Spyware, Viruses, & Security forum

General discussion

Adware/Spyware

W98SE, IE6.0, SP2
Installed: AdAware, Spybot Search & Destroy, SpywareBlaster.

I did a scan on Pest Patrol and the scan found the following adware/spyware:

Hi-Wire - Adware
BonziBuddy - Spyware
AdShooter.SearchForIt - Adware

I'm wondering why AdAware or the other programs didn't find these items. Also, how do I remove them, please?

TIA

Discussion is locked
You are posting a reply to: Adware/Spyware
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: Adware/Spyware
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Re: Adware/Spyware

In reply to: Adware/Spyware

Collapse -
Re: Adware/Spyware

In reply to: Re: Adware/Spyware

Donna: None of these items are "running" or installed on my PC. In reading Pest Patrol's removal procedures it sounds as though they should be installed programs. Am I wrong?

TIA

Collapse -
Re: Adware/Spyware

In reply to: Re: Adware/Spyware

Shirley,

Now this is interesting. If PestPatrol really detected those items, you should see the following items in your system:

1. Hi-wire - you should see: hwmedia.exe or hwreal.exe if you'll press Ctrl+Alt+delete as running.
Use the search utility of Windows to find them:
hwaudio.dll
hwutils.dll
hwmedia.exe
hwreal.exe

You should see the following in Windows registry:
HKEY_CLASSES_ROOT\adagent.advertisementagent
HKEY_CLASSES_ROOT\adagent.advertisementagent.1
HKEY_CLASSES_ROOT\adagent.bannerlistitem
HKEY_CLASSES_ROOT\adagent.bannerlistitem.1
HKEY_CLASSES_ROOT\adagent.compositeitem
HKEY_CLASSES_ROOT\adagent.compositeitem.1
HKEY_CLASSES_ROOT\adagent.spotlistitem
HKEY_CLASSES_ROOT\adagent.spotlistitem.1
HKEY_CLASSES_ROOT\clsid\{08e05eee-5ee9-11d4-9caf-00d0b76063fd}
HKEY_CLASSES_ROOT\clsid\{11032fc2-c2f4-11d3-ad67-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{11032fc2-c2f5-11d3-ad67-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{28f00b04-dc4e-11d3-abec-005004a44eeb}
HKEY_CLASSES_ROOT\clsid\{28f00b0f-dc4e-11d3-abec-005004a44eeb}
HKEY_CLASSES_ROOT\clsid\{28f00b20-dc4e-11d3-abec-005004a44eeb}
HKEY_CLASSES_ROOT\clsid\{28f00b21-dc4e-11d3-abec-005004a44eeb}
HKEY_CLASSES_ROOT\clsid\{315ffe67-cebe-11d3-ad70-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{5ca9d47f-4bbc-45e0-815f-670ae736a678}
