc5.exe' in shortcut areas.
Checking for 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc5.exe' in startup areas.
Cleaning 'C:\RECYCLER\S-1-5-21-1993962763-1770027372-1801674531-11652\Dc5.exe'
Checking for 'C:\WINDOWS\Buddy.exe' in shortcut areas.
Checking for 'C:\WINDOWS\Buddy.exe' in startup areas.
Cleaning 'C:\WINDOWS\Buddy.exe'
Checking for 'C:\WINDOWS\ceres.dll' in shortcut areas.
Checking for 'C:\WINDOWS\ceres.dll' in startup areas.
Cleaning 'C:\WINDOWS\ceres.dll'
[SCANMODS] WARNING: Deletion of the file 'C:\WINDOWS\ceres.dll' requires a reboot.
Checking for 'C:\WINDOWS\inf\ceres.inf' in shortcut areas.
Checking for 'C:\WINDOWS\inf\ceres.inf' in startup areas.
Cleaning 'C:\WINDOWS\inf\ceres.inf'
Checking for 'C:\WINDOWS\system32\AUNPS2.dll' in shortcut areas.
Checking for 'C:\WINDOWS\system32\AUNPS2.dll' in startup areas.
Cleaning 'C:\WINDOWS\system32\AUNPS2.dll'
Checking for 'C:\WINDOWS\system32\PopOops.dll' in shortcut areas.
Checking for 'C:\WINDOWS\system32\PopOops.dll' in startup areas.
Cleaning 'C:\WINDOWS\system32\PopOops.dll'
Checking for 'C:\WINDOWS\system32\SWLAD2.dll' in shortcut areas.
Checking for 'C:\WINDOWS\system32\SWLAD2.dll' in startup areas.
Cleaning 'C:\WINDOWS\system32\SWLAD2.dll'
Checking for 'C:\WINDOWS\tdtb.exe' in shortcut areas.
Checking for 'C:\WINDOWS\tdtb.exe' in startup areas.
Cleaning 'C:\WINDOWS\tdtb.exe'
Checking for 'C:\WINDOWS\Temp\AutoUpdate0\setup.inf' in shortcut areas.
Checking for 'C:\WINDOWS\Temp\AutoUpdate0\setup.inf' in startup areas.
Cleaning 'C:\WINDOWS\Temp\AutoUpdate0\setup.inf'
Checking for 'C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\O9UBS9AJ\AproposClientInstaller[1].exe' in shortcut areas.
Checking for 'C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\O9UBS9AJ\AproposClientInstaller[1].exe' in startup areas.
Cleaning 'C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\O9UBS9AJ\AproposClientInstaller[1].exe'
Finished Cleaning