HI
THanks for the help. Just a few notes before I post the logs.
1) I am currently using Mozilla
2) I have not been able to install Norton (the install process aborts half way through). Would you recommend that I persist with Norton or use a different virus programme.
The logs are as follows:
SPYSWEEPER
********
17:42: | Start of Session, 06 November 2005 |
17:42: Spy Sweeper started
17:42: Sweep initiated using definitions version 567
17:42: Starting Memory Sweep
17:44: Memory Sweep Complete, Elapsed Time: 00:02:00
17:44: Starting Registry Sweep
17:44: Found Adware: begin2search
17:44: HKCR\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104124)
17:44: HKCR\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104126)
17:44: HKCR\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104127)
17:44: HKCR\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104128)
17:44: HKCR\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104139)
17:44: HKCR\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104141)
17:44: HKLM\software\classes\interface\{6b882c34-a832-4f5b-bef1-7e198be3f094}\ (8 subtraces) (ID = 104174)
17:44: HKLM\software\classes\interface\{9b6b4031-1d6d-4c65-acba-021916853822}\ (8 subtraces) (ID = 104176)
17:44: HKLM\software\classes\interface\{9ff60a27-0c0c-4a6a-a15f-b21b644d67bb}\ (8 subtraces) (ID = 104177)
17:44: HKLM\software\classes\interface\{15d53b86-e055-43b1-bbee-a91a0f37bd2a}\ (8 subtraces) (ID = 104178)
17:44: HKLM\software\classes\interface\{f3c41c1d-22f1-4692-8a7a-88de70a2e9e2}\ (8 subtraces) (ID = 104189)
17:44: HKLM\software\classes\interface\{fa6fa7a5-2c49-4567-ba74-6dd1c36099ee}\ (8 subtraces) (ID = 104191)
17:44: Found Adware: elitebar
17:44: HKLM\software\microsoft\windows\currentversion\internet settings\user agent\post platform\ || iebar (ID = 125752)
17:44: Found Adware: logih adware
17:44: HKLM\software\microsoft\windows\currentversion\shellserviceobjectdelayload\ || systemcheck2 (ID = 129814)
17:44: Found Adware: visfx
17:44: HKLM\software\microsoft\windows\currentversion\uninstall\ovmon\ (2 subtraces) (ID = 712951)
17:44: HKLM\system\currentcontrolset\services\windows overlay components\ (12 subtraces) (ID = 712954)
17:44: Found Adware: clkoptimizer
17:44: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
17:44: Found Adware: cas
17:44: HKCR\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820387)
17:44: HKLM\software\classes\typelib\{1b8b502e-465b-4022-be4f-fb6d9f808a18}\ (9 subtraces) (ID = 820540)
17:44: Found Adware: maxifiles
17:44: HKCR\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829231)
17:44: HKCR\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829237)
17:44: HKCR\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829241)
17:44: HKCR\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829253)
17:44: HKLM\software\classes\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829282)
17:44: HKLM\software\classes\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829292)
17:44: HKLM\software\classes\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829298)
17:44: HKLM\software\classes\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829302)
17:44: HKLM\software\qstat\ || brr (ID = 877670)
17:44: Found Trojan Horse: trojan-downloader-pacisoft
17:44: HKU\S-1-5-21-746137067-706699826-725345543-500\software\psof1\ (15 subtraces) (ID = 136530)
17:44: Registry Sweep Complete, Elapsed Time:00:00:06
17:44: Starting Cookie Sweep
17:44: Cookie Sweep Complete, Elapsed Time: 00:00:00
17:44: Warning: Failed to open file "c:\pagefile.sys". Access is denied
17:44: Starting File Sweep
17:44: pf78.exe (ID = 156523)
17:45: Found Adware: surfsidekick
17:45: repairs302972943.dll (ID = 158242)
17:45: Found Trojan Horse: trojan-downloader-mainstreamdollars
17:45: btnetw3-995329.exe (ID = 155333)
17:45: Warning: Failed to open file "c:\winnt\system32\config\software.log". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\default.log". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\security". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\security.log". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\system.alt". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\sam". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\sam.log". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\system". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\software". The process cannot access the file because it is being used by another process
17:45: Warning: Failed to open file "c:\winnt\system32\config\default". The process cannot access the file because it is being used by another process
17:47: c:\winnt\etb (15 subtraces) (ID = -2147476235)
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs73a4149e-015c-4068-aae3-27f3d16198a2.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs34cf7392-99de-4869-b610-164f530b972d.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscse51131cf-e10b-45c4-a7a5-028505783cb8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs452ca07d-acab-468b-84a4-9cbd6263a6d8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs1bdcea69-e76e-498c-a097-b315b95e76aa.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7a7c17e9-c739-4413-8029-f81dcd9588ee.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs78adb782-c601-46ea-bedc-a71630293cf8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs64619414-0226-484e-8c71-3fac29a7d2c0.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs233e2593-c346-4afe-a932-b99b8c790fc9.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5a2f9541-2f52-40c9-ae9e-dcf9cbc142c7.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs10488fc7-6e93-4fd4-b2fb-f11b56578d6f.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs1e0c8c5c-a0ec-4409-ac16-3c41a54c4859.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs285e275d-a6c9-4fcc-8121-860fb69aa246.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf796ba6f-bec5-4bf2-ab54-9b3bbd99fbe4.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs69051158-cfd6-43b7-81aa-c33845d02150.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs6b51192e-801a-4efb-a0cf-5d4a1053d414.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfdb8ee3c-c027-46bf-8d8c-6de7db6367db.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs31c34bf4-e126-45c9-b6f6-56cda775e10b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs83b78de4-02e7-414b-8243-3c88ba209d3e.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsd5153b91-7c29-4c44-bf19-5813ad4bae7e.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa21fc029-021b-4015-b522-5751149e98a6.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs607a2194-8303-492d-a5e6-563a0a597dc5.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5b10e520-f85f-4225-b04b-5aad1fd9ada0.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscscc7083af-090f-4dbf-b6f4-a1dcaad56787.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsedaf638c-eb88-476b-82b7-89fa0ffdc53a.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9d53f3c4-0e8a-447d-99a5-6a668be61609.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs26d38b08-41ac-42c7-a6ec-ef61ef7ead00.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8138329f-27df-4ff1-90f6-ff46879cda85.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs96078cd6-857c-4301-b986-27580a6d72f0.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs357b5f15-4280-45af-a77b-528b3af6f770.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs519d11b5-d669-433a-bcce-085b477fabcc.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs52f69eb7-76cd-4329-a656-a255eedb52cf.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs429749c8-3113-4441-981b-34f20e87738d.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs6b899d86-4bc1-4891-a404-58959898fedf.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsd965c0f8-85d7-4059-a993-1709348f90fa.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs35d6b5ca-c4c1-4d3e-8827-bb72eb5f11ff.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa3bf2e08-9927-4f21-ba9f-a08212494d7b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc33b27a2-d1c0-4379-86a9-8a0bf2fe7989.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc9421f2c-4ccf-43d0-be75-106760f603fd.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5bb83fd7-56f0-4258-a783-a34ed15bcd32.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7917ff25-8c23-4d6c-a850-55f81c40e93e.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs0c4706b8-bbba-43a1-8978-65a4ab8ecc46.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf618bc9a-4c2e-4668-8c36-60a3066ebdd7.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5b956910-7c28-4caf-977d-75fdc4a8df79.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7a177ab3-3dcf-4f56-b997-db58094a68ee.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa7633aee-cf02-43ba-9bb4-b0cc4b12883b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsd6bde5f6-8974-4a13-a665-c3400a24e46c.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs20367355-1f62-4b74-8045-ed3f282173cf.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf0840f04-216b-4557-829d-b058ebab8efe.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf74ec809-7c41-4245-9fc9-943a1c698359.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsde0db90e-6f1c-4fc2-a653-719d58bc841c.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc91e712e-63a7-4a29-a6c2-aac23a1893f3.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9a5af9af-9820-4792-912b-c1bb77ff6d6b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5a4808ea-2780-4553-8147-44b2b036d846.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs829056b4-24f3-47dd-8ba3-c2c806764051.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs43fffff0-faab-409d-984b-487aba254403.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf69fd9ec-8872-42c0-b351-40359d7a8ca6.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb3683ce7-a917-4834-ad7c-1c54307dedaf.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa9344863-6b3b-4f4b-b835-4145006a0e85.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsd0dd4460-316b-4eda-b8f8-ae5d8f4cff14.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsad59efd2-f40d-46bc-a267-698332037804.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc841e342-3060-4b2e-813a-59853b2747b8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs046b4bcd-3bd9-412c-a42a-bc71d592b292.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf75482e3-064b-48a6-b8b4-e95284e046e7.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs6d6700f6-0719-48e6-b3d3-b8d89001c942.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs497e7509-20ac-4982-ba82-5ca9ad9213ad.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs128d5b56-318b-42ae-8bff-9dd4f7f31f50.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5bbc4efb-6df3-4069-97fd-6680b44e90c8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsad4c35ae-ae65-46d8-ad23-d877e6fb7f88.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8db8d043-f8e4-406e-9040-a154719434ee.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs3fc21bc2-644d-4269-89fa-5230dd684105.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs75b69996-95a8-4f97-b95d-c8ee2fe19f48.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4a4172ed-b0c7-4235-844b-57d0a67ef446.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsbd00abb5-aa6b-46ee-9446-981e65978f0d.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7f4535e4-9d74-4433-97d0-7c8bf6a7ecd1.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5fa8a318-09ba-4399-a83d-d8f6f7c199fe.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs999f3aed-8f08-4286-8d0c-13597e66874b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7033fe5d-6bf0-42f6-87b5-6d12add49eae.