Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Never-Ending Reinstallation of Pop-Ups, Malware, Etc. (Same Old Story)


  • This topic is locked This topic is locked

#1
tadghostal

tadghostal

    Member

  • Member
  • PipPip
  • 13 posts
Hey guys. Came across your website while searching the web in hopes of ending the terrible assult of [bleep]-ware I had managed to inflict upon my computer. I was able to take care of some of the problems by myself via the search option on this site. In the process of doing so I was so impressed with your work that I figured I might as well just post a hijackthis.log. and get the problem cleared up for good. Thanks for all the help in advance!

Logfile of HijackThis v1.99.1
Scan saved at 5:39:33 PM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\izvbawi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis.exe
C:\WINDOWS\notepad.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTP07618 - {2296428D-C133-4928-B76A-A200FF409572} - C:\PROGRA~1\FREEPR~1\tbu00193\freeprod.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: - {57b82b9b-e271-41c9-a122-a2b85250d8e3} - C:\WINDOWS\jxi.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [sveokvu] C:\WINDOWS\system32\izvbawi.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [zrmi] C:\PROGRA~1\COMMON~1\zrmi\zrmim.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll (file missing)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {11113111-1411-1611-8111-111111111413} - mhtml:file://c:\nul.mht!http://www.capital-s...et//browser.exe
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Hi tadghostal and welcome to the Geeks to Go Forums.

My name is Trevuren and I will be helping you with your log.


BEFORE BEGINNING, Please read completely through the instructions below and download the files from the links provided. You may want to save or print out these instructions for easier reference.

1. Download Ewido Security Suite.

2. Download Lavasoft's Ad-Aware and the VX2 Cleaner Plug-in.
  • Install Ad-Aware using the default options.
  • Then install vx2cleaner_inst.exe, using all the defaults there as well.
3. Run Ad-Aware
  • Update to the latest definitions
  • Then click on Add-ons in the lefthand column.
  • Select VX2 Cleaner V2.0 and click Run Tool. Click "OK".
  • If something is found, click "Clean" as in the directions given.
  • Click "Close", and EXIT Ad-Aware.
4. Reboot your PC and run Ad-Aware again.
  • This time, click on the Start button in Ad-Aware
  • Select "Perform smart system scan" and click Next.
  • Once the scan finishes, click "Next" again.
  • Select all objects found ("right click anywhere in the list of found objects and click "Select All Objects").
  • Click "Next" one more time, then "OK" to confirm the removal.
  • You will be prompted to set Ad-Aware to run on reboot, click "OK".
  • Exit Ad-Aware
  • REBOOT your PC
  • When Ad-Aware starts up, click on "Start", then "Next".
  • Follow the steps above if anything is found, or click "Finish", then EXIT Ad-Aware.

5. Now, run HJT, click SCAN and place a checkmark beside the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: XBTP07618 - {2296428D-C133-4928-B76A-A200FF409572} - C:\PROGRA~1\FREEPR~1\tbu00193\freeprod.dll (file missing)
O2 - BHO: - {57b82b9b-e271-41c9-a122-a2b85250d8e3} - C:\WINDOWS\jxi.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll
O2 - BHO: BestOffers Shopping BHO - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - C:\Program Files\TBONAS\TBONlchr.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: BestOffers Shopping v1.20 - {7FD44536-9DF0-4034-939F-5BD4D98E3187} - C:\Program Files\TBONAS\TBONlchr.dll
O4 - HKLM\..\Run: [sveokvu] C:\WINDOWS\system32\izvbawi.exe r
O4 - HKCU\..\Run: [zrmi] C:\PROGRA~1\COMMON~1\zrmi\zrmim.exe
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll (file missing)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll (file missing)
O16 - DPF: {11113111-1411-1611-8111-111111111413} - mhtml:file://c:\nul.mht!http://www.capital-s...et//browser.exe
O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab


With all items checked, and all windows closed, click Fix checked and EXIT the program

6. REBOOT into Safe Mode

7. Using Windows Explorer, locate and DELETE the following files and Folders (with all their content), if still present:

C:\WINDOWS\system32\izvbawi.exe
C:\WINDOWS\jxi.dll
C:\WINDOWS\isrvs<==Folder
C:\Program Files\TBONAS<==Folder
C:\PROGRA~1\COMMON~1\zrmi<==Folder
C:\install.cab


8. Reboot back into Normal Mode

9. For a final cleanup, please install and run Ewido.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
  • From the main ewido screen, click on update in the left menu, then click the Start update button.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
  • If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
10. Please finish up by rebooting your system once more, and posting a new HijackThis log and the log from the Ewido scan.

Regards,

Trevuren

  • 0

#3
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Sorry for the delayed responce . . . I'm a college student and the end of the term is approaching so as you can guess, I am fairly busy. The computer seems to be running much better but I'm still seeing some pop-ups here and there . . .

Logfile of HijackThis v1.99.1
Scan saved at 7:23:25 PM, on 11/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ruyvhawgx] C:\WINDOWS\System32\bedrjg.exe
O4 - HKLM\..\Run: [pozicvu] C:\WINDOWS\System32\hduqnsl.exe r
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [rtcdll] C:\WINDOWS\System32\rtcdll.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:04:41 PM, 11/19/2005
+ Report-Checksum: B8766B65

+ Scan result:

HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000020DD-C72E-4113-AF77-DD56626C6C42} -> Spyware.TwainTech : Ignored
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Ignored
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9FB534E3-67CB-4307-AE0A-9E8B5581BE2C} -> Spyware.WindowsSearchBar : Ignored
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A1DD937D-71E1-4BB5-BD5D-1B01B9CB1C2F} -> Spyware.WindowsSearchBar : Ignored
HKLM\SOFTWARE\Altnet -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0494D0D9-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/version.txt\\.Owner -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/System32/version.txt\\{1C78AB3F-A857-482E-80C0-3A1E5238A565} -> Spyware.iSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ext\CLSID\\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Security -> Spyware.iSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\delprot\Enum -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{1C78AB3F-A857-482E-80C0-3A1E5238A565} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{0494D0D9-F8E0-41AD-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-0000-0000-000000000001} -> Spyware.AutoSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-0000-0000-000000000221} -> Spyware.ClearSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-0000-0000-000000000240} -> Spyware.ClearSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-0000-8835-3EFF76BF2657} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-0000-BFA1-D7EE6696B865} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-41a3-98CF-00000000168B} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-47c5-A90F-2CDE8F7638DB} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-5DFC-5652-1705043F6518} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0000-7EBF-57C6-0BAE047EA682} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0001-0345-2280-0287F27A63EE} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0001-1DBE-075A-39EC04BD88AF} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0001-F7A6-1F38-0204019E355E} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0002-53D4-0622-35EA0235778E} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0008-D357-0798-004401965D4A} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0009-1C42-7D61-6CFF050894A7} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0015-BD9C-263A-493001BA0C6C} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-002B-EFE6-6B08-560C01922D3B} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0033-C1AC-0E62-0C1F0537605D} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-008C-1E65-6AA6-3A270279F027} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-00FA-71ED-4ABA-348801BAA0A9} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-0C95-B1F8-547A-405204D6961A} -> Spyware.TX4 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-10D6-4e5f-8F7F-29B32C1C0FC4} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-167B-41bc-95FF-86A07B14712C} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-2565-4c5b-A455-A74C8A2247AB} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-5eb9-11d5-9d45-009027c14662} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-64C4-4a64-9767-895AB4921E41} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-6CB0-410C-8C3D-8FA8D2011D0A} -> Spyware.iMesh : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000000-D9E3-4BC6-A0BD-3D0CA4BE5271} -> Spyware.AdBreak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000000DA-0786-4633-87C6-1AA7A4429EF1} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000000F1-34E3-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000185-B716-11D3-92F3-00D0B709A7D8} -> Spyware.SmartBrowser : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000185-C745-43D2-44F1-01A1C789C738} -> Spyware.SmartBrowser : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000250-0320-4DD4-BE4F-7566D2314352} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0000026A-8230-4DD4-BE4F-6889D1E74167} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000273-8230-4DD4-BE4F-6889D1E74167} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000004CC-E4FF-4F2C-BC30-DBEF0B983BC9} -> Spyware.IPInsight : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000580-C637-11D5-831C-00105AD6ACF0} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000006B1-19B5-414A-849F-2A3C64AE6939} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00000EF1-34E3-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00010a21-b924-4cd6-893c-eea1071ae8b3} -> Spyware.AdsStore : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000277A3-7D84-406a-9799-D12A81594693} -> Spyware.SearchFast : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00041A26-7033-432C-94C7-6371DE343822} -> Spyware.SearchEnhancement : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000E6ED5-E3FC-4c93-99E9-D38D2A9F9B09} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000E7270-CC7A-0786-8E7A-DA09B51938A6} -> Spyware.NetPal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00110011-4B0B-44D5-9718-90C88817369B} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0019C3E2-DD48-4A6D-AB2D-8D32436313D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0019C3E2-DD48-4A6D-ABCD-8D32436313D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{001DAE60-95C0-11d3-924E-009027950886} -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{001F2470-5DF5-11d3-B991-00A0C9BB0874} -> Spyware.AtHoc : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00320615-B6C2-40A6-8F99-F1C52D674FAD} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0036F389-FEF8-43AC-9220-16430E0012ED} -> Spyware.NauPointBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00673769-777F-4814-BE0F-74CBA1D823B8} -> Spyware.ASN1exploit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00A0A40C-F432-4C59-BA11-B25D142C7AB7} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00A6FAF1-072E-44cf-8957-5838F569A31D} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00D6A7E7-4A97-456f-848A-3B75BF7554D7} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{00F16DC8-1B2A-42F4-B18B-E21DA9D2D7FD} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0140DF95-9128-4053-AE72-F43F0CFCA062} -> Spyware.PolyFilter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{014DA6C1-189F-421a-88CD-07CFE51CFF10} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{014DA6C9-189F-421a-88CD-07CFE51CFF10} -> Spyware.MySearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} -> Spyware.PeopleOnPage : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{01CD4DDA-166D-4831-A373-ACCC27E1BB9D} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{021BB032-80A8-4FB6-B3D5-CF27B1553B95} -> Spyware.Slagent : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{024DE5EB-3649-445E-8D57-C09A9A33D479} -> Spyware.Adlogix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{029BB53A-C312-4b09-9B4F-ED57AF027B28} -> Spyware.LizardBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0345B059-8731-42BC-B7B7-5121014B02C6} -> Spyware.Muulcom : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0352960F-47BE-11D5-AB93-00D0B760B4EB} -> Spyware.TOPicks : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{04079851-5845-4dea-848C-3ECD647AA554} -> Spyware.MySearchBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0421701D-CF13-4E70-ADF0-45A953E7CB8B} -> Spyware.SmartPops : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0428FFC7-1931-45b7-95CB-3CBB919777E1} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{046D6EA4-15E3-4b27-8010-45BD78A9219E} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{04719991-296F-4958-AA0F-FA25FFA5008B} -> Spyware.ExciteSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0494D0D9-F8E0-41ad-92A3-14154ECE70AC} -> Spyware.MyWay : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{05BBB56A-2A69-4A5C-BFDA-43295DD67434} -> Spyware.ShopForGood : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{06594350-D723-11D8-9669-0800200C9A66} -> Spyware.StickyPops : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{06DFEDAA-6196-11D5-BFC8-00508B4A487D} -> Spyware.7Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{074E3AA7-7718-4404-B3F8-FF8FB5414E0E} -> Spyware.BrowserAcclerator : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{07B18EA1-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Spyware.MyWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08227B4B-54FE-4C4D-809F-BCA46292FC5B} -> Spyware.Superlogy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08351226-6472-43BD-8A40-D9221FF1C4CE} -> Spyware.SideStep : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08351227-6472-43BD-8A40-D9221FF1C4CE} -> Spyware.SideStep : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{086AE192-23A6-48D6-96EC-715F53797E85} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{086CEFD5-A88D-4981-8915-D51F04360ED1} -> Spyware.TrafficHog : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{087173EF-9829-4F49-8340-A524177D3F60} -> Spyware.SearchandClick : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08C63920-DC18-11D2-9E1E-00A0247061AB} -> Spyware.Linkz.com : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08DBDE36-DF28-11D5-8CA5-0050DA44A764} -> Spyware.Friends.fr : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{08E1C8E1-E565-44fc-A766-C9539BB3ABB7} -> Spyware.iWon : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0982868C-47F0-4EFB-A664-C7B0B1015808} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{09F0F280-FB9A-481B-B69A-CB00DC44D027} -> Spyware.AdvancedSearchbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0A1A2A3A-4A5A-6A7A-8A9A-AABACADAEAFA} -> Spyware.IAGold : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0A5CF411-F0BF-4AF8-A2A4-8233F3109BED} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0A68C5A2-64AE-4415-88A2-6542304A4745} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0AAF602E-72A1-45FE-BAB1-06971E07EAA2} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0AEE4D0C-4B38-4196-AE32-70ACE5656647} -> Spyware.TheSearchMall : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0B519E07-7824-4adc-8890-93D5EABBF285} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0B90AA1B-F649-44C3-9FD3-736C332CBBCF} -> Spyware.Adlogix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0BA1C6EB-D062-4E37-9DB5-B07743276324} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0C9CBFE1-91CD-40C2-BB64-1EC84C4C46AF} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0D7DC475-59EB-4781-985F-A6F5D4E2BC73} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0DDBB570-0396-44C9-986A-8F6F61A51C2F} -> Spyware.FeaturedResults : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0E1230F8-EA50-42A9-983C-D22ABC2E0099} -> Spyware.SearchIT : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0E1230F8-EA50-42A9-983C-D22ABC2EEB4C} -> Spyware.AroundWeb : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0FC817C2-3B45-11D4-8340-0050DA825906} -> Spyware.Deltabar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1028F737-81E7-452B-A860-E50CAD90A08C} -> Spyware.SpyAssassin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{10955232-B671-11D7-8066-0040F6F477E4} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{118CE65F-5D86-4AEA-A9BD-94F92B89119F} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11904CE8-632A-4856-A7CC-00B33FE71BD8} -> Spyware.Sexxxpassport : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11990E9F-2A4D-11D6-9507-02608CDD2842} -> Spyware.SearchSquire : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{11F6B95F-0774-4B8D-8C9E-6B552CBCAD14} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{12D02C08-218F-4A11-BDE1-6611ADB7B81F} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{12DF6E3E-6272-4AE8-880B-2158D60791C0} -> Spyware.Winpage : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{12F02779-6D88-4958-8AD3-83C12D86ADC7} -> Spyware.ActiveSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{136A9D1D-1F4B-43D4-8359-6F2382449255} -> Spyware.SuperBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{13707362-08A2-11D3-A26D-0060976E9E6A} -> Spyware.Bizrate : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{139D88E5-C372-469D-B4C5-1FE00852AB9B} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{13F90341-AD79-4A9F-9B57-0234675670D6} -> Spyware.Pornrelated : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{14B3D246-6274-40B5-8D50-6C2ADE2AB29B} -> Spyware.ShopNav : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{150FA160-130D-451F-B863-B655061432BA} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{166348F1-2C41-4C9F-86BB-EB2B8ADE030C} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1678F7E1-C422-11D0-AD7D-00400515CAAA} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{179E4B4A-76C3-4F65-BCED-C9FA1A28D2EF} -> Spyware.NetNucleus : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{17DA0C9E-4A27-4ac5-BB75-5D24B8CDB972} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{18B79968-1A76-4953-9EBB-B651407F8998} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{19A447BA-9C2E-4864-93F5-A0645229771E} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{19E41A2D-BD9D-48bb-9576-27B2CF0877C0} -> Spyware.ZippyLookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1A98BCA2-0BD1-47DE-9710-C7665F7F1FCB} -> Spyware.SearchEx : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1B0E7716-898E-48cc-9690-4E338E8DE1D3} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1B13BF1B-A528-4CC4-B5BF-553CAA6487AC} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1B7D753B-1981-4bd2-91F3-6D055EE113A0} -> Spyware.PurityScan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1BC1FC4B-B0D2-4D8D-9307-2E40E2A8C257} -> Spyware.HyperBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1BDD55B8-3985-4E59-B906-5E0AD56D6710} -> Spyware.Browserplugin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Spyware.IEPageHelper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1C78AB3F-A857-482e-80C0-3A1E5238A565} -> Spyware.iSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1D022C27-3771-4D1D-B1B7-1953E271C6CA} -> Spyware.SpiderSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1D71DB63-D72A-4479-98F8-5BCB84FAE0F6} -> Spyware.Zettasearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1D870C86-AA3C-4451-81E4-71D480A1A652} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1D9B10E0-E90C-11D7-A399-B7BAC8911A3F} -> Spyware.ArrowToolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-30C7-11D4-8DDF-525400E483E3} -> Spyware.NJStarAsian : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-000000000003} -> Backdoor.Lixy.B : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-000000000004} -> Backdoor.Lixy.B : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-123457123457} -> Spyware.Clitor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-D7ACAC31337F} -> Spyware.Bukaw : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-D7ACAC95951A} -> Backdoor.Lixy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-D7ACAC95951F} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D2-8D96-D7ACAC97972F} -> Spyware.Pornrelated : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D3-8D96-D7ACAC95951A} -> Spyware.Antispykeylog : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1E1B2879-88FF-11D3-8D96-D7ACAC95951F} -> Spyware.PerfectKeylogger : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA2} -> Spyware.ToolbarCC : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA7} -> Spyware.ToolbarCC : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA8} -> Spyware.ToolbarCC : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} -> Spyware.ToolbarCC : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2038A287-4221-4F76-A7C0-ADDD77AFABB3} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{204F937E-519E-4597-96FA-8F1F59F3CB6D} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{21301D69-B8F1-46AA-B0B5-09EE2285914C} -> Spyware.CustomToolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{223405EC-01F9-48a2-BDBB-D519913E2765} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{224530A0-C9CB-4AEE-9C0F-54AC1B533211} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{22941A26-7033-432C-94C7-6371DE343822} -> Spyware.SearchEnhancement : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{22998D24-B789-4CA2-A7FC-CD7CE7DEB14C} -> Spyware.Seek99 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{23BC1CCF-4BE7-497F-B154-6ADA68425FBB} -> Spyware.Expext : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{23DDAE8C-6A79-4d62-80AA-E95D89CB9811} -> Spyware.SearchExplorer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{25F7FA20-3FC3-11D7-B487-00D05990014C} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2662BDD7-05D6-408F-B241-FF98FACE6054} -> Spyware.Xupiter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{267D5BD3-0DC2-4724-A196-7F4794FBB9EB} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{269B6797-664E-48AA-B283-B012BDF6E525} -> Spyware.eUniverse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{270B845C-712C-4773-BEE0-AE2D2001CD0F} -> Spyware.EZCybersearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2737A6C0-7E24-11D7-B299-00E0297E0844} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{27557cf1-a237-496d-8c8f-08f3844c6a8b} -> Spyware.WhistleSoftware : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{275636E4-A535-4668-9FF1-86DC0C62D446} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{27A5FF76-9919-492C-98E3-EDA3502FC829} -> Spyware.MyPageFinder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{28A19C3E-91E4-4bca-A623-BAF3C43C4F49} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{28CAEFF3-0F18-4036-B504-51D73BD81C3A} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{297caf50-e4f7-11d1-a380-00600896eccc} -> Spyware.Segue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{29A38549-AF6F-11D4-89D6-BC1DFD912B00} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{29F7B7FA-ADC8-48ea-9E1C-EA87A05AE642} -> Spyware.Commander : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2A57772A-D963-4533-A999-A4D66B7EF424} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2A7B720A-7A28-4e99-80A0-2DF985EC93D0} -> Spyware.Make-deal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2AF8CED6-5BD8-4310-A90C-9664EFB16B10} -> Spyware.LookThruCool : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2B3452C5-1B9A-440F-A203-F6ED0F64C895} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2BC43670-C0BD-4794-BB11-F60F3E001DC5} -> Spyware.DynamicDesktopMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C0-5297EF71F443} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C0-5297EF71F444} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C0-5297EF71F44A} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C0-5297EF71F44B} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C2-5297EF71F44A} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2CF0B992-5EEB-4143-99C2-5297EF71F44B} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2D38A51A-23C9-48a1-A33C-48675AA2B494} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2D556983-83D7-4630-9AA5-27C74CA27B79} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2D7CB618-CC1C-4126-A7E3-F5B12D3BCF71} -> Spyware.AdBlaster : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2D877C0B-3F44-42CD-A283-57AAA9186CB9} -> Spyware.GoGoData : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2E12B523-3D4C-4FAC-9B04-0376A8F5E879} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2E77E33F-671E-4334-ABAA-0C2E2BE654F1} -> Spyware.Pornrelated : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2E9CAFF6-30C7-4208-8807-E79D4EC6F806} -> Spyware.SubmitHook : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2F24B54D-3A27-11D8-8169-00C02623048A} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{2FF5573C-0EB5-43db-A1B2-C4326813468E} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{30192F8D-0958-44E6-B54D-331FD39AC959} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-
  • 0

#4
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Sorry, here is the rest of the scan:

HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{30A56549-9D5B-4D34-AFA7-440A7F0538A9} -> Spyware.OpenSite : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{312FA154-E1B7-4336-9833-EE6B38D58B56} -> Spyware.ProBotActivity : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{31995C64-CB4D-483E-82C2-CCFFE2F66CAB} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{319A68DB-06D0-46DA-9F93-A810D5A70836} -> Spyware.ZipClix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{337D0C1D-4053-4FAB-AF2B-45C2F7B0FAA6} -> Spyware.FinditQuick : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{337D0C1D-4053-4FAB-AF2B-45C2F7B0FAA7} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3392BD0A-A851-4AA4-86E0-4651006F9EA8} -> Spyware.Atomica : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{34A44FCF-50E3-63A5-A8DA-7835752B9571} -> Spyware.SeeqToolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{34D516EA-40E3-4E3B-8BA8-505112738ED5} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{35CC7369-C6EB-4A64-AB05-44CF0B5087A0} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3611204F-4B3C-11D4-B416-E159A5067F41} -> Spyware.Rusurecom : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3643ABC2-21BF-46B9-B230-F247DB0C6FD6} -> Spyware.E2Give : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3717DF55-0396-463d-98B7-647C7DC6898A} -> Spyware.HitHopper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3750BFA3-1392-4AF3-AF86-9D2D4776E5A4} -> Spyware.Burnaby : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{3789CBF0-C4CA-4e98-B93B-22ACF0587FBA} -> Spyware.Qidion : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{423BD222-52BE-471A-BE01-75FCCEB3D48F} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{432D8C41-8586-11D8-997D-00C026232EB9} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{43FA5935-E36E-4937-8127-A90191B2EC68} -> Spyware.LoveTester : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} -> Spyware.E-booksystems : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{447160CD-ECF5-4EA2-8A8A-1F70CA363F85} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{44A23DAB-8D31-43AE-9F68-5AC24CF7CE8C} -> Spyware.Msinfosys : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{44BE0690-5429-47f0-85BB-3FFD8020233E} -> Spyware.UCmore : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{499DB658-1909-420B-931A-4A8CAEFD232F} -> Trojan.Aspam : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{49E0E0F0-5C30-11D4-945D-000000000000} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{49F2248D-1734-4B0F-A7B8-542E526EE07C} -> Spyware.YellowPages : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4B021269-DD24-48B2-96B4-DA121E9C0502} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4B2F5308-2CB0-40E2-8030-59936ED5D22C} -> Spyware.HyperBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4B8E6575-1013-45e9-BF77-9852ECEF07A9} -> Spyware.TheLocalSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4B8F38C7-62FC-4762-B9A0-27E63F768167} -> Spyware.TheSearchMall : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4BCF322B-9621-4e90-9678-F1424EB7584E} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4C4871FD-30F6-4430-8834-BC75D58F1529} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} -> Spyware.Fastseeker : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4CEBBC6B-5CEE-4644-80CF-38980BAE93F6} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4D568F0F-8AC9-40AB-88B7-415134C78777} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E1075F4-EEC4-4a86-ADD7-CD5F52858C31} -> Spyware.2020Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-92C6-CE7EB590A94D} -> Spyware.2020Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-95BE-B378BA9CB52D} -> Spyware.NauPointBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-96F7-EB6DB99AA92E} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-98F7-EB6DB99AA93B} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A08D-8F6FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A08E-8E1CA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A0E4-EA6FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A0E8-ED6DB696BB7D} -> Spyware.Americlicks : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A0E8-F76FA694BF2E} -> Spyware.Push : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A1E4-EA6FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A3FA-F161A787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A58D-8F6FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-A68E-8E1CA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-AA8E-8E1CA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FB-EF60B19DA02A} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FB-EF60B19DB42E} -> Spyware.ShopNav : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FB-EF60B19DBC34} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FC-F76FA694BF2E} -> Spyware.eUniverse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FF-FD63B29BB37D} -> Spyware.eUniverse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FF-FD63B399BC7D} -> Spyware.eUniverse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FF-FD69B994BD7D} -> Spyware.Gamebar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C0FF-FD7BA09AAA7D} -> Spyware.PickOfTheWeb toolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C6ED-ED6AA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-C8EF-F36FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D0EE-E86FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D1F0-E56FA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D1F7-EB6DB99AA97D} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D3FA-F27BA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D4F3-F66DA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D4FF-ED78A787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D6F5-F66EA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D7E4-F660B597BF2A} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-D9FB-FA6BAD98FA7D} -> Spyware.MyGeek : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-DBFC-ED1CA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-DFF7-EC6BF4D5FA7D} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-DFF7-EC7DA787AD2D} -> Spyware.PowerSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4E7BD74F-2B8D-469E-EEFD-ED6DB186CE4D} -> Spyware.404Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4F869C58-D71D-4850-8BDD-7B5CDF8EC911} -> Spyware.iBest : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{4FC95EDD-4796-4966-9049-29649C80111D} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5074851C-F67A-488E-A9C9-C244573F4068} -> Spyware.SeekSeek : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{51641EF3-8A7A-4D84-8659-B0911E947CC8} -> Spyware.AdBars : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{525BBD23-1863-46C6-86D6-5F9A3715D44E} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{528DA727-EC08-461E-9564-DF5C971E8574} -> Spyware.NetNucleus : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{52FE5233-367C-4EFB-BDD7-0BE4D212C107} -> Spyware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4} -> Spyware.404Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{53CBEE82-D747-11d3-9ED0-005004189684} -> Spyware.UCmore : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{53D3C442-8FEE-4784-9A21-6297D39613F0} -> Spyware.WinAd : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{53E10C2C-43B2-4657-BA29-AAE179E7D35C} -> Spyware.HighTraffic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{54A85A38-A699-4AEC-8F88-AB542210C93B} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{54EC170F-6EB1-47C6-9C4D-EB0BE20CE45E} -> Spyware.AdBlock : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{54ED9B49-81D1-4866-95A6-30F01DE0047E} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{54F8C0E2-34F9-474F-B47F-2CFCFE2300A2} -> Spyware.Imucomcn : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{55910916-8B4E-4C1E-9253-CCE296EA71EB} -> Spyware.eZula : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{57CD6D2E-0291-488F-B846-AF101B367DD5} -> Spyware.Margoc : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{57E69D5A-6539-4d7d-9637-775DE8A385B4} -> Spyware.Xupiter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{58359010-BF36-11D3-99A2-0050DA2EE1BE} -> Spyware.eZula : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5843A29E-1246-11D4-BA8C-0050DA707ACD} -> Spyware.Gratisware : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{587DBF2D-9145-4c9e-92C2-1F953DA73773} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5886A6DC-AAF4-45E9-979A-8E5E6DEE30E7} -> Spyware.TotalVelocity : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5998B08E-CFAC-11D5-822A-0050048E6E38} -> Spyware.JimmySurf : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5A3A5040-4210-11D7-BD2E-00080E34122F} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5C472352-90D0-4214-BF20-8E4A2B82F980} -> Spyware.eSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5CF8A355-F8C6-4883-9C25-49D01A7D25BE} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5D60FF48-95BE-4956-B4C6-6BB168A70310} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5DAFD089-24B1-4c5e-BD42-8CA72550717B} -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5E92F538-B50B-46C5-9C5F-C6EECED3F6C6} -> Spyware.Dogpile : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5ED50735-B0D9-47C6-9774-02DD8E6FE053} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5F1ABCDB-A875-46c1-8345-B72A4567E486} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5F5564AC-DE7A-4DCD-9296-32E71A35DCB6} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5F5564AC-DE7A-4DCD-9296-32E71A35DCB7} -> Spyware.BrowserPal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{5FA6752A-C4A0-4222-88C2-928AE5AB4966} -> Spyware.Adlogix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{60112085-E1CE-4e0e-823A-EBB1AD98804C} -> Spyware.VirtuMonde : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6085FB5B-C281-4B9C-8E5D-D2792EA30D2F} -> Spyware.NetPal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{60E78CAC-E9A7-4302-B9EE-8582EDE22FBF} -> Spyware.iGetNet : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{61D029AC-972B-49FE-A155-962DFA0A37BB} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{62160EEF-9D84-4C19-B7B8-6AC2526CD726} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{622CC208-B014-4FE0-801B-874A5E5E403A} -> Spyware.123Mania : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6231D512-E4A4-4DF2-BE62-5B8F0EE348EF} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{634EFDE4-087D-4ce9-952F-63C9EEB2E0BF} -> Spyware.Townews : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{63B78BC1-A711-4D46-AD2F-C581AC420D41} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{63CF97E8-4133-438a-A831-CC9C6D47D673} -> Spyware.FlashTrack : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{645FD3BC-C314-4F7A-9D2E-64D62A0FDD78} -> Spyware.PeopleOnPage : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{657B9354-BB3B-4500-A9B0-109B4FA64815} -> Spyware.Aspam. : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6596829B-37D4-40ad-971B-1E9041725C52} -> Spyware.Commander : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{65C8C1F5-230E-4DC9-9A0D-F3159A5E7778} -> Spyware.PeopleOnPage : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6607C683-AE7C-11D4-ACD7-0050DAC291A2} -> Spyware.OpinionBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6656B666-992F-4D74-8588-8CAC9E79D90C} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{665ACD90-4541-4836-9FE4-062386BB8F05} -> Spyware.FlashTrack : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{66993893-61B8-47DC-B10D-21E0C86DD9C8} -> Spyware.LinkReplacer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{66F67511-2665-4C34-9E20-FAC2C0954EF2} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{68513770-A18E-11D7-B77C-00C0DFF3F600} -> Spyware.PrecisionPop : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{69550BE2-9A78-11D2-BA91-00600827878D} -> Spyware.TinyBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6A85D97D-665D-4825-8341-9501AD9F56A3} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6AF9BC61-3CC5-42A7-82D1-FFC2562A7289} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6B12DABB-0B7C-44FA-B0B3-4BAFF3790256} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6CC1C918-AE8B-4373-A5B4-28BA1851E39A} -> Spyware.Winshow : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6CC1C91A-AE8B-4373-A5B4-28BA1851E39A} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6CDF3C49-20E6-48d7-811B-9F5DD17F1D90} -> Spyware.SafeguardProtect : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6D0AC7F7-B628-4581-A8B2-14D97F24AA76} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6D55490C-1BD4-4790-BA31-84D261316E28} -> Spyware.ABCSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6E1C5E3D-A8E6-4a92-820F-BFCFE45BA158} -> Spyware.SafeguardProtect : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6E34D984-4054-45E3-8452-0159A2F0D232} -> Spyware.SafeguardProtect : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6EF3AE25-5A7D-40C2-9B44-9ED0068621C0} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{6F8ADBE2-8C92-4362-B0E6-7321AA49EE46} -> Spyware.NewToolbarDogs : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7011471D-3F74-498E-88E1-C0491200312D} -> Spyware.FriendGreetings : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{702AD576-FDDB-4d0f-9811-A43252064684} -> Spyware.Xupiter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{707E6F76-9FFB-4920-A976-EA101271BC25} -> Spyware.CleverIEHooker : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{710089CF-87C3-763F-C8F6-5A0DBFD3AEC3} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{71B8AB7E-CB3F-4471-878E-8E1DFDF49B8B} -> Spyware.BonziBuddy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{71CC3BD4-6217-44AB-B8D0-96AEAF9A8678} -> Spyware.UCmore : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{71ED4FBA-4024-4bbe-91DC-9704C93F453E} -> Spyware.BlazeFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{72557F9F-13AE-44C9-B3D7-5091B599027C} -> Spyware.LoveTester : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{727D45C4-2BD1-41D2-B54E-97DEAF06AD9A} -> Spyware.123Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{72A58725-2635-4725-8C53-676DFD1FEB8D} -> Spyware.ZeroPopupBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{72CEAE02-DF9C-49F3-9689-10D1B82DC343} -> Spyware.FindItQuick : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{730F2451-A3FE-4A72-938C-FC8A74F15978} -> Spyware.iGetNet : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7371F073-AC0F-4b80-BB2F-96A488CEFB32} -> Spyware.FlashTrack : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{748A5D0A-68D3-11D4-A67E-00E098823A80} -> Spyware.Kugoo : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{753AA023-02D1-447D-8B55-53A91A5ABF18} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{75A46C7E-D7AB-55F3-8DF2-D9A7FFD913E6} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{760A9DDE-1433-4A7C-8189-D6735BB5D3DD} -> Spyware.EZCybersearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{765E6B09-6832-4738-BDBE-25F226BA2AB0} -> Spyware.Qcbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{76EC9B95-D244-41F9-A5BE-6896EFFB40CF} -> Spyware.SearchToolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{77712A64-F30B-47C8-A363-CDA1CEC7DC1B} -> Spyware.AdvancedSearchbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{79049BCB-7C3A-467B-BFA9-0B8C1CD44463} -> Spyware.StartMake : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{79369D5C-2903-4b7a-ADE2-D5E0DEE14D24} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{799A370D-5993-4887-9DF7-0A4756A77D00} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{79C03BC5-6C55-4B5B-921F-C02B6F1ABD7B} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{79C9FB71-7827-11D3-8DF7-00105A119B7C} -> Spyware.NovaPortal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7B49A2A5-B45F-46F3-AC60-2578477671EE} -> Spyware.UltraBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7B55BB05-0B4D-44fd-81A6-B136188F5DEB} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7B64270B-1216-47CE-9708-DE9D2D628CC5} -> Spyware.ProvenTactics : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7C24A476-8B03-46ed-8CCF-CE8AE7213C99} -> Spyware.Seek99 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7DD896A9-7AEB-430F-955B-CD125604FDCB} -> Spyware.DailyWinner : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{7E6CDC1C-3B90-47D7-B2A8-24438CA96075} -> Spyware.iBest : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{80672997-D58C-4190-9843-C6C61AF8FE97} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{80841D20-757E-4A6B-9934-2B3CB9AE83CB} -> Spyware.Showbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8085E374-ACBB-42F9-873F-49EC7E244F97} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{80E81A0E-9741-4FBC-8EE3-3B78C04ADA1D} -> Spyware.TOPicks : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{81270159-E8F9-4713-9646-03531E0EEF58} -> Spyware.HTMLEdit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{81D66134-ADC3-4C6D-B0A9-03D4EE35B849} -> Spyware.Margoc : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{82315A18-6CFB-44a7-BDFD-90E36537C252} -> Spyware.NewDotNet : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{82599E0A-8C81-11d7-9F97-0050FC5441CB} -> Spyware.TinyBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{825CF5BD-8862-4430-B771-0C15C5CA880F} -> Spyware.EliteBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{82B98006-7A56-11D2-A26F-00C04F962769} -> Spyware.Flyswat : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8333C319-0669-4893-A418-F56D9249FCA6} -> Spyware.DailyToolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{834261E1-DD97-4177-853B-C907E5D5BD6E} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{83DE62E0-5805-11D8-9B25-00E04C60FAF2} -> Spyware.BlazeFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8403CB53-12B3-4537-9DEC-4F12F70A883D} -> Spyware.Pornrelated : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{856D6A8E-A24C-498A-A55A-2B25C606A6B4} -> Spyware.NetsterSmartBrowse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{858126B0-3708-4051-AE8E-B48521401CA2} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E} -> Spyware.Medialoads : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{85C2C2A1-3F20-4EAD-ADC3-BD3217391543} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{85CBFDE0-B26B-4EE5-BD3C-4DE111DE763E} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{85DDD882-701E-401B-8A7D-D51227048214} -> Spyware.IEWatch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8786386E-4B22-11D6-9C60-E5DA06D87378} -> Spyware.BandObjects : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{87B1E57C-FF70-4C69-9CE8-57CB8F67ABA8} -> Spyware.WishBone : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{88DECE3E-B7BB-4B13-96FE-924AF77C3780} -> Spyware.iMatchup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{89044184-F260-4FDD-8FAB-2662814846E5} -> Spyware.SpectorPro : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{89AEAB46-8E8A-4045-9003-5614BFBFE90B} -> Spyware.Xlocator : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8A05273A-2EA5-42DE-AA75-59EA7D9D50D7} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} -> Spyware.NetNucleus : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8B224779-3B0E-4FEA-8AE1-B66C20DD840F} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8DB672BD-330F-11D8-8168-00C02623048A} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8E4C16F3-45C8-4B24-99E6-F55082B7C4F1} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8E9C4F32-BD3F-4C49-9AF5-3F4C5D32EBD7} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8F0D6EED-BC11-4E7F-8276-9748947E4A50} -> Spyware.Xlocator : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} -> Spyware.MoneyTree : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8F5A62E2-71F2-72D3-E045-DDF234CAE228} -> Spyware.i-search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{8FB0F3E2-5193-11d7-9F88-0050FC5441CB} -> Spyware.TinyBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} -> Spyware.FizzleWizzle : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{907CA0E5-CE84-11D6-9508-02608CDD2841} -> Spyware.SearchSquire : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{907CA0E5-CE84-11D6-9508-02608CDD2842} -> Spyware.SearchSquire : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{907CA0E5-CE84-11D6-9508-02608CDD2846} -> Spyware.SearchSquire : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{90DA654C-083C-11D6-8A9D-0050BA8452C0} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{90E34F98-E3E6-4CD7-A592-E964FED8AF78} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{91397D20-1446-11D4-8AF4-0040CA1127B6} -> Spyware.Yandez : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{914AFB33-550B-4BD0-B4EF-8DA185504836} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{92C7D65C-52F3-4545-8A35-213D730DB1ED} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{94326E3F-F51F-4863-A832-4ACD0D7D4BC3} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{947E6D5A-4B9F-4CF4-91B3-562CA8D03313} -> Spyware.ClearSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{94927A13-4AAA-476A-989D-392456427688} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9527D42F-D666-11D3-B8DD-00600838CD5F} -> Spyware.GhostSurf : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{95E02C52-05FC-425D-8378-9DA70F9CD763} -> Spyware.Superlogy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{965E6B07-6832-4738-BDBE-25F226BA2AB0} -> Spyware.AdultLinks : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9677F3F1-E994-451F-805F-7148CC8AE040} -> Spyware.WebCrawler : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{96BBDFE1-2951-4F81-811E-31DF6436A329} -> Spyware.Scntoolbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{96BE1D9A-9E54-4344-A27A-37C088D64FB4} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{96DA5BEE-4ACC-476C-B3EC-54C6730C4293} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9819C369-5F62-4D37-9A42-44043A742C1E} -> Spyware.DynamicDesktopMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9896231A-C487-43A5-8369-6EC9B0A96CC0} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{98D7B53E-B1D2-4755-B0A4-703E18FF91E8} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{98DBBF16-CA43-4c33-BE80-99E6694468A4} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{99EBA16F-C13A-40a6-A9C7-5F3EEC4E7BE6} -> Spyware.AdKiller : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} -> Spyware.NetNucleus : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9AD55269-A21C-4260-BA7F-866FD09E8A8E} -> Spyware.EasyBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9C5B2F29-1F46-4639-A6B4-828942301D3E} -> Spyware.123Mania : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF} -> Spyware.WinFavorites : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9C777253-3E17-42d6-897A-11B8617A8F7C} -> Spyware.RedV : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9DD4258A-7138-49C4-8D34-587879A5C7A4} -> Spyware.MSNSmartTags : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9E992732-295F-4987-8BE3-16FAC1639198} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9FF528A9-7314-4658-B497-3D1D4597B300} -> Spyware.iLookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A045DC85-FC44-45be-8A50-E4F9C62C9A84} -> Spyware.KeenValue : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A096A159-4E58-45A9-8EE6-B11466851181} -> Spyware.123Search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A097840A-61F8-4B89-8693-F68F641CC838} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A116A5C1-AD77-446C-992A-F56200B112DB} -> Spyware.SearchEx : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A2833482-B023-4C65-B09D-EE47A4E8CC56} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A28C2A31-3AB0-4118-922F-F6B3184F5495} -> Spyware.BonziBuddy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A3DFDA85-1D92-4E28-8C0C-522574ACDC8A} -> Spyware.CasinoPalazzo : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A3E02B37-8608-4f57-AD58-AB91F32BA4F4} -> Spyware.Masterbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A3E3F04C-F98C-4295-95EF-41C57425B077} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A49AA76F-7215-4F80-97D6-9A7E16A5FEE1} -> Spyware.LookThruCool : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A5483501-070C-41DD-AF44-9BD8864B3015} -> Spyware.Httper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A55581DC-2CDB-4089-8878-71A080B22342} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A6250FB8-2206-499E-A7AA-E1EC437E71C0} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578
  • 0

