Thanks for the help. It was tedious, but I think we are making progress.
Here is the HijackThis file:
Logfile of HijackThis v1.99.1
Scan saved at 10:28:54 PM, on 10/4/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\S4F\FILTER7.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\AIM95\AIM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSFTSN.EXE
C:\PROGRAM FILES\HIJACK THIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [S4F] "C:\Program Files\S4F\Filter7.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [THGuard] "C:\PROGRAM FILES\TROJANHUNTER 4.2\THGUARD.EXE"
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\RunServices: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://C:\PROGRAM FILES\AIM TOOLBAR\AIMBAR.DLL/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) -
http://download.toon...4.21/ttinst.cabO16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://support.gatew...r/PCPitStop.CABO16 - DPF: {D44C75D8-C827-473E-8F68-A77E42500782} (Uploader Class) -
http://photo.walmart...ploadClient.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabAnd here is the Session Log from WebRoot SpySweeper:
********
9:10 PM: |··· Start of Session, 10/4/05 9:10:11 PM ···|
9:10 PM: Spy Sweeper started
9:10 PM: Sweep initiated using definitions version 549
9:10 PM: Starting Memory Sweep
9:11 PM: Sweep Canceled
********
8:53 PM: |··· Start of Session, 10/4/05 8:53:30 PM ···|
8:53 PM: Spy Sweeper started
8:53 PM: Sweep initiated using definitions version 549
8:53 PM: Starting Memory Sweep
8:53 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MSGSRV32.EXE
8:53 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MMTASK.TSK
8:54 PM: Found Adware: icannnews
8:54 PM: Detected running threat: C:\WINDOWS\SYSTEM\LXDIS11n.dll (ID = 157088)
8:55 PM: Detected running threat: C:\WINDOWS\SYSTEM\htsjvset.dll (ID = 157088)
8:59 PM: Memory Sweep Complete, Elapsed Time: 00:06:18
8:59 PM: Starting Registry Sweep
8:59 PM: Found Adware: winad
8:59 PM: HKLM\software\adtools service\ (2 subtraces) (ID = 103252)
8:59 PM: Found Adware: adtools
8:59 PM: HKLM\software\adtools service\ (2 subtraces) (ID = 103252)
9:00 PM: Found Adware: coolwebsearch (cws)
9:00 PM: HKCR\clsid\{66deb589-b6d4-e95e-2e36-26287464cd11}\ (2 subtraces) (ID = 107502)
9:00 PM: HKLM\software\classes\clsid\{66deb589-b6d4-e95e-2e36-26287464cd11}\ (2 subtraces) (ID = 108889)
9:00 PM: Found Adware: cws_ns3
9:00 PM: HKCR\clsid\{0b5c5d8e-38cb-964c-0902-24d9e96e6f3b}\ (2 subtraces) (ID = 117603)
9:00 PM: HKCR\clsid\{576846ba-17e1-4625-e44e-433dc7152ed6}\ (2 subtraces) (ID = 118641)
9:00 PM: HKCR\clsid\{cc6b2b65-2d60-cc2d-b4a6-7c0945964771}\ (2 subtraces) (ID = 119048)
9:00 PM: HKCR\clsid\{eceaf197-b6ef-9e38-0846-ff3bb03983ad}\ (2 subtraces) (ID = 119305)
9:00 PM: HKLM\software\classes\clsid\{0b5c5d8e-38cb-964c-0902-24d9e96e6f3b}\ (2 subtraces) (ID = 119483)
9:00 PM: HKLM\software\classes\clsid\{576846ba-17e1-4625-e44e-433dc7152ed6}\ (2 subtraces) (ID = 120488)
9:00 PM: HKLM\software\classes\clsid\{cc6b2b65-2d60-cc2d-b4a6-7c0945964771}\ (2 subtraces) (ID = 120885)
9:00 PM: HKLM\software\classes\clsid\{eceaf197-b6ef-9e38-0846-ff3bb03983ad}\ (2 subtraces) (ID = 121136)
9:01 PM: Found Adware: hotbar
9:01 PM: HKCR\appid\weatherontray.exe\ (1 subtraces) (ID = 127217)
9:01 PM: HKCR\appid\{0507fdde-f3b7-49f5-9e8f-c557e991f39b}\ (1 subtraces) (ID = 127218)
9:01 PM: HKCR\clsid\{0ab71193-ec19-4d70-85c2-e46e2ff02755}\ (20 subtraces) (ID = 127227)
9:01 PM: HKCR\clsid\{1e0004ec-5df0-48c7-a8f0-fbb0488a3d94}\ (11 subtraces) (ID = 127231)
9:01 PM: HKCR\clsid\{3fa917b9-df69-477f-9e4f-b60d929de79f}\ (23 subtraces) (ID = 127235)
