PDA

View Full Version : Anyone heard of SpyZooka



Firebird
2005-12-29, 19:20
Hi, I am at my wits end! I have come to you in desperation. I am infected with spyaxe and I have had millions of antispyware on my pc and I cant get rid of it.

I have come accross SpyZooka.com which guarantees 100% removal of all spyware or your money back. Has anyone heard of it?

Help would be very much appreciated.

tashi
2005-12-29, 23:37
Hi there.
If you have not asked for help at another site then please go here and follow instructions.
Before you post a log (http://forums.spybot.info/showthread.php?t=288)

Then post the hjt log in this thread so that someone can take a look at the system.

As to SpyZooka.
http://www.spywarewarrior.com/rogue_anti-spyware.htm#notes

Cheers.

Please do not start multiple topics for the same problem, the other two topics were removed.
We need to see the hjt log please, no need for other logs unless requested.

Thank you. :)

Firebird
2005-12-30, 00:02
I am currently following the instructions for the spyaxe removal and got to Ad-adware follow the instructions here which askes me

"6) When the scan has completed, click "Show Logfile". Copy/paste the complete log file in a thread of your own. Do not quarantine or remove anything at this time, just post a complete logfile. This sometimes takes 2-3 posts to get it all posted. You will know you are at the end when you see the "Summary of this scan" information has been posted".

am I doing the right thing or am I just chasing my tail?::(

Firebird
2005-12-30, 00:09
Logfile of HijackThis v1.99.1
Scan saved at 22:07:04, on 29/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\CConnect\CConnect.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\SpyZooka24\spyzooka.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ntlhome.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hp10E0.tmp
O3 - Toolbar: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - (no file)
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [SpyZooka] C:\Program Files\SpyZooka24\SpyZookaLdr.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: CorrectConnect.lnk = C:\Program Files\CConnect\CConnect.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135786105593
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver/racing/dodgespeedway/microsoft/wtinst.cab
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

tashi
2005-12-30, 00:11
Hi there, I can see why it became confusing as the link to freedomlist showed how to post an AAW log at that site.

However here we request that you follow the instructions for posting in this forum which is as follows:

J. Create a topic of your own (or a reply if you have an existing topic) and post the following logs:
The first HijackThis log
The contents of the C:\smitfiles.txt log
The Ewido Log.
The second HijackThis log

I will edit the topic that was posted earlier today so there will not be any more confusion.

Sorry about that. Let's just start with the HJT log.

Firebird
2005-12-30, 00:18
So I need do nothing more yet until someone comes back to me after looking at the Hjt log I have just posted?

Thanks so much for your help.

LonnyRJones
2005-12-30, 02:29
Hello Firebird

Download smitRem.exe (http://noahdfear.geekstogo.com/click%20counter/click.php?id=1) and save the file to your desktop. (By noahdfear.)
Double click on the file to extract it to it's own folder on the desktop.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Next, please reboot your computer in SafeMode by doing the following:
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
Instead of Windows loading as normal, a menu should appear
Select the first option, to run Windows in Safe Mode.


Start Hijackthis and place a check next to these items If there.
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hp10E0.tmp
O3 - Toolbar: (no name) - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - (no file)
O4 - HKCU\..\Run: [SpyZooka] C:\Program Files\SpyZooka24\SpyZookaLdr.exe
====================================
Hit fix checked and close Hijackthis.

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
Open Spybot check for and fix any problems found.
Open Ad-aware and do a full scan. Remove all it finds.

Run Ewido:

Click on scanner
Click on Complete System Scan and the scan will begin.
NOTE: During some scans with ewido it is finding cases of false positives.
You will need to step through the process of cleaning files one-by-one.
If ewido detects a file you KNOW to be legitimate, select none as the action.
DO NOT select "Perform action on all infections"
If you are unsure of any entry found select none for now.
When the scan is finished, click the Save report button at the bottom of the screen.
Save the report to your desktop
Close Ewido

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Restart back to a normal windows session
Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Get this free onlines scan and post the results
Kaspersky Lab - Free Online scan:
http://www.kaspersky.com/virusscanner
Click scan settings and place a check next to use [x]extended this database etc etc. Click ok.
Then choose: my computer: scan all your hard drives and mapped disks.
when finished click save as text and post that in your reply.

