WOW this actually helped A LOT!
here's the log for the spysweeper:
********
3:56 PM: | Start of Session, Tuesday, November 01, 2005 |
3:56 PM: Spy Sweeper started
3:56 PM: Sweep initiated using definitions version 564
3:56 PM: Starting Memory Sweep
3:57 PM: Found Adware: icannnews
3:57 PM: Detected running threat: C:\WINNT\system32\k2lq0c35ef.dll (ID = 83)
4:00 PM: Detected running threat: C:\WINNT\system32\mmdart32.dll (ID = 83)
4:00 PM: Found Adware: elitebar
4:00 PM: Detected running threat: C:\WINNT\etb\pokapoka78.exe (ID = 179560)
4:01 PM: Detected running threat: C:\WINNT\system32\guard.tmp (ID = 83)
4:01 PM: Memory Sweep Complete, Elapsed Time: 00:05:06
4:01 PM: Starting Registry Sweep
4:02 PM: Found Adware: findthewebsiteyouneed hijacker
4:02 PM: HKLM\software\microsoft\internet explorer\main\ || search page (ID = 125241)
4:02 PM: Found Adware: multidial
4:02 PM: HKCR\dialerr.dialerr\ (3 subtraces) (ID = 135344)
4:02 PM: HKLM\software\classes\dialerr.dialerr\ (3 subtraces) (ID = 135355)
4:02 PM: Found Adware: targetsoft
4:02 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
4:02 PM: Found Adware: targetsaver
4:02 PM: HKLM\software\microsoft\windows\currentversion\uninstall\tsl installer\ (1 subtraces) (ID = 143608)
4:02 PM: HKLM\software\tsa\ (1 subtraces) (ID = 143615)
4:02 PM: HKCR\dialerr.dialerr.1\ (3 subtraces) (ID = 661961)
4:02 PM: HKCR\icwconn.apprentice\ (5 subtraces) (ID = 661963)
4:02 PM: HKCR\icwconn.gifconvert\ (5 subtraces) (ID = 661968)
4:02 PM: HKCR\icwconn.ispdata\ (5 subtraces) (ID = 661973)
4:02 PM: HKCR\icwconn.walker\ (5 subtraces) (ID = 661978)
4:02 PM: HKCR\icwconn.webview\ (5 subtraces) (ID = 661983)
4:02 PM: HKCR\icwsystemconfig.icwsystemconfig\ (3 subtraces) (ID = 661988)
4:02 PM: HKCR\inshandler.inshandler\ (3 subtraces) (ID = 661992)
4:02 PM: HKCR\refdial.refdial\ (3 subtraces) (ID = 661996)
4:02 PM: HKCR\smartstart.smartstart\ (3 subtraces) (ID = 662000)
4:02 PM: HKCR\tapilocationinfo.tapilocationinfo\ (3 subtraces) (ID = 662004)
4:02 PM: HKCR\userinfo.userinfo\ (3 subtraces) (ID = 662008)
4:02 PM: HKCR\webgate.webgate\ (3 subtraces) (ID = 662012)
4:02 PM: HKCR\clsid\{462f7758-8848-11d1-add8-0000f87734f0}\control\ (ID = 662065)
4:02 PM: HKLM\software\classes\dialerr.dialerr.1\ (3 subtraces) (ID = 662143)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\main\ || default_search_url (ID = 125236)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\main\ || search bar (ID = 125237)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\main\ || search page (ID = 125238)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\tsl2\ (1 subtraces) (ID = 143616)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555437)
4:02 PM: Found Adware: the818search-co.com hijack
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\ || searchurl (ID = 751006)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\main\ || search bar (ID = 790268)
4:02 PM: HKU\S-1-5-21-1993962763-152049171-1060284298-500\software\microsoft\internet explorer\main\ || default_search_url (ID = 790269)
4:02 PM: Registry Sweep Complete, Elapsed Time:00:01:00
4:02 PM: Starting Cookie Sweep
4:02 PM: Found Spy Cookie: belnk cookie
4:02 PM: administrator@belnk[1].txt (ID = 2292)
4:02 PM: Found Spy Cookie: azjmp cookie
4:02 PM: administrator@azjmp[2].txt (ID = 2270)
4:02 PM: Found Spy Cookie: rn11 cookie
4:02 PM: administrator@rn11[2].txt (ID = 3261)
4:02 PM: Found Spy Cookie: starware.com cookie
4:02 PM:
[email protected][2].txt (ID = 3442)
4:02 PM: Found Spy Cookie: centrport net cookie
4:02 PM: administrator@centrport[1].txt (ID = 2374)
4:02 PM: Found Spy Cookie: advertising cookie
4:02 PM: administrator@advertising[1].txt (ID = 2175)
4:02 PM: Found Spy Cookie: zedo cookie
4:02 PM: administrator@zedo[2].txt (ID = 3762)
4:02 PM: Found Spy Cookie: atlas dmt cookie