9:01 PM: HKCR\clsid\{7e66936c-fea0-4984-ad26-7b6661ac5b2e}\ (26 subtraces) (ID = 127239)
9:01 PM: HKCR\clsid\{31a59636-0fa3-4a56-954d-db7ad02840d8}\ (14 subtraces) (ID = 127242)
9:01 PM: HKCR\clsid\{40d8240a-e3a0-4d59-ac55-0443120188d1}\ (11 subtraces) (ID = 127244)
9:01 PM: HKCR\clsid\{66b90adb-0be3-40ae-8680-84a6f0577ca0}\ (17 subtraces) (ID = 127246)
9:01 PM: HKCR\clsid\{74cc49f7-eb32-4a08-b204-948962a6e3db}\ (11 subtraces) (ID = 127248)
9:01 PM: HKCR\clsid\{a14c0d8d-e753-4e73-9e2b-4070791d8940}\ (10 subtraces) (ID = 127261)
9:01 PM: HKCR\clsid\{c2baa4c9-ae1e-4605-ae2f-a1c49a30d881}\ (11 subtraces) (ID = 127267)
9:01 PM: HKCR\clsid\{fa16bce1-5e36-472a-8466-e0cdd5ce00e6}\ (10 subtraces) (ID = 127272)
9:01 PM: HKCR\hbcoresrv.dynamicprop.1\ (3 subtraces) (ID = 127276)
9:01 PM: HKCR\hbcoresrv.dynamicprop\ (5 subtraces) (ID = 127277)
9:01 PM: HKCR\hbtcoresrv.hbtcoreservices.1\ (3 subtraces) (ID = 127291)
9:01 PM: HKCR\hbtcoresrv.hbtcoreservices\ (5 subtraces) (ID = 127292)
9:01 PM: HKCR\hbtcoresrv.lfgax.1\ (3 subtraces) (ID = 127293)
9:01 PM: HKCR\hbtcoresrv.lfgax\ (5 subtraces) (ID = 127294)
9:01 PM: HKCR\hbthostie.bho.1\ (3 subtraces) (ID = 127295)
9:01 PM: HKCR\hbthostie.bho\ (5 subtraces) (ID = 127296)
9:01 PM: HKCR\hbthostol.hbtmailanim.1\ (3 subtraces) (ID = 127297)
9:01 PM: HKCR\hbthostol.hbtmailanim\ (5 subtraces) (ID = 127298)
9:01 PM: HKCR\hbthostol.hbtwebmailsend.1\ (3 subtraces) (ID = 127299)
9:01 PM: HKCR\hbthostol.hbtwebmailsend\ (5 subtraces) (ID = 127300)
9:01 PM: HKCR\hbtinstie.hbinstobj.1\ (3 subtraces) (ID = 127301)
9:01 PM: HKCR\hbtinstie.hbinstobj\ (5 subtraces) (ID = 127302)
9:01 PM: HKCR\hbtools.hbtcommband.1\ (3 subtraces) (ID = 127306)
9:01 PM: HKCR\hbtools.hbtcommband\ (5 subtraces) (ID = 127307)
9:01 PM: HKCR\hbtools.hbttravelcomparebar.1\ (3 subtraces) (ID = 127308)
9:01 PM: HKCR\hbtools.hbttravelcomparebar\ (5 subtraces) (ID = 127309)
9:01 PM: HKCR\hbtsrv.hbtcoreservices.1\ (3 subtraces) (ID = 127310)
9:01 PM: HKCR\hbtsrv.hbtcoreservices\ (5 subtraces) (ID = 127311)
9:01 PM: HKCR\hbttoolbar.hbthtmlmenuui.1\ (3 subtraces) (ID = 127312)
9:01 PM: HKCR\hbttoolbar.hbthtmlmenuui\ (5 subtraces) (ID = 127313)
9:01 PM: HKCR\hbttoolbar.hbttoolbarctl.1\ (3 subtraces) (ID = 127314)
9:01 PM: HKCR\hbttoolbar.hbttoolbarctl\ (5 subtraces) (ID = 127315)
9:01 PM: HKCR\hbttools.hbmain.1\ (3 subtraces) (ID = 127316)
9:01 PM: HKCR\hbttools.hbmain\ (5 subtraces) (ID = 127317)
9:01 PM: HKCR\interface\{3f04cbf7-cd62-4403-b090-b432dedcb159}\ (8 subtraces) (ID = 127325)
9:01 PM: HKCR\interface\{34f4d917-31e4-464c-b8b3-84c1ce76b395}\ (8 subtraces) (ID = 127334)
9:01 PM: HKCR\interface\{8578d35e-c6c0-4808-9a80-0f6c29a2c423}\ (8 subtraces) (ID = 127339)
9:01 PM: HKCR\interface\{bc190da5-0187-4d99-b3ac-6c45ea1b9324}\ (8 subtraces) (ID = 127353)
9:01 PM: HKCR\rprtspsclient.psexecuter.1\ (3 subtraces) (ID = 127362)
9:01 PM: HKCR\rprtspsclient.psexecuter\ (5 subtraces) (ID = 127363)
9:01 PM: HKCR\shprrprts.hbax.1\ (3 subtraces) (ID = 127365)
9:01 PM: HKCR\shprrprts.hbax\ (5 subtraces) (ID = 127366)
9:01 PM: HKCR\shprrprts.hbinfoband.1\ (3 subtraces) (ID = 127369)
9:01 PM: HKCR\shprrprts.hbinfoband\ (5 subtraces) (ID = 127370)
9:01 PM: HKCR\shprrprts.iebutton.1\ (3 subtraces) (ID = 127371)
9:01 PM: HKCR\shprrprts.iebutton\ (5 subtraces) (ID = 127372)
9:01 PM: HKCR\shprrprts.iebuttona.1\ (3 subtraces) (ID = 127373)
9:01 PM: HKCR\shprrprts.iebuttona\ (5 subtraces) (ID = 127374)
9:01 PM: HKCR\shprrprts.smrtshprctl.1\ (3 subtraces) (ID = 127375)
9:01 PM: HKCR\shprrprts.smrtshprctl\ (5 subtraces) (ID = 127376)
