Vicki
2006-06-06, 06:27
I have followed the instructions posted by Tashi on 2006-04-26 to get rid of this fake anti spyware popup but it still continues. Worse it has somehow affected my virus protection (Norton) as I can not enable it. Here are the logs that you requested. Thank you so-oo much for your help. Vicki
SmitFraudFix v2.53
Scan done at 23:26:16.96, Wed 05/31/2006
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\uniq Deleted
C:\winstall.exe Deleted
C:\WINDOWS\warnhp.html Deleted
C:\WINDOWS\system32\dlh9jkdq?.exe Deleted
C:\WINDOWS\system32\oleext.dll Deleted
C:\WINDOWS\system32\reger.exe Deleted
C:\WINDOWS\system32\TheMatrixHasYou.exe Deleted
C:\WINDOWS\system32\winbl32.dll Deleted
C:\WINDOWS\system32\winmuse.exe Deleted
C:\Documents and Settings\Owner\Application Data\Install.dat Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Reboot
C:\WINDOWS\system32\winsrv32.exe Deleted
»»»»»»»»»»»»»»»»»»»»»»»» End
Ewido-
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 12:59:56 AM, 6/1/2006
+ Report-Checksum: 3239D681
+ Scan result:
HKLM\SOFTWARE\180solutions -> Adware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\180solutions\msbb -> Adware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\SysWebTelecom.SysWebTelecom -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\SysWebTelecom.SysWebTelecom\CurVer -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CLSID -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute\CLSID -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute\CurVer -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute.1 -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHomeSelect Agent -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\surebar -> Adware.SureBar : Cleaned with backup
HKLM\SOFTWARE\twaintec -> Adware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\VGroup\SAHAgent -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\VGroup\SAHPopup -> Adware.SAHA : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38535 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536\Objects -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536\Objects\5 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38537 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538\Objects -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538\Objects\5 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38539 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Stat -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\RX Toolbar -> Adware.RXToolbar : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\surebar -> Adware.SureBar : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\surebar\Script -> Adware.SureBar : Cleaned with backup
[468] C:\WINDOWS\System32\lsp.dll -> Adware.Sahat : Cleaned with backup
C:\awuakqbw.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-3c0efa2b-730c3530.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Error during cleaning
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-588fab9e-48d0a73e.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-1fac6572-30ad781c.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-487b52a0-1077147f.zip/BlackBox.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-487b52a0-1077147f.zip/Beyond.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-6af29691-225917f0.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-16e6c0b4-5a59af2a.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\nj.exe -> Not-A-Virus.Hoax.Win32.Renos.bb : Cleaned with backup
C:\Program Files\Altnet -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab -> Adware.Altnet : Cleaned with backup
C:\Program Files\ClockSync -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen\dl_ad.gif -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen\index.htm -> Adware.WhenU : Cleaned with backup
C:\Program Files\Common Files\uctatnqq\saqemrlb\lubfrrpc.exe -> Adware.Gator : Cleaned with backup
C:\Program Files\Common Files\uctatnqq\ubceoldfrt\robdrqnls.exe -> Adware.Gator : Cleaned with backup
C:\Program Files\IncrediFind -> Adware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO -> Adware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO\date.txt -> Adware.Incredifind : Cleaned with backup
C:\Program Files\INSTAFINK -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache\instafinktb0302.cfg -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache\NewCfg -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Uninstall.exe -> Adware.404Search : Cleaned with backup
C:\Program Files\Internet Explorer\loader.exe -> Downloader.Agent.akj : Cleaned with backup
C:\Program Files\Internet Explorer\lock.exe -> Downloader.Delf.ang : Cleaned with backup
C:\Program Files\Internet Explorer\update.exe -> Adware.BHO : Cleaned with backup
C:\Program Files\VVSN\VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\bsx32 -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CCS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\KanFinance3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\imloader.exe -> Not-A-Virus.Downloader.Win32.ImLoader.c : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\lsp_.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WEBInstaller.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\SAHUninstall.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\lsp.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\msbb.exe -> Adware.180Solutions : Cleaned with backup
C:\WINDOWS\system32\msbb321.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\pxdcexuv.mhn -> Hijacker.Small.js : Cleaned with backup
C:\WINDOWS\system32\SahAgent.exe -> Adware.ShopAtHome : Cleaned with backup
C:\WINDOWS\system32\sahagent1019.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\SahHtml.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\zwnhpzne.exe -> Trojan.Small : Cleaned with backup
C:\WINDOWS\Temp\Altnet -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Atl.dll -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\dmfiles.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\DMinfo3.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\dminstall7.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\msvcirt.dll -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\pmexe.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\pminstall.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Setup.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Setup.exe -> Adware.Altnet : Cleaned with backup
::Report End
SmitFraudFix v2.53
Scan done at 23:26:16.96, Wed 05/31/2006
Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\uniq Deleted
C:\winstall.exe Deleted
C:\WINDOWS\warnhp.html Deleted
C:\WINDOWS\system32\dlh9jkdq?.exe Deleted
C:\WINDOWS\system32\oleext.dll Deleted
C:\WINDOWS\system32\reger.exe Deleted
C:\WINDOWS\system32\TheMatrixHasYou.exe Deleted
C:\WINDOWS\system32\winbl32.dll Deleted
C:\WINDOWS\system32\winmuse.exe Deleted
C:\Documents and Settings\Owner\Application Data\Install.dat Deleted
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Reboot
C:\WINDOWS\system32\winsrv32.exe Deleted
»»»»»»»»»»»»»»»»»»»»»»»» End
Ewido-
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 12:59:56 AM, 6/1/2006
+ Report-Checksum: 3239D681
+ Scan result:
HKLM\SOFTWARE\180solutions -> Adware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\180solutions\msbb -> Adware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM25.ADM25.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\ADM4.ADM4.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\SysWebTelecom.SysWebTelecom -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\SysWebTelecom.SysWebTelecom\CurVer -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CLSID -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CurVer -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\TopSearch.TSLink.1 -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band.1 -> Adware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute\CLSID -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute\CurVer -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Classes\WEBInstaller.execute.1 -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopAtHomeSelect Agent -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\surebar -> Adware.SureBar : Cleaned with backup
HKLM\SOFTWARE\twaintec -> Adware.BetterInternet : Cleaned with backup
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\VGroup\SAHAgent -> Adware.SAHA : Cleaned with backup
HKLM\SOFTWARE\VGroup\SAHPopup -> Adware.SAHA : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38535 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536\Objects -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38536\Objects\5 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38537 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538\Objects -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38538\Objects\5 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Reports\38539 -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\INSTAFINK\Stat -> Adware.InstaFinder : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp\Config -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\RX Toolbar -> Adware.RXToolbar : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\surebar -> Adware.SureBar : Cleaned with backup
HKU\S-1-5-21-1750992869-2818318449-903111354-1003\Software\surebar\Script -> Adware.SureBar : Cleaned with backup
[468] C:\WINDOWS\System32\lsp.dll -> Adware.Sahat : Cleaned with backup
C:\awuakqbw.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-3c0efa2b-730c3530.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Error during cleaning
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-588fab9e-48d0a73e.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arc.zip-1fac6572-30ad781c.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-487b52a0-1077147f.zip/BlackBox.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-487b52a0-1077147f.zip/Beyond.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-6af29691-225917f0.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-16e6c0b4-5a59af2a.zip/Gummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup
C:\nj.exe -> Not-A-Virus.Hoax.Win32.Renos.bb : Cleaned with backup
C:\Program Files\Altnet -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab -> Adware.Altnet : Cleaned with backup
C:\Program Files\Altnet\My Altnet Shares\Bullguard Protection\plugins.cab.cab -> Adware.Altnet : Cleaned with backup
C:\Program Files\ClockSync -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen\dl_ad.gif -> Adware.WhenU : Cleaned with backup
C:\Program Files\ClockSync\screen\index.htm -> Adware.WhenU : Cleaned with backup
C:\Program Files\Common Files\uctatnqq\saqemrlb\lubfrrpc.exe -> Adware.Gator : Cleaned with backup
C:\Program Files\Common Files\uctatnqq\ubceoldfrt\robdrqnls.exe -> Adware.Gator : Cleaned with backup
C:\Program Files\IncrediFind -> Adware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO -> Adware.Incredifind : Cleaned with backup
C:\Program Files\IncrediFind\BHO\date.txt -> Adware.Incredifind : Cleaned with backup
C:\Program Files\INSTAFINK -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache\instafinktb0302.cfg -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Cache\NewCfg -> Adware.404Search : Cleaned with backup
C:\Program Files\INSTAFINK\Uninstall.exe -> Adware.404Search : Cleaned with backup
C:\Program Files\Internet Explorer\loader.exe -> Downloader.Agent.akj : Cleaned with backup
C:\Program Files\Internet Explorer\lock.exe -> Downloader.Delf.ang : Cleaned with backup
C:\Program Files\Internet Explorer\update.exe -> Adware.BHO : Cleaned with backup
C:\Program Files\VVSN\VVSN.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\bsx32 -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\ADVC3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BID1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\BingoRoom1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CARS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CASH2.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\CCS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\DEBT1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\INK1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\KanFinance3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\MORT1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\OPPS1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\SPZ3.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\TMP1.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\bsx32\XTFL2.bsx -> Adware.BookedSpace : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\imloader.exe -> Not-A-Virus.Downloader.Win32.ImLoader.c : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\lsp_.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\SAHAgent_.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WEBInstaller.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\SAHUninstall.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\lsp.dll -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\msbb.exe -> Adware.180Solutions : Cleaned with backup
C:\WINDOWS\system32\msbb321.dll -> Adware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\pxdcexuv.mhn -> Hijacker.Small.js : Cleaned with backup
C:\WINDOWS\system32\SahAgent.exe -> Adware.ShopAtHome : Cleaned with backup
C:\WINDOWS\system32\sahagent1019.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\SahHtml.exe -> Adware.Sahat : Cleaned with backup
C:\WINDOWS\system32\zwnhpzne.exe -> Trojan.Small : Cleaned with backup
C:\WINDOWS\Temp\Altnet -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Atl.dll -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\dmfiles.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\DMinfo3.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\dminstall7.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\msvcirt.dll -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\pmexe.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\pminstall.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Setup.cab -> Adware.Altnet : Cleaned with backup
C:\WINDOWS\Temp\Altnet\Setup.exe -> Adware.Altnet : Cleaned with backup
::Report End