Hi Danny,
Thanks for the help.
I installed SpySweeper on the 26th after reading some other posts, and have since done three sweeps, so I've posted all three logs...
The pop-ups went with the first sweep, and today's sweep showed no traces, but the computer still seems a bit sluggish...does this program get rid of all traces? I still seem to be having some sort of problems (doesn't shut down properly and freezes occasioanlly), but I think these may have something to do with Norton blocking things...
Anyway, here are the logs...
********
12:04 PM: | Start of Session, Sunday, 30 October 2005 |
12:04 PM: Spy Sweeper started
12:04 PM: Sweep initiated using definitions version 564
12:04 PM: Starting Memory Sweep
12:07 PM: Memory Sweep Complete, Elapsed Time: 00:03:11
12:07 PM: Starting Registry Sweep
12:08 PM: Registry Sweep Complete, Elapsed Time:00:00:26
12:08 PM: Starting Cookie Sweep
12:08 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
12:08 PM: Starting File Sweep
12:15 PM: File Sweep Complete, Elapsed Time: 00:06:56
12:15 PM: Full Sweep has completed. Elapsed time 00:10:44
12:15 PM: Traces Found: 0
********
4:55 PM: | Start of Session, Friday, 28 October 2005 |
4:55 PM: Spy Sweeper started
4:55 PM: Sweep initiated using definitions version 562
4:55 PM: Starting Memory Sweep
4:59 PM: Memory Sweep Complete, Elapsed Time: 00:03:24
4:59 PM: Starting Registry Sweep
4:59 PM: Found Adware: coolwebsearch (cws)
4:59 PM: HKU\S-1-5-18\software\microsoft\windows\currentversion\run\ || quicktime task (ID = 112405)
4:59 PM: Registry Sweep Complete, Elapsed Time:00:00:31
4:59 PM: Starting Cookie Sweep
4:59 PM: Found Spy Cookie: belnk cookie
4:59 PM: hp_owner@belnk[1].txt (ID = 2292)
4:59 PM:
[email protected][2].txt (ID = 2293)
4:59 PM: Found Spy Cookie: gamespy cookie
4:59 PM: hp_owner@gamespy[1].txt (ID = 2719)
4:59 PM: Found Spy Cookie: directtrack cookie
4:59 PM:
[email protected][2].txt (ID = 2528)
4:59 PM: Found Spy Cookie: statcounter cookie
4:59 PM: hp_owner@statcounter[1].txt (ID = 3447)
4:59 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
4:59 PM: Starting File Sweep
5:13 PM: File Sweep Complete, Elapsed Time: 00:13:35
5:13 PM: Full Sweep has completed. Elapsed time 00:17:41
5:13 PM: Traces Found: 6
5:16 PM: Removal process initiated
5:17 PM: Quarantining All Traces: coolwebsearch (cws)
5:17 PM: Quarantining All Traces: belnk cookie
5:17 PM: Quarantining All Traces: directtrack cookie
5:17 PM: Quarantining All Traces: gamespy cookie
5:17 PM: Quarantining All Traces: statcounter cookie
5:17 PM: Removal process completed. Elapsed time 00:00:45
8:53 PM: Processing Startup Alerts
8:53 PM: Allowed Startup entry: wextract_cleanup0
6:34 PM: Your spyware definitions have been updated.
11:25 AM: Processing Internet Explorer Favorites Alerts
11:25 AM: Allowed IE Favorite: EVIL WinFixwer 2005 popups (and others) on a brand new system - Geeks to Go Forums
11:33 AM: Updating spyware definitions
11:33 AM: Your definitions are up to date.
11:34 AM: | End of Session, Sunday, 30 October 2005 |
********
6:30 PM: | Start of Session, Wednesday, 26 October 2005 |
6:30 PM: Spy Sweeper started
6:30 PM: Sweep initiated using definitions version 561
6:30 PM: Starting Memory Sweep
6:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:31 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:31 PM: Found Adware: look2me
6:31 PM: Detected running threat: C:\WINDOWS\system32\kcdhe220.dll (ID = 163672)
6:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:33 PM: Detected running threat: C:\WINDOWS\system32\mkvci70.dll (ID = 163672)
6:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:34 PM: Memory Sweep Complete, Elapsed Time: 00:03:43
6:34 PM: Starting Registry Sweep
6:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:35 PM: Found Adware: sp2ms
6:35 PM: HKLM\software\microsoft\windows\currentversion\run\ || msresearch (ID = 754357)
6:35 PM: Registry Sweep Complete, Elapsed Time:00:00:24
6:35 PM: Starting Cookie Sweep
6:35 PM: Found Spy Cookie: 2o7.net cookie
6:35 PM:
[email protected][1].txt (ID = 1958)
6:35 PM: Found Spy Cookie: atwola cookie
6:35 PM: hp_owner@atwola[1].txt (ID = 2255)
6:35 PM: Found Spy Cookie: belnk cookie
6:35 PM: hp_owner@belnk[1].txt (ID = 2292)
6:35 PM:
[email protected][2].txt (ID = 1958)
6:35 PM:
[email protected][2].txt (ID = 2293)
6:35 PM:
[email protected][1].txt (ID = 1958)
6:35 PM:
[email protected][2].txt (ID = 1958)
6:35 PM: Found Spy Cookie: paypopup cookie
6:35 PM: hp_owner@paypopup[2].txt (ID = 3119)
6:35 PM:
[email protected][1].txt (ID = 3120)
6:35 PM: Found Spy Cookie: directtrack cookie
6:35 PM:
[email protected][1].txt (ID = 2528)
6:35 PM: Found Spy Cookie: myaffiliateprogram.com cookie
6:35 PM:
[email protected][2].txt (ID = 3032)
6:35 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:35 PM: Starting File Sweep
6:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:35 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:35 PM: icont.exe (ID = 65722)
6:35 PM: appwrap[1].exe (ID = 65739)
6:35 PM: appwrap[1].exe (ID = 65722)
6:35 PM: bw2.com (ID = 65721)
