Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


cws problems plus others


  • This topic is locked This topic is locked
25 replies to this topic

#1 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 19 January 2006 - 12:03 AM

This is my mother in laws computer and ive done everything from adaware se to the trend micro spy removal trial. cwshredder picked up 2 cws hijacks (cws.mupdate & q2=q4-`) tryed to remove using the shredder but the computer blinked to another page and started a countdown...turned it off immeadiately and restarted and did another adaware scan to find the same problems. i downloaded HJT and placed it in its own folder on the c drive...ran a scan and got this: (any help will greatly be appreciated, this dang computer is in slow motion)

Logfile of HijackThis v1.99.1
Scan saved at 12:52:02 AM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=??? ??? ??? ? ? ??

F3 - REG:win.ini: run=??? ??? ??? ? ? ??

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1.EXE -b
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [fwwu] C:\PROGRA~1\COMMON~1\fwwu\fwwum.exe
O4 - HKCU\..\Run: [Finding Nemo ScreenMate] C:\Program Files\Finding Nemo ScreenMate\Finding Nemo ScreenMate.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Bridge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Chess by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.co...z-ob-assets.cab
O16 - DPF: Spades by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://accelerator.b...oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bel...oad/tgctlsr.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://www.imgag.com...stall/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensave.../sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} - http://hoylegames.si...cherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com...all/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.c...ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.254 205.152.144.235
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Advertisements

Register to Remove


#2 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 19 January 2006 - 08:31 AM

current log:

Logfile of HijackThis v1.99.1
Scan saved at 9:29:33 AM, on 1/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=??? ??? ??? ? ? ??

F3 - REG:win.ini: run=??? ??? ??? ? ? ??

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll (file missing)
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [WINSTA~1.EXE] C:\WINDOWS\System\WINSTA~1.EXE -b
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [WebScan] C:\PROGRA~1\ACCELE~1\ANTI-V~1\DEFSCA~1.EXE -k
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner\RegClean.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [fwwu] C:\PROGRA~1\COMMON~1\fwwu\fwwum.exe
O4 - HKCU\..\Run: [Finding Nemo ScreenMate] C:\Program Files\Finding Nemo ScreenMate\Finding Nemo ScreenMate.exe
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Bridge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Chess by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.co...z-ob-assets.cab
O16 - DPF: Spades by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://accelerator.b...oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bel...oad/tgctlsr.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.5.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://www.imgag.com...stall/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensave.../sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} - http://hoylegames.si...cherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com...all/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.c...ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#3 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 23 January 2006 - 04:49 PM

Hello next, Welcome to the forum.

This is what I suggest you do.


Please do not delete anything unless instructed to.

Use Add/Remove Programs and remove:
NewDotNet

Download CWShredder from my signature below. Unzip it on the desktop.
Open CWShredder and with ALL other windows closed, click fix.


Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
-- Click the Gear wheel at the top of the Ad-Aware window
-- Click General > Safety & Settings: Check (Green) all three.
-- Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.

Next:

Please download the trial version of ewido anti-malware 3.5 here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.


Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Then please run Ewido, click on the Scanner run a full scan and let it clean everything it finds. Save the logfile from the scan.


Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#4 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 24 January 2006 - 03:41 PM

ok...first all thanks for the reply...while i was waiting for your initial reply...i had done all of the things above...i did save the log from the initial ewido scan and i will post it after this message.

things to note:

this will have to be divied into several posts considering the length, the first post will half of the first wido scan...then second will be the second half of the ewido scan...the third reply will be the 2 new scans (ewido and hijackthis)

my mcaffee virus scan keeps eating my HijackThis Program saying its a worm...So this scan will be done with a new downloaded HijackThis program (after i disabled the virus scan)

the ewido program seems to work the first time i use it...after that it seems to open (name of program is down in the system tray) but nothing comes up on the screen...i had to uninstall it and then redownload it so i could run it properly again and get you a new log.

computer still starts very slow and access to the internet seems like it takes nearly 45 minutes before it allows access. SOmethings holding it up either in the start menu or a hijacker.