#5
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
. . . and more. Sigh and sorry.

HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A6475E6B-3C2E-4B1F-82FD-8F1C0B1D8AD0} -> Spyware.CommonName : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB} -> Spyware.Azsearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA} -> Spyware.IEPageHelper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A76066C9-941B-4209-9D96-0AC80501100D} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A78CC2FF-6E4E-4556-B27C-D7C3A70D7A50} -> Spyware.Clickspring : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A85C4A1B-BD36-44E5-A70F-8EC347D9B24F} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A8B9F08F-2FC4-4ADE-9049-CFBA586971BA} -> Spyware.HighTraffic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A9A674BF-771F-42E5-A440-D20DDA85A862} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A9EEF0D7-5695-45BA-8943-ED3B95A50BD2} -> Spyware.CheckUrl : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{AC109D01-32D6-4EB5-8300-D3C5EBAC7C83} -> Spyware.ClearStream : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{AEE46806-2C5A-4A4E-A5DD-B4531F64A187} -> Spyware.SearchSprint : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{AEFCDEC8-EB7D-429F-BC73-4F30D07BFE41} -> Spyware.EZCybersearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{AF657644-964C-4348-A8AD-72524B3A3FF1} -> Spyware.TopSurfer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B195B3B3-8A05-11D3-97A4-0004ACA6948E} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B3269F9A-6521-4793-A951-3E9A9B2E55E7} -> Spyware.Douwantit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B3ECCAC9-C7FA-462C-894B-8E9930A70E14} -> Spyware.KugooIEHelper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B405EE45-1AA2-410D-A6CF-1A74371DCD62} -> Spyware.SearchEx : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B40A6610-1D16-11D3-80B2-005004994DA2} -> Spyware.iChoose : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B418B139-414D-4374-820F-EE74520C5A0D} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B549456D-F5D0-4641-BCED-8648A0C13D83} -> Spyware.AdTomi : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B580CF65-E151-49C3-B73F-70B13FCA8E86} -> Spyware.BaiDu : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B6598677-4B54-42A9-BA67-8B64E3FCD92D} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B7FDA31E-A16D-47F9-B374-78A866AC813D} -> Spyware.BonusBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B847676D-72AC-4393-BFFF-43A1EB979352} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B8C0220D-763D-49A4-95F4-61DFDEC66EE6} -> Spyware.MediaUpdate : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B957F25D-F812-44c4-A23C-249CCFE0AAE0} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B98F79F4-3619-49FB-A7E7-B737E58C5727} -> Spyware.NetsterSmartBrowse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{B9D90B27-AD4A-413a-88CB-3E6DDC10DC2D} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BA3D9F56-5EC1-497D-881A-93A28F58D9AD} -> Spyware.GoHip : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BA7270AE-5636-4618-BAF3-F86ADA39F036} -> Spyware.P2PNetworking : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BB9AAAF3-4F8D-48B5-A565-FF3E58433DC2} -> Spyware.DivagoSurfairy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BC0D2038-2DE5-4A6F-92BC-B18A3E0DE32A} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BC207F7D-3E63-4ACA-99B5-FB5F8428200C} -> Spyware.BDplugin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BC97B254-B2B9-4D40-971D-78E0978F5F26} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BCF96FB4-5F1B-497B-AECC-910304A55011} -> Spyware.HungryHands : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BD0BA5CD-7C8E-47ED-935E-1ABBAC9B29E0} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BD51AEC6-7991-4A60-94D6-D5FEBB655D10} -> Spyware.IETray : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BDF6CE3D-F5C5-4462-9814-3C8EAC330CA8} -> Spyware.AdRoar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C109664B-CEB1-420b-B353-D55A561536DD} -> Spyware.AdShooter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C10A16B7-70FE-4CE3-A261-6FBA7CC3DD5B} -> Spyware.LookQuick : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} -> Spyware.NavExcel : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C298fb42-e3e2-11d3-adcd-0050dac24e8f} -> Spyware.iWon : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C331BD6E-06AB-41A0-B95F-D7CA379ACEAA} -> Spyware.WishBone : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C3BCC488-1AE7-11D4-AB82-0010A4EC2338} -> Spyware.VividenceConnector : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C4CA6559-2CF1-48B6-96B2-8340A06FD129} -> Spyware.AdBars : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C4D99500-4C77-11D4-93B7-0040950570BA} -> Spyware.eBoom : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C5941EE5-6DFA-11D8-86B0-0002441A9695} -> Spyware.BlazeFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C6335B00-E8D9-423e-A691-48D17CBB6C5A} -> Spyware.Praize : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE51} -> Spyware.OnWebMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE56} -> Spyware.OnWebMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C77E900A-FF55-400E-9BAA-E042C8212898} -> Spyware.EasyBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C7967580-5F17-11D4-AAC2-0000B4936E0C} -> Spyware.System61 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C7ADE150-743D-11D4-8141-00E029626F6A} -> Spyware.NetPal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C82B55F0-60E0-478C-BC55-E4E22F11301D} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C84F7AEA-636B-4882-AD5D-56A1DC837FE1} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C900B400-CDFE-11D3-976A-00E02913A9E0} -> Spyware.Webhancer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{C9176930-9C9F-4cba-9723-0F58C3E7CED6} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CA0B9B71-C2AF-11D3-B376-0800460222F0} -> Spyware.iWon : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CA1D1B05-9C66-11D5-A009-000103C1E50B} -> Spyware.4Arcade : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CA92B524-BC8A-4610-BD2C-6BD3E28155D0} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CB7CE223-955E-11D3-81AA-344203C10000} -> Spyware.SpIEMonitoring : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CBA523B2-1906-4D14-95A2-CD8E233701C7} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} -> Spyware.Dashbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CC916B4B-BE44-4026-A19D-8C74BBD23361} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CCE83E45-30B2-4BAE-B1F5-25D128D27A43} -> Spyware.EZCybersearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CD209A08-98B5-4669-AF9F-447AC5253356} -> Spyware.CSApp : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CD2A865B-6C0F-44F9-BAA1-7CDB31E04BC8} -> Spyware.SearchCentrix : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CD4C3CF0-4B15-11D1-ABED-709549C10000} -> Spyware.GoZilla : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CDBCFEAE-10BA-482C-9F6E-FC67207082D8} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CE31A1F7-3D90-4874-8FBE-A5D97F8BC8F1} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CE7C3CF0-4B15-11D1-ABED-709549C10000} -> Spyware.URLBlaze : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CE7C3CF0-4B15-11D1-ABED-709549C10001} -> Spyware.IeMonit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CE7EF827-47CC-48EB-B570-C367F1E1277E} -> Spyware.RideMG : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-716D61788264} -> Spyware.MakeMeSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-717177657972} -> Spyware.MakeMeSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-717177658264} -> Spyware.MakeMeSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-71766C641306} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-717765721306} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{CF021F40-3E14-23A5-CBA2-717965726032} -> Spyware.MakeMeSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D14641FA-445B-448E-9994-209f7AF15641} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D14D6793-9B65-11D3-80B6-00500487BDBA} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D157330A-9EF3-49F8-9A67-4141AC41ADD4} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D1F6ABEF-B889-11D2-8E3C-DCCA155F9A71} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D319662B-D5BF-4538-ADF3-8D3E36362608} -> Spyware.ClearStreamAccelerator : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D34F08C5-4F18-477c-86CB-1A9BEECFE37B} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D34F641F-5210-4EB0-8ED5-9179F47E15B7} -> Spyware.BrowserPal : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D3F01312-8A3D-4D41-A4FA-FB61D295CB6B} -> Spyware.EZCybersearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D44B5436-B3E4-4595-B0E9-106690E70A58} -> Spyware.LOP : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D48F2E28-68E2-4920-9848-D6E6C7AB3EB7} -> Spyware.Xupiter : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D4D505DF-D582-400c-91B6-84921012AFE3} -> Spyware.PopUpDefence : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D537A3D0-8C07-4D62-953F-162207F5090D} -> Spyware.Margoc : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D5B72AED-E54A-11D6-B1B2-444553540000} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D5C778F1-CF13-4E70-ADF0-45A953E7CB8B} -> Spyware.SmartPops : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D6223CBC-A263-4CB1-B35E-1AE40FEF3B3B} -> Spyware.powerlinkingprofits : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D6862A22-1DD6-11D3-BB7C-444553540000} -> Spyware.InetSpeak : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D6E66235-7AA6-44ED-A06C-6F2033B1D993} -> Spyware.HuntBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D6FC35D1-04AB-4D40-94CF-2E5AE4D0F8D2} -> Spyware.Qcbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D714A94F-123A-45CC-8F03-040BCAF82AD6} -> Spyware.SideStep : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D7258ABE-571F-4DC2-ABD1-8393B13B1269} -> Spyware.BrowserAid : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D7D7004C-A763-4F8C-B0D4-55A7E017E69D} -> Spyware.Whazit : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D80E1356-AC78-4218-961C-A7689B4CB7FE} -> Spyware.ComodoTrust : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} -> Spyware.DealHelper : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D8569837-3CD6-4AD7-9A77-65975B581925} -> Trojan.Delf.cr : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D879A0F1-2B3B-4409-8879-FAD6E49E1EA9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D8E25C53-9508-4f5c-9249-D98D438891D5} -> Spyware.MediaUpdate : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D8FA0364-7866-40A7-B340-A6069265AD9F} -> Spyware.Csearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D97287B6-4018-4060-948D-54D2122FC5C3} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D985E70B-97F1-477E-AF6C-66E496DEDBD6} -> Spyware.SecondPower : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{D9A5A49C-60EB-4C07-8570-8FB8FE825E7C} -> Spyware.SubSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{DB0018A2-F7D9-4B71-9651-640143DF23F9} -> Spyware.ezSearching : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{DE614603-6320-4046-A7A7-6A69CEC26F14} -> Spyware.MagicControl : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E0B9B5FE-B66E-4FB0-A1D9-726F0E743CFD} -> Spyware.DivagoSurfairy : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E0F0E0E1-5D45-11D4-BC00-2DCC73302D70} -> Spyware.AdRoar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E2B1672A-DA31-4F7D-A2BF-C18C50BF8F6F} -> Spyware.SearchBoss : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E2DDF680-9905-4dee-8C64-0A5DE7FE133C} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E3EEBBE8-9CAB-4C76-B26A-747E25EBB4C6} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E412F14A-E998-4543-9E7A-1031A3189A87} -> Trojan.Delf.cf : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E539DEA3-BA67-4F1F-A897-5F2F4F29A063} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E5E4E352-6947-44EE-A420-DB84EFD3FE93} -> Spyware.CnsMin : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E720B458-B65A-438C-9FF3-B1DF65D7DB3E} -> Spyware.Locators : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E720B458-B65A-438C-9FF3-B1DF65D7DB3F} -> Spyware.Locators : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E7AFFF2A-1B57-49C7-BF6B-E5123394C970} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E8B4F3AA-9509-4081-9A85-914D5E9BEC81} -> Spyware.BestPhrases : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E8EAEB34-F7B5-4C55-87FF-720FAF53D841} -> Spyware.MidAddle : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{E9147A0A-A866-4214-B47C-DA821891240F} -> Spyware.ESD : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EAD0B31D-9DAE-42CE-9821-EF9794AEC515} -> Spyware.CrackedEarth : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EB23F789-F17F-4bcc-988B-6B70A3A67E9C} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EB386233-65D7-46DC-A73D-0E02F2F844A9} -> Spyware.SpiderSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EBBD88E5-C372-469D-B4C5-1FE00352AB9B} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EBBFE27C-BDF0-11D2-BBE5-00609419F467} -> Spyware.Aureate : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EC788B03-A743-4274-AC9E-DB4F2A03F515} -> Spyware.SearchAndBrowse : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{ECAD9C14-ED46-D58A-E847-ADBEFC8D37EB} -> Spyware.i-search : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{ED657BAF-1EE5-4A07-9D2E-6D0525EFC69B} -> Spyware.P2PNetworking : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{ED8DB0FD-D8F4-4b2c-BB5B-9EF040FE104D} -> Spyware.UCmore : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EE392A64-F30B-47C8-A363-CDA1CEC7DC1B} -> Spyware.NewtonKnows : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EFD84954-6B46-42f4-81F3-94CE9A77052D} -> Spyware.RelatedLinks : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EFEE6B59-ADDB-40eb-BA2C-AF860F5B42B5} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{EFF80427-F837-4B74-8834-BAF18E0553FD} -> Spyware.Parasite : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F0DC0CFE-D11A-489B-84C0-63748AFAABF3} -> Spyware.ZyncosMark : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F104576A-91BA-40AD-91DE-2C20801339AB} -> Spyware.KazaaMate : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F14AABDD-0232-4e5a-9B52-4178AC0A62B5} -> Spyware.AdSubtract : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F195A1A9-4033-4E5B-B85C-848C3E31A83A} -> Spyware.Syslibie : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F1FABE79-25FC-46de-8C5A-2C6DB9D64333} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F281FFC7-6C63-4bf9-83F2-AB7A6157B109} -> Spyware.SafeguardProtect : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F2863EDE-7980-443A-AEA2-0F46076D590F} -> Spyware.RoingsSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F325E940-45EE-11D7-A420-444553540000} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F36C1198-FC6B-4012-9928-DFA76FB56CC3} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F4A645D0-D4D5-439E-9DBC-B31BBD9CB890} -> Spyware.BestPhrases : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F585D290-1BF4-480A-AEC2-4182593F1E32} -> Spyware.Netguarder : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F59D88CF-939A-4E50-9587-65A2E22EF077} -> Spyware.WurldMedia : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F61CAB7A-1E02-4cc2-8832-54B5AB28601D} -> Spyware.LZIO : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F760CB9E-C60F-4A89-890E-FAE8B849493E} -> Spyware.MagicAds : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F7B040B5-307B-4FAC-BB93-556A08156BAC} -> Spyware.ACSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{F9765480-72D1-11D4-A75A-004F49045A87} -> Spyware.eXact : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FA040B34-FBE9-4BEF-9D85-F90BECAACA99} -> Spyware.Margoc : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FA6548E9-78F5-4025-9D7B-FC1367789C38} -> Spyware.SearchMiracle : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FA79FA22-8DB3-43D1-997B-6DBFD8845569} -> Spyware.Meridian : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FAC6E0E1-5D45-4907-BC00-302D702DCC73} -> Spyware.AdRoar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} -> Spyware.SupaSeek : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FB986A68-EAE4-11D4-9BD1-0080C6F60B6A} -> Spyware.Coupon : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FBAA0B9E-A059-43E4-9699-76EB0AEB975B} -> Spyware.i-Lookup : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FBED6A02-71FB-11D8-86B0-0002441A9695} -> Spyware.BlazeFind : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FC2593E3-3E5A-410F-AF3D-82613CCE58E5} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FC4C5EAE-66EE-11D4-BC67-0000E8E582D2} -> Spyware.Hijacker.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FCADDC14-BD46-408A-9842-111111111111} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FCADDC14-BD46-408A-9842-CDB57890086B} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Spyware.ClientMan : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FD7D6851-616E-48DE-AF55-EE2E34F389B0} -> Spyware.SearchScout : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FD9BC004-8331-4457-B830-4759FF704C22} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FE6BC4EF-5676-484B-88AE-883323913256} -> Spyware.CometCursor : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FF4E2C50-BCF3-47cf-952A-A512F5B5D0E8} -> Spyware.StickyPops : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FF7FD490-34E7-4FA1-927A-F5799E6AAD7B} -> Spyware.Surferbar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FF905E0C-CFE9-4A90-AFFF-C13AF5D908F0} -> Spyware.CasinoRewards : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FFD2825E-0785-40C5-9A41-518F53A8261F} -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{FFFFFFFF-FFFF-FFFF-FFFF-5F8507C5F4E9} -> Spyware.MPGcom : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{ba77911b-a393-4a2e-b5b5-5b8ed17d7b43} -> Spyware.ClientMan : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\angel@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\angel@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\angel@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\angel@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\angel@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Angel\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat/files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\Documents and Settings\Angel\Local Settings\Temp\B187218722\build.exe -> Spyware.iSearch : Cleaned with backup
C:\Documents and Settings\Angel\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Angel\Local Settings\Temp\rndrcus.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Angel\Local Settings\Temp\THI3DF7.tmp\polall1b.exe -> TrojanDropper.Small.pv : Cleaned with backup
C:\Documents and Settings\Renate Rader\Cookies\renate rader@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temporary Internet Files\Content.IE5\2T3CPSVQ\inclAds[1].aspx -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temporary Internet Files\Content.IE5\4BSPEZOF\re-mix[2].htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\jedimaster[1] -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\original[2].htm -> Spyware.BookedSpace : Cleaned with backup
C:\Documents and Settings\Renate Rader\Local Settings\Temporary Internet Files\Content.IE5\OT2JQP0H\swk_videos[2].htm -> Spyware.BookedSpace : Cleaned with backup
C:\Program Files\backups\backup-20051116-193406-300.dll -> Spyware.ActivShopper : Cleaned with backup
C:\Program Files\backups\backup-20051118-204752-875.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Program Files\Common Files\Download\freeprodtb.exe -> Spyware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\Download\mc-110-12-0000166.exe -> Spyware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\InetGet\mc-110-12-0000166.exe -> Spyware.Maxifiles : Cleaned with backup
C:\Program Files\Common Files\zrmi\zrmia.exe -> TrojanDownloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\zrmi\zrmil.exe -> TrojanDownloader.TSUpdate.j : Cleaned with backup
C:\Program Files\Common Files\zrmi\zrmip.exe -> Spyware.Xupiter : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP596\A0020403.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020461.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020462.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020463.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020466.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020467.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020468.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020469.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020474.exe -> Spyware.AdSquash : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020476.exe -> Trojan.Agent.km : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020477.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0020606.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0020607.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0020608.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0020609.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP599\A0020610.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0021606.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0021607.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0021608.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP601\A0021609.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022606.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022607.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022608.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022609.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022615.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP605\A0022821.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP605\A0022822.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP605\A0022823.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP605\A0022825.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP605\A0022826.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP608\A0024605.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP608\A0024607.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP608\A0024608.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026410.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026765.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026777.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026778.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026779.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP624\A0026785.exe -> TrojanDownloader.TSUpdate.k : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027066.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027133.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027135.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027136.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027137.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027151.dll -> Trojan.Agent.ic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027152.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027253.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027283.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027284.bat -> Trojan.KillProc.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027285.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027321.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027323.dll -> Trojan.Agent.ic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027324.exe -> Backdoor.IRCBot.ie : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027325.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027326.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027334.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027335.sys -> Trojan.Rootkit.h : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027341.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027342.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027350.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027352.exe -> Spyware.AdSquash : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027353.dll -> Trojan.Agent.ic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027354.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027361.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP627\A0027480.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP627\A0027481.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP627\A0027489.exe -> Spyware.AdSquash : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP627\A0027490.dll -> Trojan.Agent.ic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP627\A0027491.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP628\A0027559.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP628\A0027561.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027652.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027653.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027654.exe -> Adware.AdSquash : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027655.dll -> Trojan.Agent.db : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027656.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027700.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027704.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027714.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027716.dll -> TrojanDownloader.Ieser.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027727.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027728.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027729.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027730.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027731.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027732.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027733.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027734.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027735.dll -> Spyware.WildTangent : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027736.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027737.exe -> Trojan.Poler.a : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027770.exe -> Spyware.Maxifiles : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\isrvs\ffisearch.exe -> Spyware.iSearch : Cleaned with backup
C:\WINDOWS\isrvs\isearch.xpi/chrome/isearch.jar/content/isearch/isearch.js -> Spyware.iSearch : Cleaned with backup