HKEY_CLASSES_ROOT\clsid\{5dcde22e-e64f-11d3-ad74-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{5dcde22e-e650-11d3-ad74-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{80f1b906-d066-11d3-ad70-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{bcddab74-c3a8-11d3-ad69-009027b8adbc}
HKEY_CLASSES_ROOT\clsid\{c357398a-8e21-4505-8bd7-784a4e9ac659}
HKEY_CLASSES_ROOT\clsid\{c357398b-8e21-4505-8bd7-784a4e9ac659}
HKEY_CLASSES_ROOT\clsid\{c357398c-8e21-4505-8bd7-784a4e9ac659}
HKEY_CLASSES_ROOT\hiwire.configurator
HKEY_CLASSES_ROOT\hiwire.configurator.1
HKEY_CLASSES_ROOT\hiwire.register
HKEY_CLASSES_ROOT\hiwire.register.1
HKEY_CLASSES_ROOT\hiwire.transportcenter
HKEY_CLASSES_ROOT\hiwire.transportcenter.1
HKEY_CLASSES_ROOT\hiwire.userregrequest
HKEY_CLASSES_ROOT\hiwire.userregrequest.1
HKEY_CLASSES_ROOT\hwadinsertion.adplayer
HKEY_CLASSES_ROOT\hwadinsertion.adplayer.1
HKEY_CLASSES_ROOT\hwadinsertion.adscheduler
HKEY_CLASSES_ROOT\hwadinsertion.adscheduler.1
HKEY_CLASSES_ROOT\hwadinsertion.audioplayers
HKEY_CLASSES_ROOT\hwadinsertion.audioplayers.1
HKEY_CLASSES_ROOT\hwadinsertion.radioplayers
HKEY_CLASSES_ROOT\hwadinsertion.radioplayers.1
HKEY_CLASSES_ROOT\hwadinsertion.realadplayer
HKEY_CLASSES_ROOT\hwadinsertion.realadplayer.1
HKEY_CLASSES_ROOT\hwadinsertion.rreventmanager
HKEY_CLASSES_ROOT\hwadinsertion.rreventmanager.1
HKEY_CLASSES_ROOT\hwwebplayer.webplayer
HKEY_CLASSES_ROOT\hwwebplayer.webplayer.1
HKEY_CLASSES_ROOT\rmactivex.rmplayer
HKEY_CLASSES_ROOT\rmactivex.rmplayer.1
HKEY_CLASSES_ROOT\typelib\{08e05ee1-5ee9-11d4-9caf-00d0b76063fd}
HKEY_CLASSES_ROOT\typelib\{96b2d8d3-e66d-11d3-ad74-009027b8adbc}
HKEY_CLASSES_ROOT\typelib\{edc2d623-4d9e-4c3e-843f-74b1b2429b43}
HKEY_CLASSES_ROOT\typelib\{f5ee52d3-2ecc-409e-a92f-a73f2b8dd407}
HKEY_CURRENT_USER\software\hiwire
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{28f00b0f-dc4e-11d3-abec-005004a44eeb}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{80f1b906-d066-11d3-ad70-009027b8adbc}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hwaudio.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hwmedia.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hwreal.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hwutils.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\hwaudio.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\hwmedia.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\hwreal.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\downloaded program files\hwutils.dll