4:02 PM: administrator@atdmt[2].txt (ID = 2253)
4:02 PM:
[email protected][1].txt (ID = 3442)
4:02 PM: Found Spy Cookie: overture cookie
4:02 PM:
[email protected][1].txt (ID = 3106)
4:02 PM: Found Spy Cookie: targetnet cookie
4:02 PM: administrator@targetnet[1].txt (ID = 3489)
4:02 PM: Found Spy Cookie: abcsearch cookie
4:02 PM: administrator@abcsearch[2].txt (ID = 2033)
4:02 PM: Found Spy Cookie: adserver cookie
4:02 PM:
[email protected][1].txt (ID = 2142)
4:02 PM: Found Spy Cookie: linksynergy cookie
4:02 PM: administrator@linksynergy[1].txt (ID = 2926)
4:02 PM: Found Spy Cookie: adecn cookie
4:02 PM: administrator@adecn[2].txt (ID = 2063)
4:02 PM: Found Spy Cookie: adprofile cookie
4:02 PM: administrator@adprofile[2].txt (ID = 2084)
4:02 PM: Found Spy Cookie: yieldmanager cookie
4:02 PM:
[email protected][1].txt (ID = 3751)
4:02 PM: Found Spy Cookie: reliablestats cookie
4:02 PM:
[email protected][1].txt (ID = 3254)
4:02 PM:
[email protected][2].txt (ID = 2293)
4:02 PM: Found Spy Cookie: paypopup cookie
4:02 PM: administrator@paypopup[1].txt (ID = 3119)
4:02 PM: Found Spy Cookie: falkag cookie
4:02 PM:
[email protected][2].txt (ID = 2650)
4:02 PM: Found Spy Cookie: realmedia cookie
4:02 PM: administrator@realmedia[2].txt (ID = 3235)
4:02 PM: Found Spy Cookie: fastclick cookie
4:02 PM: administrator@fastclick[2].txt (ID = 2651)
4:02 PM: Found Spy Cookie: adknowledge cookie
4:02 PM: administrator@adknowledge[2].txt (ID = 2072)
4:02 PM: Found Spy Cookie: realtracker cookie
4:02 PM:
[email protected][2].txt (ID = 3242)
4:02 PM: Found Spy Cookie: findthewebsiteyouneed cookie
4:02 PM:
[email protected][2].txt (ID = 2673)
4:02 PM: Found Spy Cookie: servedby advertising cookie
4:02 PM:
[email protected][2].txt (ID = 3335)
4:02 PM: Found Spy Cookie: revenue.net cookie
4:02 PM: administrator@revenue[2].txt (ID = 3257)
4:02 PM:
[email protected][3].txt (ID = 2142)
4:02 PM: Found Spy Cookie: empnads cookie
4:02 PM: administrator@empnads[1].txt (ID = 5012)
4:02 PM: Found Spy Cookie: upspiral cookie
4:02 PM:
[email protected][2].txt (ID = 3615)
4:02 PM: Cookie Sweep Complete, Elapsed Time: 00:00:05
4:02 PM: Starting File Sweep
4:02 PM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
4:03 PM: Found Adware: effective-i toolbar
4:03 PM: ucmoreiex.exe (ID = 59853)
4:03 PM: Found Adware: look2me
4:03 PM: installer.exe (ID = 168558)
4:03 PM: 113_dollarrevenue_4_0_3_9.exe (ID = 166444)
4:03 PM: icont.exe (ID = 65722)
4:03 PM: iconu.exe (ID = 65721)
4:03 PM: Warning: Failed to open file "c:\winnt\system32\mmdart32.dll". The process cannot access the file because it is being used by another process
4:03 PM: Warning: Failed to open file "c:\winnt\system32\k2lq0c35ef.dll". The process cannot access the file because it is being used by another process
4:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
4:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
4:04 PM: Warning: Failed to open file "c:\winnt\system32\k444lehq1h4e.dll". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\software.log". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\default.log". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\security". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\security.log". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\system.alt". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\sam". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\sam.log". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\system". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\software". The process cannot access the file because it is being used by another process
4:05 PM: Warning: Failed to open file "c:\winnt\system32\config\default". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\winnt\temp\zlt047fa.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\winnt\etb\nt_hide78.dll". Access is denied