::Report End

Thanks so much again.
  • 0

#6
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
A. Please print out or copy this page to Notepad . Make sure to work through the steps in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fix.
  • Download DSRFIX from HERE onto your Desktop.
    • Unzip and EXTRACT the files to your Desktop.
    • The program creates and names the new folder to house the files.
    • DO NOT RUN IT YET
  • Download Cleanup from Here (Alternate site if the above is not working Go Here)
    • A window will open and choose SAVE, then DESKTOP as the destination.
    • On your Desktop, click on Cleanup40.exe icon.
    • Then, click RUN and place a checkmark beside "I Agree"
    • Then click NEXT followed by START and OK.
    • A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
    • Click OK
    • DO NOT RUN IT YET
  • CLOSE INTERNET EXPLORER, if it is open


  • Open the folder dsrfix
    • Double click on the dsrfix batch file( the one with the little gear in it )
    • Once dsrfix has completed it will close on its own
  • Run Cleanup
    • Click on the "Cleanup" button and let it run.
    • Once its done, close the program.
  • REBOOT your system.


  • Please restart HJT and post back a fresh HJT log for review.

B. You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

1. Please download AproposFix © Swandog46 from here:
http://swandog46.gee.../aproposfix.exe

Save it to your desktop but do NOT run it yet.

2. Then please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


3. Once in Safe Mode, please double-click aproposfix.exe and unzip it to the desktop. Open the aproposfix folder on your desktop and run RunThis.bat. Follow the prompts.

4. When the tool is finished,
  • please reboot back into normal mode,
  • post a new HijackThis log, along with the entire contents of the log.txt file in the aproposfix folder.
Regards,

Trevuren

  • 0

#7
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Here are the newest logs. My computer is running so much better already, thank you so much.


************

Running from directory:
C:\Documents and Settings\Angel\Desktop\aproposfix

************

Registry entries found:

[HKEY_LOCAL_MACHINE\Software\C6TirAFsaTm9]
@="vIKU7WafggfgghgXW2ZQQfggfvigB\\2w3B7gXdXYJRmlgIWNaJWXgUYNaNIJThXdX"
"Device"="\\\\.\\srNull"
"DriverPath"="C:\\WINDOWS\\system32\\drivers\\ptivideo.sys"
"DriverName"="CdfpSrv"
"HideUninstallerName"="C:\\Program Files\\Normatch\\diawmpui.exe"
"HDll"="C:\\WINDOWS\\system32\\nbtntext.dll"
"ServerAddress"="adchannel.contextplus.net"
"LegalNote"="http://adchannel.con...onbranded.html"
"PartnerId"="CP.GH2"
"InstallationId"="{X15ea3bd-f57d-23b5-12ac-5e4caeb69ece}"
"PageFiltering"=dword:00000001
"ClientName"="C:\\Program Files\\Normatch\\umdmdlgs.exe"
"AutoUpdater"="C:\\WINDOWS\\system32\\wjvpsnap.exe"
"Version"="2.0.128"
"LastAURestoreMsgTS"="2005:10:28-08:36:36:365"

************

Removing hidden service:
Service CdfpSrv removed.

Removing hidden folder:
Deletion of folder Normatch succeeded!

Deleting files:

Deletion of file C:\WINDOWS\system32\drivers\ptivideo.sys succeeded!
Deletion of file C:\WINDOWS\system32\wjvpsnap.exe succeeded!
Deletion of file C:\WINDOWS\system32\nbtntext.dll succeeded!

Backing up files:
Done!

Removing registry entries:

REGEDIT4

[-HKEY_CURRENT_USER\Software\C6TirAFsaTm9]
[-HKEY_LOCAL_MACHINE\Software\C6TirAFsaTm9]

Done!

Finished!

Logfile of HijackThis v1.99.1
Scan saved at 10:56:58 PM, on 11/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ruyvhawgx] C:\WINDOWS\System32\bedrjg.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [rtcdll] C:\WINDOWS\System32\rtcdll.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#8
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.
  • First we need to make all files and folders VISIBLE:
    • Go to start>control panel>folder options>view (tab)
    • Choose to "show hidden files and folders,"
    • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
    • Close the window with ok
  • Please RUN HijackThis.
    . Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O4 - HKLM\..\Run: [ruyvhawgx] C:\WINDOWS\System32\bedrjg.exe
    O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
    O4 - HKCU\..\Run: [rtcdll] C:\WINDOWS\System32\rtcdll.exe


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

  • Reboot Your System in Safe Mode

    How to use the F8 method to Start Your Computer in Safe Mode

    • Restart the computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
    • Use the arrow keys to select the Safe mode menu item
    • Press Enter.
  • Using Windows Explorer, locate the following files/folders, and DELETE them (if they are present):

    C:\WINDOWS\System32\bedrjg.exe
    C:\WINDOWS\isrvs<==Folder
    C:\WINDOWS\System32\rtcdll.exe

  • Exit Explorer, and REBOOT BACK INTO NORMAL MODE

  • RUN Hijackthis again and produce a new HJT log. Post it in the forum so we can check how everything looks now.