Post a new HijackThis Log, the contents of the smitfiles.txt log and the Ewido Log by using Add Reply.
Let us know if any problems persis

Firebird
2005-12-30, 16:29
Logfile of HijackThis v1.99.1
Scan saved at 14:26:29, on 30/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\CConnect\CConnect.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.ntlhome.com
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: CorrectConnect.lnk = C:\Program Files\CConnect\CConnect.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mov: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-24.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135786105593
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - http://www.wildtangent.com/install/wdriver/racing/dodgespeedway/microsoft/wtinst.cab
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Firebird
2005-12-30, 16:31
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Friday, December 30, 2005 14:23:43
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 30/12/2005
Kaspersky Anti-Virus database records: 168306
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 55564
Number of viruses found: 4
Number of infected objects: 15
Number of suspicious objects: 0
Duration of the scan process: 6763 sec

Infected Object Name - Virus Name
C:\Documents and Settings\Mike Bond\Desktop\Mijn Playplay.exe Infected: not-a-virus:Dialer.Win32.Dialxs.b
C:\Documents and Settings\Mike Bond\Local Settings\Temp\dfiTempA.exe Infected: not-a-virus:Dialer.Win32.Dialxs.b
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP712\A0077043.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077089.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077105.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077425.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077744.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077773.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP714\A0077942.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP714\A0077996.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP715\A0078039.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP715\A0078055.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP716\A0078099.tlb Infected: Trojan-Downloader.Win32.Zlob.dl
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP716\A0078100.exe Infected: Trojan-Downloader.Win32.Zlob.bu
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP716\A0078109.dll Infected: not-virus:Hoax.Win32.Renos.ak

Scan process completed.

Firebird
2005-12-30, 16:33
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 12:09:29, 30/12/2005
+ Report-Checksum: FAAF35AB

+ Scan result:

HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000EF1-0786-4633-87C6-1AA7A44296DA} -> Spyware.FavoriteMan : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75D2080B-4857-4B96-9B7D-732634FBD01F} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{79849612-A98F-45B8-95E9-4D13C7B6B35C} -> Spyware.Crazywinnings : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B195B3B3-8A05-11D3-97A4-0004ACA6948E} -> Spyware.HotBar : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7} -> Spyware.MoneyTree : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005\Software\Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
HKU\S-1-5-21-1974565712-4269483969-3991436212-1005_Classes\CLSID\{A2C8F6B1-7C2A-3D1C-A3C6-A1FDA113B43F} -> Downloader.SpyAxe : Cleaned with backup
[1600] C:\WINDOWS\system32\wbeconm.dll -> Downloader.SpyAxe : Cleaned with backup
C:\Documents and Settings\Kristy Bond\Cookies\kristy bond@cz3.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Kristy Bond\Cookies\kristy bond@cz6.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Kristy Bond\Cookies\kristy bond@cz7.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\IESkins -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\reports.txt -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOI -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOI\dynamic -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOI\static -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOL -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOL\dynamic -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\HostOL\static -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\1.sdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\ASPL1.dat -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\domains.txt -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\25466 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\28750 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\31919 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\33697 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\46021 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\48166 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\52335 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\53541 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\583049 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\73922 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\74576 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\77468 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\90008 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\TooltipXML\91589 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\dynamic\ustat -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\ads.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\business_promo.htm -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\components.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\default.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_categorize.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_comparison.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_explorer-Mails.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_fastutilities.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_favorites.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_Games.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_Hide.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_hotbarcom.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_Hotmail.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_hsskin.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_Mails.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_new.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_premium.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_searchfor.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_searchgo.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_weather.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Default_yellowpages.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_1000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_2000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_3000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bar.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar1.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar10.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar11.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar12.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar13.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar14.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar2.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar3.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar4.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar5.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar6.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar7.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar8.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_bbar9.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_logos.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_other.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_buttons_x.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\d_icons_weather.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\email-def-511724-9595.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\email-t1-bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\hotbar-premium-hotbar-premium.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\hotbar-premium.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\hotbar_promo.htm -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\icons2.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\keywords.idx -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\keywords1.dat -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\keywords_idx.idx -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\keywords_sdf.sdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\layout.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\linkpathlegal.txt -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\progress.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\s_icons_buttons.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\t2_bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\top7.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\Top7_theweb.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\1\tsd_bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2 -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\ads.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\business_promo.htm -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\components.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\default.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_categorize.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_comparison.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_explorer-Mails.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_fastutilities.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_favorites.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_Games.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_Hide.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_hotbarcom.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_Hotmail.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_hsskin.mnu -> Spyware.HotBar : Cleaned with backup

Firebird
2005-12-30, 16:34
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_Mails.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_new.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_premium.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_searchfor.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_searchgo.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_weather.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Default_yellowpages.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_1000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_2000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_3000.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bar.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar1.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar10.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar11.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar12.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar13.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar14.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar2.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar3.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar4.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar5.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar6.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar7.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar8.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_bbar9.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_logos.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_other.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_buttons_x.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\d_icons_weather.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\email-def-511724-9595.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\email-t1-bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\hotbar-premium-hotbar-premium.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\hotbar-premium.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\hotbar_promo.htm -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\icons2.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\keywords.idx -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\keywords1.dat -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\keywords_idx.idx -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\keywords_sdf.sdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\layout.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\linkpathlegal.txt -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\progress.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\s_icons_buttons.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\t2_bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\top7.cdf -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\Top7_theweb.mnu -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\2\tsd_bg.res -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\ads.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\business_promo.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\default.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_1000.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_2000.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_3000.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bar.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar1.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar10.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar11.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar12.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar13.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar14.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar2.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar3.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar4.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar5.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar6.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar7.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar8.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_bbar9.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_logos.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_other.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_buttons_x.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\d_icons_weather.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\email-t1-bg.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\hotbar-premium.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\hotbar_promo.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\icons2.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\keywords.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\keywords1.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\keywords_idx.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\keywords_sdf.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\layout.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\linkpathlegal.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\progress.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\samplegroups2.txt -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\samplegroups2.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\s_icons_buttons.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\t2_bg.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\top7.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Application Data\Hotbar\v3.0\Hotbar\static\DownLoad\tsd_bg.xip -> Spyware.HotBar : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@adorigin[1].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz11.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz3.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz5.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz6.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz7.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@cz8.clickzs[1].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@e-2dj6wfk4ejd5khp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@e-2dj6wjlyendzmlq.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@e-2dj6wjmiuoczsdp.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@hypertracker[2].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@vip.clickzs[2].txt -> Spyware.Cookie.Clickzs : Cleaned with backup
C:\Documents and Settings\Mike Bond\Cookies\mike bond@www.myaffiliateprogram[1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Mike Bond\Local Settings\Temp\dia8.exe -> Heuristic.Win32.Dialer : Cleaned with backup
C:\Program Files\Hijackthis\backups\backup-20051230-100242-901.dll -> Downloader.Zlob.dl : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\5FC28F46-0E36-41E2-9643-46A220\DC8509E2-A48D-4120-889D-88D30C -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\6B1C6AFB-0C77-4EC2-A565-811743\49C95824-2678-461E-917B-96CB25 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\731D47EA-3C1F-465D-B931-A8F81A\529C866F-AF19-4BE3-A22F-FB1C1F -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\ADA39990-5A04-47F2-BA21-3EB179\0DD0B56A-0FEB-41BA-A7FF-029B21 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\CDDFB6B5-3ACB-4B2C-8076-7F75AE\B65B2981-40F2-4F0C-A5D2-F99186 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\DA2DA6A6-8CB7-4DC9-A1D3-02525F\2229FEB6-ACF3-4163-BBE9-869552 -> Adware.Spyaxe : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\F1D22E8E-A6FB-44AE-AC1E-79E8E2\E1CC9477-5927-4E61-9857-5EF1BB -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077090.dll -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077091.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077626.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP713\A0077740.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP714\A0077786.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP715\A0078019.exe -> Adware.Spyaxe : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP716\A0078102.exe -> Downloader.Zlob.dl : Cleaned with backup
C:\System Volume Information\_restore{311E6A08-95AE-4983-A563-0B10CCED3453}\RP716\A0078103.exe -> Downloader.Zlob.bv : Cleaned with backup
C:\WINDOWS\system32\wbeconm.dll -> Downloader.SpyAxe : Cleaned with backup


::Report End

Firebird
2005-12-30, 16:40
smitRem log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: 30/12/2005
The current time is: 10:07:07.17

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!

spyaxe uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

1024 dir
msvol.tlb
mssearchnet.exe
ncompat.tlb
nvctrl.exe
mscornet.exe
hp***.tmp


~~~ Icons in System32 ~~~

ot.ico


~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 748 'explorer.exe'

Starting registry repairs

Deleting files


Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)


I think that is all you need. The annoying speech bubble has gone advising me that I was infected, thank god! What do I do with the Kaspersky results?

Thank you so much for your help.

LonnyRJones
2005-12-30, 17:04
Hi
Delete that hotbar folder
C:\Documents and Settings\Mike Bond\Application Data\Hotbar
The other's in the log can be addressed by turning off then on system restore

Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Then Reboot. < Dont skip that step.
Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.

What antivirus program do you use ?

Firebird
2005-12-30, 18:08
Done this although I could not find the application data/hotbar within the search but have delted a file within cookies which was a txt file that said hotbar under c:documents and settings/Mike Bond.

I am currently looking for new anti virus, I am using the zone alarm secuity suite on the 15 day free trial at present, would you be able to suggest what anti virus and anti spyware I need to purchase to stop all this happening again? Is there anything that stops them getting through in the first place?

I am now wary about using my credit cards and ebanking incase someone can see all the passwords and private details.

Your help is greatly appreciated!

LonnyRJones
2005-12-30, 18:51
Hi

Dont use search, open a folder and navigate to
C:\Documents and Settings\Mike Bond\Application Data\ and delete the Hotbar folder

zone alarm does have a free version if your intrested, uninstall the trial first if you decide to get it.

free programs
Install atleast a free anti virus and firewall program
Dont make the common mistake of installing more than one anti virus or firewall
AVG Anti-Virus-Free: http://www.grisoft.com/us/us_dwnl_free.php
AntiVir Personal Edition: http://www.free-av.com/
avast! 4 Home - Free antivirus software :
http://www.asw.cz/eng/free_virus_protectio.html
Understanding and Using Firewalls:
http://www.bleepingcomputer.com/forums/index.php?showtutorial=60
ZoneAlarm provide's a paid for and free version http://www.zonelabs.com/
http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za
Kerio Personal Firewall
For home users, Kerio Personal Firewall 4 is available in two flavors -
the full edition and the limited free edition.
http://www.kerio.com/us/kpf_download.html
Sygate free for personal/home http://soho.sygate.com/products/spf_standard.htm
outpost http://www.outpost.uk.com/download/outpost1.html

Firebird
2005-12-30, 21:31
I did have the free zone alarm for the firewall, however, I changed it when all this spyaxe happened. Would I be better paying for all in one protection like zone alarm security suite as it has the anti-spyware, or would the free ones do the job just as well?

LonnyRJones
2005-12-31, 06:31
Hi

I personaly believe a program dedicated to just spyware is better than those package deals, But i am not familur with ZA's other programs.
Firewalls and antivirus programs, If you have the choice yes the paid for version's are the ones to get.

LonnyRJones
2006-01-04, 07:50
Im Glad we could help
Since the problems are solved Im going to close the topic now, this keeps others with similar problems from posting there logs/question here, they should start a new topic.
If you should need to post another log for the same PC let me or Tashi know.