4:06 PM: c:\winnt\etb (17 subtraces) (ID = -2147476235)
4:06 PM: pokapoka78.exe (ID = 179560)
4:07 PM: bw2.com (ID = 65721)
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs56b3e18e-acdd-4af9-8fa0-ddfbed9f8017.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs2872ce28-298e-4fb4-961e-cb91aed5cd54.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs897e6a8e-b8ba-49ee-bca2-0c74dd362106.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfe01032e-903b-4e8a-8987-b22c3c6e3ed6.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs92402bfb-f1a6-414d-9d70-c4dc4dde542e.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfb589e51-995d-48cd-82bf-8051edcb431a.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4f5095a6-ce99-4d93-8806-ecf87f4f515e.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8af71e97-bfd6-4b8f-b045-b23d326e2969.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs90191360-7e44-46b9-ae11-f572bffb0a4c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs27a34d60-c9a5-4c14-b149-99d48175d0a7.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4d6da3f4-9758-4bfd-b628-253f042c0484.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs90b23301-7a2c-49a6-8cec-f615322f214b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsabf56a51-bd4b-4dfd-9447-f01747c75dda.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs760df0da-f3d5-41a4-8c4e-4081c6f497f6.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs6c7f5696-1b56-432d-b2ab-e50b70c5e151.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs75d2f6f8-6205-4192-be03-4804915ff912.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs0cf8acfd-ae87-4391-8434-a1270c2139a0.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb61c1323-e83a-4b97-b237-dab2c948a31b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs43d74f53-9f06-4e8d-89e5-50e797f6989c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5193a205-fcc3-4a49-8113-e6739b59b018.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8692911e-ca43-4aa5-9712-432f928cb901.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf7978e60-2391-4646-ac89-1f1d2073c8d3.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs3fcbaa6f-c8ce-4aee-87ad-3469f5a88410.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs08ad0952-c0af-4895-b1b5-863655cca614.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs43563b7b-74d5-4e91-b5af-146cc656250d.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs998f5a72-59b7-4d2d-bd50-594b190883ed.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa6cbec10-978b-4ff0-8f42-23fc13b92c3b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf4f9f04f-8dda-43f1-8ff9-caf3c7df2cd2.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs565ca92d-62c4-42d2-92cd-3624e08f4c25.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs0a6ef264-339e-4b3e-8ac0-2c40298aaee5.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc92ecc4d-e53c-460c-a17f-e57f1ca6050b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs5d631d37-0a20-4694-8bcc-9c5d29dc1bec.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsbe9a4272-176a-4346-b91f-63544d89fcdb.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs38a2185d-9fb3-43fd-8ef5-f3e04c51ca53.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7e952fa4-c3c2-4156-a523-aefe48fbfffa.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs417da523-9b6d-4a10-a3ab-8f588ded6617.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9f015843-665c-4463-aa80-5496771be6a6.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs1d9cfb7b-baff-4d0a-adc7-6fe97ab487ca.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb855113d-ab3c-4e23-9341-ec87c990b398.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs73c4539a-7b3a-496c-a8c1-ce993f80f5f7.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs55851a1f-cb5e-4adf-9e3d-d658e577e2bb.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9bbdb7c6-1e02-429b-834a-44978f3011dd.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7a710521-e4fd-4cf6-b8c4-fc2015b1cf2b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf91d792a-cf58-4ccb-9409-f8b6452216ba.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs3583e666-e6c9-4586-be14-364cfc33ab76.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs67bbb5b7-1fae-4094-bf76-984c7fb173d9.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9b2b9e80-0011-4235-a4ee-c7ed8c368db1.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsae208f12-4c4a-4bd6-b39f-81d2e7880674.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsf99c3977-a976-416f-82aa-dbf1a50d58ba.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs36cf34b2-60cf-4c2e-82d4-0d9294c4c7ef.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa27a1c39-54c5-4bc5-8b48-d956f12e0597.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs71f6571e-5a89-41e7-941e-76667449a43a.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs7ec62cc2-6224-4d41-be94-02eea4ed6dc7.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs1d06931b-a465-40f5-9ee3-a480f7b2651c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs29b29136-82ad-4c58-bb6a-8cd5c33627e7.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs3d59fb5f-56b1-45b6-83ec-37d64e9bde9f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsfeca3b01-1cf1-4ca5-ab0e-9c980d70cb5c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc96ddc5f-3de9-49c6-86db-3f1286b35fa3.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs63e9c867-2805-4f85-9b95-8d2cddb0d0d6.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc04db985-363b-4998-b087-422dea13768f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4b1cf7e1-1efc-4a3b-a4e9-1f1957d98752.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs63b5c8a8-88b1-4a3d-b84e-4844c3a4dffa.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsee5176c9-d21c-44cd-85cb-1a0bdf2b2f70.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs323677c5-2d1c-4d09-bca3-aae9f0926281.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs189f9ae6-f0a3-4607-b0df-135b6b112b9b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs8b153cb3-ed99-4384-b05f-fa00c03b450f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs955be967-90e7-4a0c-9edb-2bfcfe5bea47.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs2668b513-946b-4927-a8b4-e534e19d4435.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc88dc713-e2e7-43ca-bbd0-f0fefb0cd7fd.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs91ec05fb-4f3c-4b59-8e89-a526b34a2c0c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscse027be81-418a-4410-81ec-cda153bdb5e4.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs3ab49109-446f-481c-9432-61fc123b1afd.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsbc3027ea-3f9a-44a3-8cc7-ce313b7eacc3.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs78edb3c9-6c5f-4ebf-bdc5-9d018bde879e.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc2049ad5-68fa-4080-b753-0e5ca0af8fa3.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa3a74b44-b2e4-45bf-9a8d-8a67d20f881f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs45754072-6cd1-4dc3-81e3-ee6d6e658900.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs0e8e8a7d-e120-4243-8dde-71395d058442.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs2b0a0019-c507-47e7-b1b7-2a414e80c512.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscse1a67301-b292-4b5f-9e9d-c05b0911b664.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs177236db-d28b-4861-94c2-e8ee178af3ad.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs83599491-5f20-4047-91e8-624ded5b5318.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs710b35b5-7d56-4232-b95f-cef0078129c0.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs99430a70-6655-44ef-8e76-177aa1247757.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsb54eadb6-e731-4cab-b122-65cd601aed92.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsbdc50348-7950-4f6b-9101-e2ab827c2a4d.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs401a71af-c544-479b-a95d-b3552f0c226f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs0c5c2a7d-e277-4ba4-8687-e0d335800cc4.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsc89d1c02-7562-4f2e-9cc1-1137d8a671a1.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs43e15090-3344-470f-b644-1741da9ed13c.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4d91a46e-d94d-47bf-8591-f578d79fe1a7.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa46edebe-29c1-4664-9b7a-8bfe4235e350.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsd108bb1f-c8b6-4905-a6d1-a5275352b42b.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsbd8dad19-8615-4b9f-a5b4-a1d27e4cd5b8.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsee845794-794f-4108-ac25-e998cbb1c94a.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4a0de9d7-11cb-4bef-bd23-18bb93a553a9.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs4b283c6a-f614-4cc0-bd1b-bb8791b52d99.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa803e7e7-a3bf-408b-b68f-f172aeef7259.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscsa6cfb3ca-464a-4e2b-ace1-20f4ff4b52c3.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs86f87f6d-939b-49f2-b50a-fe80407cfa4f.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscscefcd7c0-a756-4083-928e-2b5e262977e6.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs6276f0b8-b6e4-4a2b-aa69-89b43fe2075d.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs9cd05423-cb6b-419b-9056-feb82de6c7e9.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\all users\application data\webroot\spy sweeper\temp\sscs05fb6193-a7f8-4ee8-90fd-b5d1f2ebc2de.tmp". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\administrator\ntuser.dat". The process cannot access the file because it is being used by another process
4:09 PM: Warning: Failed to open file "c:\documents and settings\administrator\ntuser.dat.log". The process cannot access the file because it is being used by another process
4:09 PM: glf44glf44.exe (ID = 166444)
4:09 PM: tsinstall_4_0_3_8_b17.exe (ID = 78267)
4:09 PM: tsupdate_4_0_3_9_b2.exe (ID = 78281)
4:09 PM: glf60glf60.exe (ID = 78276)
4:10 PM: Warning: Failed to open file "c:\documents and settings\administrator\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
4:10 PM: Warning: Failed to open file "c:\documents and settings\administrator\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
4:10 PM: glf316glf316.exe (ID = 78276)
4:10 PM: appwrap[1].exe (ID = 65721)
4:10 PM: appwrap[1].exe (ID = 65722)
4:10 PM: Warning: Failed to open file "c:\windows\msresearch.exe". Access is denied
4:12 PM: Found Adware: purityscan
4:12 PM: a0018643.inf (ID = 73158)
4:13 PM: Warning: Unhandled Archive Type
4:13 PM: backup.zip (ID = 163672)
4:13 PM: File Sweep Complete, Elapsed Time: 00:10:16
4:13 PM: Full Sweep has completed. Elapsed time 00:16:40
4:13 PM: Traces Found: 160
4:13 PM: Removal process initiated
4:14 PM: Quarantining All Traces: elitebar
4:14 PM: Quarantining All Traces: look2me
4:14 PM: Quarantining All Traces: purityscan
4:14 PM: Quarantining All Traces: effective-i toolbar
4:14 PM: Quarantining All Traces: findthewebsiteyouneed hijacker
4:14 PM: Quarantining All Traces: icannnews
4:14 PM: icannnews is in use. It will be removed on reboot.
4:14 PM: C:\WINNT\system32\k2lq0c35ef.dll is in use. It will be removed on reboot.
4:14 PM: C:\WINNT\system32\mmdart32.dll is in use. It will be removed on reboot.
4:14 PM: C:\WINNT\system32\guard.tmp is in use. It will be removed on reboot.