6:36 PM: Found Adware: surf accuracy
6:36 PM: uninstall.exe (ID = 180136)
6:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:36 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:37 PM: Found Adware: isearch desktop search
6:37 PM: mte3ndi6odoxng[1].exe (ID = 178687)
6:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:37 PM: uninstaller.prod.24oct2005.exe[1].67ed8085ef4da0dd46732bc56aa91a66 (ID = 180136)
6:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:37 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:38 PM: Found Adware: effective-i toolbar
6:38 PM: ucmoreiex[1].exe (ID = 59853)
6:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:38 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:38 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:38 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:39 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:39 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:39 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:39 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:39 PM: Found Adware: isearch toolbar
6:39 PM: cmdinst.exe (ID = 154747)
6:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:40 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:40 PM: gp2sl3f71.dll (ID = 163672)
6:41 PM: Found Adware: ist yoursitebar
6:41 PM: yoursitebar[1].xml (ID = 131226)
6:41 PM: Found Adware: powerscan
6:41 PM: power_remove[1].exe (ID = 72675)
6:41 PM: ysbinstall_1003585[1].exe (ID = 166206)
6:41 PM: ysb[1].dll (ID = 161559)
6:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:41 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:41 PM: sacc[1].cfg (ID = 162775)
6:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:42 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:43 PM: mkvci70.dll (ID = 163672)
6:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:43 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:43 PM: appwrap[1].exe (ID = 65721)
6:44 PM: kcdhe220.dll (ID = 163672)
6:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:44 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:46 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:47 PM: File Sweep Complete, Elapsed Time: 00:12:14
6:47 PM: Full Sweep has completed. Elapsed time 00:16:33
6:47 PM: Traces Found: 32
6:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:47 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:48 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:50 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:51 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:52 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:53 PM: Removal process initiated
6:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:53 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:54 PM: Quarantining All Traces: effective-i toolbar
6:54 PM: Quarantining All Traces: isearch desktop search
6:54 PM: Quarantining All Traces: isearch toolbar
6:54 PM: Quarantining All Traces: ist yoursitebar
6:54 PM: Quarantining All Traces: powerscan
6:54 PM: Quarantining All Traces: sp2ms
6:54 PM: Quarantining All Traces: surf accuracy
6:54 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:54 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
6:54 PM: Quarantining All Traces: 2o7.net cookie
6:54 PM: Quarantining All Traces: atwola cookie
6:54 PM: Quarantining All Traces: belnk cookie
6:54 PM: Quarantining All Traces: directtrack cookie
6:54 PM: Quarantining All Traces: myaffiliateprogram.com cookie
6:54 PM: Quarantining All Traces: paypopup cookie
6:54 PM: Quarantining All Traces: look2me
6:54 PM: look2me is in use. It will be removed on reboot.
6:55 PM: Warning: Launched explorer.exe
6:55 PM: Warning: Quarantine process could not restart Explorer.
6:55 PM: Preparing to restart your computer. Please wait...
6:55 PM: Removal process completed. Elapsed time 00:01:42
8:06 PM: Deletion from quarantine initiated
8:06 PM: Processing: 2o7.net cookie
8:06 PM: Processing: atwola cookie
8:06 PM: Processing: belnk cookie
8:06 PM: Processing: directtrack cookie
8:06 PM: Processing: effective-i toolbar
8:06 PM: Processing: isearch desktop search
8:06 PM: Processing: isearch toolbar
8:06 PM: Processing: ist yoursitebar
8:06 PM: Processing: look2me
8:06 PM: Processing: myaffiliateprogram.com cookie
8:06 PM: Processing: paypopup cookie
8:06 PM: Processing: powerscan
8:06 PM: Processing: sp2ms
8:06 PM: Processing: surf accuracy
8:06 PM: Deletion from quarantine completed. Elapsed time 00:00:00
8:06 PM: Processing Internet Explorer Favorites Alerts
8:06 PM: Allowed IE Favorite: Bored of Studies
8:07 PM: Processing Internet Explorer Favorites Alerts
8:07 PM: Allowed IE Favorite: Board of Studies NSW
6:30 PM: Your spyware definitions have been updated.
********
6:10 PM: | Start of Session, Wednesday, 26 October 2005 |
6:10 PM: Spy Sweeper started
6:29 PM: Your spyware definitions have been updated.
6:30 PM: ActiveX Shield: found: Adware: look2me, version 1.0.0.0 -- Installation denied
6:30 PM: | End of Session, Wednesday, 26 October 2005 |
Thanks for your help
-Trent