  • Finally, I need you to do the following:

    I need you to download MWav to a convenient location.

    This scan might take around 3+ hours to finish when set to scan everything.
    I need you to run MWav by double-clicking on mwav.exe. This scan only produces a report, it doesn't clean your system. I will analyze the report and recommend a course of action depending on the results.

    Put a check next to the below items before scanning:
    • Memory
    • Startup Folders
    • Drive - All Local Drives
    • Folder - then click "browse" to change the directory to C: (default is C:\Windows)
    • Registry
    • System Folders
    • Services
    • Include Sub-Directory
    • Scan All Files
    Please make sure ALL of these are checked, then press the Scan button. This typically will take hours to complete.

    **NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

    On the bottom portion of the window, you will see the lower panel where MWav is listing "infected items", please highlight everything in that lower panel and copy them by holding CTRL + C then paste it here. The whole log will be extremely BIG so there is no way to post the log. I just need the infected items list.
Regards,

Trevuren

  • 0

#9
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Here is the Hijack This log . . . I will post up the additional scan's results once it has finished running. Let me know when I can hide my system files again in this process please. Thanks again for everything.

Logfile of HijackThis v1.99.1
Scan saved at 11:57:44 PM, on 11/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#10
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Trevuren,
The Mwav scan has finally finished after an astonishing run of 07:39:13. Made me a tad nervous. However, I have yet to see any sneaky pop ups at all, which has made me quite pleased. Do your family and friends know what a saint you are to complete strangers? Thanks once again . . . :tazz:

Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adware.softomate Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adware.softomate Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adware.softomate Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "myway Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "adware.softomate Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "target saver Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "topsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "my way speedbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "p2p networking Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "desktop search Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "p2p networking Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "lop.com Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "desktop search Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "desktop search Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "aurora Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "imiserver ieplugin Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "target saver Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "weatherbug Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "ezula Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "clipgenie Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "target saver Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\version.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\EarthLink 5.0\putkey.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\aim95\ElnIM.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\pxwma.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\version.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\spool\PRTPROCS\W32X86\Wfxprint2000.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MOH.exe" refers to invalid object "C:\Program Files\Dell Modem-On-Hold\MOH.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ORUN32.EXE" refers to invalid object "C:\WINDOWS\ORUN32.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\udfrinst.exe" refers to invalid object "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\udfrinst.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\WLANMon.exe" refers to invalid object "C:\Program Files\D-Link\AirPlus G\WLANMon.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\YourApp.exe" refers to invalid object "C:\Program Files\ANI\ANIWZCS2 Service\YourApp.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\Alert\bin\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\Alert\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\DSLogDB\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Support\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Dell\Support\bin\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Alert\0\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Dell\Alert\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\aim95\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Favorites\Financial Links\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\WMPLYR\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VSRCPLIN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DELLCUSTOM\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\AUDP\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\AUSTRM\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDBURNING\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RMJPLN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDEXTRACT\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDINFO\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\CDROMS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\COMMON\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DATACACHE\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DEVICES\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FIRSTRUN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\DTDRPLINDIR\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\EPLUGINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FAUST\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FFTRANSCDIR\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FIRSTRUN_LOCALGUIDE\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FLASH\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\FREE\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\GEMSETUP\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\GEMXMLBIN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\HOWTO\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\HOWTOHANDLER\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\JSCRIPT\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MinAim\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MINHELP\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3PL\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MP3PLN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGIMG\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGROOT\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MSGUI\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\MULTICST\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNDEVICEINI\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNENGINE\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNPLUGINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNRPPLUGINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDBURNSUPPORT\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PDMGR\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYER\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERPLUGINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERPLUGOCX\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLAYERUNINST\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLSHARED\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\PLUS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RACODECS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJBRES\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJBVIZ\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJDLG\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJMPMED\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RJMPZIP\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RMXPLN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RNADMIN\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RTPLINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RV9CODECS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\RVCODECS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\SECURITY\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\SKINS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TDWNMGR\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TEMPLATES\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\TFILESYS\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\UI\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\UPDATE\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VIDP\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VIZ\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\Owner\Application Data\Real\RealOne Player\Setup\VMPG\". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".1". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BAK". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bpd". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".doc?bsession=2058932&bsession_str=session_id=2058932,user_id_pk1=95259,user_id_sos_id_pk2=1,user_id=hkyler,one_time_token=,batch_uid=2848744". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".doc?mailpart=1". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dsp". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".FRM". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".isu". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".nes". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".OS2". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".PAL". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".pf". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ST1". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ST2". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".STA". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".THM". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".VOL". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".VPF". Action Taken: No Action Taken.
Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".~y~". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "AltnetDM". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ieupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB821557". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823182". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823559". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823980". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824105". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824141". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824146". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB825119". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828028". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828035". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828741". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB835732". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB837001". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB839643". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB840374". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB842773". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB890923-IE6SP1-20050225.103456". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q328310". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329115". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329170". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329390". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329441". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329834". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810565". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810577". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q810833". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q811493". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q814033". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q815021". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817287". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q817606". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q819696". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q828026". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wcmdmgr.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtdmmp". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "wtwebdriver". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{43FCA273-9534-40DB-B7C5-D7758875616A}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{00014C0D-B007-4448-B89B-4EC3E857961D}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0025F2F6-5458-478E-997C-76BBB056B3D6}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01118c00-3e00-11d2-8470-0060089874ed}" refers to invalid object "C:\DOCUME~1\Angel\LOCALS~1\Temp\Comcast High-Speed Internet Install Wizard\install.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{014DA6CD-189F-421a-88CD-07CFE51CFF10}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0494D0D2-F8E0-41ad-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0494D0D3-F8E0-41ad-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0494D0D5-F8E0-41ad-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0494D0D7-F8E0-41ad-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0494D0DB-F8E0-41ad-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1167C47F-01F9-4C08-8564-1D6C9BAAFB60}" refers to invalid object "C:\Program Files\America Online 8.0\media\pathfinder.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1ADD57B8-A7A9-4518-B9B5-862590FF9EB4}" refers to invalid object "C:\WINDOWS\System32\divxdec.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1B62A3D1-9C04-4BD5-84B5-D2607302501F}" refers to invalid object "C:\WINDOWS\System32\divxdec.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{205D2DFB-BBAD-4DC4-A0BB-CDA12A1639CE}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{21DB24D5-9DD7-4F6F-993A-5FB0980EC5DB}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{22803C10-1FD3-11D5-BE64-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\g2p.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{229b78d5-38f5-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{229b78df-38f5-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{229b78e0-38f5-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{229b78e1-38f5-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{229b78e2-38f5-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{250B0184-3052-4EFB-AAA7-24429B8C0627}" refers to invalid object "C:\Program Files\America Online 8.0\CTABridge.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{28E74E8D-7B99-4486-AE32-11B67F93B54B}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3A7FE611-1994-4ef1-A09F-99456752289D}" refers to invalid object "C:\Program Files\WildTangent\Apps\CDA\ActiveLauncher0101.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3C9E6D35-8D21-4a14-B0A4-56848DFA5325}" refers to invalid object "C:\Program Files\TBONAS\TBONcomp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3ED232B4-0346-4A74-A883-B85B69ADA6A4}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{40D41A8B-D79B-43d7-99A7-9EE0F344C385}" refers to invalid object "C:\Program Files\AIM Toolbar\AIMBar.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{475d9c4f-ee99-4e4a-90e8-0a0382e7a09b}" refers to invalid object "C:\PROGRA~1\SHOCKW~1.COM\BLASTE~1\BLASTE~1.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4E97BE17-3300-4A4F-B380-5988DD771F1F}" refers to invalid object "C:\Program Files\America Online 8.0\media\ares.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5696745A-F3BD-11D4-8A1D-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5788DAE8-4B72-4BE6-89A0-1E6123E4CBC2}" refers to invalid object "C:\Program Files\America Online 8.0\media\cerberus.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{639A19DD-1D97-4A6E-A0D1-01E04FED563F}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6833E600-F6D8-11D4-8A1F-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6EDA439D-F7C7-11d4-8A20-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{75D44B92-DCAF-43f3-A7D1-91041F34E719}" refers to invalid object "C:\Program Files\Common Files\aol\Flasha.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F}" refers to invalid object "C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{78766964-0000-0010-8000-00AA00389B71}" refers to invalid object "C:\WINDOWS\System32\divxdec.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{78D0C657-22F0-4E19-A34A-757B14A30344}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7C9688C3-7279-474D-ABA5-A632373D2CDB}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7FD44536-9DF0-4034-939F-5BD4D98E3187}" refers to invalid object "C:\Program Files\TBONAS\TBONlchr.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83E66439-05D5-488C-A236-AA20E543D384}" refers to invalid object "C:\WINDOWS\System32\divxdec.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A105BD70-BF56-4D10-BC91-41C88321F47C}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{a37186b4-03be-4c61-bdbd-0ef206b89de9}" refers to invalid object "C:\PROGRA~1\SHOCKW~1.COM\BLASTE~1\BLASTE~1.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A62FA99E-922E-4ECA-A1D9-B54EF294A3CC}" refers to invalid object "C:\Program Files\WildTangent\Apps\CDA\CDALogger0401.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{AED456C4-4866-4420-863F-35767EBED514}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B02F4EEB-78D3-414D-8814-7E88F4828C28}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B4F80028-5714-4B7B-B9B1-5748B204799A}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}" refers to invalid object "C:\Program Files\America Online 8.0\media\axtrack.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c4-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c5-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c6-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c7-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{bc8a96c8-3909-11d5-9001-00c04f4c3b9f}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BF4C25B5-CD0A-4770-B2F5-750A4407957F}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C1145550-A454-11D4-9020-00D0B7239081}" refers to invalid object "C:\Program Files\Common Files\aol\Flasha.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C1145551-A454-11D4-9020-00D0B7239081}" refers to invalid object "C:\Program Files\Common Files\aol\Flasha.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C657669A-754D-4E13-BB96-B7269F2078F0}" refers to invalid object "c:\PROGRA~1\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CDECC4C3-7377-11d3-9A6C-00C04FF40D52}" refers to invalid object "c:\program files\mcafee.com\shared\mghtml.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D465B936-C361-4417-9AC5-35167066F84B}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D9F99C6B-A3A6-11D4-AF64-444553546170}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DF0E9111-01DF-11D5-BA23-001083780941}" refers to invalid object "C:\Program Files\America Online 8.0\CalPrinting.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E3852604-B619-11d6-94EC-00047521F020}" refers to invalid object "C:\Program Files\America Online 8.0\media\nmpxchat\nmpxchat.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E5151CBE-F61D-11D4-BA21-001083780941}" refers to invalid object "C:\Program Files\America Online 8.0\CalPrinting.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E981D791-F499-4837-A483-5AB22F1C548F}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EB511AE4-87FE-4EFB-91A3-428B2F2601F7}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{01118C01-3E00-11D2-8470-0060089874ED}" refers to invalid object "C:\DOCUME~1\Angel\LOCALS~1\Temp\Comcast High-Speed Internet Install Wizard\install.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}" refers to invalid object "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{06645894-E73C-413B-8704-71823A9C39B5}" refers to invalid object "C:\Program Files\America Online 8.0\media\cerberus.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{229B78B8-38F5-11D5-9001-00C04F4C3B9F}" refers to invalid object "C:\Program Files\America Online 8.0\media\cddbcontrol.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{296802FE-345A-4CA4-B941-692B8622CC69}" refers to invalid object "C:\Program Files\America Online 8.0\media\axtrack.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3F8E02B4-6601-41A2-95E7-6BD102935C55}" refers to invalid object "C:\Program Files\America Online 8.0\media\phobos.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{46FF31B8-ADA0-484F-9140-056C99713BB0}" refers to invalid object "C:\DOCUME~1\Angel\LOCALS~1\Temp\Word8.0\MSForms.exd". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4A165BD0-165F-474F-AF66-40CD5AC4613E}" refers to invalid object "C:\Program Files\WildTangent\Apps\CDA\ActiveLauncher0101.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4EF67630-DD6C-4E66-B175-60BCCD1CA89B}" refers to invalid object "C:\Program Files\TBONAS\TBONlchr.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4F0876E2-8ECB-4C93-94AD-4E1EAAF7C0F8}" refers to invalid object "C:\Program Files\America Online 8.0\CTABridge.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5279231E-FABE-4ABF-83A8-7C7E17E3CE1A}" refers to invalid object "C:\Program Files\Freeprod Toolbar\tbu00193\freeprod.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5696743D-F3BD-11D4-8A1D-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\IE_NDS.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{5D5D14E4-E652-46CA-8D82-E27B68861205}" refers to invalid object "C:\Program Files\TBONAS\TBONcomp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{6883B133-1B30-45E1-842F-B8670389559D}" refers to invalid object "c:\program files\mcafee.com\shared\mccomctl.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}" refers to invalid object "C:\Program Files\WildTangent\Apps\CDA\CDALogger0401.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8D66A700-5DF0-4706-9ACA-FEB467A7A853}" refers to invalid object "C:\Program Files\America Online 8.0\media\ares.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8F73AC0F-5769-4282-8762-B396A3BFF377}" refers to invalid object "C:\WINDOWS\dsr.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{BA41B112-035B-4D37-B29E-FF4858C3A0EB}" refers to invalid object "C:\Program Files\Shockwave.com\Blasterball 2\BlasterBall2Launch.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C114555B-A454-11D4-9020-00D0B7239081}" refers to invalid object "C:\Program Files\Common Files\aol\Flasha.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{CDECC4C0-7377-11D3-9A6C-00C04FF40D52}" refers to invalid object "c:\program files\mcafee.com\shared\mghtml.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCCAF17F-7581-4C86-9867-56D9405FAC3F}" refers to invalid object "C:\Program Files\America Online 8.0\media\pathfinder.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E3852602-B619-11D6-94EC-00047521F020}" refers to invalid object "C:\Program Files\America Online 8.0\media\nmpxchat\nmpxchat.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E5151CB1-F61D-11D4-BA21-001083780941}" refers to invalid object "C:\Program Files\America Online 8.0\CalPrinting.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{EADCE179-1CC2-11D5-BE60-001083023C0D}" refers to invalid object "C:\Program Files\America Online 8.0\g2p.dll". Action Taken: No Action Taken.
Entry "HKCR\.dgr" refers to invalid object "Viewer". Action Taken: No Action Taken.
Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken.
Entry "HKCR\.t31" refers to invalid object "Viewer". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Automap.Map.NA" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
Entry "HKCR\Automap.Map.NA.9" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
Entry "HKCR\Automap.Template.NA.9" refers to invalid object "{A49EEA00-9231-4C77-AA9E-2F89D72B4804}". Action Taken: No Action Taken.
Entry "HKCR\CDDBControlApple.CddbFullName.1" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken.
Entry "HKCR\CDDBControlApple.FullName" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken.
Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\System32\CMMGR32.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken.
Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken:
  • 0

Advertisements


#11
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
. . . and the rest. Sorry for the breakup again.
Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken.
Entry "HKCR\DSrch.Band" refers to invalid object "{00F1D395-4744-40f0-A611-980F61AE2C59}". Action Taken: No Action Taken.
Entry "HKCR\msbackupfile\shell\open\command" refers to invalid object "%SystemRoot%\system32\ntbackup.exe". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\ppifile\shell\open\command" refers to invalid object "%SystemRoot%\System32\msppcnfg.exe /Config %1". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken.
Entry "HKCR\ToolBand.XBTP07618" refers to invalid object "{2296428D-C133-4928-B76A-A200FF409572}". Action Taken: No Action Taken.
Entry "HKCR\ToolBand.XBTP07618.1" refers to invalid object "{2296428D-C133-4928-B76A-A200FF409572}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
File C:\WINDOWS\jxi.dll infected by "Trojan-Spy.Win32.Lodis.c" Virus! Action Taken: No Action Taken.
File C:\Program Files\backups\backup-20051118-204753-415.dll infected by "Trojan-Spy.Win32.Lodis.c" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020475.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022613.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022614.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024613.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024614.dll infected by "Trojan.Win32.Agent.db" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024615.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027150.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027322.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027699.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027701.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027868.dll tagged as "not-a-virus:AdWare.Win32.ActivShopper.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027869.dll tagged as "not-a-virus:AdWare.Win32.ImiBar.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027870.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.u". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027877.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.u". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027878.exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027879.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027880.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027881.exe tagged as "not-a-virus:AdWare.Win32.Xupiter.m". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027897.exe tagged as "not-a-virus:AdWare.Win32.ImiBar.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027899.exe tagged as "not-a-virus:AdWare.Win32.MDH.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027913.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027914.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027915.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027916.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027917.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027955.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\jxi.dll infected by "Trojan-Spy.Win32.Lodis.c" Virus! Action Taken: No Action Taken.
File C:\Program Files\backups\backup-20051118-204753-415.dll infected by "Trojan-Spy.Win32.Lodis.c" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP598\A0020475.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022613.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP604\A0022614.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024613.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024614.dll infected by "Trojan.Win32.Agent.db" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP609\A0024615.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP625\A0027150.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP626\A0027322.exe tagged as "not-a-virus:AdWare.Win32.AdSquash.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027699.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.b". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027701.dll infected by "Trojan.Win32.Agent.ic" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027868.dll tagged as "not-a-virus:AdWare.Win32.ActivShopper.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027869.dll tagged as "not-a-virus:AdWare.Win32.ImiBar.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027870.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.u". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027877.exe tagged as "not-a-virus:AdWare.Win32.Maxifiles.u". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027878.exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027879.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027880.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027881.exe tagged as "not-a-virus:AdWare.Win32.Xupiter.m". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027897.exe tagged as "not-a-virus:AdWare.Win32.ImiBar.h". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027899.exe tagged as "not-a-virus:AdWare.Win32.MDH.a". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027913.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027914.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027915.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027916.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027917.exe infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027955.dll infected by "Trojan.Win32.Crypt.t" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\jxi.dll infected by "Trojan-Spy.Win32.Lodis.c" Virus! Action Taken: No Action Taken.
:tazz:
  • 0

#12
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
Here at home, the halo is often slightly tilted :tazz:

1. Please rerun Ad-Aware as recommended as per instructions previouly given

2. Reboot your machine.

3. Update your Ewido definitions, then boot into Safe Mode:

a. Using Windows Explorer, please DELETE the following file:

C:\WINDOWS\jxi.dll

b. Then run Ewido, full scan, and let it remove anything that it wants. Save the log to a Notepad file

4. Reboot into Normal Mode

5. Run HJT and post a fresh HJT log for confirmation as well as your Ewido log



Regards,

Trevuren

  • 0

#13
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Trevuren,
Everything is running so smoothly now! :tazz: It's pretty impressive considering that I have several friends who are Comp. Science majors who gave up on trying to fix my system altogether. Again (ad naseum, I know) THANK YOU KINDLY. Here are the last two scans:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:23:35 PM, 11/21/2005
+ Report-Checksum: 7418F4B0

+ Scan result:

HKLM\SOFTWARE\Altnet -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Spyware.Altnet : Error during cleaning
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{000020DD-C72E-4113-AF77-DD56626C6C42} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{0000607D-D204-42C7-8E46-216055BF9918} -> Spyware.TwainTech : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{9FB534E3-67CB-4307-AE0A-9E8B5581BE2C} -> Spyware.WindowsSearchBar : Cleaned with backup
HKU\S-1-5-21-1910578130-823895254-951247151-1008\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\\{A1DD937D-71E1-4BB5-BD5D-1B01B9CB1C2F} -> Spyware.WindowsSearchBar : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Angel\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027699.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027701.dll -> Trojan.Agent.ic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027868.dll -> Spyware.ActivShopper : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027869.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027870.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027877.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027878.exe -> Spyware.Maxifiles : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027879.exe -> TrojanDownloader.TSUpdate.l : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027880.exe -> TrojanDownloader.TSUpdate.j : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027881.exe -> Spyware.Xupiter : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027897.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP629\A0027899.exe -> Spyware.iSearch : Cleaned with backup


::Report End

Logfile of HijackThis v1.99.1
Scan saved at 7:28:52 PM, on 11/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#14
Trevuren

Trevuren

    Old Dog

  • Retired Staff
  • 18,699 posts
1. Download "Registry Search Tool" (RegSrch.vbs) from HERE

2. Start it and paste in altnet.

3. Wait for it to complete the search, click ok at the prompt.

4. Then when wordpad opens, copy the text as a reply into this thread.

Regards,

Trevuren

  • 0

#15
tadghostal

tadghostal

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts
Gee, the computer didn't like that program much. It slowed down a bunch but thankfully kept going and produced this result. I'll be awaiting further instructions, captain :tazz:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "altnet" 11/21/2005 9:03:20 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Altnet]

[HKEY_LOCAL_MACHINE\SOFTWARE\Altnet]
"ALTNET_DIR"="C:\\Program Files\\Altnet"

[HKEY_LOCAL_MACHINE\SOFTWARE\Altnet\Dashboard]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AltnetDM]

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"name"="Altnet Points Manager"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"test"="\"C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe\" -p 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"PM-Home"="C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"PM-Points"="\"C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe\" -p 1"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"PM-Redeem"="\"C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe\" -p 2"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"PM-Wallet"="\"C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe\" -p 3"

[HKEY_LOCAL_MACHINE\SOFTWARE\MyWay\myBar\partner]
"PM-Settings"="\"C:\\Program Files\\Altnet\\Points Manager\\Points Manager.exe\" -p 4"

[HKEY_USERS\S-1-5-21-1910578130-823895254-951247151-1008\Software\P2P Networking\JcdeAgent\P2PNetworkingGUI\DownloadHistory\Altnet TopSearch]

[HKEY_USERS\S-1-5-21-1910578130-823895254-951247151-1008\Software\P2P Networking\JcdeAgent\P2PNetworkingGUI\DownloadHistory\Altnet TopSearch\tsi031013.cab-10000-0x06087d57c4756fe6916b35a53c7e1b6b]
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP