Started Scanning
Internet Cookies
Found 'a.websponsors.com' in 'Internet Explorer Cache'
Found 'abetterinternet.com' in 'Internet Explorer Cache'
Found 'edge.ru4.com' in 'Internet Explorer Cache'
Found 'azjmp.com' in 'Internet Explorer Cache'
Found 'com.com' in 'Internet Explorer Cache'
Found 'dist.belnk.com' in 'Internet Explorer Cache'
Found 'offeroptimizer.com' in 'Internet Explorer Cache'
Found 'revenue.net' in 'Internet Explorer Cache'
Found 'realmedia.com' in 'Internet Explorer Cache'
Found 'partypoker.touchclarity.com' in 'Internet Explorer Cache'
Found 'partypoker.com' in 'Internet Explorer Cache'
Found 'zedo.com' in 'Internet Explorer Cache'
Found 'a.websponsors.com' in 'Internet Explorer Cache'
Found 'cliks.org' in 'Internet Explorer Cache'
Found 'z1.adserver.com' in 'Internet Explorer Cache'
Found 'hits.clickandtrack.net' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'btg.btgrab.com' in 'Internet Explorer Cache'
Found 'belnk.com' in 'Internet Explorer Cache'
Found 'trafficmp.com' in 'Internet Explorer Cache'
Found 'adknowledge.com' in 'Internet Explorer Cache'
Found 'casalemedia.com' in 'Internet Explorer Cache'
Found 'btg.btgrab.com' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\Classes\ed2k'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}\TypeLib'
Found '' in 'Software\AppConf'
Found 'confset' in 'Software\AppConf'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\HELPDIR'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Found '' in 'SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/VBouncer/INSTALL.LOG'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}\1.0\0'
Found '' in 'SOFTWARE\Classes\TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}\TypeLib'
Found '' in 'SOFTWARE\Classes\Remove'
Found '' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC'
Found '' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'Service' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'Legacy' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'DeviceDesc' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'ConfigFlags' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'ClassGUID' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'Class' in 'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'
Found 'PluginLevel' in 'SYSTEM\CurrentControlSet\Control\Session Manager'
Found '' in 'Interface\{3E589169-86AD-44FE-B426-F0BF105D5582}'
Found '' in 'TypeLib\{57ADD57B-173E-418A-8F70-17E5C9F2BCC9}'
Found '' in 'Interface\{E4458B4A-6149-4450-84F2-864ADB7E8C52}'
Found '' in 'Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}'
Internet URL Shortcuts
Files and Directories
Found 'alchem.inf' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'alchem.ini' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'libexpat.dll' in 'C:\Documents and Settings\Owner\Local Settings\Temp\AutoUpdate1'
Found '' in 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK'
Found 'kmd10B.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd10C.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd10D.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd10E.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd10F.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd110.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd111.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd112.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd115.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd117.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd118.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd119.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd11A.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd11B.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd11C.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd11D.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd448.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd449.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44A.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44B.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44C.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44D.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44E.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd44F.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd454.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd455.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd456.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd457.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd458.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd459.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd45A.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'kmd45B.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'msbbau.dat' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'temp.fr8F97' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found '~DFAD13.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found '~DFBCB0.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found '~DFBE6F.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found '~DFC990.tmp' in 'C:\Documents and Settings\Owner\Local Settings\Temp'
Found 'QFle06052005154825496093.asw' in 'C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup'
Found '' in 'C:\Program Files\Lycos'
Found 'A83E0671-AE26-4FA2-94A1-E5965A' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE'
Found 'AD841373-A60E-4500-973E-068457' in 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE'
Found '' in 'C:\Program Files\WinMX'
Found 'Dc2.html' in 'C:\RECYCLER\S-1-5-21-568730901-2907011200-4168273537-1003'
Found 'EECH1.bsx' in 'C:\WINDOWS\cfgmgr52'
Found 'SPZ3.bsx' in 'C:\WINDOWS\cfgmgr52'
Found 'kqomde.xml' in 'C:\WINDOWS\system32'
Found '~DF884D.tmp' in 'C:\WINDOWS\Temp'
Finished Scanning
Started Backup
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Unable to create the registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000 for restore. [SCANMODS] Error=5.
Finished Backup
Started Cleaning
[SCANMODS] WARNING: Unable to remove registry keys under 'HKLM\'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC'. Error=5.