If none of them exist then PestPatrol is wrong. Marketing?

2. BonziBuddy

You should see the following in your registry:
HKEY_CLASSES_ROOT\.bbma
HKEY_CLASSES_ROOT\.bonzimail_message
HKEY_CLASSES_ROOT\bonzibdy.document
HKEY_CLASSES_ROOT\bonzibuddy.ccalendarvbperiod
HKEY_CLASSES_ROOT\bonzibuddy.ccalendarvbperiods
HKEY_CLASSES_ROOT\bonzibuddy.clsaddressbook
HKEY_CLASSES_ROOT\bonzibuddy.clsbbplayer
HKEY_CLASSES_ROOT\bonzibuddy.clsclickthebutton
HKEY_CLASSES_ROOT\bonzibuddy.clsdownloadmanager
HKEY_CLASSES_ROOT\bonzibuddy.clsstoryreader
HKEY_CLASSES_ROOT\bonzibuddy.cperiod
HKEY_CLASSES_ROOT\bonzibuddy.cperiods
HKEY_CLASSES_ROOT\bonzictbhelper.clsbonzictbhelper
HKEY_CLASSES_ROOT\bonzimail_messagefile
HKEY_CLASSES_ROOT\bonzitapfilters.clsbonzicontent
HKEY_CLASSES_ROOT\bonzitapfilters.clscommanddownloadfile
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandhttppost
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandmsgbox
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandmsgboxonno
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandmsgboxonyes
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandopenweb
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandplay
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandraiseevent
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandsetiehomepage
HKEY_CLASSES_ROOT\bonzitapfilters.clscommandspeak
HKEY_CLASSES_ROOT\bonzitapfilters.clscontent
HKEY_CLASSES_ROOT\bonzitapfilters.clsfiltration
HKEY_CLASSES_ROOT\bonzitapfilters.clstapevent
HKEY_CLASSES_ROOT\clsid\{f4900f67-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f6a-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f8d-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f96-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{22eb59ae-1cb8-4153-9dfc-b5ce048357cf}
HKEY_CLASSES_ROOT\clsid\{3b89ad5a-42a2-4258-9242-d67eb0c80442}
HKEY_CLASSES_ROOT\clsid\{50a2c2b1-5a56-4183-b1d0-3f59877bad60}
HKEY_CLASSES_ROOT\clsid\{53f082c5-72fe-49d5-a34f-c054cad30dd0}
HKEY_CLASSES_ROOT\clsid\{57da7e73-b94f-49a2-9fef-9f4b40c8e221}
HKEY_CLASSES_ROOT\clsid\{5d11b6dc-358a-44b3-b2ac-22b5dcbc936b}
HKEY_CLASSES_ROOT\clsid\{6a96c266-f125-4d60-8be0-c247349a7ce4}
HKEY_CLASSES_ROOT\clsid\{7c3845b5-4b34-43ce-99de-3bfad5308e68}
HKEY_CLASSES_ROOT\clsid\{82ca10ae-d2f8-441e-a01d-4dfc46f37612}
HKEY_CLASSES_ROOT\clsid\{837cca31-1813-40ea-80bc-aba9d97cb64b}
HKEY_CLASSES_ROOT\clsid\{856b6cbe-b0c1-4b4d-8586-2d6e9df3e4f2}
HKEY_CLASSES_ROOT\clsid\{962f96f8-624c-4b0e-b055-f2f1d1deff0e}
HKEY_CLASSES_ROOT\clsid\{a031fbf6-81a7-4440-9e20-51abb2289e4b}
HKEY_CLASSES_ROOT\clsid\{a28c2a31-3ab0-4118-922f-f6b3184f5495}
HKEY_CLASSES_ROOT\clsid\{a7aa73e0-f6f9-4967-b209-aa1b11c47dcf}
HKEY_CLASSES_ROOT\clsid\{aab7faed-91f8-4591-8e4c-9291d2b7f381}
HKEY_CLASSES_ROOT\clsid\{bd11a280-2e73-11cf-b6cf-00aa00a74daf}
HKEY_CLASSES_ROOT\clsid\{cb6f59f9-fa69-4d14-9d96-4bb3190e3df5}
HKEY_CLASSES_ROOT\clsid\{d3cd5f89-bfe3-4bad-ac10-25751a08811c}
HKEY_CLASSES_ROOT\clsid\{e26dd3cd-b06c-47ba-9766-5f264b858e09}
HKEY_CLASSES_ROOT\clsid\{e509d0e0-da02-4d16-ba63-70f23cac74c8}
HKEY_CLASSES_ROOT\clsid\{f2394898-748d-4415-8ce8-65e429445b33}
HKEY_CLASSES_ROOT\clsid\{f4900f5d-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f67-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f6a-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f8d-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f4900f96-055f-11d4-8f9b-00104ba312d6}
HKEY_CLASSES_ROOT\clsid\{f5a31f2f-122f-4615-a9b7-90841538ec7c}
HKEY_CLASSES_ROOT\clsid\{f77a2b0f-476c-4536-beb1-2cb17ca6bcbc}
HKEY_CLASSES_ROOT\clsid\{f91f3264-454b-45be-a402-fe0e56bb9315}
HKEY_CLASSES_ROOT\clsid\{fe56c7a2-aaf1-47f2-9b68-4057d7ff5b4a}
HKEY_CLASSES_ROOT\interface\{6a96c266-f125-4d60-8be0-c247349a7ce4}
HKEY_CLASSES_ROOT\interface\{cb6f59f9-fa69-4d14-9d96-4bb3190e3df5}
HKEY_CLASSES_ROOT\mime\database\content type\application/bonzi-mail-message
HKEY_CLASSES_ROOT\mime\database\content type\application\/bonzi-mail-message
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{a28c2a31-3ab0-4118-922f-f6b3184f5495}
HKEY_CLASSES_ROOT\typelib\{50a2c2b1-5a56-4183-b1d0-3f59877bad60}
HKEY_CLASSES_ROOT\typelib\{aab7faed-91f8-4591-8e4c-9291d2b7f381}
HKEY_CLASSES_ROOT\typelib\{f4900f5d-055f-11d4-8f9b-00104ba312d6}
HKEY_CURRENT_USER\software\vb and vba program settings\bonzibuddy
HKEY_LOCAL_MACHINE\clsid\{a28c2a31-3ab0-4118-922f-f6b3184f5495}
HKEY_LOCAL_MACHINE\software\bonzi software
