Hi
I’m not an avast user…yet. This site was recommended to me as a great place for help.
A couple of days ago, I was hit with w32:checkout. When I saw something was going on, I got off line and ran a scan with mcafee. It found and quarinted the bug. I turned off system restore, rebooted and rescanned. the system showed clean. Created a new restore point and scanned with avg anti spyware and sas. Neither found much other than cookies and a toolbar which has weater reports.
avg (without cookies)
C:\Program Files\HbTools\HBTV\HBTV.exe → Adware.180Solutions : Ignored.
C:\Program Files\HbTools\HBTV\uninstaller.exe → Adware.180Solutions : Ignored.
C:\Program Files\HbTools\Bin\4.8.4.0\Cml.exe → Adware.HotBar : Ignored.
C:\Program Files\HbTools\Bin\4.8.4.0\HbtHostIE.dll → Adware.HotBar : Ignored.
C:\Program Files\HbTools\Bin\4.8.4.0\HbtSrv.exe → Adware.Hotbar : Ignored.
C:\Program Files\HbTools\Bin\4.8.4.0\HbtWallpaper.dll → Adware.Hotbar : Ignored.
C:\Program Files\HbTools\HBTV\HBTVHelper.dll → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand.1 → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CLSID → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbTools.HbtCommBand\CurVer → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho.1 → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CLSID → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtHostIE.Bho\CurVer → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices.1 → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CLSID → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtSrv.HbtCoreServices\CurVer → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtTools.HbMain → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtTools.HbMain.1 → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CLSID → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Classes\HbtTools.HbMain\CurVer → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\HbTools → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\HbTools\Install → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\HbTools\PI → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\HbTools\PI\3.2 → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\Install → Adware.HotBar : Ignored.
HKLM\SOFTWARE\HbTools\Install\CmpMap → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsOutlookTools → Adware.HotBar : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HbToolsWebTools → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\HbTools → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\HbTools\options → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\HbTools\updates → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\Time → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\Time\HostIE → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1006\Software\HbTools\Time\HostIE\updates → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\HbTools → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\HbTools\MultiUrl → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\HbTools\mail → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\HbTools\options → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\HbTools\updates → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\Time → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\Time\HostIE → Adware.HotBar : Ignored.
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\HbTools\Time\HostIE\updates → Adware.HotBar : Ignored.
sas (without cookies)
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 10/02/2007 at 04:35 PM
Application Version : 3.9.1008
Core Rules Database Version : 3317
Trace Rules Database Version: 1318
Scan type : Complete Scan
Total Scan Time : 00:30:39
Memory items scanned : 809
Memory threats detected : 0
Registry items scanned : 7272
Registry threats detected : 49
File items scanned : 50478
File threats detected : 569
Adware.HotBar/SpamBlockerUtility (Low Risk)
HKLM\Software\Classes\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\InprocServer32
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\InprocServer32#ThreadingModel
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\ProgID
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\Programmable
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\TypeLib
HKCR\CLSID{74CC49F7-EB32-4A08-B204-948962A6E3DB}\VersionIndependentProgID
C:\PROGRAM FILES\HBTOOLS\BIN\4.8.4.0\HBTHOSTIE.DLL
HKLM\Software\Classes\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Control
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Implemented Categories
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Implemented Categories{00021494-0000-0000-C000-000000000046}
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\InprocServer32
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\InprocServer32#ThreadingModel
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance#CLSID
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance\InitPropertyBag
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Instance\InitPropertyBag#Url
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\MiscStatus
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\MiscStatus\1
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\ProgID
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Programmable
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\ToolboxBitmap32
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\TypeLib
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\Version
HKCR\CLSID{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}\VersionIndependentProgID
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{74CC49F7-EB32-4A08-B204-948962A6E3DB}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{74CC49F7-EB32-4A08-B204-948962A6E3DB}
HKCR\HbtHostIE.Bho.1
HKCR\HbtHostIE.Bho.1\CLSID
HKCR\HbtHostIE.Bho
HKCR\HbtHostIE.Bho\CLSID
HKCR\HbtHostIE.Bho\CurVer
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}\1.0
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}\1.0\0
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}\1.0\0\win32
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}\1.0\FLAGS
HKCR\TypeLib{45397063-D7D0-47C2-9508-26487608A298}\1.0\HELPDIR
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
HKU\S-1-5-21-2826111230-2069346872-300340464-1007\Software\Microsoft\Internet Explorer\Explorer Bars{7E66936C-FEA0-4984-AD26-7B6661AC5B2E}
Adware.Zango Toolbar/Hb
HKCR\Wallpaper.WallpaperManager
HKCR\Wallpaper.WallpaperManager\CLSID
HKCR\Wallpaper.WallpaperManager\CurVer
HKCR\Wallpaper.WallpaperManager.1
HKCR\Wallpaper.WallpaperManager.1\CLSID
Adware.HotBar (Low Risk)
C:\PROGRAM FILES\HBTOOLS\BIN\4.8.4.0\HBTSRV.EXE
C:\PROGRAM FILES\HBTOOLS\BIN\HBTUNINST.EXE