[SCANMODS] WARNING: Unable to remove registry keys under 'HKLM\'SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TBPSSVC\0000'. Error=5.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.inf' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.inf' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.inf'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.ini' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.ini' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\alchem.ini'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\AutoUpdate1\libexpat.dll' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\AutoUpdate1\libexpat.dll' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\AutoUpdate1\libexpat.dll'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK\msbb.log' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK\msbb.log' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\FLEOK\msbb.log'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10B.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10B.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10B.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10C.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10C.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10C.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10D.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10D.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10D.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10E.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10E.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10E.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10F.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10F.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd10F.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd110.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd110.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd110.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd111.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd111.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd111.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd112.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd112.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd112.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd115.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd115.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd115.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd117.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd117.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd117.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd118.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd118.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd118.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd119.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd119.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd119.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11A.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11A.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11A.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11B.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11B.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11B.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11C.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11C.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11C.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11D.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11D.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd11D.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd448.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd448.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd448.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd449.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd449.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd449.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44A.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44A.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44A.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44B.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44B.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44B.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44C.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44C.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44C.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44D.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44D.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44D.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44E.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44E.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44E.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44F.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44F.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd44F.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd454.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd454.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd454.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd455.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd455.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd455.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd456.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd456.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd456.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd457.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd457.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd457.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd458.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd458.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd458.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd459.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd459.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd459.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45A.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45A.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45A.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45B.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45B.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\kmd45B.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\msbbau.dat' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\msbbau.dat' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\msbbau.dat'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr8F97' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr8F97' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\temp.fr8F97'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFAD13.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFAD13.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFAD13.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBCB0.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBCB0.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBCB0.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBE6F.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBE6F.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFBE6F.tmp'
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFC990.tmp' in shortcut areas.
Checking for 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFC990.tmp' in startup areas.
Cleaning 'C:\Documents and Settings\Owner\Local Settings\Temp\~DFC990.tmp'
Checking for 'C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle06052005154825496093.asw' in shortcut areas.
Checking for 'C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle06052005154825496093.asw' in startup areas.
Cleaning 'C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle06052005154825496093.asw'
Checking for 'C:\Program Files\Lycos' in shortcut areas.
Checking for 'C:\Program Files\Lycos' in startup areas.
Cleaning 'C:\Program Files\Lycos'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\A83E0671-AE26-4FA2-94A1-E5965A' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\A83E0671-AE26-4FA2-94A1-E5965A' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\A83E0671-AE26-4FA2-94A1-E5965A'
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\AD841373-A60E-4500-973E-068457' in shortcut areas.
Checking for 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\AD841373-A60E-4500-973E-068457' in startup areas.
Cleaning 'C:\Program Files\Microsoft AntiSpyware\Quarantine\501C4B89-EBFF-40CB-A2C3-A4E2FE\AD841373-A60E-4500-973E-068457'
Checking for 'C:\Program Files\WinMX' in shortcut areas.
Checking for 'C:\Program Files\WinMX' in startup areas.
Cleaning 'C:\Program Files\WinMX'
Checking for 'C:\Program Files\WinMX\wpnpchannelcmds.txt' in shortcut areas.
Checking for 'C:\Program Files\WinMX\wpnpchannelcmds.txt' in startup areas.
Cleaning 'C:\Program Files\WinMX\wpnpchannelcmds.txt'
Checking for 'C:\RECYCLER\S-1-5-21-568730901-2907011200-4168273537-1003\Dc2.html' in shortcut areas.
Checking for 'C:\RECYCLER\S-1-5-21-568730901-2907011200-4168273537-1003\Dc2.html' in startup areas.
Cleaning 'C:\RECYCLER\S-1-5-21-568730901-2907011200-4168273537-1003\Dc2.html'
Checking for 'C:\WINDOWS\cfgmgr52\EECH1.bsx' in shortcut areas.
Checking for 'C:\WINDOWS\cfgmgr52\EECH1.bsx' in startup areas.
Cleaning 'C:\WINDOWS\cfgmgr52\EECH1.bsx'
Checking for 'C:\WINDOWS\cfgmgr52\SPZ3.bsx' in shortcut areas.
Checking for 'C:\WINDOWS\cfgmgr52\SPZ3.bsx' in startup areas.
Cleaning 'C:\WINDOWS\cfgmgr52\SPZ3.bsx'
Checking for 'C:\WINDOWS\system32\kqomde.xml' in shortcut areas.
Checking for 'C:\WINDOWS\system32\kqomde.xml' in startup areas.
Cleaning 'C:\WINDOWS\system32\kqomde.xml'
Checking for 'C:\WINDOWS\Temp\~DF884D.tmp' in shortcut areas.
Checking for 'C:\WINDOWS\Temp\~DF884D.tmp' in startup areas.
Cleaning 'C:\WINDOWS\Temp\~DF884D.tmp'
Finished Cleaning
hijackthis log :
Logfile of HijackThis v1.99.1
Scan saved at 9:27:20 PM, on 7/11/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\WMP54GS Wireless Network Monitor\WLService.exe
C:\Program Files\WMP54GS Wireless Network Monitor\WMP54G.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Owner\My Documents\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://us6.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us6.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://srch-us6.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhos;;<local>
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [buqelwf] c:\windows\system32\msjolxs.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.aol.com
O16 - DPF: Yahoo! Hearts -
http://download.game...nts/y/ht1_x.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121057390639O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WMP54GSVC - Unknown owner - C:\Program Files\WMP54GS Wireless Network Monitor\WLService.exe" "WMP54G.exe (file missing)