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.ccalendarvbperiod
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.ccalendarvbperiods
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsaddressbook
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsbbplayer
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsclickthebutton
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsdownloadmanager
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsregistration
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.clsstoryreader
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.cperiod
HKEY_LOCAL_MACHINE\software\classes\bonzibuddy.cperiods
HKEY_LOCAL_MACHINE\software\classes\bonzictbhelper.clsbonzictbhelper
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clsbonzicontent
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandclosetoast
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommanddownloadfile
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandhttppost
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandmsgbox
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandmsgboxonno
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandmsgboxonyes
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandopenweb
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandplay
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandraiseevent
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandsetiehomepage
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandshowtoast
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscommandspeak
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clscontent
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clsfiltration
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clssubscription
HKEY_LOCAL_MACHINE\software\classes\bonzitapfilters.clstapevent
HKEY_LOCAL_MACHINE\software\classes\clsid\{210787c2-92b0-4776-8e80-14c02174893d}
HKEY_LOCAL_MACHINE\software\classes\clsid\{22eb59ae-1cb8-4153-9dfc-b5ce048357cf}
HKEY_LOCAL_MACHINE\software\classes\clsid\{3b89ad5a-42a2-4258-9242-d67eb0c80442}
HKEY_LOCAL_MACHINE\software\classes\clsid\{4610e7bf-710f-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\clsid\{53f082c5-72fe-49d5-a34f-c054cad30dd0}
HKEY_LOCAL_MACHINE\software\classes\clsid\{57da7e73-b94f-49a2-9fef-9f4b40c8e221}
HKEY_LOCAL_MACHINE\software\classes\clsid\{5d11b6dc-358a-44b3-b2ac-22b5dcbc936b}
HKEY_LOCAL_MACHINE\software\classes\clsid\{6b1be804-567f-11d1-b652-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\clsid\{71a2702f-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27032-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27034-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7b6b6079-a483-43f4-9376-1cc374ba3600}
HKEY_LOCAL_MACHINE\software\classes\clsid\{7c3845b5-4b34-43ce-99de-3bfad5308e68}
HKEY_LOCAL_MACHINE\software\classes\clsid\{80de8b24-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\clsid\{82ca10ae-d2f8-441e-a01d-4dfc46f37612}
HKEY_LOCAL_MACHINE\software\classes\clsid\{837cca31-1813-40ea-80bc-aba9d97cb64b}
HKEY_LOCAL_MACHINE\software\classes\clsid\{83d4679e-b6d7-11d2-bf36-00c04fb90a03}
HKEY_LOCAL_MACHINE\software\classes\clsid\{856b6cbe-b0c1-4b4d-8586-2d6e9df3e4f2}
HKEY_LOCAL_MACHINE\software\classes\clsid\{86e5d750-02eb-11d3-a464-0080c858f182}
HKEY_LOCAL_MACHINE\software\classes\clsid\{962f96f8-624c-4b0e-b055-f2f1d1deff0e}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a031fbf6-81a7-4440-9e20-51abb2289e4b}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a28c2a31-3ab0-4118-922f-f6b3184f5495}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a7aa73e0-f6f9-4967-b209-aa1b11c47dcf}
HKEY_LOCAL_MACHINE\software\classes\clsid\{aaa403c6-03b3-11d3-a465-0080c858f182}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d3cd5f89-bfe3-4bad-ac10-25751a08811c}
HKEY_LOCAL_MACHINE\software\classes\clsid\{d985e1b8-e314-4d36-b095-ebd4c5295f69}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e0faf7cf-d53e-11d1-9a1c-00c04fb90a03}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e26dd3cd-b06c-47ba-9766-5f264b858e09}