OK....here is the first log from ewido....I have another one i just ran also which is much shorter...i dodnt know if you needed all the stuff from the first log or not...so here it is anyway...it will be followed by the new ewido log and hijackthislog.


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 12:13:20 AM, 1/21/2006
+ Report-Checksum: 43C59921

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{954814C0-40F3-4249-8528-B4922CD2964E} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A54814C0-40F3-4249-8528-B4922CD2964E} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -> Spyware.PopularScreensavers : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\nCASE -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{15C9938F-CB96-496D-800A-B827F2E34EA1}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{D14D679 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{D14D6793-9B65-11D3-80B6-00500487BDBA} -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Spyware.NewDotNet : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{8776624 -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{8776624 -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{69135BDE-5FDC-4B61-98AA-82AD2091BCCC}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{8776624 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457 -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{CA356D7 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{65D886A2-7CA7-479B-BB95-14D1EFB7946A}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{D14D679 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{68132581-10F2-416E-B188-4E648075325A} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}\{68132581-10F2-416E-B188-4E648075325A}\{722D2939-A14A-41A9-9EAC-AB8F4E295819}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{CA356D7 -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\{68132581-10F2-416E-B188-4E648075325A}\{87766247-311C-43B4-8499-3D5FEC94A183}\{8DA5457F-A8AA-4CCF-A842-70E6FD274094}\{D14D6793-9B65-11D3-80B6-00500487BDBA} -> Spyware.CometCursor : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-37365415-2813461199-664845151-1013\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
[472] C:\Program Files\NewDotNet\newdotnet7_14.dll -> Adware.NewDotNet : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\eskin -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\IESkins -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\reports.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0 -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\dynamic -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1 -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\blank.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\blocked.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\block_sm.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\block_smli.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_back-but.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_left_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_middle_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_middle_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\btn_right_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\buttondir.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\components.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_cattree.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_frbottom.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_objects.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_recentlyused.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_shadows.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\css_topbuttons.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\delete.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_clear_sound.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_freditpreferences.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_frtop.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_fs.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_select.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_sn_frbottom.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_sn_frobjects.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_sn_frtree.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\edit_sn_fs.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-bcards.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-ecards.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-edit.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-emoticons.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-funny.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-help.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-images.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-info.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-more.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-tell.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-temp.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-text.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def-email-voice.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-def.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\email-t1-bg.res -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\flashpreview.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\frbottom3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\frobjects3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\frtop4.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\frtree3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\fs3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\hotbar_promo.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_checked_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_checked_pressed.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_clear_sound.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_close_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_close_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_edit_send.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_recently_used.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_remove_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_remove_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tell_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tell_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_tree_null.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_unchecked_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\icon_unchecked_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\img_corner_left.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_basetemplate.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_hbgroups.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_hbobject3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_hbobjectset3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_iteratorsandreaders3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_pagingmoduleobj3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_texts3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\js_xmltree3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\layout.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\linkpathlegal.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\n.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\nav_bb_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\nav_b_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\nav_ff_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\nav_f_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\sn_flashplayer_top.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\tab_bg.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\tab_r.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_animations.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_backgrounds.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_ecards.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_edit.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_emoticons.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\treedata_text.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\tree_dots.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\tree_minus.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\1\tree_plus.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2 -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\blank.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\blocked.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\block_sm.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\block_smli.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_back-but.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_left_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_middle_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_middle_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\btn_right_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\buttondir.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\components.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_cattree.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_frbottom.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_objects.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_recentlyused.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_shadows.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\css_topbuttons.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\delete.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_clear_sound.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_freditpreferences.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_frtop.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_fs.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_select.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_sn_frbottom.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_sn_frobjects.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_sn_frtree.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\edit_sn_fs.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-bcards.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-ecards.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-edit.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-emoticons.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-funny.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-help.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-images.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-info.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-more.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-photo.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-tell.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-temp.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-text.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def-email-voice.mnu -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-def.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\email-t1-bg.res -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\flashpreview.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\frbottom3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\frobjects3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\frtop4.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\frtree3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\fs3.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\hotbar_promo.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_checked_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_checked_pressed.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_clear_sound.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_close_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_close_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_edit_send.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_recently_used.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_remove_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_remove_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tell_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tell_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_tree_null.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_unchecked_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\icon_unchecked_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\img_corner_left.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_basetemplate.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_hbgroups.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_hbobject3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_hbobjectset3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_iteratorsandreaders3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_pagingmoduleobj3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_texts3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\js_xmltree3.js -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\layout.cdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\linkpathlegal.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\n.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\nav_bb_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\nav_b_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\nav_ff_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\nav_f_2.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\sn_flashplayer_top.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\tab_bg.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\tab_r.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_animations.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_backgrounds.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_ecards.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_edit.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_emoticons.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\treedata_text.xml -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\tree_dots.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\tree_minus.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\2\tree_plus.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\buttondir.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\code.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\email-def.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\email-t1-bg.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\hotbar_promo.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\images.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\layout.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\linkpathlegal.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOI\static\DownLoad\treexml.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\dynamic -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\1 -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\blank.htm -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\blocked.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\block_sm.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\block_smli.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_back-but.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_left_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_left_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_left_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_middle_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_middle_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_right_cut_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_right_enabled_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\btn_right_pressed_1.gif -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\buttondir.txt -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\buttondir.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\code.xip -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_cattree.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_frbottom.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_objects.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_recentlyused.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_shadows.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\HostOL\static\DownLoad\css_topbuttons.css -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\