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9562ba3b-bc58-41d1-b6f8-0a1f6c9192de.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9c335b12-4060-4e96-9af0-04f3cf5fddf1.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb16d8045-cf7d-431d-a5ce-3954755e9a51.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs96934f65-8089-45d6-97ba-362464f5a030.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf92348c8-fa8d-4c04-b5e4-411908b147b7.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4564339f-4f51-4f1b-8625-19479193be57.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs18c64525-af9b-427f-8a32-8392dbf2f859.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7a60fd91-121d-4905-86cd-265f65209c55.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa3c24874-19e8-433f-b26d-4cf3619ed41b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs750e1ee4-80ae-4ab4-96f6-672485074f0b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscscc322504-87aa-4816-9e63-cce3b3bbe19c.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb17b1c0e-eb36-4e16-8eea-44723d3991fc.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsffd7d290-6d0b-4b76-a01d-8dda32229f96.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs76fae2af-b152-4c5e-9c26-75d7d6e2d774.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc1f58f73-5079-4a3b-9e03-9ad318bb853e.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8365329e-bccb-4f22-9e8d-a6e494a4c5e7.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfa3d7885-dbc0-4ef0-84ea-223fc3abd640.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsdfc86d62-9828-451b-bbeb-8eda0a39edc6.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb3a693be-d4ae-4f59-8506-143880bcf1cc.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7c3e7e68-f7d6-4067-a7b4-f8801e2f93e8.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9099b053-38a2-4447-b597-851986aa835c.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscse211df81-9561-492f-9450-e95db12a4125.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs13e475e2-5e3f-4aaa-8695-423883239a8b.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfb66a0a1-b38c-465f-a275-79e1604e93aa.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs1c4c9b88-98c9-4e13-a7e1-24f0db97251f.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs57434588-cc67-452b-ab05-b4cbbf9ec809.tmp". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\administrator\ntuser.dat". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\administrator\ntuser.dat.log". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\administrator\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
17:48: Warning: Failed to open file "c:\documents and settings\administrator\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
17:51: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcrst.dll". The process cannot access the file because it is being used by another process
17:51: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcsys.dll". The process cannot access the file because it is being used by another process
17:51: Found Trojan Horse: trojan downloader matcash
17:51: c:\program files\common files\inetget (ID = -2147477182)
17:51: c:\program files\common files\inetget2 (ID = -2147471395)
17:51: autoit3.exe (ID = 119348)
17:51: catcher.dll (ID = 156267)
17:51: x.bmp (ID = 69314)
17:51: cwebpage.dll (ID = 69301)
17:54: backup-20051016-115820-416.inf (ID = 65702)
17:58: File Sweep Complete, Elapsed Time: 00:13:54
17:58: Full Sweep has completed. Elapsed time 00:16:01
17:58: Traces Found: 259
18:12: Removal process initiated
18:12: Quarantining All Traces: clkoptimizer
18:12: Quarantining All Traces: elitebar
18:12: Quarantining All Traces: surfsidekick
18:12: Quarantining All Traces: trojan downloader matcash
18:12: Quarantining All Traces: visfx
18:12: Quarantining All Traces: begin2search
18:12: Quarantining All Traces: cas
18:12: Quarantining All Traces: trojan-downloader-mainstreamdollars
18:12: Quarantining All Traces: trojan-downloader-pacisoft
18:12: Quarantining All Traces: logih adware
18:12: Quarantining All Traces: maxifiles
18:13: Removal process completed. Elapsed time 00:00:48
********
17:39: | Start of Session, 06 November 2005 |
17:39: Spy Sweeper started
17:39: Messenger service has been disabled.
17:40: Your spyware definitions have been updated.
17:42: | End of Session, 06 November 2005 |
------------------------------------------------------------------------------------
HIJACK THIS LOG
Logfile of HijackThis v1.99.1
Scan saved at 18:16:21, on 06/11/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\WINNT\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Norton Password Manager\AcctMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\Program Files\Red Chair Software\Notmad Explorer\notmgr.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\Administrator\My Documents\Applications\Virus Programmes\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BTopenworld
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Norton PasswordManager] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID {D1AFB197-5F24-49f4-9571-2F28A9798936}
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: Notmad Manager.lnk = C:\Program Files\Red Chair Software\Notmad Explorer\notmgr.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O12 - Plugin for .bcf: C:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} -
http://www.imagestat...ion=4,3,2,20802O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) -
https://a248.e.akama...ol/SymDlBrg.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{7610BF65-6F83-4DD3-8FB9-EB82BC9A93C8}: NameServer = 194.72.0.98 194.72.9.38
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: RMOQQDIFPNJ - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\RMOQQDIFPNJ.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe