Tech Support banner

Status
Not open for further replies.
1 - 14 of 14 Posts

·
Registered
Joined
·
10 Posts
Discussion Starter #1
i have uninstalled morpheus as you asked... here is a recap of my problem

I have been struggling with this for a few days and i cant figure it out. any help would be greatly appreciated.
i have mulltiple problems which seem to have started at the same time. the only program i can recall installing around that time was yahoo messenger.
problems include: ie6 wont open any page (hourglass never goes away), trillian never opens, mozilla opens and then goes to "not responding", i cant sync my pda (dell axim running a windows environment) (also goes to not responding). when i try to shut down or restart the sequence gets stuck on "saving your settings".
programs that are ok: outlook can pull down all my mail (and send), and i can surf the net with mozilla
i have run spy bot, and ad-aware using the custom settings you suggest.
i cant run any of the online spyware/virus checkers you suggest because they all require ie as the browser
i have run hijackthis and hijackthis analyzer the following are the logs


Logfile of HijackThis v1.99.1
Scan saved at 8:44:41 PM, on 9/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\symlcsvc.exe
C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
C:\WINDOWS\System32\vmnetdhcp.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CloneCD\ElbyCheck.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DynSite\DynSite.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Shannon\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net
F0 - system.ini: Shell=Explorer.exe c:\windows\system32\setup.exe
F1 - win.ini: run=c:\windows\system32\setup.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy 1.1\SpyBotSD.exe" /autoclose /waitstart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Win32D] c:\windows\system32\setup.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [DynSite] C:\Program Files\DynSite\DynSite.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: PowerReg Scheduler.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra 'Tools' menuitem: LifeFX Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
O23 - Service: APC PBE Server (APCPBEServer) - Unknown owner - C:\Program Files\APC\PowerChute Business Edition\server\pbeserver.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec - C:\WINDOWS\System32\symlcsvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - Unknown owner - C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\System32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - Unknown owner - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)




====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 8/4/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 8:44:41 PM, on 9/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
C:\WINDOWS\System32\symlcsvc.exe
C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
C:\WINDOWS\System32\vmnetdhcp.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\CloneCD\ElbyCheck.exe
C:\Program Files\DynSite\DynSite.exe
C:\Documents and Settings\Shannon\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net
F0 - system.ini: Shell=Explorer.exe c:\windows\system32\setup.exe
F1 - win.ini: run=c:\windows\system32\setup.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll (file missing)
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy 1.1\SpyBotSD.exe" /autoclose /waitstart
O4 - HKLM\..\Run: [Win32D] c:\windows\system32\setup.exe
O4 - HKCU\..\Run: [DynSite] C:\Program Files\DynSite\DynSite.exe
O4 - Startup: PowerReg Scheduler.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra 'Tools' menuitem: LifeFX Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
O23 - Service: APC PBE Server (APCPBEServer) - Unknown owner - C:\Program Files\APC\PowerChute Business Edition\server\pbeserver.exe (file missing)
O23 - Service: Symantec Core LC - Symantec - C:\WINDOWS\System32\symlcsvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - Unknown owner - C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\System32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - Unknown owner - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)


End of KRC HijackThis Analyzer Log.
====================================================================
 

·
Registered
Joined
·
10 Posts
Discussion Starter #2
adobe acrobat dies too

ps....
i just discovered when trying to open a pdf file with mozilla both adobe acrobat and mozilla die out (not responding)
the fun continues
 

·
Premium Member
Joined
·
14,311 Posts
I will ask you to download a program...if you still have problems going online to download it, try getting it from another computer and burn it on a CD to copy over to this computer.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually.

Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Don't run it yet.

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work.

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.

Now open Ewido and do a scan on your system.

* Click on scanner
* Click on Complete System Scan and the scan will begin.
* NOTE: During some scans with Ewido it is finding cases of false positives.
o You will need to step through the process of cleaning files one-by-one.
o If Ewido detects a file you KNOW to be legitimate, select none as the action.
o Do NOT select 'Perform action on all infections'
o If you are unsure of any entry found, select none for now as the action.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

F0 - system.ini: Shell=Explorer.exe c:\windows\system32\setup.exe
F1 - win.ini: run=c:\windows\system32\setup.exe
O4 - HKLM\..\Run: [Win32D] c:\windows\system32\setup.exe
O4 - Startup: PowerReg Scheduler.exe


Locate and delete the following:

c:\windows\system32\setup.exe

Restart your computer. Post the logs for HijackThis and Ewido.F0 - system.ini: Shell=Explorer.exe c:\windows\system32\setup.exe
 

·
Registered
Joined
·
10 Posts
Discussion Starter #4
followed instructions, still not working

hi, i followed your instructions. ewido cleaned 110 spyware programs and i found 3 of the 4 entries to remove with hijackthis. here are the ewido and hijack reports. (hijackthis log is post removal of entries)

Logfile of HijackThis v1.99.1
Scan saved at 1:05:55 AM, on 9/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy 1.1\SpyBotSD.exe" /autoclose /waitstart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra 'Tools' menuitem: LifeFX Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
O23 - Service: APC PBE Server (APCPBEServer) - Unknown owner - C:\Program Files\APC\PowerChute Business Edition\server\pbeserver.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec - C:\WINDOWS\System32\symlcsvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - Unknown owner - C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\System32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - Unknown owner - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)


--------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 1:02:47 AM, 9/19/2005
+ Report-Checksum: AE8C5A87

+ Scan result:

HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{51958167-D5E3-11D1-AA42-0000E842E40A} -> Spyware.BrilliantDigital : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{51958168-D5E3-11D1-AA42-0000E842E40A} -> Spyware.BrilliantDigital : Cleaned with backup
HKLM\SOFTWARE\iefeatures -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\iefeatures\KeyWord -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\system32\chktrust.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Shannon\Local Settings\Temp\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Shannon\Local Settings\Temp\Cookies\[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][2].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\s[email protected][1].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][4].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][2].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][2].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][1].txt -> Spyware.Cookie.Ysbweb : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Shannon\Cookies\[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Shannon\Application Data\Mozilla\Profiles\default\tppj07gh.slt\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Shannon\Application Data\Phoenix\Profiles\default\lgsvrmaw.slt\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom.zip/[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc.zip/[email protected][2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\BFast.zip/[email protected][2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Clop.zip/[email protected][1].txt -> Spyware.Cookie.Lop : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\CommonName.zip/SaveNowInst.exe/SaveNow.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\CommonName.zip/SaveNowInst.exe/SaveNow.exe -> Adware.SaveNow : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\CoreMetrics.zip/[email protected][2].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\CoreMetrics1.zip/[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\DoubleClick.zip/[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick.zip/[email protected][4].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick1.zip/[email protected][3].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick2.zip/[email protected][6].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick3.zip/[email protected][2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick4.zip/[email protected][1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox1.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox2.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox3.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox4.zip/[email protected][3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox5.zip/[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox6.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox7.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox8.zip/[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox9.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox10.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox11.zip/[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox12.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitsLink.zip/[email protected][2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\MediaPlex.zip/[email protected][1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\MediaPlex1.zip/[email protected][2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\ValueClick.zip/[email protected][3].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\ValueClick1.zip/[email protected][2].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc1.zip/[email protected][2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\BFast1.zip/[email protected][2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\CoreMetrics2.zip/[email protected][2].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\DoubleClick1.zip/[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox13.zip/[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox14.zip/[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox15.zip/[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\MediaPlex2.zip/[email protected][1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\ValueClick2.zip/[email protected][1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\System Volume Information\_restore{B8669E7B-8E95-4775-A4AF-9C8A5ADF8EA6}\RP598\A0064909.dll -> Spyware.TopSearch : Cleaned with backup


::Report End


thanks for your help
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Good work! What is the condition of your system now, please?

Can you access the internet on this system? Your answers will dictate the next approach.
 

·
Registered
Joined
·
10 Posts
Discussion Starter #6
faster response, but same problems

i am having the same problems, although i have noticed the speed of the computer is faster.
problems include
- ie6 will not load any webpage; also happened in safe mode
-trillian will not start
- adobe acrobat will not start
-cannot sync pda to computer
-when shutting down or restarting system gets stuck at "saving your settings"; although this did not happen in safe mode
- i can still access internet through mozilla and outlook is working fine

i hope you might have some ideas to try. thanks
here is the latest hijack this report
Logfile of HijackThis v1.99.1
Scan saved at 5:59:09 PM, on 9/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\symlcsvc.exe
C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
C:\WINDOWS\System32\vmnetdhcp.exe
C:\WINDOWS\system32\vmnat.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CloneCD\ElbyCheck.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\DynSite\DynSite.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Documents and Settings\Shannon\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bellsouth.net
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [TotalRecorderScheduler] C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy 1.1\SpyBotSD.exe" /autoclose /waitstart
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [DynSite] C:\Program Files\DynSite\DynSite.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: PowerReg Scheduler.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra 'Tools' menuitem: LifeFX Facemail - {E88D3D6B-BA62-11D4-A211-00B0D021F6DD} - C:\Program Files\LifeFX\LifeFXtb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
O16 - DPF: cpcScanner - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
O23 - Service: APC PBE Server (APCPBEServer) - Unknown owner - C:\Program Files\APC\PowerChute Business Edition\server\pbeserver.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Symantec - C:\WINDOWS\System32\symlcsvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - Unknown owner - C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\System32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - Unknown owner - C:\WINDOWS\system32\vmnat.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\ORL\VNC\WinVNC.exe" -service (file missing)
 

·
Registered
Joined
·
10 Posts
Discussion Starter #7
please dont forget about me

just reposting because it has been more than 24hrs. i still cant figure this out.
thanks
 

·
TSF Security Manager, Emeritus
Joined
·
42,837 Posts
Hello miamifly,

Thank you for your patience. Please use another computer to download these two programs to a disc to bring to the infected PC.

Download StartDreck http://www.greyknight17.com/spy/StartDreck.zip

Unzip to its own folder and start the program:
Press 'Config'
Press 'mark all'

Uncheck the following boxes only:
System/Running Process -> List Modules
System/Drivers -> NT Services
System/Drivers -> NT Kernel- and FS-drivers
Press 'OK'

Press 'Save' and select the location to save the log file (default is the same folder as the application)

Post the log in this thread.