HKEY_LOCAL_MACHINE\software\classes\clsid\{e509d0e0-da02-4d16-ba63-70f23cac74c8}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f2394898-748d-4415-8ce8-65e429445b33}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f4900f67-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f4900f6a-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f4900f8d-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f4900f96-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f5a31f2f-122f-4615-a9b7-90841538ec7c}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f77a2b0f-476c-4536-beb1-2cb17ca6bcbc}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f8b44545-c2e0-46c3-b78b-11e821c9d2e1}
HKEY_LOCAL_MACHINE\software\classes\clsid\{f91f3264-454b-45be-a402-fe0e56bb9315}
HKEY_LOCAL_MACHINE\software\classes\clsid\{fe56c7a2-aaf1-47f2-9b68-4057d7ff5b4a}
HKEY_LOCAL_MACHINE\software\classes\interface\{0570bf7b-e1bf-4ef3-bc37-7ae3f54bd605}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd2-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd4-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd5-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd6-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd7-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd9-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fdb-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fdd-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fde-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe0-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe1-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe2-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe4-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe5-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe7-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe8-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{0a45db49-bd0d-11d2-8d14-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{0a45db4b-bd0d-11d2-8d14-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{0a45db4d-bd0d-11d2-8d14-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{0a45db4e-bd0d-11d2-8d14-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{120c5484-09ba-4936-98b9-1b0c15c9ce5e}
HKEY_LOCAL_MACHINE\software\classes\interface\{159c2806-4a71-45b4-8d4e-74c181cd6842}
HKEY_LOCAL_MACHINE\software\classes\interface\{17b3c2cb-6697-4736-bee7-69f363f1f35e}
HKEY_LOCAL_MACHINE\software\classes\interface\{22df5084-12bc-4c98-8044-4fad06f4119a}
HKEY_LOCAL_MACHINE\software\classes\interface\{28e4193c-f276-4568-bcdc-dd15d88fadcc}
HKEY_LOCAL_MACHINE\software\classes\interface\{3d08842d-983e-4226-8d6e-612965eb32d9}
HKEY_LOCAL_MACHINE\software\classes\interface\{44279f35-8ed3-4234-9d61-069ae93efbec}
HKEY_LOCAL_MACHINE\software\classes\interface\{4610e7bd-710f-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{4610e7be-710f-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{4bbfaacc-619c-4a9d-a32c-a8b3453ce783}
HKEY_LOCAL_MACHINE\software\classes\interface\{565029f7-d84e-4edc-bf87-a204645da3ea}
HKEY_LOCAL_MACHINE\software\classes\interface\{62fcac31-2581-11d2-baf1-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\interface\{6549f504-c43a-43f3-b8cd-d077af0427c8}
HKEY_LOCAL_MACHINE\software\classes\interface\{6a96c266-f125-4d60-8be0-c247349a7ce4}
HKEY_LOCAL_MACHINE\software\classes\interface\{6b1be803-567f-11d1-b652-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\interface\{6b1be807-567f-11d1-b652-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\interface\{6dc6a7a5-0862-406e-8fd9-e4d5adb93aed}
HKEY_LOCAL_MACHINE\software\classes\interface\{71a2702e-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\interface\{71a27031-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\interface\{71a27033-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\interface\{71a27036-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\interface\{7679e16d-9af0-439d-be07-7bff15459c59}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b1b-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b1c-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b1d-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b1e-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b1f-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b20-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b21-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{80de8b23-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\interface\{86e5d74f-02eb-11d3-a464-0080c858f182}
HKEY_LOCAL_MACHINE\software\classes\interface\{86e5d751-02eb-11d3-a464-0080c858f182}
HKEY_LOCAL_MACHINE\software\classes\interface\{89e800de-5c96-4802-8da6-2cf50c9d19af}
HKEY_LOCAL_MACHINE\software\classes\interface\{8cfc92fa-7057-4a98-a3be-9c34d3d255fd}
HKEY_LOCAL_MACHINE\software\classes\interface\{8db2224e-d2fa-4b2e-8402-085ea7cc826b}
HKEY_LOCAL_MACHINE\software\classes\interface\{8e71a3f9-cecf-4dc4-accf-3dd01c843a45}
HKEY_LOCAL_MACHINE\software\classes\interface\{916694a8-8ad6-11d2-b6fd-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\interface\{916694a9-8ad6-11d2-b6fd-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\interface\{993d6cac-49a8-40d9-bd97-405281136e78}
HKEY_LOCAL_MACHINE\software\classes\interface\{9fbcd665-010a-4c21-be40-9de2bdf34e50}
HKEY_LOCAL_MACHINE\software\classes\interface\{a4e0988e-24be-4570-b4d8-982f1386e0c6}
HKEY_LOCAL_MACHINE\software\classes\interface\{a56be8e7-6b37-43dd-88f4-6d42e57ca1d7}
HKEY_LOCAL_MACHINE\software\classes\interface\{b2676d5b-8d53-4569-af2c-a55a0d90c132}
HKEY_LOCAL_MACHINE\software\classes\interface\{bd6f0855-7792-4131-a06f-aa2a991e0549}
HKEY_LOCAL_MACHINE\software\classes\interface\{cb6f59f9-fa69-4d14-9d96-4bb3190e3df5}
HKEY_LOCAL_MACHINE\software\classes\interface\{d7ba20a4-7049-416f-a7e4-97530442d62f}
HKEY_LOCAL_MACHINE\software\classes\interface\{dacb7a39-cc0d-4b85-908b-10d2451761a5}
HKEY_LOCAL_MACHINE\software\classes\interface\{decc98e1-ec4e-11d2-93e5-00104b9e078a}
HKEY_LOCAL_MACHINE\software\classes\interface\{e91e27a1-c5ae-11d2-8d1b-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{e91e27a2-c5ae-11d2-8d1b-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4043742-ac8d-4f86-88e9-f3fd3369dd8c}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f66-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f68-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f69-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f6b-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f8c-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{f4900f95-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\classes\interface\{fdf3d1e0-2da2-4238-af4f-026670289749}
HKEY_LOCAL_MACHINE\software\classes\typelib\{065e6fd1-1bf9-11d2-bae8-00104b9e0792}
HKEY_LOCAL_MACHINE\software\classes\typelib\{0a45db48-bd0d-11d2-8d14-00104b9e072a}
HKEY_LOCAL_MACHINE\software\classes\typelib\{4b7f8bf4-99c2-11d2-b3c3-00a0cc3a50b9}
HKEY_LOCAL_MACHINE\software\classes\typelib\{50a2c2b1-5a56-4183-b1d0-3f59877bad60}
HKEY_LOCAL_MACHINE\software\classes\typelib\{6b1be80a-567f-11d1-b652-0060976c699f}
HKEY_LOCAL_MACHINE\software\classes\typelib\{71a2702d-c7d8-11d2-bef8-525400dfb47a}
HKEY_LOCAL_MACHINE\software\classes\typelib\{80de8b22-710a-11d3-813d-00c04f6b92d0}
HKEY_LOCAL_MACHINE\software\classes\typelib\{83d4678d-b6d7-11d2-bf36-00c04fb90a03}
HKEY_LOCAL_MACHINE\software\classes\typelib\{86e5d740-02eb-11d3-a464-0080c858f182}
HKEY_LOCAL_MACHINE\software\classes\typelib\{aab7faed-91f8-4591-8e4c-9291d2b7f381}
HKEY_LOCAL_MACHINE\software\classes\typelib\{ac6f478c-d48d-11d1-9a1b-00c04fb90a03}
HKEY_LOCAL_MACHINE\software\classes\typelib\{f4900f5d-055f-11d4-8f9b-00104ba312d6}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{a28c2a31-3ab0-4118-922f-f6b3184f5495}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bonzi buddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\bonzibuddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\clickthebutton
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\program files\bonzibuddy\bbuddymini.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\program files\limewire\2.8.6\bonzi.url
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\program files\limewire\3.6.15\bonzi.url
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\msagent\chars\short.acs
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\system\iehelpermiddleman.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\windows\system32\bonzitapfilters.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\winnt\system32\bonzitapfilters.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\d:\program files\bonzibuddy\bbuddymini.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\d:\program files\limewire\3.6.6\bonzi.url
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\d:\windows\system32\bonzitapfilters.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\d:\winnt\system32\bonzitapfilters.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bonzibuddy
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bonzibuddy\displayname
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\bonzibuddy\uninstallstring

and the following in your system:

c:\windows\system32\bonzitapfilters.dll
programfilesdir+\bonzi.com web compass\wclogic.dll
programfilesdir+\bonzi.com web compass\webcompass.dll
programfilesdir+\bonzibuddy\bonzictb.dll
systemroot+\lastgood\lhsp\tv\tv_enua.dll
systemroot+\lastgood\lhsp\tv\tvenuax.dll
systemroot+\lastgood\speech\spchtel.dll
systemroot+\lastgood\speech\speech.dll
systemroot+\lastgood\speech\vcmshl.dll
systemroot+\lastgood\speech\vdict.dll
systemroot+\lastgood\speech\vtext.dll
systemroot+\lastgood\speech\wrapsapi.dll
systemroot+\lastgood\speech\xcommand.dll
systemroot+\lastgood\speech\xlisten.dll
systemroot+\lastgood\speech\xtel.dll
systemroot+\lastgood\speech\xvoice.dll
systemroot+\system\bonzitapfilters.dll
systemroot+\system\webcompass.dll
systemroot+\system32\bonzitapfilters.dll
systemroot+\system32\webcompass.dll
webcompassbar.dll

If none of them exist, false scan result again.

3. AdShooter.SearchForIt

Look for:
basis.dst
basis.kwd
basis.pu
basis.pu.dyn
basis.rst
commonprograms+\earn\about earn.lnk
commonprograms+\earn\earn website.url
dnldapp.cfg
eabh.dll
ezstub.exe
favorites+\hot sites\amateurs\college **** tour.url
favorites+\hot sites\amateurs\discount amateur pass.url
favorites+\hot sites\amateurs\i want amateurs.url
favorites+\hot sites\amateurs\milf riders.url
favorites+\hot sites\amateurs\simply amateur.url
favorites+\hot sites\anal\anal cravings.url
favorites+\hot sites\anal\discount hardcore pass.url
favorites+\hot sites\asian\asian cream.url
favorites+\hot sites\asian\discount asian pass.url
favorites+\hot sites\asian\interracial tv.url
favorites+\hot sites\big *****\discount ***** pass.url
favorites+\hot sites\big *****\real and natural.url
favorites+\hot sites\big ****\discount monster **** sex pass.url
favorites+\hot sites\big ****\freakish cocks.url
favorites+\hot sites\big ****\monster **** farm.url
favorites+\hot sites\big ****\white ***** black cocks.url
favorites+\hot sites\college\college **** tour.url
favorites+\hot sites\college\discount collegegirls pass.url
favorites+\hot sites\college\teen sluts gone wild.url
favorites+\hot sites\ebony\discount ebony pass.url
favorites+\hot sites\ebony\ebony girls online.url
favorites+\hot sites\ebony\interracial tv.url
favorites+\hot sites\ebony\white ***** black cocks.url
favorites+\hot sites\facials\discount facials pass.url
favorites+\hot sites\facials\facial buffet.url
favorites+\hot sites\facials\hot sperm facials.url
favorites+\hot sites\fetish\discount gangbang pass.url
favorites+\hot sites\fetish\fetish view.url
favorites+\hot sites\fetish\mature hotel.url
favorites+\hot sites\fetish\orgy fantasy.url
favorites+\hot sites\hairy\bush hunter.url
favorites+\hot sites\interracial\asian cream.url
favorites+\hot sites\interracial\discount interracial pass.url
favorites+\hot sites\interracial\interracial tv.url
favorites+\hot sites\interracial\white ***** black cocks.url
favorites+\hot sites\latina\discount latina pass.url
favorites+\hot sites\latina\wild latina girls.url
favorites+\hot sites\lesbian\discount lesbian pass.url
favorites+\hot sites\lesbian\lesbian lessons.url
favorites+\hot sites\lesbian\lesbo rama.url
favorites+\hot sites\mature\discount mature pass.url
favorites+\hot sites\mature\mature hotel.url
favorites+\hot sites\mature\milf riders.url
favorites+\hot sites\movies\adult movie network.url
favorites+\hot sites\movies\adult video network.url
favorites+\hot sites\movies\adult xxx pornstars.url
favorites+\hot sites\movies\discount broadband pass.url
favorites+\hot sites\movies\discount move pass.url
favorites+\hot sites\movies\discount porn star pass.url
favorites+\hot sites\movies\discount video pass.url
favorites+\hot sites\movies\hardcore movie station.url
favorites+\hot sites\movies\movie erotica.url
favorites+\hot sites\petite\discount petite pass.url
favorites+\hot sites\petite\petite beaver.url
favorites+\hot sites\petite\teen sluts gone wild.url
favorites+\hot sites\petite\teen thrills.url
favorites+\hot sites\reality\college **** tour.url
favorites+\hot sites\reality\discount live cam pass.url
favorites+\hot sites\reality\lesbian lessons.url
favorites+\hot sites\reality\milf riders.url
favorites+\hot sites\reality\teen sluts gone wild.url
favorites+\hot sites\reality\white ***** black cocks.url
favorites+\hot sites\shaved\18 teen live.url
favorites+\hot sites\shaved\shaved'n wet.url
favorites+\hot sites\teen\18 teen live.url
favorites+\hot sites\teen\college **** tour.url
favorites+\hot sites\teen\discount teen pass.url
favorites+\hot sites\teen\pure teen porn.url
favorites+\hot sites\teen\teen sluts gone wild.url
favorites+\hot sites\teen\teen thrills.url
favorites+\hot sites\toons\discount anime pass.url
favorites+\hot sites\toons\hentai xxx sex.url
favorites+\hot sites\toons\**** toons.url
favorites+\hot sites\tranny\discount shemale pass.url
favorites+\hot sites\tranny\real trannies.url
favorites+\hot sites\tranny\shemale seduction.url
install.log
mmod.exe
programfilesdir+\clocksync\screen\index.htm
seng.dll
sync.exe
systemroot+\system\syssfitb.dll
systemroot+\system32\syssfitb.dll
wndbannn.src

