http://www.kephyr.com/spywarescanner/library/targetsoft.inetadpt/index.phtml
The URL above is for the inetadpt.dll entry.......spy/adware.
http://www.pestpatrol.com/PestInfo/b/backdoor_vb_bw.asp
The above is for the bw.exe entry.
Have you updated your Adaware and Spybot? Suggest you get HijackThis! as
well, just do a Google search for download locations.
Heirloom, old and looks like a mess
Look below at the additions to your post:
> [rename]
> NUL=c:\windows\twaintec.dll >probable printer/scanner
> NUL=c:\windows\temp\dummy.htm >questionable
> NUL=c:\windows\temp\bw.exe >definite spyware
> NUL=c:\windows\system\inetadpt.dll >definite spyware
> NUL=c:\windows\system\cidrules.dll >definite spyware
> NUL=c:\windows\system\wincore.dll
> NUL=c:\windows\system\winhost32.exe
> NUL=c:\windows\system\winupd.dll >definite spyware (VirtuMonde)
> NUL=c:\windows\system\updinstall.exe
> NUL=c:\windows\cookies\default@questionmarket[2].txt
disposable
> NUL=c:\windows\cookies\default@servedby.advertising[1].txt "
> NUL=c:\windows\cookies\default@webpdp.gator[1].txt
"
> NUL=c:\windows\cookies\default@0[2].txt
"
> NUL=c:\windows\cookies\default@maxserving[2].txt
"
> NUL=c:\windows\cookies\default@realmedia[2].txt
"
> NUL=c:\windows\cookies\default@gator[1].txt
"
> NUL=c:\windows\cookies\default@linksynergy[2].txt
"
> NUL=c:\windows\cookies\default@trafficmp[2].txt
"
> NUL=c:\windows\cookies\default@doubleclick[1].txt
"
> NUL=c:\windows\cookies\default@tmpad[2].txt
"
> NUL=c:\windows\cookies\default@qksrv[1].txt
"
> NUL=c:\windows\cookies\default@zedo[1].txt
"
> NUL=c:\windows\cookies\default@2o7[2].txt
"
> NUL=c:\windows\cookies\default@advertising[1].txt
"
> NUL=c:\windows\cookies\default@z1.adserver[1].txt
"
> NUL=c:\windows\cookies\default@atdmt[2].txt
"
> NUL=c:\windows\cookies\default@mediaplex[1].txt
"
> NUL=c:\windows\cookies\default@bluestreak[1].txt
"
> NUL=c:\windows\system\inetadpt.dll
>definite spyware
> NUL=c:\windows\downloaded program files\conflict.1\ds3.dll >VirtuMonde?
> NUL=c:\windows\system\bhczlba.exe >don't know, very
suspicious
> NUL=TARGET~1.EXEC:\WINDOWS\TEMP\MONITO~1.DAT=C:\WINDOWS\TEM
> P\MONITO~1.DAT
[quoted text clipped - 6 lines]
> [Rename]
> NUL=C:\WINDOWS\FIX19105.EXE
heirloom - 29 May 2004 17:08 GMT
Well, that didn't print very well............
All of the cookies, if you look closely, starting with the first one, I put
'disposable' next to it and then there is (") a ditto mark under the others.
Sorry about that, it looked good when I sent it.
Heirloom, old and hate it when it gets rearranged
maddy116 - 30 May 2004 05:07 GMT
Heirloom...thanxs for the help....I did what u
suggested..and my computer is running a little
smoother...I am still working in getting some of the kinks
out....help was very much appreciated....
I know where to come for help in the future...which might
be sooner than I realize....
>-----Original Message-----
>Well, that didn't print very well............
[quoted text clipped - 5 lines]
>
>.
heirloom - 30 May 2004 06:13 GMT
Just remember it is a lot easier to keep the junk out of your computer than
it is to remove it. A must have AV, good spyware/adware apps,
anti-hijackers, firewall, HOSTS file, just to name a few. As Figgy would
say, practice safe hex.
Glad you're doing better,
Heirloom, old and getting tired
> Heirloom...thanxs for the help....I did what u
> suggested..and my computer is running a little
[quoted text clipped - 16 lines]
> >
> >.
heirloom - 30 May 2004 06:19 GMT
One other item of consequence, check your startup axis.......the following
sites will help you determine what is needed and what is fluff and tell you
how to remedy the situation:
http://www.pacs-portal.co.uk/startup_content.php
http://www.sysinfo.org/startuplist.php
http://www.3feetunder.com/krick/startup/list.html
http://ww2.whidbey.net/djdenham/Uncheck.htm
http://www.answersthatwork.com/Tasklist_pages/tasklist.htm
http://www.greatis.com/regrun3appdatabase.htm
Post back if you need more help........
Heirloom, old and 'bout bed time
> Heirloom...thanxs for the help....I did what u
> suggested..and my computer is running a little
[quoted text clipped - 16 lines]
> >
> >.