9:01 PM: HKLM\software\classes\appid\weatherontray.exe\ (1 subtraces) (ID = 127380)
9:01 PM: HKLM\software\classes\appid\{0507fdde-f3b7-49f5-9e8f-c557e991f39b}\ (1 subtraces) (ID = 127381)
9:01 PM: HKLM\software\classes\clsid\{0ab71193-ec19-4d70-85c2-e46e2ff02755}\ (20 subtraces) (ID = 127393)
9:01 PM: HKLM\software\classes\clsid\{1e0004ec-5df0-48c7-a8f0-fbb0488a3d94}\ (11 subtraces) (ID = 127396)
9:01 PM: HKLM\software\classes\clsid\{3fa917b9-df69-477f-9e4f-b60d929de79f}\ (23 subtraces) (ID = 127399)
9:01 PM: HKLM\software\classes\clsid\{7e66936c-fea0-4984-ad26-7b6661ac5b2e}\ (26 subtraces) (ID = 127402)
9:01 PM: HKLM\software\classes\clsid\{31a59636-0fa3-4a56-954d-db7ad02840d8}\ (14 subtraces) (ID = 127405)
9:01 PM: HKLM\software\classes\clsid\{40d8240a-e3a0-4d59-ac55-0443120188d1}\ (11 subtraces) (ID = 127407)
9:01 PM: HKLM\software\classes\clsid\{66b90adb-0be3-40ae-8680-84a6f0577ca0}\ (17 subtraces) (ID = 127409)
9:01 PM: HKLM\software\classes\clsid\{74cc49f7-eb32-4a08-b204-948962a6e3db}\ (11 subtraces) (ID = 127411)
9:01 PM: HKLM\software\classes\clsid\{460ac4db-b0de-4626-a0f0-175dd84dcb9b}\ (2 subtraces) (ID = 127416)
9:01 PM: HKLM\software\classes\clsid\{a14c0d8d-e753-4e73-9e2b-4070791d8940}\ (10 subtraces) (ID = 127425)
9:01 PM: HKLM\software\classes\clsid\{c2baa4c9-ae1e-4605-ae2f-a1c49a30d881}\ (11 subtraces) (ID = 127431)
9:01 PM: HKLM\software\classes\clsid\{ed8525ea-2bfc-4440-bd8a-20efb9d5e541}\ (11 subtraces) (ID = 127436)
9:01 PM: HKLM\software\classes\clsid\{fa16bce1-5e36-472a-8466-e0cdd5ce00e6}\ (10 subtraces) (ID = 127437)
9:01 PM: HKLM\software\classes\hbcoresrv.dynamicprop\ (5 subtraces) (ID = 127441)
9:01 PM: HKLM\software\classes\hbtcoresrv.hbtcoreservices.1\ (3 subtraces) (ID = 127457)
9:01 PM: HKLM\software\classes\hbtcoresrv.hbtcoreservices\ (5 subtraces) (ID = 127458)
9:01 PM: HKLM\software\classes\hbtcoresrv.lfgax.1\ (3 subtraces) (ID = 127459)
9:01 PM: HKLM\software\classes\hbtcoresrv.lfgax\ (5 subtraces) (ID = 127460)
9:01 PM: HKLM\software\classes\hbthostie.bho.1\ (3 subtraces) (ID = 127461)
9:01 PM: HKLM\software\classes\hbthostie.bho\ (5 subtraces) (ID = 127462)
9:01 PM: HKLM\software\classes\hbthostol.hbtmailanim.1\ (3 subtraces) (ID = 127463)
9:01 PM: HKLM\software\classes\hbthostol.hbtmailanim\ (5 subtraces) (ID = 127464)
9:01 PM: HKLM\software\classes\hbthostol.hbtwebmailsend.1\ (3 subtraces) (ID = 127465)
9:01 PM: HKLM\software\classes\hbthostol.hbtwebmailsend\ (5 subtraces) (ID = 127466)
9:01 PM: HKLM\software\classes\hbtinstie.hbinstobj.1\ (3 subtraces) (ID = 127467)
9:01 PM: HKLM\software\classes\hbtinstie.hbinstobj\ (5 subtraces) (ID = 127468)
9:01 PM: HKLM\software\classes\hbtools.hbtcommband.1\ (3 subtraces) (ID = 127472)
9:01 PM: HKLM\software\classes\hbtools.hbtcommband\ (5 subtraces) (ID = 127473)
9:01 PM: HKLM\software\classes\hbtools.hbttravelcomparebar.1\ (3 subtraces) (ID = 127474)
9:01 PM: HKLM\software\classes\hbtools.hbttravelcomparebar\ (5 subtraces) (ID = 127475)
9:01 PM: HKLM\software\classes\hbtsrv.hbtcoreservices.1\ (3 subtraces) (ID = 127476)
9:01 PM: HKLM\software\classes\hbtsrv.hbtcoreservices\ (5 subtraces) (ID = 127477)
9:01 PM: HKLM\software\classes\hbttoolbar.hbthtmlmenuui.1\ (3 subtraces) (ID = 127478)
9:01 PM: HKLM\software\classes\hbttoolbar.hbthtmlmenuui\ (5 subtraces) (ID = 127479)
9:01 PM: HKLM\software\classes\hbttoolbar.hbttoolbarctl.1\ (3 subtraces) (ID = 127480)
9:01 PM: HKLM\software\classes\hbttoolbar.hbttoolbarctl\ (5 subtraces) (ID = 127481)
9:01 PM: HKLM\software\classes\hbttools.hbmain.1\ (3 subtraces) (ID = 127482)
9:01 PM: HKLM\software\classes\hbttools.hbmain\ (5 subtraces) (ID = 127483)
9:01 PM: HKLM\software\classes\interface\{3f04cbf7-cd62-4403-b090-b432dedcb159}\ (8 subtraces) (ID = 127490)
9:01 PM: HKLM\software\classes\interface\{34f4d917-31e4-464c-b8b3-84c1ce76b395}\ (8 subtraces) (ID = 127499)
9:01 PM: HKLM\software\classes\interface\{8578d35e-c6c0-4808-9a80-0f6c29a2c423}\ (8 subtraces) (ID = 127503)
9:01 PM: HKLM\software\classes\interface\{bc190da5-0187-4d99-b3ac-6c45ea1b9324}\ (8 subtraces) (ID = 127514)
9:01 PM: HKLM\software\classes\rprtspsclient.psexecuter.1\ (3 subtraces) (ID = 127521)
9:01 PM: HKLM\software\classes\rprtspsclient.psexecuter\ (5 subtraces) (ID = 127522)
9:01 PM: HKLM\software\classes\shprrprts.hbax.1\ (3 subtraces) (ID = 127524)
9:01 PM: HKLM\software\classes\shprrprts.hbax\ (5 subtraces) (ID = 127525)
9:01 PM: HKLM\software\classes\shprrprts.hbinfoband.1\ (3 subtraces) (ID = 127528)
9:01 PM: HKLM\software\classes\shprrprts.hbinfoband\ (5 subtraces) (ID = 127529)
9:01 PM: HKLM\software\classes\shprrprts.iebutton.1\ (3 subtraces) (ID = 127530)
9:01 PM: HKLM\software\classes\shprrprts.iebutton\ (5 subtraces) (ID = 127531)
9:01 PM: HKLM\software\classes\shprrprts.iebuttona.1\ (3 subtraces) (ID = 127532)
9:01 PM: HKLM\software\classes\shprrprts.iebuttona\ (5 subtraces) (ID = 127533)
9:01 PM: HKLM\software\classes\shprrprts.smrtshprctl.1\ (3 subtraces) (ID = 127534)
9:01 PM: HKLM\software\classes\shprrprts.smrtshprctl\ (5 subtraces) (ID = 127535)
9:01 PM: HKLM\software\classes\typelib\{4cf5a3c1-07a2-4336-9b54-6870452ebde1}\ (9 subtraces) (ID = 127537)
9:01 PM: HKLM\software\classes\typelib\{71e9cf40-af72-4b55-bd3f-1fea2a0eaea6}\ (9 subtraces) (ID = 127542)
9:01 PM: HKLM\software\classes\typelib\{71efe583-62fe-4419-9918-ca3b683f7b36}\ (9 subtraces) (ID = 127543)
9:01 PM: HKLM\software\classes\typelib\{793af621-5cd0-4b92-b765-6712f6aaf48e}\ (9 subtraces) (ID = 127545)
9:01 PM: HKLM\software\classes\typelib\{9967a873-40f3-4c7e-9239-6c8760f19f61}\ (9 subtraces) (ID = 127547)
9:01 PM: HKLM\software\classes\typelib\{45397063-d7d0-47c2-9508-26487608a298}\ (9 subtraces) (ID = 127549)
9:01 PM: HKLM\software\classes\typelib\{b9f51d42-cca0-4408-bb02-d433d1865a3a}\ (9 subtraces) (ID = 127552)
9:01 PM: HKLM\software\classes\typelib\{f8ee014f-b34c-4544-8e45-95a7971d323b}\ (9 subtraces) (ID = 127558)
9:01 PM: HKLM\software\classes\wallpaper.wallpapermanager\ (5 subtraces) (ID = 127559)
9:01 PM: HKU\.DEFAULT\software\hbtools\ (256 subtraces) (ID = 127563)
9:01 PM: HKLM\software\hbtools\ (70 subtraces) (ID = 127564)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\explorer bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e}\ (2 subtraces) (ID = 127568)
9:01 PM: HKLM\software\microsoft\internet explorer\explorer bars\{7e66936c-fea0-4984-ad26-7b6661ac5b2e}\ (1 subtraces) (ID = 127569)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\explorer bars\{66b90adb-0be3-40ae-8680-84a6f0577ca0}\ (2 subtraces) (ID = 127570)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\explorer bars\{2178c864-b8bc-41ae-a1fb-eb6a32f87eb1}\ (2 subtraces) (ID = 127571)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping\ || {946b3e9e-e21a-49c8-9f63-900533fafe14} (ID = 127575)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping\ || {e77eda01-3c56-4a96-8d08-02b42891c169} (ID = 127576)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{946b3e9e-e21a-49c8-9f63-900533fafe14}\ (6 subtraces) (ID = 127577)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{946b3e9e-e21a-49c8-9f63-900533fafe14}\ || buttontext (ID = 127578)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{946b3e9e-e21a-49c8-9f63-900533fafe14}\ || default visible (ID = 127579)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{946b3e9e-e21a-49c8-9f63-900533fafe14}\ || hoticon (ID = 127580)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{946b3e9e-e21a-49c8-9f63-900533fafe14}\ || icon (ID = 127581)