commonprograms+\earn
favorites+\hot sites\amateurs
favorites+\hot sites\anal
favorites+\hot sites\asian
favorites+\hot sites\big *****
favorites+\hot sites\big ****
favorites+\hot sites\college
favorites+\hot sites\ebony
favorites+\hot sites\facials
favorites+\hot sites\fetish
favorites+\hot sites\hairy
favorites+\hot sites\interracial
favorites+\hot sites\latina
favorites+\hot sites\lesbian
favorites+\hot sites\mature
favorites+\hot sites\movies
favorites+\hot sites\petite
favorites+\hot sites\reality
favorites+\hot sites\shaved
favorites+\hot sites\teen
favorites+\hot sites\toons
favorites+\hot sites\tranny
programfilesdir+\clocksync\screen

If doesn't exist, forget PestPatrol scan result.

Collapse -
Re: Adware/Spyware

In reply to: Re: Adware/Spyware

Same thing here, Pest Patrol found adshooter.Searchforit , but I didn't found any of the running processes and/or files mention, although I found the registry entry -

hkey_local_machine\oftware\Microsoft\IE\activex compatibility\{c109664b-ceb-420b-b353-d55a561536dd}

Should I delete this key?

Thank You

Collapse -
Re: Adware/Spyware

In reply to: Re: Adware/Spyware

Hi

That means PP is detecting what others can't Grin

http://computercops.biz/clsid-899.html

Should I delete this key?

Try to delete it then run another online scan using PP. See what it will show this time.

Note (not needed but recommended): Export that HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C109664B-CEB1-420B-B353-D55A561536DD} string/key first before deleting it so if anything goes wrong you can simply merge it or if possible, run the BackUp utility in Windows XP to backup your windows registry.

Collapse -
Shirley

In reply to: Re: Adware/Spyware

I and I'm sure some regulars here would like to hear if any of those files and registry entries really exist in your system.

When I ran PestPatrol scan last time, it detected broweraid. I investigate by looking for the "file or registry entry" that it does exist. It does so it is not false or wrong detection by PestPatrol to my system.

The other day, I ran another scan, it found spyster. It exist so it's not detecting a ghost file (or doesn't exist) but its so happen that the detected spyster is a related to a trusted/safe program so I ignored it.

I will really appreciate Shirley, if you could spend time to search for those files/registry if they really exist before you'll allow any anti-spyware program to clean it.

You might also want to consider running another online scan using another free online service by:
Aluria free spyware scanner

If they exist, just follow the manual removal method from the link I provided earlier or download the trial of PestPatrol to get rid of them.

Thanks!

Collapse -
Re: Donna

In reply to: Shirley

None of these items show up when I press CTRL, ALT, DEL.

I did a "Find" for most of the files and found nothing.

I will check the registry items tomorrow, but I don't think I will find anything. Will let you know tomorrow.

Thank you.

Collapse -
(NT) (NT) Thanks Shirley. Excited to hear from you :)

In reply to: Re: Donna

Collapse -
Re: Donna, it took a while,

In reply to: (NT) Thanks Shirley. Excited to hear from you :)

but I checked all of the items and the only thing I fould was:

HKey-Current User\software\hiwire (should I remove this?)

None of these programs are installed, as I mentioned before.

Collapse -
Re: Donna, it took a while,

In reply to: Re: Donna, it took a while,

Hi,

Thanks Shirley for writing back. You should delete it. Just be careful in deleting entry. Make sure you are deleting the bad string.
If possible export the key/string as your backup copy just in case. Or backup your registry.

You should also use BHODemon from http://www.definitivesolutions.com/bhodemon.htm

Collapse -
Re: Donna, it took a while,

In reply to: Re: Donna, it took a while,

I find this very interesting because on another board, people were complaining that PP was finding many things that Adaware and Spybot weren't. After they checked it out, they really had nothing. I think PP is not very reliable. I'll stick with Adaware.

Popular Forums

icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

GRAMMYS 2019

Here's Everything to Know About the 2019 Grammys

Find out how to watch the Grammy Awards if you don't have cable and more.