the online scan might have deleted some things but it crashed on me so im not sure.
here is the hijackthis log and the antispyware log:
Logfile of HijackThis v1.99.1
Scan saved at 10:51:10 AM, on 7/16/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DEVLDR16.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
C:\WINDOWS\START MENU\PROGRAMS\STARTUP\NNND.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\SNDSRVC.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCOMSERVER_2_5.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\WUAUCLT.EXE
C:\HJT\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [Symantec Core LC] C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\SYSTEM\VIDCTRL\VIDCTRL.EXE
O4 - HKLM\..\Run: [autoupdate] rundll32 C:\WINDOWS\SYSTEM\DATADX.DLL,SHStart
O4 - HKLM\..\Run: [dlylygu] c:\windows\system\dlylygu.exe
O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\jjjanl.exe reg_run
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
O4 - HKLM\..\RunServices: [NPFMonitor] C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - Startup: nnnd.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmwordtrans.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate Page into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: PDFtypewriter - {B5EE1724-E26C-4431-A8F3-96FC5FE55CA1} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com/tech...ActiveData.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} -
http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: Yahoo! Literati -
http://download.games.yahoo.com/game...ts/y/tt3_x.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} -
https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -
http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
Started Scanning
Files and Directories
Found 'A0007714.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008645.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008759.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008760.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008797.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008801.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008808.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008812.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008849.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008853.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008882.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008886.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008893.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008897.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0008942.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009085.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009089.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009097.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009101.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009108.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009112.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009120.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009124.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009133.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009137.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009202.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009206.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009214.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009218.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009227.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009231.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009297.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009301.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009308.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009312.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009352.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009356.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009408.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009412.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0005643.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009638.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009645.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0009723.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0010724.CPY' in 'c:\_RESTORE\TEMP'
Found 'A0010842.CPY' in 'c:\_RESTORE\TEMP'
Found '' in 'c:\WINDOWS\SYSTEM\FLEOK'
Found 'desktrf-fran-162813.exe' in 'c:\WINDOWS\SYSTEM\Cache'
Found 'bthdde.xml' in 'c:\WINDOWS\SYSTEM'
Found 'wcpsu.exe' in 'c:\WINDOWS\SYSTEM'
Found 'nsvsvc.exe' in 'c:\WINDOWS\SYSTEM\nsvsvc'
Found 'nsvs.dll' in 'c:\WINDOWS\SYSTEM\nsvsvc'
Found 'License.txt' in 'c:\WINDOWS\SYSTEM\nsvsvc'
Found 'BIINI.INF' in 'c:\WINDOWS\INF'
Found 'BELT.INF' in 'c:\WINDOWS\INF'
Found 'CERES.INF' in 'c:\WINDOWS\INF'
Found 'pav22.TMP' in 'c:\WINDOWS\TEMP'
Found 'pav24.TMP' in 'c:\WINDOWS\TEMP'
Found 'pav164.TMP' in 'c:\WINDOWS\TEMP'
Found 'pav40D5.TMP' in 'c:\WINDOWS\TEMP'
Found 'pav40E0.TMP' in 'c:\WINDOWS\TEMP'
Found 'pav4374.TMP' in 'c:\WINDOWS\TEMP'
Found 'wmv0104.dbd' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0204.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0504.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0904.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0412.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0106.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv1215.dbd' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv0315.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv1204.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv2007.dbd' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv1125.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv1920.dbd' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'wmv1909.ddx' in 'c:\WINDOWS\All Users\Application Data\nsv'
Found 'CERES.DLL' in 'c:\WINDOWS'
Found 'EECH1.bsx' in 'c:\WINDOWS\cfgmgr52'
Found 'Buddy.exe' in 'c:\WINDOWS'
Found 'tdtb.exe' in 'c:\WINDOWS'
Found '' in 'c:\Program Files\Media Access'
Found '' in 'c:\Program Files\Toolbar'
Found '' in 'c:\Program Files\MySearch'
Found '' in 'c:\Program Files\MySearch\bar'
Found 'data.bin' in 'c:\Program Files\Aprps'
Found 'backup-20050715-225328-231.dll' in 'c:\HJT\backups'
Programs in Memory
Found 'nsvsvc.exe' in 'C:\WINDOWS\SYSTEM\nsvsvc'
Internet URL Shortcuts
Found 'WeirdOnTheWeb.url' in 'C:\WINDOWS\Favorites\'
Internet Cookies
Found 'go.com' in 'Internet Explorer Cache'
Windows Registry
Found '' in 'SOFTWARE\E2G'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\GAIN Publishing'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\PrecisionTime'
Found '' in 'software\classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}'
