This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

180 Solutions and 2nd Thought

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
  • If you are taken to the internet page, just close the page.
  • You will be prompted to check for updated definitions, please do so.
    (This may take several minutes)
  • Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.
  • Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!
  • When the sweep has finished, click Remove. Click Select All and then Next
  • From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Results from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Here is the SpySweeper log

8:17 PM: Deletion from quarantine completed. Elapsed time 00:00:00
8:17 PM: Processing: Troj/Patch-F
8:17 PM: Processing: Troj/Patch-F
8:17 PM: Deletion from quarantine initiated
8:16 PM: Removal process completed. Elapsed time 00:00:16
8:16 PM: Quarantining All Traces: Troj/Patch-F
8:16 PM: Removal process initiated
8:14 PM: Traces Found: 2
8:14 PM: Full Sweep has completed. Elapsed time 01:23:53
8:14 PM: File Sweep Complete, Elapsed Time: 01:17:11
8:10 PM: Warning: Failed to access drive D:
8:04 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\seatrek\my documents\my received files\aawsepersonal.exe]
8:01 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\pagefile.sys]
7:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:48 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\lavasoft\ad-aware se personal\skins\ad-aware se default.ask]
7:40 PM: C:\Program Files\Apollo CD & DVD Label Maker\Patch.exe.BAK (ID = 0)
7:38 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\websearch\websearchenu.pdf]
7:38 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\hiberfil.sys]
7:31 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\seatrek\application data\adobe\acrobat\7.0\messages\enu\read0700win_enuadbe0700.pdf]
7:26 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\rdrmsgsplash.pdf]
7:24 PM: C:\Program Files\Apollo CD & DVD Label Maker\Patch.exe (ID = 0)
7:24 PM: Found Troj/Patch-F: Troj/Patch-F
7:07 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\enu\rdrmsgenu.pdf]
7:06 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\enu\read0600win_enuyhoo0010.pdf]
6:57 PM: Starting File Sweep
6:57 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:57 PM: Starting Cookie Sweep
6:57 PM: Registry Sweep Complete, Elapsed Time:00:00:48
6:56 PM: Starting Registry Sweep
6:56 PM: Memory Sweep Complete, Elapsed Time: 00:05:28
6:50 PM: Starting Memory Sweep
6:50 PM: Start Full Sweep
6:50 PM: Sweep initiated using definitions version 842
6:50 PM: Spy Sweeper 5.2.3.2138 started
6:50 PM: | Start of Session, Friday, January 19, 2007 |
********
6:50 PM: | End of Session, Friday, January 19, 2007 |
6:50 PM: Your virus definitions have been updated.
6:50 PM: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 1/18/2007 1:34:56 PM (GMT)
6:49 PM: Your definitions are up to date.
6:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
6:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
6:44 PM: The Internet Communication shield has blocked access to: AD.ELTEXT.COM
6:44 PM: The Internet Communication shield has blocked access to: AD.ELTEXT.COM
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
6:43 PM: Shield States
6:43 PM: Spyware Definitions: 842
6:43 PM: Warning: Virus definitions files are invalid, please update your virus definitions. 220
6:37 PM: Spy Sweeper 5.2.3.2138 started
5:46 PM: | End of Session, Friday, January 19, 2007 |
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:43 PM: The Internet Communication shield has blocked access to: AD.T2T2.COM
5:43 PM: The Internet Communication shield has blocked access to: AD.T2T2.COM
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:42 PM: Shield States
5:40 PM: Spyware Definitions: 842
5:40 PM: Warning: Virus definitions files are invalid, please update your virus definitions. 220
5:36 PM: Spy Sweeper 5.2.3.2138 started
5:36 PM: Spy Sweeper 5.2.3.2138 started
5:36 PM: | Start of Session, Friday, January 19, 2007 |
********
6:29 PM: Deletion from quarantine completed. Elapsed time 00:00:00
6:29 PM: Processing: ccbill cookie
6:29 PM: Deletion from quarantine initiated
6:28 PM: Removal process completed. Elapsed time 00:00:12
6:28 PM: Quarantining All Traces: ccbill cookie
6:28 PM: Removal process initiated
6:26 PM: Traces Found: 1
6:26 PM: Full Sweep has completed. Elapsed time 00:40:04
6:26 PM: File Sweep Complete, Elapsed Time: 00:32:47
6:25 PM: Warning: Stream read error
6:22 PM: Warning: Stream read error
6:21 PM: Warning: Stream read error
6:17 PM: Warning: Stream read error
6:14 PM: Warning: Failed to access drive D:
5:53 PM: Starting File Sweep
5:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
5:53 PM: c:\documents and settings\seatrek\cookies\seatrek@ccbill[2].txt (ID = 2369)
5:53 PM: Found Spy Cookie: ccbill cookie
5:53 PM: Starting Cookie Sweep
5:53 PM: Registry Sweep Complete, Elapsed Time:00:00:42
5:52 PM: Starting Registry Sweep
5:52 PM: Memory Sweep Complete, Elapsed Time: 00:06:04
5:46 PM: Starting Memory Sweep
5:46 PM: Start Full Sweep
5:46 PM: Sweep initiated using definitions version 842
5:46 PM: Spy Sweeper 5.2.3.2138 started
5:46 PM: | Start of Session, Friday, January 19, 2007 |
********


And the HJT log

Logfile of HijackThis v1.99.1
Scan saved at 8:23:56 PM, on 1/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Launch Notepad, and copy/paste all the code items below to it
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults]
@=""
"http"=dword:00000003
"https"=dword:00000003
"ftp"=dword:00000003
"file"=dword:00000003
"@ivt"=dword:00000001
"shell"=dword:00000000

Back on the Desktop, double-click on the fixme.reg file you just saved and click on Yes when asked to merge the information.

REboot and post a new HJT log.
Current HJT log


Logfile of HijackThis v1.99.1
Scan saved at 10:39:24 PM, on 1/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =

Close ALL windows and browsers except HijackThis and click "Fix checked"





You need to update SunJava.
Updating Java:
Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on 6-windowsi586-p.exe to install the newest version.
Once installed you can test to see that it is in fact installed
Sun Java Test
http://www.java.com/en/download/installed.jsp



Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
SunJava is updated and here is the most recent HJT logs. Again, many thanks. Chuck


Logfile of HijackThis v1.99.1
Scan saved at 12:46:19 PM, on 1/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
You can remove any programs I had you install

Log looks good :D


You need to create a new Clean restore point.

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.



If you dont have any programs like these, I would recommend that you get them.
Spywareblaster,
Spywareguard.


Also get a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Do not use Ad-aware if you have McAfee's VirusScan and AntiSpyware


Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
I don't know if I am missing something or what but the latest scan by AdsGone shows even more entries. It had been two to four and is now up to twelve. Here is a copy of the log. I am running SpyBlaster and SpyGuard with ZoneAlarm Pro as well as AVG7 Anti-Virus and the AdsGone Spyware and Pop-Up blocker AND Spybot. I don't understand why AdsGone continues to find these entries when none of the other programs do. What is this entry for persistenthandler? Again, These show mostly as 180Solutions entries. Chuck "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 6:08:24 PM" "aspfile\persistenthandler, Found , 1/15/2007 6:08:26 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 6:08:27 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM" "software\vb and vba program settings, Found , 1/15/2007 6:08:29 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 6:08:31 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 6:08:32 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 6:08:32 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM" "software\speedbit, Found , 1/15/2007 6:08:32 PM" "software\speedbit, Found , 1/15/2007 6:08:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 6:08:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 6:08:44 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 6:08:48 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 6:08:48 PM" "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 7:49:56 PM" "aspfile\persistenthandler, Found , 1/15/2007 7:49:59 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 7:50:01 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM" "software\vb and vba program settings, Found , 1/15/2007 7:50:05 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 7:50:09 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 7:50:11 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 7:50:11 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM" "software\speedbit, Found , 1/15/2007 7:50:11 PM" "software\speedbit, Found , 1/15/2007 7:50:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 7:50:23 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 7:50:23 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 7:50:27 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 7:50:27 PM" "SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 8:03:02 PM" "aspfile\persistenthandler, Found , 1/15/2007 8:03:05 PM" "software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 8:03:06 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM" "software\vb and vba program settings, Found , 1/15/2007 8:03:09 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 8:03:13 PM" "software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 8:03:14 PM" "software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 8:03:14 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM" "software\speedbit, Found , 1/15/2007 8:03:14 PM" "software\speedbit, Found , 1/15/2007 8:03:14 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 8:03:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 8:03:27 PM" "software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 8:03:31 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 8:03:31 PM" "SOFTWARE\Microsoft\DownloadManage, Remove, 1/15/2007 8:03:40 PM" "aspfile\persistenthandle, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\mediaplayer\control\playba, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM" "software\vb and vba program setting, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\menuext\&download with &da, Remove, 1/15/2007 8:03:40 PM" "software\classes\anigifctrl.anigif\insertabl, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9, Remove, 1/15/2007 8:03:40 PM" "software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM" "software\speedbi, Remove, 1/15/2007 8:03:40 PM" "software\speedbi, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/15/2007 8:03:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\moduleusage, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/15/2007 8:03:40 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:05:02 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:05:02 PM" "software\speedbit, Found , 1/15/2007 8:05:03 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:05:26 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:05:26 PM" "software\speedbi, Remove, 1/15/2007 8:05:26 PM" "software\vb and vba program settings, Found , 1/15/2007 8:06:35 PM" "software\vb and vba program setting, Remove, 1/15/2007 8:07:04 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-03-40.asr, Removed from Quarantined, 1/15/2007 8:11:23 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-05-26.asr, Removed from Quarantined, 1/15/2007 8:11:28 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-07-04.asr, Removed from Quarantined, 1/15/2007 8:11:32 PM" "software\vb and vba program settings, Found , 1/16/2007 12:46:51 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM" "software\vb and vba program setting, Remove, 1/16/2007 12:48:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM" "aspfile\persistenthandler, Found , 1/16/2007 6:31:05 PM" "software\vb and vba program settings, Found , 1/16/2007 6:31:11 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM" "aspfile\persistenthandle, Remove, 1/16/2007 7:13:57 PM" "software\vb and vba program setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 7:16:03 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/16/2007 7:16:18 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:30:09 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/16/2007 7:30:09 PM" "aspfile\persistenthandler, Found , 1/17/2007 7:14:38 PM" "software\vb and vba program settings, Found , 1/17/2007 7:14:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/17/2007 7:14:55 PM" "aspfile\persistenthandle, Remove, 1/17/2007 7:40:53 PM" "software\vb and vba program setting, Remove, 1/17/2007 7:40:53 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/17/2007 7:40:53 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-12-48-18.asr, Removed from Quarantined, 1/17/2007 8:22:42 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-19-40-53.asr, Removed from Quarantined, 1/17/2007 8:22:49 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-30-09.asr, Removed from Quarantined, 1/17/2007 8:22:53 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-13-58.asr, Removed from Quarantined, 1/17/2007 8:22:57 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/17/2007 8:24:50 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/17/2007 8:25:03 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/17/2007 8:33:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/17/2007 8:33:22 PM" "software\vb and vba program settings, Found , 1/17/2007 8:34:44 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:34:45 PM" "software\vb and vba program setting, Remove, 1/17/2007 8:35:10 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:35:10 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 8:51:28 PM" "software\vb and vba program settings, Found , 1/18/2007 8:51:28 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-35-10.asr, Removed from Quarantined, 1/18/2007 9:05:24 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-33-22.asr, Removed from Quarantined, 1/18/2007 9:05:30 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 9:13:32 PM" "software\vb and vba program settings, Found , 1/18/2007 9:13:33 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/18/2007 9:20:17 PM" "software\vb and vba program setting, Remove, 1/18/2007 9:20:17 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM" "software\vb and vba program settings, Found , 1/18/2007 10:53:40 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 10:53:45 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 10:53:45 PM" "software\vb and vba program setting, Remove, 1/18/2007 10:54:21 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 10:54:21 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 10:54:21 PM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/19/2007 4:47:35 PM" "software\vb and vba program settings, Found , 1/19/2007 4:47:35 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/19/2007 4:48:09 PM" "software\vb and vba program setting, Remove, 1/19/2007 4:48:09 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:15:31 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:15:31 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:16:05 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:16:05 PM" "software\vb and vba program settings, Found , 1/19/2007 5:17:15 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:17:16 PM" "software\vb and vba program setting, Remove, 1/19/2007 5:17:39 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:17:39 PM" "software\vb and vba program settings, Found , 1/19/2007 10:20:01 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 10:20:04 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 10:20:04 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/19/2007 10:20:23 PM" "software\vb and vba program setting, Remove, 1/19/2007 10:21:42 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 10:21:42 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 10:21:42 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/19/2007 10:21:42 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine18-01-2007-21-20-17.asr, Removed from Quarantined, 1/19/2007 10:21:58 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-22-21-43.asr, Removed from Quarantined, 1/19/2007 10:22:05 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-17-17-39.asr, Removed from Quarantined, 1/19/2007 10:22:09 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-17-16-05.asr, Removed from Quarantined, 1/19/2007 10:22:12 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-16-48-10.asr, Removed from Quarantined, 1/19/2007 10:22:20 PM" "C:\Program Files\AdsGone\Quarantine\Quarantine18-01-2007-22-54-21.asr, Removed from Quarantined, 1/19/2007 10:22:24 PM" "software\vb and vba program settings, Found , 1/20/2007 11:47:42 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 11:47:45 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 11:47:45 AM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/20/2007 11:47:47 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/20/2007 11:48:00 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/20/2007 11:48:00 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/20/2007 11:48:00 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/20/2007 11:48:00 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/20/2007 11:48:00 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/20/2007 11:48:00 AM" "software\vb and vba program setting, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 11:48:39 AM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/20/2007 11:48:39 AM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/20/2007 11:48:39 AM" "C:\Program Files\AdsGone\Quarantine\Quarantine20-01-2007-11-48-39.asr, Removed from Quarantined, 1/20/2007 11:49:06 AM" "software\microsoft\internet explorer\urlsearchhooks, Found , 1/20/2007 12:51:21 PM" "software\vb and vba program settings, Found , 1/20/2007 12:51:22 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 12:51:25 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 12:51:25 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/20/2007 12:51:27 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/20/2007 12:51:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/20/2007 12:51:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/20/2007 12:51:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/20/2007 12:51:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/20/2007 12:51:41 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/20/2007 12:51:41 PM" "software\microsoft\windows\currentversion\shareddlls\, Found , 1/20/2007 12:51:45 PM" "software\microsoft\internet explorer\urlsearchhook, Remove, 1/20/2007 12:52:32 PM" "software\vb and vba program setting, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 12:52:32 PM" "software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/20/2007 12:52:32 PM" "Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/20/2007 12:52:32 PM" "software\microsoft\windows\currentversion\shareddlls, Remove, 1/20/2007 12:52:32 PM"
I don't know how this program works but most of those are old. It could be showing blocked items, I don't know. But then again there are Free versions of some anti-virus and anti-spyware that give false information in order to get you to purchase the Paid for versions. I suggest you try uninstalling it and reinstall it and see what happens. Be sure to use Add/Remove Programs to uninstall it.
Another problem has just cropped up. I went to the site to read "How did I get Infected" and tryed to reset my settings at Internet Options > Security > Internet, and under Custom Settings the settings are blank with only the drop down box for medium or low. Also my computer will no longer download updates at Microsoft Updates. I get an error message after it checks for latest software. Chuck
I have already done that. After kept getting MSRedist trying to install each time I rebooted and then an error message saying MSI file must be loaded from set up. I ran Microsoft Installer Cleanup and that problem seems to have gone away but still empty box in custom security settings. The MSRedist stopped when I removed all references to an old Norton Anti-Virus program that showed up on the cleaner.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI