Here is the SpySweeper log
8:17 PM: Deletion from quarantine completed. Elapsed time 00:00:00
8:17 PM: Processing: Troj/Patch-F
8:17 PM: Processing: Troj/Patch-F
8:17 PM: Deletion from quarantine initiated
8:16 PM: Removal process completed. Elapsed time 00:00:16
8:16 PM: Quarantining All Traces: Troj/Patch-F
8:16 PM: Removal process initiated
8:14 PM: Traces Found: 2
8:14 PM: Full Sweep has completed. Elapsed time 01:23:53
8:14 PM: File Sweep Complete, Elapsed Time: 01:17:11
8:10 PM: Warning: Failed to access drive D:
8:04 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\seatrek\my documents\my received files\aawsepersonal.exe]
8:01 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\pagefile.sys]
7:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:48 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\lavasoft\ad-aware se personal\skins\ad-aware se default.ask]
7:40 PM: C:\Program Files\Apollo CD & DVD Label Maker\Patch.exe.BAK (ID = 0)
7:38 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\websearch\websearchenu.pdf]
7:38 PM: Warning: AntiVirus engine returned [Access Denied] on [c:\hiberfil.sys]
7:31 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\seatrek\application data\adobe\acrobat\7.0\messages\enu\read0700win_enuadbe0700.pdf]
7:26 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\rdrmsgsplash.pdf]
7:24 PM: C:\Program Files\Apollo CD & DVD Label Maker\Patch.exe (ID = 0)
7:24 PM: Found Troj/Patch-F: Troj/Patch-F
7:07 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\enu\rdrmsgenu.pdf]
7:06 PM: Warning: AntiVirus engine returned [File Encrypted] on [c:\program files\adobe\acrobat 7.0\reader\messages\enu\read0600win_enuyhoo0010.pdf]
6:57 PM: Starting File Sweep
6:57 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:57 PM: Starting Cookie Sweep
6:57 PM: Registry Sweep Complete, Elapsed Time:00:00:48
6:56 PM: Starting Registry Sweep
6:56 PM: Memory Sweep Complete, Elapsed Time: 00:05:28
6:50 PM: Starting Memory Sweep
6:50 PM: Start Full Sweep
6:50 PM: Sweep initiated using definitions version 842
6:50 PM: Spy Sweeper 5.2.3.2138 started
6:50 PM: | Start of Session, Friday, January 19, 2007 |
********
6:50 PM: | End of Session, Friday, January 19, 2007 |
6:50 PM: Your virus definitions have been updated.
6:50 PM: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 1/18/2007 1:34:56 PM (GMT)
6:49 PM: Your definitions are up to date.
6:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
6:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
6:44 PM: The Internet Communication shield has blocked access to: AD.ELTEXT.COM
6:44 PM: The Internet Communication shield has blocked access to: AD.ELTEXT.COM
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
6:43 PM: Shield States
6:43 PM: Spyware Definitions: 842
6:43 PM: Warning: Virus definitions files are invalid, please update your virus definitions. 220
6:37 PM: Spy Sweeper 5.2.3.2138 started
5:46 PM: | End of Session, Friday, January 19, 2007 |
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:44 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
5:43 PM: The Internet Communication shield has blocked access to: AD.T2T2.COM
5:43 PM: The Internet Communication shield has blocked access to: AD.T2T2.COM
Keylogger: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites: Off
Hosts File Shield: On
Internet Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
5:42 PM: Shield States
5:40 PM: Spyware Definitions: 842
5:40 PM: Warning: Virus definitions files are invalid, please update your virus definitions. 220
5:36 PM: Spy Sweeper 5.2.3.2138 started
5:36 PM: Spy Sweeper 5.2.3.2138 started
5:36 PM: | Start of Session, Friday, January 19, 2007 |
********
6:29 PM: Deletion from quarantine completed. Elapsed time 00:00:00
6:29 PM: Processing: ccbill cookie
6:29 PM: Deletion from quarantine initiated
6:28 PM: Removal process completed. Elapsed time 00:00:12
6:28 PM: Quarantining All Traces: ccbill cookie
6:28 PM: Removal process initiated
6:26 PM: Traces Found: 1
6:26 PM: Full Sweep has completed. Elapsed time 00:40:04
6:26 PM: File Sweep Complete, Elapsed Time: 00:32:47
6:25 PM: Warning: Stream read error
6:22 PM: Warning: Stream read error
6:21 PM: Warning: Stream read error
6:17 PM: Warning: Stream read error
6:14 PM: Warning: Failed to access drive D:
5:53 PM: Starting File Sweep
5:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:02
5:53 PM: c:\documents and settings\seatrek\cookies\seatrek@ccbill[2].txt (ID = 2369)
5:53 PM: Found Spy Cookie: ccbill cookie
5:53 PM: Starting Cookie Sweep
5:53 PM: Registry Sweep Complete, Elapsed Time:00:00:42
5:52 PM: Starting Registry Sweep
5:52 PM: Memory Sweep Complete, Elapsed Time: 00:06:04
5:46 PM: Starting Memory Sweep
5:46 PM: Start Full Sweep
5:46 PM: Sweep initiated using definitions version 842
5:46 PM: Spy Sweeper 5.2.3.2138 started
5:46 PM: | Start of Session, Friday, January 19, 2007 |
********
And the HJT log
Logfile of HijackThis v1.99.1
Scan saved at 8:23:56 PM, on 1/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone (HKLM)
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) -
http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) -
http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Current HJT log
Logfile of HijackThis v1.99.1
Scan saved at 10:39:24 PM, on 1/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) -
http://www.linksysfix.com/netcheck/51/install/gtdownls.cab
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) -
http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\Software\..\Telephony: DomainName =
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
SunJava is updated and here is the most recent HJT logs. Again, many thanks. Chuck
Logfile of HijackThis v1.99.1
Scan saved at 12:46:19 PM, on 1/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\AdsGone\AdsGone.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://login.yahoo.com/config/mail?.intl=us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
https://login.yahoo.com/config/mail?.intl=us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] "C:\Program Files\Apoint2K\Apoint.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AdsGone] "C:\Program Files\AdsGone\AdsGone.exe" -s
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [AnyDVD] "C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954} (DigWebHelper Class) -
http://photos.msn.com/resources/neutral/co….cab?10,0,910,0
O17 - HKLM\System\CCS\Services\Tcpip\..\{9ACC6F43-3876-4F36-AADB-17931F525D5A}: NameServer = 24.28.99.64,24.28.99.62
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP Pro 3\Tools\NMSAccess.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
I don't know if I am missing something or what but the latest scan by AdsGone shows even more entries. It had been two to four and is now up to twelve. Here is a copy of the log. I am running SpyBlaster and SpyGuard with ZoneAlarm Pro as well as AVG7 Anti-Virus and the AdsGone Spyware and Pop-Up blocker AND Spybot. I don't understand why AdsGone continues to find these entries when none of the other programs do. What is this entry for persistenthandler? Again, These show mostly as 180Solutions entries. Chuck
"SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 6:08:24 PM"
"aspfile\persistenthandler, Found , 1/15/2007 6:08:26 PM"
"software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 6:08:27 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 6:08:29 PM"
"software\vb and vba program settings, Found , 1/15/2007 6:08:29 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 6:08:30 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 6:08:31 PM"
"software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 6:08:32 PM"
"software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM"
"software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 6:08:32 PM"
"software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 6:08:32 PM"
"software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM"
"software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM"
"software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 6:08:32 PM"
"software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 6:08:32 PM"
"software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 6:08:32 PM"
"software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 6:08:32 PM"
"software\speedbit, Found , 1/15/2007 6:08:32 PM"
"software\speedbit, Found , 1/15/2007 6:08:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 6:08:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 6:08:44 PM"
"software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 6:08:48 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 6:08:48 PM"
"SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 7:49:56 PM"
"aspfile\persistenthandler, Found , 1/15/2007 7:49:59 PM"
"software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 7:50:01 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 7:50:05 PM"
"software\vb and vba program settings, Found , 1/15/2007 7:50:05 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 7:50:08 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 7:50:09 PM"
"software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 7:50:11 PM"
"software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM"
"software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 7:50:11 PM"
"software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 7:50:11 PM"
"software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM"
"software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM"
"software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 7:50:11 PM"
"software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 7:50:11 PM"
"software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 7:50:11 PM"
"software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 7:50:11 PM"
"software\speedbit, Found , 1/15/2007 7:50:11 PM"
"software\speedbit, Found , 1/15/2007 7:50:11 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 7:50:23 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 7:50:23 PM"
"software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 7:50:27 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 7:50:27 PM"
"SOFTWARE\Microsoft\DownloadManager, Found , 1/15/2007 8:03:02 PM"
"aspfile\persistenthandler, Found , 1/15/2007 8:03:05 PM"
"software\microsoft\mediaplayer\control\playbar, Found , 1/15/2007 8:03:06 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:03:09 PM"
"software\vb and vba program settings, Found , 1/15/2007 8:03:09 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:03:11 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/15/2007 8:03:13 PM"
"software\microsoft\internet explorer\menuext\&download with &dap, Found , 1/15/2007 8:03:14 PM"
"software\classes\anigifctrl.anigif\insertable, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000}, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e}, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM"
"software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002}, Found , 1/15/2007 8:03:14 PM"
"software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000}, Found , 1/15/2007 8:03:14 PM"
"software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM"
"software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM"
"software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9}, Found , 1/15/2007 8:03:14 PM"
"software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e}, Found , 1/15/2007 8:03:14 PM"
"software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9}, Found , 1/15/2007 8:03:14 PM"
"software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df}, Found , 1/15/2007 8:03:14 PM"
"software\speedbit, Found , 1/15/2007 8:03:14 PM"