9:01 PM: HKLM\software\microsoft\internet explorer\extensions\{e77eda01-3c56-4a96-8d08-02b42891c169}\ (6 subtraces) (ID = 127582)
9:01 PM: HKU\.DEFAULT\software\microsoft\internet explorer\toolbar\webbrowser\ || {74cc49f7-eb32-4a08-b204-948962a6e3db} (ID = 127586)
9:01 PM: HKLM\software\microsoft\office\outlook\addins\hbthostol.hbtmailanim\ (4 subtraces) (ID = 127590)
9:01 PM: HKLM\software\microsoft\windows\currentversion\run\ || hbtools (ID = 127613)
9:01 PM: HKU\.DEFAULT\software\shopperreports\ (4 subtraces) (ID = 127631)
9:01 PM: HKCR\typelib\{4cf5a3c1-07a2-4336-9b54-6870452ebde1}\ (9 subtraces) (ID = 127635)
9:01 PM: HKCR\typelib\{71e9cf40-af72-4b55-bd3f-1fea2a0eaea6}\ (9 subtraces) (ID = 127640)
9:01 PM: HKCR\typelib\{71efe583-62fe-4419-9918-ca3b683f7b36}\ (9 subtraces) (ID = 127641)
9:01 PM: HKCR\typelib\{793af621-5cd0-4b92-b765-6712f6aaf48e}\ (9 subtraces) (ID = 127643)
9:01 PM: HKCR\typelib\{9967a873-40f3-4c7e-9239-6c8760f19f61}\ (9 subtraces) (ID = 127645)
9:01 PM: HKCR\typelib\{45397063-d7d0-47c2-9508-26487608a298}\ (9 subtraces) (ID = 127647)
9:01 PM: HKCR\typelib\{b9f51d42-cca0-4408-bb02-d433d1865a3a}\ (9 subtraces) (ID = 127651)
9:01 PM: HKCR\typelib\{f8ee014f-b34c-4544-8e45-95a7971d323b}\ (9 subtraces) (ID = 127657)
9:01 PM: HKCR\wallpaper.wallpapermanager.1\ (3 subtraces) (ID = 127658)
9:01 PM: HKCR\wallpaper.wallpapermanager\ (5 subtraces) (ID = 127659)
9:01 PM: Found Adware: linkmaker
9:01 PM: HKCR\clsid\{dfaa31c8-a356-4313-9d95-5edab46c5070}\ (10 subtraces) (ID = 129728)
9:01 PM: HKLM\software\classes\clsid\{dfaa31c8-a356-4313-9d95-5edab46c5070}\ (10 subtraces) (ID = 129736)
9:01 PM: Found Adware: screensavers
9:01 PM: HKCR\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (2 subtraces) (ID = 140550)
9:01 PM: HKCR\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (2 subtraces) (ID = 140551)
9:01 PM: HKLM\software\classes\clsid\{722d2939-a14a-41a9-9eac-ab8f4e295819}\ (2 subtraces) (ID = 140555)
9:01 PM: HKLM\software\classes\clsid\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (2 subtraces) (ID = 140556)
9:01 PM: HKLM\software\microsoft\code store database\distribution units\{88d758a3-d33b-45fd-91e3-67749b4057fa}\ (9 subtraces) (ID = 140566)
9:01 PM: HKLM\software\screensavers.com\ (ID = 140569)
9:02 PM: Found Adware: search fast communicator toolbar
9:02 PM: HKCR\communicator.communicator\ (3 subtraces) (ID = 140680)
9:02 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140682)
9:02 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140683)
9:02 PM: HKCR\communicator.communicatormenu button\ (3 subtraces) (ID = 140684)
9:02 PM: HKCR\communicator.communicatortoggle button\ (3 subtraces) (ID = 140685)
9:02 PM: HKLM\software\classes\communicator.communicatormenu button\ (3 subtraces) (ID = 140686)
9:02 PM: HKLM\software\classes\communicator.communicatortoggle button\ (3 subtraces) (ID = 140687)
9:02 PM: HKU\.DEFAULT\software\communicator toolbar\ (9 subtraces) (ID = 140688)
9:02 PM: HKU\.DEFAULT\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140689)
9:02 PM: HKLM\software\classes\communicator.communicator\ (3 subtraces) (ID = 140691)
9:02 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140693)
9:02 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140694)
9:02 PM: HKU\.default\software\communicator toolbar\ (9 subtraces) (ID = 140696)
9:02 PM: HKU\.default\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140697)
9:02 PM: Found Adware: shopathomeselect
9:02 PM: HKLM\software\winsock2\layered provider sample\ (ID = 141736)
9:02 PM: Found Adware: surfsidekick
9:02 PM: HKU\.default\software\surfsidekick3\ (3 subtraces) (ID = 143387)
9:02 PM: HKU\.DEFAULT\software\surfsidekick3\ (3 subtraces) (ID = 143412)
9:02 PM: HKLM\software\surfsidekick3\ (2 subtraces) (ID = 143413)
9:02 PM: Found Adware: websearch toolbar
9:02 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\qdow_as2.dll (ID = 146497)
9:02 PM: HKLM\software\classes\adtoolsx.installer\ (3 subtraces) (ID = 147163)
9:02 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\adtoolsx.dll (ID = 147215)
9:02 PM: Found Adware: quicklink search toolbar
9:02 PM: HKLM\software\classes\typelib\{ea420048-2898-4110-88c3-1f660b0c7ff3}\ (9 subtraces) (ID = 359443)
9:02 PM: HKCR\typelib\{ea420048-2898-4110-88c3-1f660b0c7ff3}\ (9 subtraces) (ID = 359446)
9:02 PM: HKCR\quicklinks.linktracker.1\ (3 subtraces) (ID = 359448)
9:02 PM: HKCR\quicklinks.linktracker\ (3 subtraces) (ID = 359449)
9:02 PM: HKCR\quicklinks.quicklinksfilter.1\ (3 subtraces) (ID = 359450)
9:02 PM: HKCR\quicklinks.quicklinksfilter\ (3 subtraces) (ID = 359451)
9:02 PM: HKLM\software\classes\quicklinks.linktracker.1\ (3 subtraces) (ID = 359452)
9:02 PM: HKLM\software\classes\quicklinks.linktracker\ (3 subtraces) (ID = 359453)
9:02 PM: HKLM\software\classes\quicklinks.quicklinksfilter.1\ (3 subtraces) (ID = 359454)
9:02 PM: HKLM\software\classes\quicklinks.quicklinksfilter\ (3 subtraces) (ID = 359455)
9:02 PM: HKLM\software\microsoft\windows\currentversion\uninstall\quick links\ (2 subtraces) (ID = 359457)
9:02 PM: HKLM\software\ql\ (2 subtraces) (ID = 359458)
9:02 PM: HKLM\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/hbinstie.dll\ (2 subtraces) (ID = 484423)
9:02 PM: Found Adware: zenosearchassistant
9:02 PM: HKLM\software\microsoft\windows\currentversion\uninstall\zeno browser enhancer\ (2 subtraces) (ID = 513784)
9:02 PM: HKLM\software\microsoft\windows\currentversion\uninstall\related sites toolbar\ (2 subtraces) (ID = 652841)
9:02 PM: HKLM\software\microsoft\windows\currentversion\shareddlls\ || c:\windows\downloaded program files\hbinstie.dll (ID = 655022)
9:02 PM: HKCR\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\ (11 subtraces) (ID = 774202)
9:02 PM: HKCR\interface\{023a4648-601a-4c30-8a2e-c72ebfa99af6}\ (8 subtraces) (ID = 774214)
9:02 PM: HKCR\interface\{175816a5-219e-4079-b2f9-53c501c409ba}\ (8 subtraces) (ID = 774223)
9:02 PM: HKCR\interface\{19ebcbe0-9245-4397-bc5d-883d34782043}\ (8 subtraces) (ID = 774232)
9:02 PM: HKCR\interface\{1c1793e0-1034-4cac-837d-aa545f6961bf}\ (8 subtraces) (ID = 774241)
9:02 PM: HKCR\interface\{1e07646f-07c4-4847-a250-0ec8114f2963}\ (8 subtraces) (ID = 774250)
9:02 PM: HKCR\interface\{27c4569f-8728-4958-a920-a607cae8153c}\ (8 subtraces) (ID = 774259)
9:02 PM: HKCR\interface\{38370864-346f-4afa-8c4b-4fbff518c0bb}\ (8 subtraces) (ID = 774268)
9:02 PM: HKCR\interface\{397a208b-3d09-4b3e-93e8-ca171886612e}\ (8 subtraces) (ID = 774277)
9:02 PM: HKCR\interface\{421745e9-16df-4ee4-a758-d51f939c49cb}\ (8 subtraces) (ID = 774286)
9:02 PM: HKCR\interface\{4331ec56-0aab-499e-8757-dd2ee44ad671}\ (8 subtraces) (ID = 774295)
9:02 PM: HKCR\interface\{54286c3a-e044-4e65-bd44-528d6ae28a18}\ (8 subtraces) (ID = 774304)
9:02 PM: HKCR\interface\{5d9c84e7-fa45-49e2-a0b8-b6b5e9a4f6be}\ (8 subtraces) (ID = 774322)
9:02 PM: HKCR\interface\{5f2b9de7-f878-4762-8cfe-e9c58f082f0e}\ (8 subtraces) (ID = 774331)
9:02 PM: HKCR\interface\{8654592e-952a-4e7c-a960-304763b35fa6}\ (8 subtraces) (ID = 774349)
9:02 PM: HKCR\interface\{8a61a950-c325-4f44-ba64-273180ff3464}\ (8 subtraces) (ID = 774358)
9:02 PM: HKCR\interface\{8d5c4ec6-af8e-4b85-ba27-64babe410510}\ (8 subtraces) (ID = 774367)
9:02 PM: HKCR\interface\{8e98faf8-794f-47f9-af90-15305564ed81}\ (8 subtraces) (ID = 774376)
9:02 PM: HKCR\interface\{af15975b-1498-4740-8e6c-90af78e4198c}\ (8 subtraces) (ID = 774385)
9:02 PM: HKCR\interface\{b53d4cd4-406d-43cc-8244-7893d72236dd}\ (8 subtraces) (ID = 774394)
9:02 PM: HKCR\interface\{b671426c-5c1a-48ac-9652-bc9402b1c404}\ (8 subtraces) (ID = 774403)
9:02 PM: HKCR\interface\{b9bb3219-f84c-4060-966b-4a1e73e24226}\ (8 subtraces) (ID = 774412)
9:02 PM: HKCR\interface\{bc8c2e5f-d8b4-4997-bce3-8775c3707956}\ (8 subtraces) (ID = 774421)
9:02 PM: HKCR\interface\{d082721f-4bd4-4b8b-bb82-06753ee6174f}\ (8 subtraces) (ID = 774430)
9:02 PM: HKCR\interface\{d24f9d3c-5d4c-47f8-9ab7-632b44ad6a0d}\ (8 subtraces) (ID = 774439)
9:02 PM: HKCR\interface\{f43ec88b-b6c8-4969-a763-e2bf55602cce}\ (8 subtraces) (ID = 774448)
9:02 PM: HKCR\interface\{f786cb18-3809-4e49-bc99-9a66da47db8b}\ (8 subtraces) (ID = 774457)
9:02 PM: HKCR\interface\{f814be58-1bf9-4b50-829a-e889f86127ad}\ (8 subtraces) (ID = 774466)
9:02 PM: HKLM\software\classes\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\inprocserver32\ (2 subtraces) (ID = 774480)
9:02 PM: HKLM\software\classes\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\progid\ (1 subtraces) (ID = 774483)
9:02 PM: HKLM\software\classes\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\programmable\ (ID = 774485)
9:02 PM: HKLM\software\classes\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\typelib\ (1 subtraces) (ID = 774486)
9:02 PM: HKLM\software\classes\clsid\{420c35c9-e4f2-49f9-bf67-2be1ecf86989}\versionindependentprogid\ (1 subtraces) (ID = 774488)
9:02 PM: HKLM\software\classes\interface\{023a4648-601a-4c30-8a2e-c72ebfa99af6}\ (8 subtraces) (ID = 774490)
9:02 PM: HKLM\software\classes\interface\{175816a5-219e-4079-b2f9-53c501c409ba}\ (8 subtraces) (ID = 774499)
9:02 PM: HKLM\software\classes\interface\{19ebcbe0-9245-4397-bc5d-883d34782043}\ (8 subtraces) (ID = 774508)
9:02 PM: HKLM\software\classes\interface\{1c1793e0-1034-4cac-837d-aa545f6961bf}\ (8 subtraces) (ID = 774517)
9:02 PM: HKLM\software\classes\interface\{1e07646f-07c4-4847-a250-0ec8114f2963}\ (8 subtraces) (ID = 774526)
9:02 PM: HKLM\software\classes\interface\{27c4569f-8728-4958-a920-a607cae8153c}\ (8 subtraces) (ID = 774535)
9:02 PM: HKLM\software\classes\interface\{38370864-346f-4afa-8c4b-4fbff518c0bb}\ (8 subtraces) (ID = 774544)
9:02 PM: HKLM\software\classes\interface\{397a208b-3d09-4b3e-93e8-ca171886612e}\ (8 subtraces) (ID = 774553)
9:02 PM: HKLM\software\classes\interface\{421745e9-16df-4ee4-a758-d51f939c49cb}\ (8 subtraces) (ID = 774562)
9:02 PM: HKLM\software\classes\interface\{4331ec56-0aab-499e-8757-dd2ee44ad671}\ (8 subtraces) (ID = 774571)
9:02 PM: HKLM\software\classes\interface\{54286c3a-e044-4e65-bd44-528d6ae28a18}\ (8 subtraces) (ID = 774580)
9:02 PM: HKLM\software\classes\interface\{5d9c84e7-fa45-49e2-a0b8-b6b5e9a4f6be}\ (8 subtraces) (ID = 774598)
9:02 PM: HKLM\software\classes\interface\{5f2b9de7-f878-4762-8cfe-e9c58f082f0e}\ (8 subtraces) (ID = 774607)
9:02 PM: HKLM\software\classes\interface\{601a9784-1114-4089-9b3e-cbd70dafc6ad}\ (8 subtraces) (ID = 774616)
9:02 PM: HKLM\software\classes\interface\{8654592e-952a-4e7c-a960-304763b35fa6}\ (8 subtraces) (ID = 774625)
9:02 PM: HKLM\software\classes\interface\{8a61a950-c325-4f44-ba64-273180ff3464}\ (8 subtraces) (ID = 774634)
9:02 PM: HKLM\software\classes\interface\{8d5c4ec6-af8e-4b85-ba27-64babe410510}\ (8 subtraces) (ID = 774643)
9:02 PM: HKLM\software\classes\interface\{8e98faf8-794f-47f9-af90-15305564ed81}\ (8 subtraces) (ID = 774652)
9:02 PM: HKLM\software\classes\interface\{af15975b-1498-4740-8e6c-90af78e4198c}\ (8 subtraces) (ID = 774661)
9:02 PM: HKLM\software\classes\interface\{b53d4cd4-406d-43cc-8244-7893d72236dd}\ (8 subtraces) (ID = 774670)
9:02 PM: HKLM\software\classes\interface\{b671426c-5c1a-48ac-9652-bc9402b1c404}\ (8 subtraces) (ID = 774679)
9:02 PM: HKLM\software\classes\interface\{b9bb3219-f84c-4060-966b-4a1e73e24226}\ (8 subtraces) (ID = 774688)
9:02 PM: HKLM\software\classes\interface\{bc8c2e5f-d8b4-4997-bce3-8775c3707956}\ (8 subtraces) (ID = 774697)
9:02 PM: HKLM\software\classes\interface\{d082721f-4bd4-4b8b-bb82-06753ee6174f}\ (8 subtraces) (ID = 774706)
9:02 PM: HKLM\software\classes\interface\{d24f9d3c-5d4c-47f8-9ab7-632b44ad6a0d}\ (8 subtraces) (ID = 774715)
9:02 PM: HKLM\software\classes\interface\{f43ec88b-b6c8-4969-a763-e2bf55602cce}\ (8 subtraces) (ID = 774724)
9:02 PM: HKLM\software\classes\interface\{f786cb18-3809-4e49-bc99-9a66da47db8b}\ (8 subtraces) (ID = 774733)
9:02 PM: HKLM\software\classes\interface\{f814be58-1bf9-4b50-829a-e889f86127ad}\ (8 subtraces) (ID = 774742)
9:02 PM: HKLM\software\microsoft\windows\currentversion\run\ || browserupdatesched (ID = 835886)
9:02 PM: Registry Sweep Complete, Elapsed Time:00:03:08
9:02 PM: Starting Cookie Sweep
9:02 PM: Found Spy Cookie: partypoker cookie
9:02 PM: martin stromberger@partypoker[1].txt (ID = 3111)
9:02 PM: Found Spy Cookie: touchclarity cookie
9:02 PM: martin
[email protected][1].txt (ID = 3567)
9:02 PM: Found Spy Cookie: paypopup cookie
9:02 PM: martin stromberger@paypopup[1].txt (ID = 3119)
9:02 PM: Found Spy Cookie: 888 cookie
9:02 PM: martin stromberger@888[1].txt (ID = 2019)
9:02 PM: Found Spy Cookie: addynamix cookie
9:02 PM: martin
[email protected][2].txt (ID = 2062)
9:03 PM: Found Spy Cookie: websponsors cookie
9:03 PM: martin
[email protected][2].txt (ID = 3665)
9:03 PM: Found Spy Cookie: falkag cookie
9:03 PM: martin
[email protected][2].txt (ID = 2650)
9:03 PM: Found Spy Cookie: ru4 cookie
9:03 PM: martin
[email protected][2].txt (ID = 3269)
9:03 PM: Found Spy Cookie: rn11 cookie
9:03 PM: martin stromberger@rn11[2].txt (ID = 3261)
9:03 PM: Found Spy Cookie: hbmediapro cookie
9:03 PM: martin
[email protected][2].txt (ID = 2768)
9:03 PM: Found Spy Cookie: yieldmanager cookie
9:03 PM: martin
[email protected][1].txt (ID = 3751)
9:03 PM: Cookie Sweep Complete, Elapsed Time: 00:00:05
9:03 PM: Starting File Sweep
9:03 PM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
********
7:55 PM: |··· Start of Session, 10/4/05 7:55:42 PM ···|
7:55 PM: Spy Sweeper started
7:55 PM: Sweep initiated using definitions version 549
7:55 PM: Starting Memory Sweep
7:56 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MSGSRV32.EXE
7:56 PM: Warning: Failed to load image: C:\WINDOWS\SYSTEM\MMTASK.TSK
7:57 PM: Found Adware: icannnews
7:57 PM: Detected running threat: C:\WINDOWS\SYSTEM\LXDIS11n.dll (ID = 157088)
7:57 PM: Detected running threat: C:\WINDOWS\SYSTEM\htsjvset.dll (ID = 157088)
8:49 PM: Found: Memory-resident threat icannnews, version 1.0.0.0
8:49 PM: Detected running threat: icannnews
8:53 PM: |··· End of Session, 10/4/05 8:53:29 PM ···|
********
7:53 PM: |··· Start of Session, 10/4/05 7:53:46 PM ···|
7:53 PM: Spy Sweeper started
7:55 PM: |··· End of Session, 10/4/05 7:55:42 PM ···|
Thanks again for any help!