Please empty any Quarantine folder in your antivirus program and purge all recovery items in the Spybot program (if you use it) before running this tool.

Download the Mwav virus checker at http://www.mwti.net/products/mwav/mwav.asp (Use Link 3)

1. Save it to a folder.
2. Reboot into Safe Mode.
3. Double click the Mwav.exe file. This is a stand alone tool and NOT just a virus checker......so it won't install anything.
4. Select all local drives, scan all files, and press SCAN. When it is completed, anything found will be displayed in the lower pane.
5. In the Virus Log Information Pane......
Left click and highlight all the information in the Lower pane --- Use CTRL C on your keyboard to copy everything found in the lower pane and save it to a notepad file
*Note* If prompted that a virus was found and you need to purchase the product to remove the malware, just close out the prompt and let it continue scanning. We are not going to use this to remove anything...but to ID the bad files.

Once you copy that to a Notepad file...highlight the text and copy it here.
 

·
Registered
Joined
·
10 Posts
Discussion Starter #9
new update

here is the result of the startdreck scan

StartDreck (build 2.1.7 public stable) - 2005-09-23 @ 13:45:59 (GMT -04:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 2)
Internet Explorer: 6.0.2900.2180
Logged in as Shannon at ONE

»Registry
»Run Keys
»Current User
»Run
*DynSite=C:\Program Files\DynSite\DynSite.exe
*H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
»RunOnce
»Default User
»Run
»RunOnce
*RunNarrator=Narrator.exe
»Local Machine
»Run
*WinVNC="C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
*TotalRecorderScheduler=C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
*CloneCDElbyCDFL="C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL
*C-Media Mixer=Mixer.exe /startup
*NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
*SpybotSnD="C:\Program Files\Spybot - Search & Destroy 1.1\SpyBotSD.exe" /autoclose /waitstart
*ccApp="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
*NAV CfgWiz=C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
*TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
*QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
*vptray=C:\PROGRA~1\SYMANT~1\VPTray.exe
*WinampAgent="C:\Program Files\Winamp\winampa.exe"
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»File Associations (CR)
+.bat
*batfile="%1" %*
+.com
*comfile="%1" %*
+.disabled
*SpybotSD.DisabledFile="C:\Program Files\Spybot - Search & Destroy 1.1\blindman.exe" %1
+.exe
*exefile="%1" %*
+.hta
*htafile=C:\WINDOWS\System32\mshta.exe "%1" %*
+.htm
*htmlfile="C:\Program Files\Internet Explorer\iexplore.exe" -nohome
+.html
*htmlfile="C:\Program Files\Internet Explorer\iexplore.exe" -nohome
+.js
*JSFile="C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe" "%1"
+.jse
*JSEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.pif
*piffile="%1" %*
+.reg
*regfile=regedit.exe "%1"
+.txt
*txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1
+.vbs
*VBSFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.vbe
*VBEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsh
*WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsf
*WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.lnk
`lnkfile= [key or value does not exist]
»Active Setup (LM)
+Internet Explorer/>{26923b43-4d38-484f-9b9e-de460746276c}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
+Browser Customizations/>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS
*StubPath=RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
+Outlook Express/>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
+Themes Setup/{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
*StubPath=%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
+Microsoft Outlook Express 6/{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
+NetMeeting 3.01/{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
+Internet Explorer/{4b218e3e-bc98-4770-93d3-2731b9329278}
*StubPath=%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
+Windows Messenger 4.7/{5945c046-1e7d-11d1-bc44-00c04fd912be}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
+Microsoft Windows Media Player/{6BF52A52-394A-11d3-B153-00C04F79FAA6}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub
+Address Book 6/{7790769C-0471-11d2-AF11-00C04FA35D02}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
+Windows Desktop Update/{89820200-ECBD-11cf-8B85-00AA005B4340}
*StubPath=regsvr32.exe /s /n /i:U shell32.dll
+Internet Explorer 6/{89820200-ECBD-11cf-8B85-00AA005B4383}
*StubPath=%SystemRoot%\system32\ie4uinit.exe
»Browser Helper Objects (LM)
*{53707962-6F74-2D53-2644-206D7942484F}
`InprocServer32=C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll
*Navbho.CNavExtBho.1/{BDF3E430-B101-42AD-A544-FADC6B084872}
`InprocServer32=C:\Program Files\Norton AntiVirus\NavShExt.dll
»Internet Explorer
»Current User
*Local Page=C:\WINDOWS\system32\blank.htm
*Search Page=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
*Start Page=http://www.bellsouth.net
*Window Title=
+SearchUrl
*provider=
»Default User
»Local Machine
*Local Page=%SystemRoot%\system32\blank.htm
*Start Page=about:blank
*CustomizeSearch=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
*SearchAssistant=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
»ShellServiceObjectDelayLoad (LM)
*PostBootReminder={7849596a-48ea-486e-8937-a2a3009f31a9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*CDBurn={fbeb8a05-beee-4442-804e-409d6c4515e9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
`InprocServer32=%SystemRoot%\System32\webcheck.dll
*SysTray={35CEC8A3-2BE6-11D2-8773-92E220524153}
`InprocServer32=C:\WINDOWS\System32\stobject.dll
»Special NT Values
»Current User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Default User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Local Machine
*AppInit_DLLs=
*SHELL=Explorer.exe
*Userinit=C:\WINDOWS\system32\userinit.exe,
»Files
»Autostart Folders
»Current User
*C:\Documents and Settings\Shannon\Start Menu\Programs\Internet\Startup\desktop.ini
*C:\Documents and Settings\Shannon\Start Menu\Programs\Internet\Startup\PowerReg Scheduler.exe
»Default User
*C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\desktop.ini
»Local Machine
*C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
»INI-Files
»WIN.INI\[windows]
*LOAD=
*RUN=
»SYSTEM.INI\[boot]
*SHELL=Explorer.exe
»Text Files
*C:\boot.ini
`[boot loader]
`timeout=30
`default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
`[operating systems]
`multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
*C:\msdos.sys
*C:\config.sys
*C:\WINDOWS\system32\config.nt
`dos=high, umb
`device=%SystemRoot%\system32\himem.sys
`files=40
*C:\autoexec.bat
*C:\WINDOWS\system32\autoexec.nt
`@echo off
`lh %SystemRoot%\system32\mscdexnt.exe
`lh %SystemRoot%\system32\redir
`lh %SystemRoot%\system32\dosx
`SET BLASTER=A220 I5 D1 P330 T3
*C:\WINDOWS\wininit.ini
`[rename]
`C:\WINDOWS\SYSTEM32\DRIVERS\CMAUDIO.OLD=C:\WINDOWS\SYSTEM32\DRIVERS\CMAUDIO.SYS
`C:\WINDOWS\SYSTEM32\CMprop.OLD=C:\WINDOWS\SYSTEM32\CMprop.DLL
`C:\WINDOWS\SYSTEM\CRLDS3D.OLD=C:\WINDOWS\SYSTEM\CRLDS3D.DLL
`NUL=InitTermMutex2ac0
`NUL=C:\WINDOWS\downlo~1\ymsgrins.exe
*C:\WINDOWS\system32\drivers\etc\hosts
`127.0.0.1 www.altnetp2p.com
`127.0.0.1 www.bonzi.com
`127.0.0.1 www.brilliantdigital.com
`127.0.0.1 www.b3d.com
`127.0.0.1 ad.dk.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.beguide.net
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.exhedra.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 afservant.guj.de
`127.0.0.1 ant.guj.de
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.de
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerads.de
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.looksmart.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 exchange-it.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 gm.preferences.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 rd.yahoo.com
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 secserv.imgis.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 sview.avenuea.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.eads.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.win24.de
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 pop3.norton.antivirus
`127.0.0.1 pop3.spa.norton.antivirus
`127.0.0.1 ad.dk.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.beguide.net
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.exhedra.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 afservant.guj.de
`127.0.0.1 ant.guj.de
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.de
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerads.de
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.looksmart.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 exchange-it.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 gm.preferences.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 rd.yahoo.com
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 secserv.imgis.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 sview.avenuea.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.eads.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.win24.de
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 pop3.norton.antivirus
`127.0.0.1 pop3.spa.norton.antivirus
`127.0.0.1 ad.dk.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.beguide.net
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.exhedra.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 afservant.guj.de
`127.0.0.1 ant.guj.de
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.de
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerads.de
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.looksmart.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 exchange-it.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 gm.preferences.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 rd.yahoo.com
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 secserv.imgis.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 sview.avenuea.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.eads.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.win24.de
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 pop3.norton.antivirus
`127.0.0.1 pop3.spa.norton.antivirus
`127.0.0.1 ad.dk.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.beguide.net
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.exhedra.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 afservant.guj.de
`127.0.0.1 ant.guj.de
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.de
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerads.de
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.looksmart.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 exchange-it.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 gm.preferences.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 rd.yahoo.com
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 secserv.imgis.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 sview.avenuea.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.eads.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.win24.de
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 pop3.norton.antivirus
`127.0.0.1 pop3.spa.norton.antivirus
`127.0.0.1 ad.dk.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.beguide.net
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.exhedra.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 afservant.guj.de
`127.0.0.1 ant.guj.de
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.de
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerads.de
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.looksmart.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 exchange-it.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 gm.preferences.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 rd.yahoo.com
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 secserv.imgis.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 sview.avenuea.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.eads.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.win24.de
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 pop3.norton.antivirus
`127.0.0.1 pop3.spa.norton.antivirus
`127.0.0.1 ad.adsmart.net
`127.0.0.1 ad.ca.doubleclick.net
`127.0.0.1 ad.doubleclick.net
`127.0.0.1 ad.es.doubleclick.net
`127.0.0.1 ad.fr.doubleclick.net
`127.0.0.1 ad.free6.com
`127.0.0.1 ad.it.doubleclick.net
`127.0.0.1 ad.iwin.com
`127.0.0.1 ad.jp.doubleclick.net
`127.0.0.1 ad.kr.doubleclick.net
`127.0.0.1 ad.linkexchange.com
`127.0.0.1 ad.linksynergy.com
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.nl.doubleclick.net
`127.0.0.1 ad.no.doubleclick.net
`127.0.0.1 ad.preferences.com
`127.0.0.1 ad.se.doubleclick.net
`127.0.0.1 ad.sma.punto.net
`127.0.0.1 ad.trafficmp.com
`127.0.0.1 ad.uk.doubleclick.net
`127.0.0.1 ad.webprovider.com
`127.0.0.1 ad08.focalink.com
`127.0.0.1 ad1.adcept.net
`127.0.0.1 ad1.icorp.net
`127.0.0.1 ad1.looksmart.com
`127.0.0.1 ad2.adcept.net
`127.0.0.1 ad2.looksmart.com
`127.0.0.1 ad3.adcept.net
`127.0.0.1 ad-adex3.flycast.com
`127.0.0.1 adcontroller.unicast.com
`127.0.0.1 adcreatives.imaginemedia.com
`127.0.0.1 addb.looksmart.com
`127.0.0.1 adevents.msn.com
`127.0.0.1 adex3.flycast.com
`127.0.0.1 adforce.ads.imgis.com
`127.0.0.1 adforce.imgis.com
`127.0.0.1 adfu.blockstackers.com
`127.0.0.1 adimage.blm.net
`127.0.0.1 adimages.earthweb.com
`127.0.0.1 adimages.go.com
`127.0.0.1 adimages.imaginemedia.com
`127.0.0.1 adimg.egroups.com
`127.0.0.1 admedia.xoom.com
`127.0.0.1 admonitor.net
`127.0.0.1 adpick.switchboard.com
`127.0.0.1 adproject.net
`127.0.0.1 adremote.pathfinder.com
`127.0.0.1 adres.internet.com
`127.0.0.1 ads.adflight.com
`127.0.0.1 ads.ad-flow.com
`127.0.0.1 ads.admaximize.com
`127.0.0.1 ads.admonitor.net
`127.0.0.1 ads.adroar.com
`127.0.0.1 ads.bfast.com
`127.0.0.1 ads.box.sk
`127.0.0.1 ads.burstnet.com
`127.0.0.1 ads.cdfreaks.com
`127.0.0.1 ads.chrbanner.com
`127.0.0.1 ads.clickagents.com
`127.0.0.1 ads.clickhouse.com
`127.0.0.1 ads.dai.net
`127.0.0.1 ads.datais.com
`127.0.0.1 ads.enliven.com
`127.0.0.1 ads.eu.msn.com
`127.0.0.1 ads.fairfax.com.au
`127.0.0.1 ads.fool.com
`127.0.0.1 ads.fortunecity.com
`127.0.0.1 ads.fortunecity.fr
`127.0.0.1 ads.freeze.com
`127.0.0.1 ads.freshmeat.net
`127.0.0.1 ads.god.co.uk
`127.0.0.1 ads.guardianunlimited.co.uk
`127.0.0.1 ads.hitcents.com
`127.0.0.1 ads.hollywood.com
`127.0.0.1 ads.i12.de
`127.0.0.1 ads.i33.com
`127.0.0.1 ads.ign.com
`127.0.0.1 ads.imaginemedia.com
`127.0.0.1 ads.indya.com
`127.0.0.1 ads.infi.net
`127.0.0.1 ads.irover.com
`127.0.0.1 ads.ixo.com
`127.0.0.1 ads.jpost.com
`127.0.0.1 ads.jwtt3.com
`127.0.0.1 ads.killerapp.com
`127.0.0.1 ads.link4ads.com
`127.0.0.1 ads.linksponsor.com
`127.0.0.1 ads.looksmart.com
`127.0.0.1 ads.lycos.com
`127.0.0.1 ads.lycos.de
`127.0.0.1 ads.madison.com
`127.0.0.1 ads.mediaodyssey.com
`127.0.0.1 ads.mediaturf.net
`127.0.0.1 ads.msn.com
`127.0.0.1 ads.musiccity.com
`127.0.0.1 ads.netomia.com
`127.0.0.1 ads.newcity.com
`127.0.0.1 ads.newcitynet.com
`127.0.0.1 ads.ninemsn.com.au
`127.0.0.1 ads.rediff.com
`127.0.0.1 ads.satyamonline.com
`127.0.0.1 ads.seattletimes.com
`127.0.0.1 ads.smartclicks.com
`127.0.0.1 ads.smartclicks.net
`127.0.0.1 ads.sptimes.com
`127.0.0.1 ads.startpath.com
`127.0.0.1 ads.station.sony.com
`127.0.0.1 ads.tiscali.fr
`127.0.0.1 ads.tripod.com
`127.0.0.1 ads.tucows.com
`127.0.0.1 ads.vcommunities.com
`127.0.0.1 ads.web.aol.com
`127.0.0.1 ads.x10.com
`127.0.0.1 ads.xtra.co.nz
`127.0.0.1 ads.zdnet.com
`127.0.0.1 ads01.focalink.com
`127.0.0.1 ads02.focalink.com
`127.0.0.1 ads03.focalink.com
`127.0.0.1 ads04.focalink.com
`127.0.0.1 ads05.focalink.com
`127.0.0.1 ads06.focalink.com
`127.0.0.1 ads07.focalink.com
`127.0.0.1 ads08.focalink.com
`127.0.0.1 ads09.focalink.com
`127.0.0.1 ads1.activeagent.at
`127.0.0.1 ads1.ad-flow.com
`127.0.0.1 ads1.speedbit.com
`127.0.0.1 ads10.focalink.com
`127.0.0.1 ads11.focalink.com
`127.0.0.1 ads12.focalink.com
`127.0.0.1 ads13.focalink.com
`127.0.0.1 ads14.focalink.com
`127.0.0.1 ads15.focalink.com
`127.0.0.1 ads16.focalink.com
`127.0.0.1 ads17.focalink.com
`127.0.0.1 ads18.focalink.com
`127.0.0.1 ads19.focalink.com
`127.0.0.1 ads2.speedbit.com
`127.0.0.1 ads2.zdnet.com
`127.0.0.1 ads20.focalink.com
`127.0.0.1 ads21.focalink.com
`127.0.0.1 ads22.focalink.com
`127.0.0.1 ads23.focalink.com
`127.0.0.1 ads24.focalink.com
`127.0.0.1 ads25.focalink.com
`127.0.0.1 ads3.speedbit.com
`127.0.0.1 ads3.zdnet.com
`127.0.0.1 ads4.speedbit.com
`127.0.0.1 ads5.gamecity.net
`127.0.0.1 ads5.speedbit.com
`127.0.0.1 ads6.speedbit.com
`127.0.0.1 ads7.speedbit.com
`127.0.0.1 ads8.speedbit.com
`127.0.0.1 adserv.bravenet.com
`127.0.0.1 adserv.bravenet.com
`127.0.0.1 adserv.iafrica.com
`127.0.0.1 adserv.internetfuel.com
`127.0.0.1 adserv.quality-channel.de
`127.0.0.1 adserver.affiliation.com
`127.0.0.1 adserver.akqa.net
`127.0.0.1 adserver.dbusiness.com
`127.0.0.1 adserver.garden.com
`127.0.0.1 adserver.humanux.com
`127.0.0.1 adserver.imaginemedia.com
`127.0.0.1 adserver.isonews.com
`127.0.0.1 adserver.janes.com
`127.0.0.1 adserver.lunarpages.com
`127.0.0.1 adserver.merc.com
`127.0.0.1 adserver.monster.com
`127.0.0.1 adserver.track-star.com
`127.0.0.1 adserver.tweakers.net
`127.0.0.1 adserver.ugo.com
`127.0.0.1 adserver.webads.nl
`127.0.0.1 adserver1.ogilvy-interactive.de
`127.0.0.1 adserver2.imaginemedia.com
`127.0.0.1 AdSubstract
`127.0.0.1 adsubstract
`127.0.0.1 ads-ussj1.focalink.com
`127.0.0.1 adtegrity.spinbox.net
`127.0.0.1 aglink.mircx.com
`127.0.0.1 antfarm-ad.flycast.com
`127.0.0.1 au.ads.link4ads.com
`127.0.0.1 bach.aureate.com
`127.0.0.1 badservant.guj.de
`127.0.0.1 banner.50megs.com
`127.0.0.1 banner.adverity.com
`127.0.0.1 banner.commissionpartner.com
`127.0.0.1 banner.de
`127.0.0.1 banner.easyspace.com
`127.0.0.1 banner.free6.com
`127.0.0.1 banner.media-system.de
`127.0.0.1 banner.orb.net
`127.0.0.1 banner.relcom.ru
`127.0.0.1 bannerad.ipgnet.com
`127.0.0.1 bannerads.de
`127.0.0.1 bannerfarm.ace.advertising.com
`127.0.0.1 bannerimages.0catch.com
`127.0.0.1 bannermaster.geektech.com
`127.0.0.1 banner-net.com
`127.0.0.1 bannerpower.com
`127.0.0.1 banners.adultfriendfinder.com
`127.0.0.1 banners.easydns.com
`127.0.0.1 banners.free6.com
`127.0.0.1 banners.hotlinks.net
`127.0.0.1 banners.looksmart.com
`127.0.0.1 banners.nextcard.com
`127.0.0.1 banners.pennyweb.com
`127.0.0.1 banners.webmasterplan.com
`127.0.0.1 bannervip.webjump.com
`127.0.0.1 banzai.moodlogic.com
`127.0.0.1 barnesandnoble.bfast.com
`127.0.0.1 beseen.com
`127.0.0.1 beseen.looksmart.com
`127.0.0.1 beseen5.looksmart.com
`127.0.0.1 beseenad.looksmart.com
`127.0.0.1 beseenad1.looksmart.com
`127.0.0.1 beseenad2.looksmart.com
`127.0.0.1 beseenad3.looksmart.com
`127.0.0.1 beseenadx.looksmart.com
`127.0.0.1 bfast.com
`127.0.0.1 bizad.nikkeibp.co.jp
`127.0.0.1 bn.bfast.com
`127.0.0.1 bsads.looksmart.com
`127.0.0.1 by.advertising.com
`127.0.0.1 c3.xxxcounter.com
`127.0.0.1 califia.imaginemedia.com
`127.0.0.1 cash4banner.com
`127.0.0.1 cash4banner.de
`127.0.0.1 cds.mediaplex.com
`127.0.0.1 cgi.sexlist.com
`127.0.0.1 click.avenuea.com
`127.0.0.1 click.go2net.com
`127.0.0.1 click.linksynergy.com
`127.0.0.1 clickagents.com
`127.0.0.1 clicks.about.com
`127.0.0.1 clit5.sextracker.com
`127.0.0.1 code02.pbtech.net
`127.0.0.1 commonwealth.riddler.com
`127.0.0.1 cookies.cmpnet.com
`127.0.0.1 cornflakes.pathfinder.com
`127.0.0.1 counter.hitbox.com
`127.0.0.1 counter1.sextracker.com
`127.0.0.1 counter10.sextracker.com
`127.0.0.1 counter11.sextracker.com
`127.0.0.1 counter12.sextracker.com
`127.0.0.1 counter13.sextracker.com
`127.0.0.1 counter14.sextracker.com
`127.0.0.1 counter15.sextracker.com
`127.0.0.1 counter16.sextracker.com
`127.0.0.1 counter2.sextracker.com
`127.0.0.1 counter3.sextracker.com
`127.0.0.1 counter4.sextracker.com
`127.0.0.1 counter5.sextracker.com
`127.0.0.1 counter6.sextracker.com
`127.0.0.1 counter7.sextracker.com
`127.0.0.1 counter8.sextracker.com
`127.0.0.1 counter9.sextracker.com
`127.0.0.1 crs.akamai.com
`127.0.0.1 crux.songline.com
`127.0.0.1 ct.iac-online.de
`127.0.0.1 ctc.amateurpages.com
`127.0.0.1 de.netstatpro.net
`127.0.0.1 desktop.grokster.com
`127.0.0.1 dialer.offshoreclicks.com
`127.0.0.1 doubleclick.net
`127.0.0.1 ehg.hitbox.com
`127.0.0.1 ehg-commjun.hitbox.com
`127.0.0.1 erie.smartage.com
`127.0.0.1 etad.telegraph.co.uk
`127.0.0.1 everyone.net
`127.0.0.1 exchange-it.com
`127.0.0.1 exitfuel.com
`127.0.0.1 exitmoney.com
`127.0.0.1 fast.mediacharger.com
`127.0.0.1 focalink.com
`127.0.0.1 fp.valueclick.com
`127.0.0.1 fragmentserv.iac-online.de
`127.0.0.1 free.****-portal.com
`127.0.0.1 freebieclub.com
`127.0.0.1 freepass.elitecities.com
`127.0.0.1 fs.dai.net
`127.0.0.1 gadgeteer.pdamart.com
`127.0.0.1 global.msads.net
`127.0.0.1 gm.preferences.com
`127.0.0.1 go.ezgreen.com
`127.0.0.1 got2goshop.com
`127.0.0.1 gp.dejanews.com
`127.0.0.1 hacker-spider.de
`127.0.0.1 hc2.humanclick.com
`127.0.0.1 hg1.hitbox.com
`127.0.0.1 hit.hotlog.ru
`127.0.0.1 hitbox.com
`127.0.0.1 hitmatic.com
`127.0.0.1 hitsfrom.popuprush.com
`127.0.0.1 hypercount.com
`127.0.0.1 ifcol.exitfuel.com
`127.0.0.1 image.click2net.com
`127.0.0.1 image.com.com
`127.0.0.1 image.eimg.com
`127.0.0.1 images.sexlist.com
`127.0.0.1 images2.nytimes.com
`127.0.0.1 img.mediaplex.com
`127.0.0.1 impnl.tradedoubler.com
`127.0.0.1 internetfuel.com
`127.0.0.1 itn.adbureau.net
`127.0.0.1 jcms.cydoor.com
`127.0.0.1 jeeves.flycast.com
`127.0.0.1 jobkeys.ngadcenter.net
`127.0.0.1 kansas.valueclick.com
`127.0.0.1 leader.linkexchange.com
`127.0.0.1 linkbuddies.com
`127.0.0.1 liquidad.narrowcastmedia.com
`127.0.0.1 liveadvert.com
`127.0.0.1 ln.doubleclick.net
`127.0.0.1 looksmartclicks.com
`127.0.0.1 lsads.looksmart.com.au
`127.0.0.1 m.doubleclick.net
`127.0.0.1 macaddictads.snv.futurenet.com
`127.0.0.1 marketing-internet.com
`127.0.0.1 maximumcash.com
`127.0.0.1 maximumpcads.imaginemedia.com
`127.0.0.1 media.carpediem.fr
`127.0.0.1 media.expedia.com
`127.0.0.1 media.preferences.com
`127.0.0.1 mediacharger.com
`127.0.0.1 mediamgr.ugo.com
`127.0.0.1 mediaplex.com
`127.0.0.1 megacash.de
`127.0.0.1 mercury.rmuk.co.uk
`127.0.0.1 millenium-hitz.com
`127.0.0.1 mjxads.internet.com
`127.0.0.1 mojofarm.sjc.mediaplex.com
`127.0.0.1 monitor.looksmart.com
`127.0.0.1 monsterhitz.to
`127.0.0.1 musiccity.streamcastnetwork.com
`127.0.0.1 n24.de
`127.0.0.1 nbc.adbureau.net
`127.0.0.1 newads.cmpnet.com
`127.0.0.1 ng3.ads.warnerbros.com
`127.0.0.1 ngads.smartage.com
`127.0.0.1 nitrous.exitfuel.com
`127.0.0.1 nsads.hotwired.com
`127.0.0.1 ntbanner.digitalriver.com
`127.0.0.1 oad.realmedia.com
`127.0.0.1 oas.benchmark.fr
`127.0.0.1 onresponse.com
`127.0.0.1 onresponse.com
`127.0.0.1 paycounter.com
`127.0.0.1 ph-ad04.focalink.com
`127.0.0.1 ph-ad05.focalink.com
`127.0.0.1 ph-ad07.focalink.com
`127.0.0.1 ph-ad16.focalink.com
`127.0.0.1 ph-ad17.focalink.com
`127.0.0.1 ph-ad18.focalink.com
`127.0.0.1 php.offshoreclicks.com
`127.0.0.1 pluto.beseen.com
`127.0.0.1 proxy.ladot.com
`127.0.0.1 pub.epiknet.org
`127.0.0.1 pub.infiniland.com
`127.0.0.1 pub.ketix.com
`127.0.0.1 pub.telmedia.fr
`127.0.0.1 pub.weborama.fr
`127.0.0.1 realads.realmedia.com
`127.0.0.1 redherring.ngadcenter.net
`127.0.0.1 redirect.click2net.com
`127.0.0.1 redirect.iac-online.de
`127.0.0.1 regio.adlink.de
`127.0.0.1 ResponseMedia-ad.flycast.com
`127.0.0.1 retaildirect.realmedia.com
`127.0.0.1 rs.webmasterplan.com
`127.0.0.1 s0.bluestreak.com
`127.0.0.1 s1.bluestreak.com
`127.0.0.1 s10.sitemeter.com
`127.0.0.1 s11.sitemeter.com
`127.0.0.1 s12.sitemeter.com
`127.0.0.1 s2.bluestreak.com
`127.0.0.1 s2.focalink.com
`127.0.0.1 s3.bluestreak.com
`127.0.0.1 s4.bluestreak.com
`127.0.0.1 s5.bluestreak.com
`127.0.0.1 s6.bluestreak.com
`127.0.0.1 s7.bluestreak.com
`127.0.0.1 s8.bluestreak.com
`127.0.0.1 script.weborama.fr
`127.0.0.1 secserv.imgis.com
`127.0.0.1 servedby.advertising.com
`127.0.0.1 servedby.advertwizard.com
`127.0.0.1 server.hamster.com
`127.0.0.1 server-uk.imrworldwide.com
`127.0.0.1 servlets.kliks.nl
`127.0.0.1 sextracker.com
`127.0.0.1 sh4banner.de
`127.0.0.1 sh4sure-images.adbureau.net
`127.0.0.1 shop.freepush.com
`127.0.0.1 specialoffers.aol.com
`127.0.0.1 spezialreporte.de
`127.0.0.1 spin.spinbox.net
`127.0.0.1 sprinks-clicks.about.com
`127.0.0.1 spylog.com
`127.0.0.1 srv1.bannercommunity.de
`127.0.0.1 srv2.bannercommunity.de
`127.0.0.1 srv3.bannercommunity.de
`127.0.0.1 static.admaximize.com
`127.0.0.1 stats.superstats.com
`127.0.0.1 stats3.porntrack.com
`127.0.0.1 Suissa-ad.flycast.com
`127.0.0.1 survey.proactive.nl
`127.0.0.1 sview.avenuea.com
`127.0.0.1 t0.extreme-dm.com
`127.0.0.1 thinknyc.eu-adcenter.net
`127.0.0.1 tpl1.realtracker.com
`127.0.0.1 tracker.clicktrade.com
`127.0.0.1 tsms-ad.tsms.com
`127.0.0.1 tuerck.de.counted.com
`127.0.0.1 twistedhumor.com
`127.0.0.1 ugo.eu-adcenter.net
`127.0.0.1 UGO.eu-adcenter.net
`127.0.0.1 uk1.linksynergy.com
`127.0.0.1 uk2.linksynergy.com
`127.0.0.1 uk3.linksynergy.com
`127.0.0.1 uk4.linksynergy.com
`127.0.0.1 uk5.linksynergy.com
`127.0.0.1 us.adserver.yahoo.com
`127.0.0.1 v0.extreme-dm.com
`127.0.0.1 v1.extreme-dm.com
`127.0.0.1 valueclick.com
`127.0.0.1 van.ads.link4ads.com
`127.0.0.1 vant.guj.de
`127.0.0.1 view.accendo.com
`127.0.0.1 view.avenuea.com
`127.0.0.1 vis1.sexlist.com
`127.0.0.1 vis2.sexlist.com
`127.0.0.1 vis3.sexlist.com
`127.0.0.1 vis4.sexlist.com
`127.0.0.1 vis5.sexlist.com
`127.0.0.1 visite.weborama.fr
`127.0.0.1 VNU.eu-adcenter.net
`127.0.0.1 w0.extreme-dm.com
`127.0.0.1 w113.hitbox.com
`127.0.0.1 w117.hitbox.com
`127.0.0.1 w25.hitbox.com
`127.0.0.1 web2.deja.com
`127.0.0.1 webads.bizservers.com
`127.0.0.1 webxprod.qualcomm.com
`127.0.0.1 www.12traffic.de
`127.0.0.1 www.1for1.com
`127.0.0.1 www.404errorpage.com
`127.0.0.1 www.7adpower.com
`127.0.0.1 www.7host.com
`127.0.0.1 www.activeannonce.com
`127.0.0.1 www.adbucks.com
`127.0.0.1 www.adexit.com
`127.0.0.1 www.adforce.com
`127.0.0.1 www.admex.com
`127.0.0.1 www.adnetz.net
`127.0.0.1 www.adserver.com
`127.0.0.1 www.adserver.net
`127.0.0.1 www.adsmart.com
`127.0.0.1 www.adsmart.net
`127.0.0.1 www.adultbizvoice.com
`127.0.0.1 www.adultclicks.com
`127.0.0.1 www.ad-up.com
`127.0.0.1 www.adverity.com
`127.0.0.1 www.adverlead.com
`127.0.0.1 www.adverline.com
`127.0.0.1 www.adverline.fr
`127.0.0.1 www.advertising.com
`127.0.0.1 www.advertwizard.com
`127.0.0.1 www.adviews-sponsor.de
`127.0.0.1 www.alladvantage.com
`127.0.0.1 www.allclicks.com
`127.0.0.1 www.amateur-galleries.com
`127.0.0.1 www.bannerads.de
`127.0.0.1 www.beseen.com
`127.0.0.1 www.bfast.com
`127.0.0.1 www.boonsolutions.com
`127.0.0.1 www.burstnet.com
`127.0.0.1 www.cash1x1.de
`127.0.0.1 www.cash2002.de
`127.0.0.1 www.cash4banner.com
`127.0.0.1 www.cash4banner.de
`127.0.0.1 www.cashcount.com
`127.0.0.1 www.cashfiesta.com
`127.0.0.1 www.cashradio.com
`127.0.0.1 www.cashsurfers.com
`127.0.0.1 www.casinoglamour.com
`127.0.0.1 www.cellularphones.com
`127.0.0.1 www.cibleclick.com
`127.0.0.1 www.cj.com
`127.0.0.1 www.click-fr.com
`127.0.0.1 www.clickxchange.com
`127.0.0.1 www.clictrafic.com
`127.0.0.1 www.coinpromo.com
`127.0.0.1 www.cometcursor.com
`127.0.0.1 www.cometsystems.net
`127.0.0.1 www.commission-junction.com
`127.0.0.1 www.cydoor.com
`127.0.0.1 www.daz.com
`127.0.0.1 www.directvalue.nl
`127.0.0.1 www.eads.com
`127.0.0.1 www.fastmetasearch.com
`127.0.0.1 www.flycast.co.uk
`127.0.0.1 www.flycast.com
`127.0.0.1 www.free-banners.com
`127.0.0.1 www.freestats.com
`127.0.0.1 www.****-portal.com
`127.0.0.1 www.gamingclub.com
`127.0.0.1 www.gator.co.uk
`127.0.0.1 www.gator.com
`127.0.0.1 www.gator.net
`127.0.0.1 www.genhit.com
`127.0.0.1 www.getsearches.com
`127.0.0.1 www.gopopup.com
`127.0.0.1 www.grokster.com
`127.0.0.1 www.hardcorepornos.org
`127.0.0.1 www.hightrafficads.com
`127.0.0.1 www.hit-parade.com
`127.0.0.1 www.hitsme.com
`127.0.0.1 www.imaginemedia.com
`127.0.0.1 www.kliks.nl
`127.0.0.1 www.lastconsole.com
`127.0.0.1 www.linkshare.com
`127.0.0.1 www.liveadvert.com
`127.0.0.1 www.looksmartclicks.com
`127.0.0.1 www.lop.com
`127.0.0.1 www.lottoforever.com
`127.0.0.1 www.mediaplex.com
`127.0.0.1 www.megacash.de
`127.0.0.1 www.modchip.com
`127.0.0.1 www.mod-chip.com
`127.0.0.1 www.money4exit.de
`127.0.0.1 www.my-stats.com
`127.0.0.1 www.netbroadcaster.com
`127.0.0.1 www.netdirect.nl
`127.0.0.1 www.netflip.com
`127.0.0.1 www.netgravity.com
`127.0.0.1 www.newtopsites.com
`127.0.0.1 www.nic.co.il
`127.0.0.1 www.nudelinkz.com
`127.0.0.1 www.oneandonlynetwork.com
`127.0.0.1 www.onresponse.com
`127.0.0.1 www.paidpopup.de
`127.0.0.1 www.popdown.de
`127.0.0.1 www.PostMasterBannerNet.com
`127.0.0.1 www.prepaidliving.com
`127.0.0.1 www.qksrv.net
`127.0.0.1 www.qualityhitz.com
`127.0.0.1 www.qualypromos.com
`127.0.0.1 www.radiate.com
`127.0.0.1 www.radiofreecash.com
`127.0.0.1 www.rankyou.com
`127.0.0.1 www.reference-sexe.com
`127.0.0.1 www.searchtraffic.com
`127.0.0.1 www.sexfranco.com
`127.0.0.1 www.sexfreelist.com
`127.0.0.1 www.sexlist.com
`127.0.0.1 www.sexspy.com
`127.0.0.1 www.sexstudio24.de
`127.0.0.1 www.sextracker.com
`127.0.0.1 www.sexyfreehost.com
`127.0.0.1 www.sexyplugin.com
`127.0.0.1 www.simplecounter.net
`127.0.0.1 www.slutzoo.com
`127.0.0.1 www.sonixwarez.com
`127.0.0.1 www.sponsor2002.de
`127.0.0.1 www.targetshop.com
`127.0.0.1 www.teknosurf.com
`127.0.0.1 www.teknosurf2.com
`127.0.0.1 www.teknosurf3.com
`127.0.0.1 www.theadultwire.com
`127.0.0.1 www.topwarez-fr.com
`127.0.0.1 www.toys-galleries.com
`127.0.0.1 www.trafficmonetizer.com
`127.0.0.1 www.unionwarez.com
`127.0.0.1 www.valueclick.com
`127.0.0.1 www.valuesponsor.com
`127.0.0.1 www.warez33.com
`127.0.0.1 www.warezfield.com
`127.0.0.1 www.web3000.co.uk
`127.0.0.1 www.web3000.com
`127.0.0.1 www.webads.nl
`127.0.0.1 www.webferret.com
`127.0.0.1 www.webhancer.com
`127.0.0.1 www.webhancer.net
`127.0.0.1 www.websitefinancing.com
`127.0.0.1 www.wedoo.com
`127.0.0.1 www.win24.de
`127.0.0.1 www.wingowin.com
`127.0.0.1 www.xiti.com
`127.0.0.1 www.xxxteenclub.de
`127.0.0.1 www.youmakemoney.com
`127.0.0.1 www.zeloop.net
`127.0.0.1 www2.burstnet.com
`127.0.0.1 www2.consumercreditusa.com
`127.0.0.1 www3.netgravity.com
`127.0.0.1 www4.netgravity.com
`127.0.0.1 www4.trix.net
`127.0.0.1 www80.valueclick.com
`127.0.0.1 xads.infospace.com
`127.0.0.1 xads.zedo.com
`127.0.0.1 z.extreme-dm.com
`127.0.0.1 z0.extreme-dm.com
`127.0.0.1 z1.extreme-dm.com
`127.0.0.1 zac.netgravity.com
»Program Files
*C:\ntldr
*C:\ntdetect.com
*C:\io.sys
*C:\WINDOWS\system32\win.com
*C:\WINDOWS\explorer.exe
»%PATH% Companion Files
+C:\WINDOWS\system32\notepad.exe
*C:\WINDOWS\notepad.exe
+C:\WINDOWS\system32\taskman.exe
*C:\WINDOWS\TASKMAN.EXE
+C:\WINDOWS\system32\winhlp32.exe
*C:\WINDOWS\winhlp32.exe
+C:\WINDOWS\system32\slrundll.exe
*C:\WINDOWS\slrundll.exe
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+292=\SystemRoot\System32\smss.exe
+408=\??\C:\WINDOWS\system32\csrss.exe
+456=\??\C:\WINDOWS\system32\winlogon.exe
+500=C:\WINDOWS\system32\services.exe
+512=C:\WINDOWS\system32\lsass.exe
+672=C:\WINDOWS\system32\svchost.exe
+716=C:\WINDOWS\system32\svchost.exe
+860=C:\WINDOWS\System32\svchost.exe
+956=C:\WINDOWS\System32\svchost.exe
+1048=C:\WINDOWS\System32\svchost.exe
+1236=C:\WINDOWS\system32\spoolsv.exe
+1336=C:\Program Files\APC\PowerChute Business Edition\agent\pbeagent.exe
+1348=C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
+1368=C:\Program Files\Symantec AntiVirus\DefWatch.exe
+1528=C:\WINDOWS\System32\inetsrv\inetinfo.exe
+1684=C:\Program Files\Norton AntiVirus\navapsvc.exe
+1736=C:\WINDOWS\System32\nvsvc32.exe
+1868=C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
+1956=C:\WINDOWS\System32\svchost.exe
+1972=C:\Program Files\Symantec AntiVirus\Rtvscan.exe
+2020=C:\WINDOWS\System32\symlcsvc.exe
+2040=C:\WINDOWS\System32\wdfmgr.exe
+208=C:\Program Files\VMware\VMware Workstation\Programs\vmware-authd.exe
+216=C:\WINDOWS\System32\vmnetdhcp.exe
+312=C:\WINDOWS\system32\vmnat.exe
+392=C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
+2012=C:\WINDOWS\Explorer.EXE
+384=C:\Program Files\CloneCD\ElbyCheck.exe
+228=C:\WINDOWS\Mixer.exe
+1032=C:\Program Files\Common Files\Symantec Shared\ccApp.exe
+580=C:\Program Files\QuickTime\qttask.exe
+1120=C:\PROGRA~1\SYMANT~1\VPTray.exe
+1268=C:\Program Files\DynSite\DynSite.exe
+628=C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
+1108=C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
+2088=C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
+268=C:\Program Files\Internet Explorer\iexplore.exe
+2248=C:\Program Files\Common Files\Real\Update_OB\realsched.exe
+3664=C:\Program Files\mozilla.org\Mozilla\mozilla.exe
+3064=C:\Program Files\startdreck\StartDreck.exe
»VMM32Files (LM)
»%System%\VMM32
»%System%\IOSUBSYS
»Application specific
»MS Office 97/8.0 STARTUP-PATH
»Current User
»Default User
»Local Machine
»ICQ NetDetect
»Current User
*Launch Browser=No
»Default User
 

·
Registered
Joined
·
10 Posts
Discussion Starter #10
and mwav scan

and the result of the mwav scan


Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iefeatures.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\iuctl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Scrabble\DX300_AudioHandler.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Scrabble\G3D_DirectX_v610.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Scrabble\G3D_OpenGL_v110.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Scrabble\Utility_NetworkInterface.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QTPlugin.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\wddx_com.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Licenses\Macromedia Flash MX_6.0_6CE1.lic". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Licenses\Macromedia Flash MX_6.0_6CE1.prf". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Common\vboxta.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Common\vboxr.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Common\vboxm.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Common\vboxa.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Vbox\Common\vboxten-us.vboxlm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\DOCUME~1\Shannon\LOCALS~1\Temp\_ISTMP3.DIR\_ISTMP0.DIR\FileGrp\Msvcrt10.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\iefeatures.ocx". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\SbCIe02a.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxsfs.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Ahead\NeroDigital\settings.xml". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero ShowTime\ShowTime-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero Recode\Recode-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ActiveListManager.exe" refers to invalid object "C:\Program Files\ICQ\ActiveList\ActiveListManager.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ActiveListServer.exe" refers to invalid object "C:\Program Files\ICQ\ActiveList\ActiveListServer.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\aim.exe" refers to invalid object "C:\temp\aim.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ASAPI" refers to invalid object "C:\Program Files\VOB\ASAPI Update\ASAPI". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe" refers to invalid object "C:\WINDOWS\System32\cmmgr32.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TTS_RUNTIME" refers to invalid object "C:\Program Files\ViaVoice TTS\TTS_RUNTIME". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\WFCMGR32.EXE" refers to invalid object "C:\Program Files\Citrix\ICA Client\WFCMGR32.EXE". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Program Files\Common Files\Microsoft Shared\Office10\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Padus DiscJuggler\English Documentation\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Padus DiscJuggler\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software\Utilities\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Jasc Software\Anniversary Resources\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\WINDOWS\Installer\{47D5D869-FE57-4F2F-A358-83CFAA7B4968}\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\LuMMInst\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Documents and Settings\All Users\Start Menu\Programs\Symantec Client Security\". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "bdeplayer". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "DivXCodec". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ieupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Invision 2.0 Build 3515". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB823182". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824105". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824141". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB824146". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB825119". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB826939". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828028". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828035". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB828741". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB835732". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB837001". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "LiveReg". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "LiveUpdate1.7". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Midtown Madness 2.0". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "MSNEXT". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q308210". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q309521". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q309691". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q310507". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q311889". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q313484". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q314147". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q315000". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q329048". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q811114". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Q828026". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Scrabble". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SoulSeek Client 139". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SoulSeek Client 146c". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SoulSeek Client 148". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SoulSeek Client 149". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "ThePlaya". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Winamp3". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{122F7F34-ED7A-4100-99C2-5B25B09373AC}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{3075C5C3-0807-4924-AF8F-FF27052C12AE}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{466ED896-E3CF-4DF3-B47E-39F74B8FC3C6}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{7BF7B688-4A95-4003-BA98-EA8A79DA0ABA}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{821DABD6-26F2-49E5-AE55-40A589ADBE6D}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{8C4504A1-9280-11D5-9F7E-00902712427E}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{90280409-6000-11D3-8CFE-0050048383C9}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{A145C3F3-00FA-4AC0-9F55-3900D02DBE07}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{A27F2A64-3D23-4449-B395-75335CED458E}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{ABEB838C-A1A7-4C5D-B7E1-8B4314B00540}". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{FB015BB0-5518-4767-9DE4-F9A5C7C62E46}". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{01112B00-3e00-11d2-8470-0060089874ed}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgrc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{018FDBA7-1999-415F-9BED-DF47E0B818BD}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{02D4863E-154F-40C3-9FF1-31F2F0F62A47}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{02FFF7E7-90B6-4CAA-8878-15D09DA3C38C}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{09FF37C1-4FC4-4857-A22B-B0EFBC7A1FA5}" refers to invalid object "C:\Program Files\STOIK Video Converter\MovieSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1147DC83-6208-4dca-8E88-DD45BAAB3043}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\pubmod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{11CB4723-D5A1-4a55-8D1D-5C2679D54CF5}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{12C8E2F8-37D9-4908-A712-DAF0553ADD49}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{138C7A3E-1D18-41AB-9683-E2C9DFF6E642}" refers to invalid object "C:\Program Files\Yahoo!\Common\yiesrvc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{189504B8-50D1-4AA8-B4D6-95C8F58A6414}" refers to invalid object "C:\temp\sb.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2018C303-E3F2-4455-AA1A-773F84F10902}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkinSelect.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2499216C-4BA5-11D5-BD9C-000103C116D5}" refers to invalid object "C:\Program Files\Yahoo!\Common\ylogin.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{24F3EAD6-8B87-4C1A-97DA-71C126BDA08F}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ft60.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{260A269E-A677-11d3-A773-00C04F68F44E}" refers to invalid object "C:\Program Files\Sonic Foundry\Shared Plug-Ins\Audio\sfxfx1.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2840354C-234F-4450-8F2D-12459E75AE71}" refers to invalid object "C:\Program Files\Yahoo!\Common\yloginids.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{29F46F81-4B2A-11D1-9BCE-00A0C96ED13A}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\MyYahoo.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2AE38A2D-371B-42F3-B803-9F6D669A411B}" refers to invalid object "C:\Program Files\Morpheus\DeskBandSearch.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2B323CD9-50E3-11D3-9466-00A0C9700498}" refers to invalid object "C:\PROGRA~1\Yahoo!\MESSEN~1\yacscom.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{307A6C42-0000-0010-8000-00AA00389B71}" refers to invalid object "c:\program files\warcraft iii\blizzard.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{32E780E7-8189-4215-9F6A-C34A3AC92CB1}" refers to invalid object "C:\Program Files\Microsoft Office\Office10\WINWORD.EXE /IMG_WIA". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{37B8167C-B9A4-4316-94B2-67B64BB2BA7C}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3B6ED8C5-5B91-11D5-803C-00D0B768B4B0}" refers to invalid object "C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3D5D83B0-47DC-4862-93D6-3E827A14AED1}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkin2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4075972B-F7F5-4702-80D2-432595125E0C}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ypagerps.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{43918f8f-f3be-4760-b4bb-6c89d9d91487}" refers to invalid object "C:\Program Files\Winamp3\Wacs\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{44b09a5f-5dee-4539-8001-d4b2d45c2876}" refers to invalid object "C:\Program Files\Winamp3\Wacs\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4528BBE0-4E08-11D5-AD55-00010333D0AD}" refers to invalid object "C:\PROGRA~1\YAHOO!\COMMON\yhexbmesus.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4643A0DC-ACD8-496C-B1CC-B42AE4B59940}" refers to invalid object "C:\Program Files\AutoCAD 2002\AcDimDynProp.arx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{47A0AD40-1590-4343-8944-E717C258E513}" refers to invalid object "C:\Program Files\Yahoo!\Common\yloginids.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4C171D40-8277-11D5-AD55-00010333D0AD}" refers to invalid object "C:\PROGRA~1\YAHOO!\COMMON\yhexbmesus.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{51653990-57B4-11CF-8EB1-02608C9BABA2}" refers to invalid object "C:\mIRC\download\Audio Filters\mpgaudio.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}" refers to invalid object "C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{58916BE6-BAFF-4f33-AEFE-B2AA03FE4C86}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\YahooBridgeLib.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{59EC0340-7506-11D2-B05F-00C04F7F89FE}" refers to invalid object "C:\temp\aimapi.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5BD5F66E-F849-4C96-ABAA-5D1D2851D590}" refers to invalid object "C:\Program Files\Yahoo!\Common\YIeTagBm.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5E4F85E7-E6AC-4BC3-8C04-0A62D65C4278}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5F99B381-AB44-11D2-9C22-00104B3801F6}" refers to invalid object "C:\mIRC\download\Audio Filters\iviaudio.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{64AA7031-C150-4118-8D31-FD273A2BB22C}" refers to invalid object "C:\Program Files\Yahoo!\Common\YVerInfo.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{67CE97C5-ABE6-429A-B6BD-3BD1333A0825}" refers to invalid object "C:\Program Files\Yahoo!\Common\Yshortcut.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6A7065BC-9BD4-4080-BA7D-B8C3B3F21371}" refers to invalid object "C:\Program Files\AutoCAD 2002\AcDimDynProp.arx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6AE4CC6E-999C-11D4-A3F0-009027427750}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yauto.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6E40017D-FB6A-4804-BDE4-3BB09F1719C1}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6FF98F64-474B-416F-A5B8-B593F8B44D24}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\PhotoShare.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7259A0E0-50EE-446C-A812-93696825DE77}" refers to invalid object "C:\Program Files\STOIK Video Converter\MovieSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}" refers to invalid object "C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{78AF2F25-A9C3-11D3-BF8C-0060B0FCC122}" refers to invalid object "C:\WINDOWS\DOWNLO~1\ACDCTO~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7D1E9C49-BD6A-11D3-87A8-009027A35D73}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yacsui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7E2E0DC1-31FD-11D2-9C21-00104B3801F6}" refers to invalid object "C:\mIRC\download\Audio Filters\iviaudio.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8505032C-6EF4-49FE-812A-B81770C329DC}" refers to invalid object "E:\WinExplorer.exe /Automation". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{852BAC69-85C1-4E22-A9F5-4A6D9100B6A4}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8B9A2A56-55A7-4A3D-8A3F-A0D3EED7477D}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\YMERemote.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8C03EE15-A677-11d3-A773-00C04F68F44E}" refers to invalid object "C:\Program Files\Sonic Foundry\Shared Plug-Ins\Audio\sfxfx3.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8CDA2F05-B2BA-4AC7-B731-51E9E6B006E1}" refers to invalid object "C:\Program Files\yEnc32\yEnc32Shell.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8D4B0BE1-C02E-11D2-A33D-00A0C94B8D0E}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\stock.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{92796D29-7921-11D4-B0F2-0050DA2B3579}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\Proxy.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{96632d1e-f3eb-4f54-ba79-9969692db659}" refers to invalid object "C:\Program Files\Winamp3\Wacs\cddbuiwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{977046B0-A87F-11d5-8FEA-FFFFFF000000}" refers to invalid object "C:\PROGRA~1\YAHOO!\COMMON\messmod.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{97D85205-80CF-4b71-90A5-D220DA4FEE58}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YAlertCenter.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9D39223E-AE8E-11D4-8FD3-00D0B7730277}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ywcvwr.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9D97C1EB-C6C6-4576-92DA-9876377E655C}" refers to invalid object "C:\Program Files\Yahoo!\Common\Yshortcut.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9EB641FB-A677-11d3-A773-00C04F68F44E}" refers to invalid object "C:\Program Files\Sonic Foundry\Shared Plug-Ins\Audio\sfxfx2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A90A5822-F108-45AD-8482-9BC8B12DD539}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A98ABF1C-107C-44E7-9254-2C3FF435D0C2}" refers to invalid object "C:\temp\sb.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B26DA9C0-7921-11D4-B0F2-0050DA2B3579}" refers to invalid object "C:\PROGRA~1\YAHOO!\MESSEN~1\YSERVER.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B448FAA5-DC36-4C3D-9436-67021CDECA82}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkin2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BAEB32D0-732D-11d2-8BF4-0060B0A4A9EA}" refers to invalid object "C:\temp\aimauto.exe". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BC5F1E50-5110-11D1-AFF5-006097C9A284}" refers to invalid object "C:\PROGRA~1\MICROS~2\Office10\BLNMGRPS.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BC5F1E51-5110-11D1-AFF5-006097C9A284}" refers to invalid object "C:\PROGRA~1\MICROS~2\Office10\BLNMGRPS.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BC5F1E53-5110-11D1-AFF5-006097C9A284}" refers to invalid object "C:\PROGRA~1\MICROS~2\Office10\BLNMGRPS.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BE265956-6F5F-4790-9CAB-EDFAC64362EF}" refers to invalid object "C:\temp\rtvideo.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D2DCCD86-F9B5-49C4-B4E2-481DF99E44AB}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D3CD7858-971A-4838-ACEC-40CA5D529DC8}" refers to invalid object "C:\mIRC\download\Audio Filters\mmswitch.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D3CD7859-971A-4838-ACEC-40CA5D529DC8}" refers to invalid object "C:\mIRC\download\Audio Filters\mmswitch.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{d4387178-98ca-4929-b8e3-a11cd2f333a6}" refers to invalid object "C:\Program Files\Winamp3\Wacs\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D5184A39-CBDF-4A4F-AC1A-7A45A852C883}" refers to invalid object "C:\Program Files\Yahoo!\Common\YVerInfo.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DA4F543C-C8A9-4E88-9A79-548CBB46F18F}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\YPagerChecker.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DB983AA0-D344-11D3-AF05-0000E885F247}" refers to invalid object "C:\Program Files\PCI Audio Applications\Bin\CMAudio.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DCE2F8B1-A520-11D4-8FD0-00D0B7730277}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ywcupl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E1A2D448-6334-45ec-8800-6D7F71DC87FC}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E1CBD8B6-BEA8-4FD3-AACF-3921FC233B57}" refers to invalid object "E:\WinExplorer.exe /Automation". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E4528244-55B0-4FBC-B27E-26851B634D02}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkin2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}" refers to invalid object "C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E7EEC168-A4C4-42C6-8601-B02816959B24}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkin2.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EA7ED7F0-9902-41AD-B9B9-5481AED1205A}" refers to invalid object "C:\Program Files\STOIK Video Converter\MovieSource.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EB54205E-BF1F-11D3-87A8-009027A35D73}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yacsui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EC1831E0-C231-11D3-87A8-009027A35D73}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yacsui.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{ECFA7321-14D6-4B33-8106-273E71ED05E8}" refers to invalid object "C:\PROGRA~1\ahead\Nero\WAVEED~1\AUDIOC~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EE533BB4-0223-4812-85BC-A85DBB761E83}" refers to invalid object "E:\WinExplorer.exe /Automation". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F27CE930-4CA3-11D1-AFF2-006097C9A284}" refers to invalid object "C:\PROGRA~1\MICROS~2\Office10\BLNMGRPS.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F281A59C-7B65-11D3-8617-0010830243BD}" refers to invalid object "C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F281A59D-7B65-11D3-8617-0010830243BD}" refers to invalid object "C:\WINDOWS\DOWNLO~1\ACPREV~1.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F51C15D4-3D0A-4DBA-A095-EBCC09F24DA2}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\YMERemote.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F5382384-CC9B-432C-B5DA-6666D477D21E}" refers to invalid object "C:\Program Files\Morpheus\Proto.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{fba38bcf-e23d-4979-811e-1326bbadb8c8}" refers to invalid object "C:\Program Files\Winamp3\Wacs\cddbcontrolwinamp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FBE30D66-39A2-4b72-8B43-6D4C335A6F34}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\YTMsgr.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{0002E540-0000-0000-C000-000000000046}" refers to invalid object "C:\Program Files\Microsoft Office\Office10\MSOWC.DLL". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{01112B01-3E00-11D2-8470-0060089874ED}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgrc.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{13BCDA40-517D-4C60-BF0B-77ED00DA3811}" refers to invalid object "C:\Program Files\Yahoo!\Common\yloginids.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1406C58F-F7A9-11D2-BEF4-00C04F990001}" refers to invalid object "C:\WINDOWS\System32\CfShellFtpRds.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{1DC0E5E5-B0EE-4A72-B89C-5A2AC5EC6455}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\YahooBridgeLib.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{23E164FF-C7FE-4712-9973-4FE9AADA149F}" refers to invalid object "C:\Program Files\AutoCAD 2002\AcDimDynProp.arx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{2573E1B7-096C-4C18-B7B7-7ABE4FFBC86E}" refers to invalid object "C:\Program Files\Morpheus\Proto.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{2B323CCC-50E3-11D3-9466-00A0C9700498}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yacscom.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{2C5D34C5-99DE-4F84-95BE-2F18DC3BE4AB}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\PhotoShare.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{35A57663-BB23-4E81-89C6-B87F580FEC47}" refers to invalid object "C:\Program Files\Yahoo!\Common\yiesrvc.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{36FAA99B-FD56-11D0-A363-00A0246B42E2}" refers to invalid object "C:\WINDOWS\System32\CFRegExp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{390CE9E4-C4A0-11D4-8A92-0090271D4F88}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ycrwin32.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{39DC8E5F-A573-4D58-8A13-6877A3B672EA}" refers to invalid object "C:\temp\sb.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3C2D2A1E-031F-4397-9614-87C932A848E0}" refers to invalid object "C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{3E18E990-2533-11D4-8A2B-0090271D4F88}" refers to invalid object "C:\PROGRA~1\YAHOO!\COMMON\messmod.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{475DAFB5-B05A-4E11-B466-00CF55C1628E}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YAlertCenter.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{48A306FD-E991-4A51-83BF-C232BAC612C9}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\cpcScan.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4A1E52AC-64F2-49E9-BFD7-0806D9494DBB}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\pubmod.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{4EF6E917-8D95-4633-8829-E1B63D8E4321}" refers to invalid object "E:\WinExplorer.exe". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{57738102-1B65-11D2-A645-00C04F99000C}" refers to invalid object "C:\WINDOWS\System32\CFFileProxy.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{59E814B8-59D5-11D4-AA69-001083342C04}" refers to invalid object "C:\temp\AimApi.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{66D3CBC4-D446-4BAA-B8B2-AF97BC09A7D2}" refers to invalid object "C:\Program Files\ahead\Nero\WaveEditor\AudioControl.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{6AE4CC61-999C-11D4-A3F0-009027427750}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yauto.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{6F84EA6C-A074-482D-911D-7C92E59CB16F}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkin2.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{78AF2F21-A9C3-11D3-BF8C-0060B0FCC122}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AcDcToday.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{78DB07DF-483E-4829-AB44-ED7952083584}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\YTMsgr.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{7D1E9C3C-BD6A-11D3-87A8-009027A35D73}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\yacsui.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{863ACC54-F798-44FC-BFFD-E849D99FEEEF}" refers to invalid object "C:\Program Files\Yahoo!\Common\YIeTagBm.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8A1AB044-787D-4309-8410-709768E484AB}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\ypubc.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{8E926E2D-BF6C-11D2-A33D-00A0C94B8D0E}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\stock.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{903A994B-C654-48F9-9E29-84A090F20838}" refers to invalid object "C:\Program Files\Yahoo!\Common\Yshortcut.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{96039CF0-551B-48DC-9DC4-1D5D1E4AF98E}" refers to invalid object "C:\temp\rtvideo.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9A5EC81C-23AD-4192-82C1-298B2058C444}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ft60.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{9D392231-AE8E-11D4-8FD3-00D0B7730277}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ywcvwr.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{A55B64BA-3BAA-11D2-BEBC-00C04FA35D22}" refers to invalid object "C:\WINDOWS\System32\CfRds.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B2865C5C-9F6D-4D28-B600-0BD6E15952C1}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\YPagerChecker.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{B722ED8B-0B38-408E-BB89-260C73BCF3D4}" refers to invalid object "C:\Program Files\Yahoo!\Companion\Installs\cpn\YMERemote.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{BB99E4EE-5085-40AA-919D-0097DAC73212}" refers to invalid object "C:\Program Files\Yahoo!\Common\YVerInfo.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{C652805E-0CD2-4AE7-A633-8300BAB8DAAC}" refers to invalid object "C:\Program Files\Yahoo!\Shared\YbSkinSelect.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DB70C3C4-0C4D-11D2-BEA8-00C04FA35D22}" refers to invalid object "C:\WINDOWS\System32\CFSDebug.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCB43485-19FB-4D6D-BB3D-73C7F48D5F00}" refers to invalid object "C:\Program Files\Messenger\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DCE2F8A1-A520-11D4-8FD0-00D0B7730277}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ywcupl.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{DD95F7E2-D1E5-4572-8D89-11FDE5F68C30}" refers to invalid object "C:\Program Files\Morpheus\DeskBandSearch.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{E5D12C41-7B4F-11D3-B5C9-0050045C3C96}" refers to invalid object "C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{EA2EE474-3090-11D2-BEB7-00C04FA35D22}" refers to invalid object "C:\WINDOWS\System32\cfssvradmin.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F0012D80-989C-11D3-B7C5-0090271D5CA7}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\MyYahoo.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F281A597-7B65-11D3-8617-0010830243BD}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AcPreview.ocx". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{F580EF9E-D49A-11D1-BDB1-00C04F990001}" refers to invalid object "C:\WINDOWS\System32\cfvalidator.dll". Action Taken: No Action Taken.
Entry "HKCR\TypeLib\{FAB4EE40-2D60-11D2-A649-00C04F99000C}" refers to invalid object "C:\WINDOWS\System32\CFFtp.dll". Action Taken: No Action Taken.
Entry "HKCR\.bpl" refers to invalid object "Winamp3.File". Action Taken: No Action Taken.
Entry "HKCR\.eps" refers to invalid object "EncapsulatedPostscript". Action Taken: No Action Taken.
Entry "HKCR\.UMX" refers to invalid object "Winamp3.File". Action Taken: No Action Taken.
Entry "HKCR\.vmdk" refers to invalid object "VMware.VirtualDisk". Action Taken: No Action Taken.
Entry "HKCR\.vmss" refers to invalid object "VMware.SuspendState". Action Taken: No Action Taken.
Entry "HKCR\.wmf" refers to invalid object "WindowsMetafile". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Civ3Edit.Document\shell\open\command" refers to invalid object "C:\PROGRA~1\CIVILI~1\Civ3Edit.exe "%1"". Action Taken: No Action Taken.
Entry "HKCR\Connection Manager Profile\shell\open\command" refers to invalid object "C:\WINDOWS\System32\CMMGR32.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\FireSFV\shell\open\command" refers to invalid object ""C:\mIRC\download\fsfv08\FireSFV.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\forge5" refers to invalid object "{2DA7002D-7E8C-11D4-8151-00C04F612EA4}". Action Taken: No Action Taken.
Entry "HKCR\magnet\shell\open\command" refers to invalid object ""C:\Program Files\Morpheus\Morpheus.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\MiniBugTransporter.MiniBugTransporterX" refers to invalid object "{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}". Action Taken: No Action Taken.
Entry "HKCR\MiniBugTransporter.MiniBugTransporterX.1" refers to invalid object "{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}". Action Taken: No Action Taken.
Entry "HKCR\MoodLogic.DevicePlugin.1\shell\open\command" refers to invalid object ""C:\Program Files\MoodLogic\MoodLogic.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\MoodLogic.Skin.1\shell\open\command" refers to invalid object ""C:\Program Files\MoodLogic\MoodLogic.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\Morpheus\shell\open\command" refers to invalid object ""C:\Program Files\Morpheus\Morpheus.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\morpheustorrent\shell\open\command" refers to invalid object ""c:\program files\morpheus\morpheus.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\Msohelp.HtmlHelp.1" refers to invalid object "{31E0DFD7-2621-11D2-AFD7-006097C9A284}". Action Taken: No Action Taken.
Entry "HKCR\MsohelpAWDlg.1" refers to invalid object "{B58C2441-A1A3-11D2-B024-006097C9A284}". Action Taken: No Action Taken.
Entry "HKCR\MsohelpKeyDlg.1" refers to invalid object "{B58C2440-A1A3-11D2-B024-006097C9A284}". Action Taken: No Action Taken.
Entry "HKCR\pdtfile\shell\open\command" refers to invalid object ""C:\Program Files\Microsoft Office\Office10\WINWORD.EXE" /n /dde "%1"". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\pls_auto_file\shell\open\command" refers to invalid object ""C:\Program Files\Winamp3\Studio.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\ppifile\shell\open\command" refers to invalid object "%SystemRoot%\System32\msppcnfg.exe /Config %1". Action Taken: No Action Taken.
Entry "HKCR\PSWFile\shell\open\command" refers to invalid object ""C:\Program Files\Microsoft Office\Office10\WINWORD.EXE" /n /dde "%1"". Action Taken: No Action Taken.
Entry "HKCR\pwdfile\shell\open\command" refers to invalid object ""C:\Program Files\Microsoft Office\Office10\WINWORD.EXE" /n /dde "%1"". Action Taken: No Action Taken.
Entry "HKCR\pwifile\shell\open\command" refers to invalid object ""C:\Program Files\Microsoft Office\Office10\WINWORD.EXE" /n /dde "%1"". Action Taken: No Action Taken.
Entry "HKCR\pwtfile\shell\open\command" refers to invalid object ""C:\Program Files\Microsoft Office\Office10\WINWORD.EXE" /n /dde "%1"". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.WebPartPage.Document" refers to invalid object "{388ED91D-7FD2-11D0-A60B-00A0C90A43FF}". Action Taken: No Action Taken.
Entry "HKCR\SharePoint.WebPartPage.Document.1.0" refers to invalid object "{388ED91D-7FD2-11D0-A60B-00A0C90A43FF}". Action Taken: No Action Taken.
Entry "HKCR\VideoPak2.Project\shell\open\command" refers to invalid object "C:\PROGRA~1\STOIKV~1\VIDEOP~1.EXE "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.1\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.2\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.3\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.4\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.5\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.6\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WinExplorer.Document.7\shell\open\command" refers to invalid object ""E:\WinExplorer.exe" "%1"". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\Ybmfile\shell\open\command" refers to invalid object "C:\PROGRA~1\YAHOO!\COMMON\YSHORT~1.EXE %1". Action Taken: No Action Taken.
Entry "HKCR\YIeTagBm.YahooTaggedBM" refers to invalid object "{65D886A2-7CA7-479B-BB95-14D1EFB7946A}". Action Taken: No Action Taken.
Entry "HKCR\YIeTagBm.YahooTaggedBM.1" refers to invalid object "{65D886A2-7CA7-479B-BB95-14D1EFB7946A}". Action Taken: No Action Taken.
Entry "HKCR\ymsgr\shell\open\command" refers to invalid object ""C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE" %1". Action Taken: No Action Taken.
Entry "HKCR\Ypager.Messenger\shell\open\command" refers to invalid object ""C:\PROGRA~1\YAHOO!\MESSEN~1\YPager.exe" %1". Action Taken: No Action Taken.
Entry "HKCR\Ypager.Messenger.1\shell\open\command" refers to invalid object ""C:\PROGRA~1\YAHOO!\MESSEN~1\YPager.exe" %1". Action Taken: No Action Taken.
Entry "HKCR\YUber.UberButton" refers to invalid object "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}". Action Taken: No Action Taken.
Entry "HKCR\YUber.UberButton.1" refers to invalid object "{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}". Action Taken: No Action Taken.
File C:\mIRC6.12 Invision2.0\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\07640000.VBN infected by "Trojan.Java.ClassLoader.c" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06F40000.VBN infected by "Virus.MSWord.Marker.fq2" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\06F40001.VBN infected by "Virus.MSWord.Marker.fq2" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Shannon\My Documents\Invision_2.0_[for_mIRC_6.12].rar tagged as not-a-virus:Client-IRC.Win32.mIRC.612. No Action Taken.
File C:\Documents and Settings\Shannon\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-1464f57b.zip infected by "Trojan-Downloader.Java.OpenStream.w" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5AB87D84 infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\2560077D infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\74C64FFE infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5ABC2781 infected by "Virus.Win32.HLLP.Hantaner.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\6B29657C infected by "Virus.Win32.HLLP.Hantaner.a" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\1D115F55 infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\07730489 infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\5ABF517D infected by "Email-Worm.Win32.Klez.h" Virus! Action Taken: No Action Taken.
 

·
Registered
Joined
·
10 Posts
Discussion Starter #11
please dont forget me....

any ideas guys? i am about to give up and reinstall windows. i just got a new hard drive in the mail, but i would like to fix the problem first.
thanks sooooo much :)
 

·
Premium Member
Joined
·
14,311 Posts
Do you still require assistance now or did you reinstall Windows already?
 

·
Registered
Joined
·
10 Posts
Discussion Starter #13
still need help

i haven't reinstalled windows yet. too busy with school. any advice would be greatly appreicated. If i dont solve this by the weekend, i will reinstall. but i think i should try to correct the problem first if i can.
thanks
 

·
Premium Member
Joined
·
14,311 Posts
Hope you're still there...

Delete this file:

C:\Documents and Settings\Shannon\My Documents\Invision_2.0_[for_mIRC_6.12].rar


For these two folders:

C:\Program Files\Norton AntiVirus\Quarantine\
C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\


I want to delete everything in those folders.

So the problem still ist that your IM programs and IE doesn't work? Boot into Safe Mode with networking support. Can you go online with those programs now? If you can, then there's a program blocking those programs from accessing the internet. Do you have the Norton Firewall program installed?
 
1 - 14 of 14 Posts
Status
Not open for further replies.
Top