"software\speedbit, Found , 1/15/2007 8:03:14 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/15/2007 8:03:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/15/2007 8:03:27 PM"
"software\microsoft\windows\currentversion\moduleusage\, Found , 1/15/2007 8:03:31 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/15/2007 8:03:31 PM"
"SOFTWARE\Microsoft\DownloadManage, Remove, 1/15/2007 8:03:40 PM"
"aspfile\persistenthandle, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\mediaplayer\control\playba, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:03:40 PM"
"software\vb and vba program setting, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\internet explorer\menuext\&download with &da, Remove, 1/15/2007 8:03:40 PM"
"software\classes\anigifctrl.anigif\insertabl, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{5bfa1daf-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{8110aea1-ad5b-4b90-883f-04a9a33b106e, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM"
"software\classes\clsid\{9738b9e6-8afa-11d2-959e-444553540002, Remove, 1/15/2007 8:03:40 PM"
"software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000, Remove, 1/15/2007 8:03:40 PM"
"software\classes\interface\{5bfa1dae-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM"
"software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM"
"software\classes\interface\{f32c7705-1dad-4b09-b60a-40f1d9b3dbc9, Remove, 1/15/2007 8:03:40 PM"
"software\classes\typelib\{5bfa1da1-5edc-11d2-959e-00c00c02da5e, Remove, 1/15/2007 8:03:40 PM"
"software\classes\typelib\{5fe38345-35a8-11d3-bd27-000021c9a4d9, Remove, 1/15/2007 8:03:40 PM"
"software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df, Remove, 1/15/2007 8:03:40 PM"
"software\speedbi, Remove, 1/15/2007 8:03:40 PM"
"software\speedbi, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\flingstone.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchbarcash.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/15/2007 8:03:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\windows\currentversion\moduleusage, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\windows\currentversion\shareddlls, Remove, 1/15/2007 8:03:40 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/15/2007 8:05:02 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/15/2007 8:05:02 PM"
"software\speedbit, Found , 1/15/2007 8:05:03 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/15/2007 8:05:26 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/15/2007 8:05:26 PM"
"software\speedbi, Remove, 1/15/2007 8:05:26 PM"
"software\vb and vba program settings, Found , 1/15/2007 8:06:35 PM"
"software\vb and vba program setting, Remove, 1/15/2007 8:07:04 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-03-40.asr, Removed from Quarantined, 1/15/2007 8:11:23 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-05-26.asr, Removed from Quarantined, 1/15/2007 8:11:28 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine15-01-2007-20-07-04.asr, Removed from Quarantined, 1/15/2007 8:11:32 PM"
"software\vb and vba program settings, Found , 1/16/2007 12:46:51 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 12:46:54 PM"
"software\vb and vba program setting, Remove, 1/16/2007 12:48:18 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 12:48:18 PM"
"aspfile\persistenthandler, Found , 1/16/2007 6:31:05 PM"
"software\vb and vba program settings, Found , 1/16/2007 6:31:11 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 6:31:14 PM"
"aspfile\persistenthandle, Remove, 1/16/2007 7:13:57 PM"
"software\vb and vba program setting, Remove, 1/16/2007 7:13:58 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:13:58 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/16/2007 7:16:03 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/16/2007 7:16:18 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/16/2007 7:30:09 PM"
"software\microsoft\windows\currentversion\shareddlls, Remove, 1/16/2007 7:30:09 PM"
"aspfile\persistenthandler, Found , 1/17/2007 7:14:38 PM"
"software\vb and vba program settings, Found , 1/17/2007 7:14:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 7:14:41 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/17/2007 7:14:55 PM"
"aspfile\persistenthandle, Remove, 1/17/2007 7:40:53 PM"
"software\vb and vba program setting, Remove, 1/17/2007 7:40:53 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 7:40:53 PM"
"software\microsoft\windows\currentversion\shareddlls, Remove, 1/17/2007 7:40:53 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-12-48-18.asr, Removed from Quarantined, 1/17/2007 8:22:42 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-19-40-53.asr, Removed from Quarantined, 1/17/2007 8:22:49 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-30-09.asr, Removed from Quarantined, 1/17/2007 8:22:53 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine16-01-2007-19-13-58.asr, Removed from Quarantined, 1/17/2007 8:22:57 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:24:49 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/17/2007 8:24:50 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/17/2007 8:25:03 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:33:22 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/17/2007 8:33:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/17/2007 8:33:22 PM"
"software\vb and vba program settings, Found , 1/17/2007 8:34:44 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/17/2007 8:34:45 PM"
"software\vb and vba program setting, Remove, 1/17/2007 8:35:10 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/17/2007 8:35:10 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 8:51:28 PM"
"software\vb and vba program settings, Found , 1/18/2007 8:51:28 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 8:51:32 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-35-10.asr, Removed from Quarantined, 1/18/2007 9:05:24 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine17-01-2007-20-33-22.asr, Removed from Quarantined, 1/18/2007 9:05:30 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/18/2007 9:13:32 PM"