#5 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 24 January 2006 - 03:54 PM

ok second half of the initial ewido scan log:

C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1001177.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1005423.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1005433.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\100608.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\101203.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1016578.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1020167.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\102218.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1022615.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1026471.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1037615.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1038775.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1045241.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1049983.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1050269.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1052703.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055411.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055531.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055548.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055558.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055617.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055620.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055669.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055671.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055674.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055693.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055738.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055782.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055938.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1055998.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056006.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056008.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056018.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056024.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056052.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056118.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056119.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056216.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056262.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056340.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056594.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056740.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056875.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1056987.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057182.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057191.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057439.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057638.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057858.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057928.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1057933.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1058131.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1058444.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1059014.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1059214.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1059648.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1060710.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1061121.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1061168.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1061691.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1062033.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1062255.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1062295.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1062631.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1063947.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1065366.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1066422.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1066749.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1066751.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1066763.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1066857.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1067162.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1067485.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1067774.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1070500.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1074144.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1082183.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1083500.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1085883.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1104849.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1112181.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1132363.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1136580.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1140770.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\114240.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1145073.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1146709.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1170896.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1175819.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1177968.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1197783.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\12077.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1208270.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\121938.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\122358.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1225978.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1226142.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\122622.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\122640.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1234328.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1244012.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1259597.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1284297.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\128606.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1292851.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1292853.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1293159.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1297772.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1304845.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1307161.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\132753.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\134294.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1368679.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383362.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383462.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383487.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383603.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383623.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383771.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1383783.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384074.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384078.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384083.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384157.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384233.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384255.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384276.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384308.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1384564.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385364.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385381.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385383.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385390.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385452.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385540.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385546.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385940.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385972.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1385987.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386000.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386068.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386098.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386476.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386484.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1386880.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387181.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387233.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387291.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387587.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387648.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1387650.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388227.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388274.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388312.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388502.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388547.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1388557.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1389046.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1389453.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1389489.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1389494.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1391574.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\1393132.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\157819.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\169334.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\180552.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\184307.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\188485.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\190903.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\197447.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\198821.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\203531.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\207176.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\213024.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\213641.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\224908.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\230181.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\23592.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\238013.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\241506.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\241551.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\2451.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\25012.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\253017.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\253527.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\273925.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\283675.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\284983.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\287227.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\307197.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\313696.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\320449.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\328370.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\330366.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\337440.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\340085.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\343532.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\344723.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\344916.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\350103.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\351966.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\355166.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\355397.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\358089.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\358861.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\359228.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\365255.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\368333.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\369037.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\374648.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\375599.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\381837.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\382766.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\39466.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\398275.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\399103.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\401725.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\40208.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\409639.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\411183.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\41254.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\414424.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\415381.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\416276.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\416309.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\421309.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\422856.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\424236.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\428480.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\430079.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\437120.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\441982.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\458561.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\459429.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\47171.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\471737.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\472535.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\482915.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\491501.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\49616.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\498796.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\499863.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\506517.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\507488.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\508423.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\513165.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\515176.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\517495.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\518969.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\519518.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\52833.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\533680.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\534271.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\534359.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\544186.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\547295.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\550799.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\551136.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\551264.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\552768.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\56230.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\566217.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\570087.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\582602.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\605842.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\621757.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\622970.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\625696.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\626353.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\631667.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\637248.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\639036.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\641148.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\644460.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\647388.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\64885.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\652534.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\658915.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\660152.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\664450.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\670828.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\671709.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\675570.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\677627.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\679709.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\680914.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\683374.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\684502.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\690129.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\691517.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\695814.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\698281.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\702871.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\70589.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\706163.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\706848.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\70858.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\710038.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\718278.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\727903.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\731481.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\734128.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\737654.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\743371.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\747344.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\748458.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\761071.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\766617.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\766692.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\769816.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\777073.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\777882.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\780452.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\780675.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\782187.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\786952.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\789954.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\790441.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\7913.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\793515.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\793957.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\801795.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\804433.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\805478.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\808553.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\816249.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\819382.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\83720.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\838863.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\854180.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\86261.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\870153.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\881678.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\890068.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\901665.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\902215.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\903164.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\904919.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\905038.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\913528.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\920086.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\921771.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\924719.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\930185.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\931830.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\93490.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\939147.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\939171.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\939787.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\949315.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\950155.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\953318.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\957291.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\958317.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\962939.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\971957.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\975681.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\976123.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\979001.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3.0\Hotbar\dynamic\984815.sdf -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\Cindy Dance\Application Data\Hotbar\v3

#6 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 24 January 2006 - 03:58 PM

ok this is the third and final part of the original ewido scan log:

Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~425274.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~425458.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~426669.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~428722.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~429438.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~431182.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~432716.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~432985.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~433295.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~437131.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~438175.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~439040.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~439802.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~441084.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~445562.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~445876.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~446468.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~446559.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~448103.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~448686.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~449745.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~450216.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~450692.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~454119.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~455071.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~457008.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~458699.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~463452.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~463910.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~464073.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~464249.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~466773.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~467982.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469436.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469736.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~469948.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~471740.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~472175.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~475421.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~475857.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~481757.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~482442.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~483041.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~494200.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~495868.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~496882.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~507463.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~508314.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~509351.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~509560.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~510255.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~511830.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~511911.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~512677.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~512738.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~513767.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~5153.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~515432.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~516643.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~519137.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~520542.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~521247.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~522571.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~523593.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~52561.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~52974.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~532517.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~533354.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~535616.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~537543.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~537988.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~539070.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~541201.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~542982.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~543856.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~544273.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~544423.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~546707.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~552079.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~552802.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~554453.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~555840.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~566581.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~569276.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~570214.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~572309.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~576281.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~576405.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~577851.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~578126.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~583047.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~584886.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~586207.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~590216.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~590732.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~592801.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~595655.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~595904.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~599646.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~600931.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~602403.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~604322.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~606770.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~608391.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~609535.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~610235.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~61337.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~614479.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~614901.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619377.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619836.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~619999.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~623997.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~624797.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~626051.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~629826.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~630139.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~635368.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~636820.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~63998.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~640851.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~642686.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~649610.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~649804.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~65083.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~652028.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~652340.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~65352.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~655497.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~656743.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~657735.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~658584.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~660785.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664260.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664616.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664821.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~664973.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~666975.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~668412.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~669351.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~670867.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~673788.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~675934.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~678549.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~683309.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684191.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684268.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684723.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~684824.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~687810.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~689057.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~689571.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~690401.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~690500.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~691458.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~693074.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~693174.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~696225.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~696936.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698723.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698792.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~698794.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~700049.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~705639.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~707116.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711163.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711569.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~711928.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~712699.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~713299.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~715535.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~716483.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~71759.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~717734.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~720205.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~721576.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~730462.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~731222.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~732813.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~732933.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~733646.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~733867.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~736114.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~737730.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~738158.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~738665.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741364.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741712.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~741845.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~742227.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~744144.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~744951.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~752062.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~756265.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~760016.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~760816.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~761161.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762285.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762609.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~762815.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~767696.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~773052.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~774949.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~776632.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~780024.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~781044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~782586.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~785290.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~788748.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~791065.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~792797.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~795401.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~799013.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~801467.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~802638.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~808044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~810358.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~818171.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~818335.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~819799.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~820066.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823653.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823764.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~823986.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~828149.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~828834.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~829831.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831062.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831287.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~831772.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~834285.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~836044.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~852710.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~869527.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~872319.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~875337.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~878632.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~87940.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~880198.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~880551.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~882888.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~886607.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~890733.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~891338.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~897966.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~898035.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~898519.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~90507.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~907472.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~908927.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~909436.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~919235.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~924910.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925396.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925671.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~925824.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~926148.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~926911.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931189.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931366.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~931451.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~932103.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~932911.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~933825.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~934417.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~935601.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~940308.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~943589.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~947805.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~950205.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~954639.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~956997.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~957231.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~962573.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~962779.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~963338.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~965513.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~968345.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~972182.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~976599.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~977998.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~978126.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~978834.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~981644.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~982920.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~983891.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~985086.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~985450.tmp -> Spyware.Wintools : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~989894.tmp -> Downloader.WinTool : Cleaned with backup
C:\Documents and Settings\Mary\Local Settings\Temp\~993275.tmp -> Downloader.WinTool : Cleaned with backup
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\newdotnet7_14.dll -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,11,2005_21,30,35.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,11,2005_21,30,35.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,3,2005_2,47,42.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\1,9,2005_17,54,37.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,14,2004_18,35,32.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/mary@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,20,2004_15,23,53.zip/mary@twci.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@statse.webtrendslive[2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,28,2005_20,39,56.zip/mary@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_15,3,20.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,3,2004_17,14,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@counter13.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,31,2004_22,49,26.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\10,6,2004_16,39,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,27,2004_18,56,58.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\11,3,2004_12,37,29.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_12,53,55.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_12,53,55.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,13,2004_22,46,45.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,2,2004_17,39,23.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,25,2004_23,57,48.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,25,2004_23,57,48.zip/mary@twci.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,29,2004_20,41,3.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,3,2004_21,38,9.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,3,2004_21,38,9.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,4,2004_21,59,4.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/mary@counter15.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,8,2004_17,38,46.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,9,2004_22,44,4.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\12,9,2004_22,44,4.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,26,2005_18,37,11.zip/csutil.dll -> Spyware.Comet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,26,2005_18,37,11.zip/fileutil.dll -> Spyware.Comet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\2,5,2005_12,40,34.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,23,2004_17,36,10.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,23,2004_22,56,30.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,25,2004_20,26,48.zip/mary@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,27,2004_15,45,5.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_17,3,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_23,3,10.zip/mary@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_23,3,10.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,28,2004_9,34,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\3,29,2004_17,44,47.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,12,2005_18,6,25.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,12,2005_18,6,25.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,16,2005_17,1,56.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,16,2005_17,1,56.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,2,2004_20,25,1.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,27,2005_1,4,42.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,3,2004_16,41,20.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,5,2004_10,16,54.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,6,2004_18,25,4.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,8,2004_14,31,32.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\4,8,2004_8,54,40.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,13,2005_17,56,50.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,22,2005_2,32,24.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,27,2005_15,4,8.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\5,6,2005_19,44,10.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,10,2004_17,23,58.zip/mary@counter12.sextracker[2].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,12,2004_22,59,51.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,14,2004_6,55,39.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,14,2004_9,4,49.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,15,2004_14,31,42.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/Hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,22,2004_16,40,16.zip/Hbinst.exe -> Adware.Hotbar : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,24,2004_0,59,38.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_0,16,50.zip/mary@gator[2].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_0,16,50.zip/mary@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_12,28,33.zip/mary@counter5.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,37,40.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,37,40.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2004_23,7,39.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,25,2005_22,18,23.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_11,59,42.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_15,41,7.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_16,22,34.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_16,22,34.zip/mary@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_9,46,7.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,26,2004_9,46,7.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,27,2004_22,5,51.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,28,2004_12,4,24.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,6,2005_16,1,41.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,8,2004_22,59,58.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,8,2004_22,59,58.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,9,2005_9,24,1.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\6,9,2005_9,24,1.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,1,2004_22,59,21.zip/mary@data.coremetrics[2].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,1,2004_22,59,21.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,10,2004_16,42,54.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,10,2004_16,42,54.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,13,2004_17,43,48.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,14,2004_15,8,24.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,17,2004_17,35,29.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,20,2004_16,33,38.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,21,2005_0,19,27.zip/mary@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/mary@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,22,2004_2,11,28.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,24,2004_1,16,19.zip/mary@counter13.sextracker[1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,24,2005_5,13,18.zip/mary@citi.bridgetrack[2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,28,2004_22,21,53.zip/mary@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\7,3,2004_12,5,56.zip/mary@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\NoAdware\NoAdwareBackup\

#7 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 24 January 2006 - 04:02 PM

ok here is the scan logs i just ran, they are much cleaner but the computer performance hasn't changed


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 3:21:51 PM, 1/24/2006
+ Report-Checksum: E0CDB77D

+ Scan result:

C:\Documents and Settings\Mary\Cookies\mary@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@e-2dj6wfkycjdjgcp.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@e-2dj6wjk4gpczsap.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@e-2dj6wjkocgajwep.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@e-2dj6wjnycgajsao.stats.esomniture[1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@e-2dj6wjnyqkd5ico.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mary\Cookies\mary@microsofteup.112.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup


::Report End


ok heres the hijackthis log from today:

Logfile of HijackThis v1.99.1
Scan saved at 3:57:37 PM, on 1/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\repair\faxxml.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Mary\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: load=??? ??? ??? ? ? ??

F3 - REG:win.ini: run=??? ??? ??? ? ? ??

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe
O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe
O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe
O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Bridge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Chess by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.co...z-ob-assets.cab
O16 - DPF: Spades by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Video Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://accelerator.b...oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bel...oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://www.imgag.com...stall/AxCtp.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...ip/RdxIE601.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX25.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensave.../sinstaller.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} - http://hoylegames.si...cherControl.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com...all/Crusher.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.43/ttinst.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.c...ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

thank you for your time and please advise what steps to take next

Chuck

#8 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 24 January 2006 - 04:14 PM

I suggest you do this:


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com

R3 - Default URLSearchHook is missing

F3 - REG:win.ini: load=??? ??? ??? ? ? ??

F3 - REG:win.ini: run=??? ??? ??? ? ? ??

O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file)

O4 - HKLM\..\Run: [*svcsys] C:\WINDOWS\svcsys.exe

O4 - HKLM\..\Run: [*expmsvc] C:\WINDOWS\Fonts\expmsvc.exe

O4 - HKLM\..\Run: [*unad] C:\WINDOWS\Microsoft.NET\unad.exe

O4 - HKLM\..\Run: [*faxxml] C:\WINDOWS\repair\faxxml.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O16 - DPF: {38578BF0-0ABB-11D3-9330-0080C6F796A1} (Create & Print ActiveX Plug-in) - http://www.imgag.com...stall/AxCtp.cab

O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150...ip/RdxIE601.cab

O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensave.../sinstaller.cab

O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} - http://hoylegames.si...cherControl.cab

O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com...all/Crusher.cab

O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://download.toon...5.43/ttinst.cab


Close ALL windows and browsers except HijackThis and click "Fix checked"


Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.



delete these files if listed:
C:\WINDOWS\svcsys.exe
C:\WINDOWS\Fonts\expmsvc.exe
C:\WINDOWS\Microsoft.NET\unad.exe
C:\WINDOWS\repair\faxxml.exe



Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#9 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 24 January 2006 - 11:47 PM

ok got everything done. here's a few things i need to note:

1. start up is still superslow...hourglass stays on for approximately 1hr and 20 minutes (i timed it this time)

2. when starting up this time, trend micro anti spyware venus flytrap monitoring program picked up many proxy server changes to the web browsing configuration...i allowed all of them...considering we made so many changes....these warnings came up through out the 1 hr and 20 minute startup.

3. the last program that came up in startup was the bellsouth accelerator...this is the program i need to be able to access the internet...even though i can connect to the internet right away after start up...i get "IE explorer cannot find server or dns error" immeadiately when the IE window opens...i can get to the internet during this time with other programs such as any of the spyware/virus update programs (they seem to be able to access the net) as well as yahoo messenger access the net just fine during the startup period.

4. ive tryed different sites using IE during this startup period all trys get the same "IE explorer cannot find server or dns error"

5. after the bell accelarator program loads (last program that starts up, 1 hr 20 minutes after reboot) i am able to access the internet through IE.

6. right after reboot...i noticed that the pointer now moves freely during start up (no stalls or freezeups like it used to do, even though the hour glass is still present)

7. actions seem to be quicker with faster reponse times...like when i press the start button...the menu pops up immeadiately...before there was a delay....when i click on folders they pop right open now displaying the contents..before there was a delay...programs seem to start quicker (except for startup)

8. after the startup (1 hr 20 minutes...lol) is complete i can access the web...seems pages load quicker...no delays or "IE explorer cannot find server or dns errors"

9. previously i could surf for an hour or so then i would get a "unknown error -1" in IE and i wouldnt be able to surf again without a reboot...which would take a longtime (1 hr 20 mnutes) to get back on IE...I dont know the status of this yet considering i havent had that problem as of yet.

20. overall quicker speed while navagating through windows and browsing the web, startup still a big problem.

Let me know what to do from here and thank you for what you have done so far.


here's the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 12:22:29 AM, on 1/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJK\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MPSExe] C:\Program Files\McAfee.com\MPS\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Bridge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Chess by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.co...z-ob-assets.cab
O16 - DPF: Spades by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Video Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://accelerator.b...oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bel...oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX25.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.c...ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#10 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 25 January 2006 - 04:14 PM

lets see if this will help speed it up.

Backup your Registry...
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run...)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

    Advertisements

Register to Remove


#11 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 25 January 2006 - 05:54 PM

ok....done the regseeker...found tons of stuff...deleted it all...then ran again...with much fewer results.....then again...with much fewer reslts...got it down to 13.....these 13 after deletion appear on the scan over and over again...the same 13.....im gonna leavem now and do a reboot and see what we have hkey_classes_root .cdf .cta .dsn .jod .lwv .pcd .pcx .tga .udl .wri these are all "extension not used" software\classes\lwvfile software\classes\odbc.filedsn these are filetype not used can't seem to get rid of these, they are on the scan everytime, prolly ran it 10 times. ok i'll report back and let you know if it helped. Chuck

#12 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 25 January 2006 - 06:23 PM

Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#13 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 25 January 2006 - 06:47 PM

ok...startup this time only 40 minutes until the bellsouth accellerator came up in the tray next to the time and allowed access to the IE and the net.

i cant really tell adifference in the preformance now and when we last talked. Still borwses great both online(after starting up) and through windows. Startup cutdown to 40 minutes...which is still just way too slow...lol.

while your looking at this, im gonna take the bellsouth accellerator off the startup. The internet connection used to work fine without it they said it would be faster if we used it in conjuction with our ISP.

I got a feeling that IE in the startup program list starts after the propel bellsouth accelerator...if the accelerator is hanging up during startup (or just takes an incredibly long tome to start) this would hold up the startup of IE. So given the above, if i take the accellerator off the startup list maybe i can get to the internet quicker through IE since it wont have to wait til the Accellerator starts. Who KNows...I'll give it a try.


Here's another Hijack log:

Logfile of HijackThis v1.99.1
Scan saved at 7:35:17 PM, on 1/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\BellSouth Internet Tools\blsloader.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\BellSouth Accelerator Technology\propelac.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\Mary\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8082
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BlspcHlpr Class - {15C9938F-CB96-496D-800A-B827F2E34EA1} - C:\Program Files\BellSouth Internet Tools\blspc.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn4\yt.dll
O4 - HKLM\..\Run: [sr1exe] "C:\Documents and Settings\All Users\Application Data\Dell\Alert\252\updtSup3.exe"
O4 - HKLM\..\Run: [Propel Accelerator] "C:\Program Files\BellSouth Accelerator Technology\propelac.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [blspcloader] "C:\Program Files\BellSouth Internet Tools\blsloader.exe"
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\BellSouth Accelerator Technology\pac-image.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Animal Ark by pogo - http://www.pogo.com/...nimal-en_US.cab
O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Big Shot Roulette TM by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Bridge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: Chess by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: EZ Win Bingo by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Hearts by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Multiline Slots by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Phlinx by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Quick Quack by pogo - http://game1.pogo.co...k-ob-assets.cab
O16 - DPF: Showbiz Slots by pogo - http://game1.pogo.co...z-ob-assets.cab
O16 - DPF: Spades by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: Stax by pogo - http://game1.pogo.co...x-ob-assets.cab
O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.co...oldem-en_US.cab
O16 - DPF: Video Poker by pogo - http://game1.pogo.co...r-ob-assets.cab
O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.co...s-ob-assets.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://accelerator.b...oad/tgctlcm.cab
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bel...oad/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1137826019312
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/.../GrooveAX25.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.c...utocomplete.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla...ller/dwnldr.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.c...ebio5_1_1_0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredim...er/imloader.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8F99AB9-567E-44DC-9A85-8401D356D4BB}: NameServer = 205.152.37.23 205.152.144.23
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

#14 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 25 January 2006 - 07:02 PM

We can get rid of some items she doesn't need now.

I suggest you do this:

use Add/Remove Programs and remove:
Trend Micro Tmas
ewido anti-malware



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe


Close ALL windows and browsers except HijackThis and click "Fix checked"


Empty Recycle Bin

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#15 Guest_nextnextelchamp42_*

Guest_nextnextelchamp42_*
  • Guests

Posted 25 January 2006 - 07:25 PM

ok...havent rebooted yet...did the scan only and the fixes to the items...and got this reply.

Unexpected error occurred!
Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

Please send a report to merijn@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

This message has been copied to your clipboard.


ok...i guess ill try another scan of hijack to make sure all of what you listed is gone...feel free to send an email to merijn if you like. it happened right after i hit FIX.

ok..gonna go scan..fix...reboot...and scan & log again for you...be right back...hopefully...lol

Chuck

Edited by nextnextelchamp42, 25 January 2006 - 07:27 PM.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users