4:14 PM: Quarantining All Traces: multidial
4:14 PM: Quarantining All Traces: targetsaver
4:14 PM: Quarantining All Traces: targetsoft
4:14 PM: Quarantining All Traces: the818search-co.com hijack
4:14 PM: Quarantining All Traces: abcsearch cookie
4:15 PM: Quarantining All Traces: adecn cookie
4:15 PM: Quarantining All Traces: adknowledge cookie
4:15 PM: Quarantining All Traces: adprofile cookie
4:15 PM: Quarantining All Traces: adserver cookie
4:15 PM: Quarantining All Traces: advertising cookie
4:15 PM: Quarantining All Traces: atlas dmt cookie
4:15 PM: Quarantining All Traces: azjmp cookie
4:15 PM: Quarantining All Traces: belnk cookie
4:15 PM: Quarantining All Traces: centrport net cookie
4:15 PM: Quarantining All Traces: empnads cookie
4:15 PM: Quarantining All Traces: falkag cookie
4:15 PM: Quarantining All Traces: fastclick cookie
4:15 PM: Quarantining All Traces: findthewebsiteyouneed cookie
4:15 PM: Quarantining All Traces: linksynergy cookie
4:15 PM: Quarantining All Traces: overture cookie
4:15 PM: Quarantining All Traces: paypopup cookie
4:15 PM: Quarantining All Traces: realmedia cookie
4:15 PM: Quarantining All Traces: realtracker cookie
4:15 PM: Quarantining All Traces: reliablestats cookie
4:15 PM: Quarantining All Traces: revenue.net cookie
4:15 PM: Quarantining All Traces: rn11 cookie
4:15 PM: Quarantining All Traces: servedby advertising cookie
4:15 PM: Quarantining All Traces: starware.com cookie
4:15 PM: Quarantining All Traces: targetnet cookie
4:15 PM: Quarantining All Traces: upspiral cookie
4:15 PM: Quarantining All Traces: yieldmanager cookie
4:15 PM: Quarantining All Traces: zedo cookie
4:15 PM: Preparing to restart your computer. Please wait...
4:15 PM: Removal process completed. Elapsed time 00:01:46
4:22 PM: Sent error log: C:\Documents and Settings\Administrator\Application Data\Webroot\Spy Sweeper\Logs\bugreport.txt
********
3:42 PM: | Start of Session, Tuesday, November 01, 2005 |
3:42 PM: Spy Sweeper started
3:45 PM: Warning: TDefFileIO.CompressAndEncrypt: Converting to LZMA Exception: Out of memory
3:45 PM: Error: Out of memory.
3:45 PM: Updating spyware definitions
3:47 PM: Deleted error log without sending: C:\Documents and Settings\Administrator\Application Data\Webroot\Spy Sweeper\Logs\bugreport.txt
3:47 PM: Updating spyware definitions
3:47 PM: Warning: TDefFileIO.CompressAndEncrypt: Converting to LZMA Exception: Out of memory
3:49 PM: Updating spyware definitions
3:50 PM: Updating spyware definitions
3:50 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:50 PM: Updating spyware definitions
3:50 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:50 PM: Updating spyware definitions
3:50 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:50 PM: Updating spyware definitions
3:50 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:50 PM: Updating spyware definitions
3:50 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:51 PM: Updating spyware definitions
3:51 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:51 PM: Updating spyware definitions
3:51 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:51 PM: Updating spyware definitions
3:51 PM: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.
3:51 PM: Updating spyware definitions
3:51 PM: Warning: TDefFileIO.CompressAndEncrypt: Converting to LZMA Exception: Out of memory
3:51 PM: Error: Out of memory.
3:51 PM: Updating spyware definitions
3:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
3:54 PM: Your spyware definitions have been updated.
3:55 PM: Processing Startup Alerts
3:55 PM: Removed Startup entry: System service78
3:56 PM: | End of Session, Tuesday, November 01, 2005 |
and here's the log for HJT:
Logfile of HijackThis v1.99.1
Scan saved at 4:26:25 PM, on 11/1/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINNT\dlhost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\jacob\hijackthis\HijackThis.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Microsoft Internet Explorer] C:\WINNT\System32\iexplore.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [Microsoft DLL Verifier] csrssv.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ruww] C:\PROGRA~1\COMMON~1\ruww\ruwwm.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1130713516917O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: DynamicHost (DLHOST) - Unknown owner - C:\WINNT\dlhost.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: WINS Client (RpcPatch) - Unknown owner - C:\WINNT\System32\wins\DLLHOST.EXE (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
Thanks
there is probably more bad stuff, and I am here all day