"software\vb and vba program settings, Found , 1/18/2007 9:13:33 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 9:13:35 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/18/2007 9:20:17 PM"
"software\vb and vba program setting, Remove, 1/18/2007 9:20:17 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 9:20:17 PM"
"software\vb and vba program settings, Found , 1/18/2007 10:53:40 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 10:53:45 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/18/2007 10:53:45 PM"
"software\vb and vba program setting, Remove, 1/18/2007 10:54:21 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 10:54:21 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/18/2007 10:54:21 PM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/19/2007 4:47:35 PM"
"software\vb and vba program settings, Found , 1/19/2007 4:47:35 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 4:47:38 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/19/2007 4:48:09 PM"
"software\vb and vba program setting, Remove, 1/19/2007 4:48:09 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 4:48:10 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:15:31 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:15:31 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:16:05 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:16:05 PM"
"software\vb and vba program settings, Found , 1/19/2007 5:17:15 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 5:17:16 PM"
"software\vb and vba program setting, Remove, 1/19/2007 5:17:39 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 5:17:39 PM"
"software\vb and vba program settings, Found , 1/19/2007 10:20:01 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 10:20:04 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/19/2007 10:20:04 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/19/2007 10:20:23 PM"
"software\vb and vba program setting, Remove, 1/19/2007 10:21:42 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 10:21:42 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/19/2007 10:21:42 PM"
"software\microsoft\windows\currentversion\shareddlls, Remove, 1/19/2007 10:21:42 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine18-01-2007-21-20-17.asr, Removed from Quarantined, 1/19/2007 10:21:58 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-22-21-43.asr, Removed from Quarantined, 1/19/2007 10:22:05 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-17-17-39.asr, Removed from Quarantined, 1/19/2007 10:22:09 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-17-16-05.asr, Removed from Quarantined, 1/19/2007 10:22:12 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine19-01-2007-16-48-10.asr, Removed from Quarantined, 1/19/2007 10:22:20 PM"
"C:\Program Files\AdsGone\Quarantine\Quarantine18-01-2007-22-54-21.asr, Removed from Quarantined, 1/19/2007 10:22:24 PM"
"software\vb and vba program settings, Found , 1/20/2007 11:47:42 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 11:47:45 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 11:47:45 AM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/20/2007 11:47:47 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/20/2007 11:48:00 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/20/2007 11:48:00 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/20/2007 11:48:00 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/20/2007 11:48:00 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/20/2007 11:48:00 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/20/2007 11:48:00 AM"
"software\vb and vba program setting, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 11:48:39 AM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/20/2007 11:48:39 AM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/20/2007 11:48:39 AM"
"C:\Program Files\AdsGone\Quarantine\Quarantine20-01-2007-11-48-39.asr, Removed from Quarantined, 1/20/2007 11:49:06 AM"
"software\microsoft\internet explorer\urlsearchhooks, Found , 1/20/2007 12:51:21 PM"
"software\vb and vba program settings, Found , 1/20/2007 12:51:22 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 12:51:25 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings, Found , 1/20/2007 12:51:25 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com, Found , 1/20/2007 12:51:27 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.com, Found , 1/20/2007 12:51:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.com, Found , 1/20/2007 12:51:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.com, Found , 1/20/2007 12:51:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.com, Found , 1/20/2007 12:51:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.net, Found , 1/20/2007 12:51:41 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.com, Found , 1/20/2007 12:51:41 PM"
"software\microsoft\windows\currentversion\shareddlls\, Found , 1/20/2007 12:51:45 PM"
"software\microsoft\internet explorer\urlsearchhook, Remove, 1/20/2007 12:52:32 PM"
"software\vb and vba program setting, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Setting, Remove, 1/20/2007 12:52:32 PM"
"software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.co, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blazefind.co, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchmiracle.co, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\slotch.co, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ysbweb.co, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\clickspring.ne, Remove, 1/20/2007 12:52:32 PM"
"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mt-download.co, Remove, 1/20/2007 12:52:32 PM"
"software\microsoft\windows\currentversion\shareddlls, Remove, 1/20/2007 12:52:32 PM"