i'm enclosing my hijack scan file… i have no flash on my computer - repeated atempts to download it say i have it but then nothing requiring flash actually plays… in addition the IE shuts down occasionally - no explanations – and of course, the typical popups…
Logfile of HijackThis v1.99.1
Scan saved at 9:54:25 AM, on 9/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Logfile of HijackThis v1.99.1
Scan saved at 5:03:40 PM, on 9/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Welcome to the forum, please reply to this thread only by using the Add-Reply button and not the New Topic button or else you will have posts all over the forum and we wont be able to keep track of you.
DO THIS FIRST
Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.
Easy to fix.
just go to My Computer > YOUR C:\ DRIVE > Program Files and create a new folder and name it Hijackthis .
Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
Now open the new folder you just created and right click within that folder and select PASTE .
Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe
Please do not proceed until you have moved HJT
Download and install the 30 day trial of Ewido Anti Spyware to your desktop.
Once you have downloaded Ewido Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
Once the setup is complete you will need run Ewido and update the definition files.
On the main screen select the icon Update then select the Update now link.
Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine<– Dont forget this
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found
Close Ewido Anti-Spyware <– Do not run the scan yet.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
Boot your computer into Safemode
Go to Start> Shut Off your Computer> Restart
As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
This will bring up a menu.
Use the Up and Down Arrow Keys to scroll up to SAFEMODE
Then press the Enter on your Keyboard
IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
Launch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
Ewido will now begin the scanning process, be patient this may take a little time.
Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply all actions
Next select the Reports icon at the top.
Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
make sure to remember where you saved that file, this is important
i cannot post the ewido scan as it makes the post too long and isn't accepted
there was no result from vundofix as it didn't find anything
here is the hijack log
Logfile of HijackThis v1.99.1
Scan saved at 5:07:42 PM, on 9/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Thats the biggest Ewido Report I have seen in the last two years Nothing in there you want to keep so open Ewido and go to the Quarantine folder and remove it all.
After you run ComboFix and post the log, you had a lot of entries for Hotbar in your Ewido log, lets make sure its all gone, you can download the removal tool from Symantec Here
what's the combofix supposed to look like when it's running
i got a blue box that says performing a scan of your computer
then under that it says Look2Me Orphaned entries found!!!
then i just get a blinking cursor - but can't tell if it's working on something or what…
do i just leave it alone and it's scanning?
Look2Me <- This one of the infections you have on your system, if the program hangs, shut it down, reboot and run it again, it will remove the bad files for this infection, be sure to post the report along with a new HJT log.
this came from the fxhotbar - which shows no hotbar installed —
Adware.Hotbar Removal Tool 1.0.5
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\s?curity: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\T?sks: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\W?nSxS: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\?dobe: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\?racle: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Application Data\?racle: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JBBEWKYE\2-PAIR-BLACK-TRIPP-HOT-TOPIC-GOTH-PANTS-SIZE-9-NO-RESER_W0QQitemZ140019865680QQihZ004QQcategoryZ63863QQssPageNameZWDVWQQrdZ1QQcmdZViewItem[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JBBEWKYE\4-pairTRIPP-PANTS-SIZE-9-HOT-TOPIC-GOTH-PUNK-NO-RESERVE_W0QQitemZ140019846867QQihZ004QQcategoryZ63863QQssPageNameZWDVWQQrdZ1QQcmdZViewItem[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JBBEWKYE\tripp-9_Clothing-Shoes-Accessories_W0QQcatrefZC12QQfromZR9QQfromZR9QQfsooZ1QQfsopZ1QQfstypeZ1QQsacatZ11450QQsspagenameZSTRKQ3aMEFSRCHQ3aSRCH[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\F?nts: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\F?nts: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\S?mantec: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\W?nSxS: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\?racle: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\??sks: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\?ymantec: (not scanned)
C:\Documents and Settings\Rachel.MAURER-BLODGETT\My Documents\??mantec: (not scanned)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\CA69WPW1.net%2Fs%2F2031855%2F8%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=27&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\CAFQL09J.net%2Fs%2F2264425%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=8&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\CAGH2BK5.net%2Fs%2F962586%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=11&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\Network=ugo&size=300x250&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=games&subchannel=flash&category=tic&PT=ct&CR=mi&pez=tic[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\red[2].net&scx=800&scy=600&scc=32&wrd=1_compele,1_compele&sta=,,,1,,,,,,,0,5,0,24897,24487,14658,389,501&iid=153294&bid=304529&dat=;ord=09230892 (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\09YZO56F\Type%3dclick%26FlightID%3d51854%26AdID%3d80732%26TargetID%3d17693%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,197,212,557,596,638,708,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\CA4ZABUY.net%2Fs%2F2031855%2F6%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=25&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\Network=ugo&size=300x250&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=filmtv&subchannel=animation&category=tic&PT=hp&CR=mi&pez=tic[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\Network=ugo&size=728x90&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=games&subchannel=flash&category=tic&PT=ct&CR=mi&pez=tic[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\45Y7ODIB\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\8DIJKD2Z\Type=click&FlightID=21444&AdID=36998&TargetID=6169&Segments=4,7,11,23,26,43,48,60,64,70,85,119,133,278,316,337,357,448,593,600,626,717,819,844,862,870,1035,1074,1407[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\8DIJKD2Z\Type=click&FlightID=22618&AdID=38767&TargetID=99&Segments=4,7,11,23,26,43,48,60,64,70,85,119,133,278,316,337,357,448,593,600,626,717,819,844,862,870,1035,1074,1407,1[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\BZ24GWEX\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422099092;eid1=2;ecn1=0;etm1=8;eid2=3;ecn2=0;etm2=3;&_dc_c[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\BZ24GWEX\CAOLUBWT.net%2Fs%2F2037015%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=40&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\BZ24GWEX\Network=ugo&size=800x600&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=filmtv&subchannel=animation&category=tic&PT=hp&CR=mi&pez=tic[1] (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAATZAAAawcAAAAAAAAAAAoAAf8BEAEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP%2Ew40IAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422085092;eid1=2;ecn1=1;etm1=6;eid2=3;ecn2=1;etm2=2;eid3=4[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422155092;eid1=2;ecn1=0;etm1=38;&_dc_ck=try[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\d%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAARlwAAawcAAAAAAAAAAP8AAP8BEAEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKHo40IAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\d%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAPUEAAARlwAAawcAAAAAAAAAAA4ABf8DCwEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAElG5kIAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\DZ8UH1SE\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP0EAAATZAAAawcAAAAAAAAAAAoAA%2E8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPwB5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAARlwAAawcAAAAAAAAAAAoAA%2E8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABcP5EIAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422091092;eid1=2;ecn1=0;etm1=6;eid2=3;ecn2=0;etm2=1;&_dc_c[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422117092;eid1=2;ecn1=0;etm1=18;&_dc_ck=try[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\ad%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAPUEAAATZAAAawcAAAAAAAAAAAkABP8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAE0H5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\d%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAARlwAAawcAAAAAAAAAAAkAAv8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAJIH5EIAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\H012L4N6\yieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAATZAAAawcAAAAAAAAAAP8AAP8BEAEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFnn40IAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879;;nc=1 (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAPUEAAATZAAAawcAAAAAAAAAAAIAB%2E8BEwEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABsQ5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAAEZgAA4wcAAAAAAAAAAP8AAP8BEAEABALLDgAA%2EQ8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEPp40IAAAAA%2C%2C;rid=1158;tid=1;ev=1;dt=1;ac=60;c=590; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\activity;src=920922;met=1;v=1;pid=11545463;aid=17903883;ko=0;cid=11014144;rid=11032040;rv=1;×tamp=1122422199092;eid1=2;ecn1=0;etm1=44;&_dc_ck=try[1].gif (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\ad%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAAcFAAATZAAAawcAAAAAAAAAAAoAAv8BEQEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABL540IAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\ad%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAATZAAAawcAAAAAAAAAAAIABv8BEwEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPwP5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\ad%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAATZAAAawcAAAAAAAAAAAMABf8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKYH5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\ad%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAPUEAAATZAAAawcAAAAAAAAAAAoABf8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMP5EIAAAAA%2C%2C;rid=673;tid=1;ev=1;dt=1;ac=60;c=879; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\d%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAARlwAAawcAAAAAAAAAAAsAAf8BEgEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAsC5EIAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\d%2Eyieldmanager%2Ecom%2Fclick%2CAAAAAP4EAAARlwAAawcAAAAAAAAAAAYABP8BEwEABALLDgAAZg8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB4Q5EIAAAAA%2C%2C;rid=1190;tid=1;ev=1;dt=1;ac=60;c=424; (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\IL6VA4VI\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\CACLAN4H.net%2Fs%2F2031855%2F5%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=24&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\CAELSR0V.net%2Fs%2F2031855%2F3%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=22&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\CAURWPYP.net%2Fs%2F2031855%2F4%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=23&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Network=ugo&size=300x250&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=filmtv&subchannel=animation&category=tic&PT=forums&CR=mi&pez=tic[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[3].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[3].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYTODBBV\Type%3dclick%26FlightID%3d51857%26AdID%3d80739%26TargetID%3d17696%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,197,212,557,596,638,708,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\UNKVIBUD\Type=click&FlightID=22624&AdID=38777&TargetID=3772&Segments=4,7,11,23,26,43,48,64,70,85,119,130,133,278,316,337,357,448,593,600,626,717,819,844,862,870,885,1035,1074[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\VIXW1NFZ\dBgorBgEEAYI3WAPVoIGOMIGLBgorBgEEAYI3WAMBoH0wewIDAgABAgJmAwICAMAECCJWFfH5N%252bRuBBBaiJrpSb9%252b2ecTA%252buED5KPBFAFzEfeHcmgF%252bVyrprNnBeiEV65qUuzpXBEyPCh4A5X0gFQ83AW&r=0 (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\CA1FVXJH.net%2Fs%2F962586%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=16&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\CASLE7WX.net%2Fs%2F2031855%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=31&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\CAU2S5YY.net%2Fs%2F2031855%2F7%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=26&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\CAUUZZP0.net%2Fs%2F2031855%2F2%2F&ad_type=text_image&image_size=468x60&feedback_link=on&cc=100&u_h=600&u_w=800&u_ah=566&u_aw=800&u_cd=32&u_tz=-240&u_his=21&u_java=true (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Network=ugo&size=1x1&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=filmtv&subchannel=animation&category=tic&PT=ct&CR=mi&pez=tic[2] (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Network=ugo&size=728x90&adtype=over&affiliate=flashplayer&suba=flashplayer&channel=filmtv&subchannel=animation&category=tic&PT=hp&CR=mi&pez=tic[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\red[2].net&scx=800&scy=600&scc=32&wrd=1_compele,1_compele&sta=,,,1,,,,,,,0,5,0,24897,24487,14658,389,501&iid=153294&bid=304529&dat=;ord=72386616 (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51596%26AdID%3d80499%26TargetID%3d10134%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51608%26AdID%3d80506%26TargetID%3d11450%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51857%26AdID%3d80739%26TargetID%3d17696%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,197,212,557,596,638,708,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51857%26AdID%3d80739%26TargetID%3d17696%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[1].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WX6Z09ER\Type%3dclick%26FlightID%3d51857%26AdID%3d80739%26TargetID%3d17696%26Segments%3d%26Targets%3d%26Values%3d25,31,43,51,60,72,82,100,110,150,155,202,212,552,557,596,638,[2].htm (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WXQB09IJ\1773075864@Button1,Button2,Button3,Button4,Button5,Button6,Button7,Button8,Button9,RichMedia,Text1,Text2,Text3,Text4,Text5,Text6,Text7,Text8,Text9,Text10,Text11,Text[1] (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WXQB09IJ\ion%3Duser%26circuitaction%3DviewProfile_commentForm%26friendID%3D36907960%26name%3Ddid%2Bthe%2Bicee%2Bthing%2Bhelp%253f%26MyToken%3Dfd248592-1cfe-48fd-aa78-dfb44a186e41&r=0 (WARNING: not scanned, path to long)
C:\Documents and Settings\Savannah.MAURER-BLODGETT\Local Settings\Temp\Temporary Internet Files\Content.IE5\WXQB09IJ\Type=click&FlightID=23329&AdID=39973&TargetID=6169&Segments=4,7,11,23,26,43,48,60,64,70,85,119,133,278,316,337,357,448,593,600,626,717,819,844,862,870,1035,1074,1407[1].htm (WARNING: not scanned, path to long)
C:\Program Files\Common Files\F?nts: (not scanned)
C:\Program Files\Common Files\F?nts: (not scanned)
C:\Program Files\Common Files\?icrosoft: (not scanned)
C:\Program Files\Common Files\??crosoft: (not scanned)
C:\Program Files\Common Files\??curity: (not scanned)
C:\Program Files\Common Files\??stem32: (not scanned)
C:\Program Files\Common Files\?ssembly: (not scanned)
C:\Program Files\Common Files\?icrosoft.NET: (not scanned)
C:\Program Files\M?crosoft: (not scanned)
C:\Program Files\s?mbols: (not scanned)
C:\Program Files\s?stem: (not scanned)
C:\Program Files\T?sks: (not scanned)
C:\Program Files\?icrosoft.NET: (not scanned)
C:\Program Files\??curity: (not scanned)
C:\Program Files\??mantec: (not scanned)
C:\Program Files\??mbols: (not scanned)
C:\Program Files\??stem32: (not scanned)
C:\Program Files\?dobe: (not scanned)
C:\WINDOWS\SYSTEM32\F?nts: (not scanned)
C:\WINDOWS\SYSTEM32\M?crosoft.NET: (not scanned)
C:\WINDOWS\SYSTEM32\?ppPatch: (not scanned)
C:\WINDOWS\SYSTEM32\??crosoft: (not scanned)
C:\WINDOWS\SYSTEM32\?racle: (not scanned)
C:\WINDOWS\SYSTEM32\?ymantec: (not scanned)
C:\WINDOWS\SYSTEM32\??curity: (not scanned)
C:\WINDOWS\SYSTEM32\??mbols: (not scanned)
C:\WINDOWS\SYSTEM32\??stem: (not scanned)
C:\WINDOWS\SYSTEM32\??sembly: (not scanned)
C:\WINDOWS\SYSTEM32\??pPatch: (not scanned)
C:\WINDOWS\SYSTEM32\??sks: (not scanned)
C:\WINDOWS\S?mantec: (not scanned)
C:\WINDOWS\T?sks: (not scanned)
C:\WINDOWS\?icrosoft: (not scanned)
C:\WINDOWS\?ymantec: (not scanned)
C:\WINDOWS\??stem32: (not scanned)
C:\WINDOWS\?ppPatch: (not scanned)
D:\System Volume Information: (not scanned)
Adware.Hotbar has not been found on your computer.
finally - here is the most recent hijack this scan
Logfile of HijackThis v1.99.1
Scan saved at 12:24:30 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)