Found '' in 'software\classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}\InprocServer32'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Control'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\InprocServer32'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus\1'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ProgID'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ToolboxBitmap32'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\TypeLib'
Found '' in 'software\classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Version'
Found '' in 'software\classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}'
Found '' in 'software\classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\ProxyStubClsid'
Found '' in 'software\classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\ProxyStubClsid32'
Found '' in 'software\classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\TypeLib'
Found '' in 'software\classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}'
Found '' in 'software\classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\ProxyStubClsid'
Found '' in 'software\classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\ProxyStubClsid32'
Found '' in 'software\classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\TypeLib'
Found '' in 'software\classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0'
Found '' in 'software\classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\0\win32'
Found '' in 'software\classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\FLAGS'
Found '' in 'software\classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\HELPDIR'
Found '' in 'software\classes\VCCPGDATAACCESS.PgDataAccessCtrl.1'
Found '' in 'software\classes\VCCPGDATAACCESS.PgDataAccessCtrl.1\CLSID'
Found '' in 'SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}'
Found '' in 'SOFTWARE\Classes\CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Control'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\InprocServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\MiscStatus\1'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\ToolboxBitmap32'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Version'
Found '' in 'SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}'
Found '' in 'SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}'
Found '' in 'SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{41700749-A109-4254-AF13-BE54011E8783}\TypeLib'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\HELPDIR'
Found '' in 'SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1'
Found '' in 'SOFTWARE\Classes\VCCPGDATAACCESS.PgDataAccessCtrl.1\CLSID'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\LocalServer32'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\ProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}\VersionIndependentProgID'
Found '' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\NumMethods'
Found '' in 'SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/VBouncer/INSTALL.LOG'
Found '' in 'SOFTWARE\ClickSpring'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\HELPDIR'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\FLAGS'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\0\win32'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj\CurVer'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj\CLSID'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj.1\CLSID'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj.1'
Found '' in 'SOFTWARE\Classes\CeresDll.CeresDllObj'
Found '' in 'Software\Ceres'
Found '' in 'Software\Dynamic Toolbar'
Found '' in 'SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}'
Found '' in 'SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}\TypeLib'
Found '' in 'SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}\ProxyStubClsid32'
Found '' in 'SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}\ProxyStubClsid'
Found '' in 'SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}'
Found 'ThreadingModel' in 'SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}\InProcServer32'
Found '' in 'SOFTWARE\Vendor\xml'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}'
Found '' in 'SOFTWARE\Classes\TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}\1.0\0'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}\1.1\0'
Found '' in 'SOFTWARE\Classes\TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}'
Found 'Version' in 'SOFTWARE\Classes\Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}\TypeLib'
Found '' in 'Software\PTech'
Found 'PluginLevel' in 'SYSTEM\CurrentControlSet\Control\Session Manager'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\Version'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\TypeLib'
Found '' in 'SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A}\ProgID'
Found '' in 'SOFTWARE\Mvu'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DisplayUtility'
Found '' in 'Software\Mvu'
Found 'Nsv' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}'
Found '' in 'SOFTWARE\Classes\CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}\Implemented Categories'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WAFAIE'
Found '' in 'TypeLib\{92DAF5C1-2135-4E0C-B7A0-259ABFCD3904}'
Found '' in 'Interface\{BB0D5ADC-028D-4185-9288-722DDCE2C757}'
Found '' in 'TypeLib\{2A7DB8D1-43BE-4AD3-A81E-9BB8C9D00073}'
Found '' in 'Interface\{2BB15D36-43BE-4743-A3A0-3308F4B1A610}'
Found '' in 'Interface\{41700749-A109-4254-AF13-BE54011E8783}'
Found '' in 'CLSID\{A8BD9566-9895-4FA3-918D-A51D4CD15865}'
Found '' in 'CLSID\{D0070620-1E72-42E7-A14C-3A255AD31839}'
Found '' in 'VCCPGDATAACCESS.PgDataAccessCtrl.1'
Found '' in 'CeresDll.CeresDllObj'
Found '' in 'CeresDll.CeresDllObj.1'
Found '' in 'CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212}'
Found '' in 'CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Found '' in 'Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA}'
Finished Scanning
Started Backup
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0104.dbd'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0204.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0504.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0904.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0412.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0106.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv1215.dbd'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv0315.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv1204.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv2007.dbd'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv1125.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv1920.dbd'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Unable to backup the item 'c:\WINDOWS\All Users\Application Data\nsv\wmv1909.ddx'. [SCANMODS] FCIAddFile failed. FCI Error=1, 'File not found'.
Finished Backup
Started Cleaning
Checking for 'c:\_RESTORE\TEMP\A0007714.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0007714.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0007714.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0007714.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008645.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008645.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008645.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008645.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008759.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008759.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008759.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008759.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008760.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008760.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008760.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008760.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008797.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008797.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008797.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008797.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008801.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008801.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008801.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008801.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008808.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008808.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008808.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008808.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008812.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008812.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008812.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008812.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008849.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008849.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008849.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008849.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008853.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008853.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008853.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008853.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008882.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008882.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008882.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008882.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008886.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008886.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008886.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008886.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008893.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008893.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008893.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008893.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008897.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008897.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008897.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008897.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0008942.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0008942.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0008942.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0008942.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009085.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009085.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009085.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009085.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009089.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009089.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009089.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009089.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009097.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009097.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009097.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009097.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009101.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009101.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009101.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009101.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009108.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009108.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009108.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009108.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009112.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009112.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009112.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009112.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009120.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009120.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009120.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009120.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009124.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009124.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009124.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009124.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009133.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009133.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009133.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009133.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009137.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009137.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009137.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009137.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009202.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009202.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009202.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009202.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009206.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009206.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009206.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009206.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009214.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009214.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009214.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009214.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009218.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009218.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009218.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009218.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009227.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009227.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009227.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009227.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009231.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009231.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009231.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009231.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009297.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009297.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009297.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009297.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009301.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009301.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009301.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009301.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009308.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009308.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009308.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009308.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009312.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009312.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009312.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009312.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009352.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009352.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009352.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009352.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009356.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009356.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009356.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009356.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009408.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009408.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009408.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009408.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009412.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009412.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009412.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009412.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0005643.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0005643.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0005643.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0005643.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009638.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009638.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009638.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009638.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009645.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009645.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009645.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009645.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0009723.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0009723.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0009723.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0009723.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0010724.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0010724.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0010724.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0010724.CPY' requires a reboot.
Checking for 'c:\_RESTORE\TEMP\A0010842.CPY' in shortcut areas.
Checking for 'c:\_RESTORE\TEMP\A0010842.CPY' in startup areas.
Cleaning 'c:\_RESTORE\TEMP\A0010842.CPY'
[SCANMODS] WARNING: Deletion of the file 'c:\_RESTORE\TEMP\A0010842.CPY' requires a reboot.
Checking for 'c:\WINDOWS\SYSTEM\FLEOK' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\FLEOK' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\FLEOK'
Checking for 'c:\WINDOWS\SYSTEM\Cache\desktrf-fran-162813.exe' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\Cache\desktrf-fran-162813.exe' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\Cache\desktrf-fran-162813.exe'
Checking for 'c:\WINDOWS\SYSTEM\bthdde.xml' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\bthdde.xml' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\bthdde.xml'
Checking for 'c:\WINDOWS\SYSTEM\wcpsu.exe' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\wcpsu.exe' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\wcpsu.exe'
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe'
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\nsvs.dll' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\nsvs.dll' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\nsvsvc\nsvs.dll'
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\License.txt' in shortcut areas.
Checking for 'c:\WINDOWS\SYSTEM\nsvsvc\License.txt' in startup areas.
Cleaning 'c:\WINDOWS\SYSTEM\nsvsvc\License.txt'
Checking for 'c:\WINDOWS\INF\BIINI.INF' in shortcut areas.
Checking for 'c:\WINDOWS\INF\BIINI.INF' in startup areas.
Cleaning 'c:\WINDOWS\INF\BIINI.INF'
Checking for 'c:\WINDOWS\INF\BELT.INF' in shortcut areas.
Checking for 'c:\WINDOWS\INF\BELT.INF' in startup areas.
Cleaning 'c:\WINDOWS\INF\BELT.INF'
Checking for 'c:\WINDOWS\INF\CERES.INF' in shortcut areas.
Checking for 'c:\WINDOWS\INF\CERES.INF' in startup areas.
Cleaning 'c:\WINDOWS\INF\CERES.INF'
Checking for 'c:\WINDOWS\TEMP\pav22.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav22.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav22.TMP'
Checking for 'c:\WINDOWS\TEMP\pav24.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav24.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav24.TMP'
Checking for 'c:\WINDOWS\TEMP\pav164.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav164.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav164.TMP'
Checking for 'c:\WINDOWS\TEMP\pav40D5.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav40D5.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav40D5.TMP'
Checking for 'c:\WINDOWS\TEMP\pav40E0.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav40E0.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav40E0.TMP'
Checking for 'c:\WINDOWS\TEMP\pav4374.TMP' in shortcut areas.
Checking for 'c:\WINDOWS\TEMP\pav4374.TMP' in startup areas.
Cleaning 'c:\WINDOWS\TEMP\pav4374.TMP'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0104.dbd' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0104.dbd' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0104.dbd'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0204.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0204.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0204.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0504.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0504.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0504.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0904.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0904.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0904.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0412.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0412.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0412.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0106.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0106.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0106.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1215.dbd' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1215.dbd' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv1215.dbd'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0315.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv0315.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv0315.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1204.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1204.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv1204.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv2007.dbd' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv2007.dbd' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv2007.dbd'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1125.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1125.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv1125.ddx'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1920.dbd' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1920.dbd' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv1920.dbd'
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1909.ddx' in shortcut areas.
Checking for 'c:\WINDOWS\All Users\Application Data\nsv\wmv1909.ddx' in startup areas.
Cleaning 'c:\WINDOWS\All Users\Application Data\nsv\wmv1909.ddx'
Checking for 'c:\WINDOWS\CERES.DLL' in shortcut areas.
Checking for 'c:\WINDOWS\CERES.DLL' in startup areas.
Cleaning 'c:\WINDOWS\CERES.DLL'
[SCANMODS] WARNING: Deletion of the file 'c:\WINDOWS\CERES.DLL' requires a reboot.
Checking for 'c:\WINDOWS\cfgmgr52\EECH1.bsx' in shortcut areas.
Checking for 'c:\WINDOWS\cfgmgr52\EECH1.bsx' in startup areas.
Cleaning 'c:\WINDOWS\cfgmgr52\EECH1.bsx'
Checking for 'c:\WINDOWS\Buddy.exe' in shortcut areas.
Checking for 'c:\WINDOWS\Buddy.exe' in startup areas.
Cleaning 'c:\WINDOWS\Buddy.exe'
Checking for 'c:\WINDOWS\tdtb.exe' in shortcut areas.
Checking for 'c:\WINDOWS\tdtb.exe' in startup areas.
Cleaning 'c:\WINDOWS\tdtb.exe'
Checking for 'c:\Program Files\Media Access' in shortcut areas.
Checking for 'c:\Program Files\Media Access' in startup areas.
Cleaning 'c:\Program Files\Media Access'
Checking for 'c:\Program Files\Toolbar' in shortcut areas.
Checking for 'c:\Program Files\Toolbar' in startup areas.
Cleaning 'c:\Program Files\Toolbar'
Checking for 'c:\Program Files\Toolbar\tbps.dat' in shortcut areas.
Checking for 'c:\Program Files\Toolbar\tbps.dat' in startup areas.
Cleaning 'c:\Program Files\Toolbar\tbps.dat'
Checking for 'c:\Program Files\MySearch' in shortcut areas.
Checking for 'c:\Program Files\MySearch' in startup areas.
Cleaning 'c:\Program Files\MySearch'
Checking for 'c:\Program Files\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS' in shortcut areas.
Checking for 'c:\Program Files\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS' in startup areas.
Cleaning 'c:\Program Files\MySearch\bar\1.bin\MYSEARCHPLUGINPROXY.CLASS'
Checking for 'c:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL' in shortcut areas.
Checking for 'c:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL' in startup areas.
Cleaning 'c:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL'
Checking for 'c:\Program Files\MySearch\bar\1.bin\S42NS.EXE' in shortcut areas.
Checking for 'c:\Program Files\MySearch\bar\1.bin\S42NS.EXE' in startup areas.
Cleaning 'c:\Program Files\MySearch\bar\1.bin\S42NS.EXE'
Checking for 'c:\Program Files\MySearch\bar\1.bin\S4BAR.DLL' in shortcut areas.
Checking for 'c:\Program Files\MySearch\bar\1.bin\S4BAR.DLL' in startup areas.
Cleaning 'c:\Program Files\MySearch\bar\1.bin\S4BAR.DLL'
Checking for 'c:\Program Files\MySearch\bar' in shortcut areas.
Checking for 'c:\Program Files\MySearch\bar' in startup areas.
Cleaning 'c:\Program Files\MySearch\bar'
[SCANMODS] The file 'c:\Program Files\MySearch\bar' was not found. Most likely already cleaned by another scanner module.
Checking for 'c:\Program Files\Aprps\data.bin' in shortcut areas.
Checking for 'c:\Program Files\Aprps\data.bin' in startup areas.
Cleaning 'c:\Program Files\Aprps\data.bin'
Checking for 'c:\HJT\backups\backup-20050715-225328-231.dll' in shortcut areas.
Checking for 'c:\HJT\backups\backup-20050715-225328-231.dll' in startup areas.
Cleaning 'c:\HJT\backups\backup-20050715-225328-231.dll'
Checking for 'C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe' in shortcut areas.
Checking for 'C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe' in startup areas.
Cleaning 'C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe'
[SCANMODS] The file 'C:\WINDOWS\SYSTEM\nsvsvc\nsvsvc.exe' was not found. Most likely already cleaned by another scanner module.
Unable to delete registry value 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Nsv'. Error=2.
Finished Cleaning