Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Hijackthis Log/Ewido Log [RESOLVED]


  • This topic is locked This topic is locked

#1
ep3w

ep3w

    Member

  • Member
  • PipPip
  • 34 posts
Today i started getting popups that would come up every 5 minutes or so regardless of whether i was using firefox/IE or not. :tazz: I also ran CCleaner and Spybot S&D and it did not help.
Also now sometimes when i try to open firefox, firefox.exe will open and in the taskmanager it takes up 95-99% of the CPU useage and the actual firfox window won't open. After a couple tries this will happen to explorer.exe so i am forced to shut it down because it freezes. And now when i reboot this screen comes up: An exception occured while trying to run ""C:\WINDOWS\system32\erent.dll",DllGetVersion"
Thanks for the help!
Here is my Ewido log:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:22:17 PM, 11/11/2005
+ Report-Checksum: 9E93E52A

+ Scan result:

[1716] C:\WINDOWS\system32\myr2c.dll -> Spyware.Look2Me : Cleaned without backup
[2168] C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned without backup
:mozilla.6:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.7:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.9:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.10:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.11:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.13:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.14:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.15:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.16:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.17:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.19:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.24:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.38:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.[bleep]-access : Cleaned without backup
:mozilla.41:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.42:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.43:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.44:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.45:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.46:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.47:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.48:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.49:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.110:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
:mozilla.111:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
:mozilla.112:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
:mozilla.113:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
:mozilla.114:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned without backup
:mozilla.117:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Com : Cleaned without backup
:mozilla.118:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Com : Cleaned without backup
:mozilla.133:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.134:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.135:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.136:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.137:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.155:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned without backup
:mozilla.156:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned without backup
:mozilla.157:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned without backup
:mozilla.184:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned without backup
:mozilla.185:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned without backup
:mozilla.290:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned without backup
:mozilla.291:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned without backup
:mozilla.295:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned without backup
:mozilla.296:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned without backup
:mozilla.311:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned without backup
:mozilla.312:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned without backup
:mozilla.313:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned without backup
:mozilla.329:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned without backup
:mozilla.455:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.456:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.457:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.458:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Falkag : Cleaned without backup
:mozilla.467:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned without backup
:mozilla.468:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned without backup
:mozilla.469:C:\Documents and Settings\Ryan Maas\Application Data\Mozilla\Firefox\Profiles\default.lj5\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned without backup
C:\drsmartload.exe -> Spyware.SmartLoad : Cleaned without backup
C:\installer.exe -> Spyware.Look2Me : Cleaned without backup
C:\WINDOWS\system32\guard.tmp -> Spyware.Look2Me : Cleaned without backup
C:\WINDOWS\system32\ssreamci.dll -> Spyware.Look2Me : Cleaned without backup
C:\WINDOWS\system32\__delete_on_reboot__kwdbene.dll -> Spyware.Look2Me : Cleaned without backup


::Report End

Now my Hijackthis log :

Logfile of HijackThis v1.99.1
Scan saved at 8:24:14 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ryan Maas\Desktop\ \Security\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...603/mcfscan.cab
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: Run - C:\WINDOWS\system32\i0nmla511d.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Ad-aware also got this:

Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : File
Data : A0007945.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{6858ADA2-A446-4103-A4FD-946787D11A04}\RP19\



CoolWebSearch Object Recognized!
Type : File
Data : A0007960.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{6858ADA2-A446-4103-A4FD-946787D11A04}\RP19\



CoolWebSearch Object Recognized!
Type : File
Data : A0007961.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\System Volume Information\_restore{6858ADA2-A446-4103-A4FD-946787D11A04}\RP19\



CoolWebSearch Object Recognized!
Type : File
Data : d40m0ed1eh0.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\system32\



Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

CoolWebSearch Object Recognized!
Type : Regkey
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\microsoft\downloadmanager

CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Use Custom Search URL

CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\search
Value : SearchAssistant

CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\new windows
Value : PopupMgr

CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Enable Browser Extensions

CoolWebSearch Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Search Bar

CoolWebSearch Object Recognized!
Type : RegData
Data : no
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\main
Value : Use Search Asst
Data : no

CoolWebSearch Object Recognized!
Type : File
Data : wbemess.log
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\system32\wbem\logs\

Thanks again for the help. :)


EDIT: Fresh Hijack this log as of Nov 14:
Logfile of HijackThis v1.99.1
Scan saved at 7:46:12 PM, on 11/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Java\jre1.5.0_05\bin\javaw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Gaim\gaim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ryan Maas\Desktop\ \Security\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...603/mcfscan.cab
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: SharedDLLs - C:\WINDOWS\system32\m8juli1918.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Sorry for all the logs...

Edited by ep3w, 14 November 2005 - 06:47 PM.

  • 0

Advertisements


#2
retrac

retrac

    Visiting Staff

  • Member
  • PipPipPip
  • 578 posts
Hello ep3w :) Welcome to Geeks To Go ! I am working on a fix for your computer now. Thanks for the updated HJT log :tazz:

retrac
  • 0

#3
retrac

retrac

    Visiting Staff

  • Member
  • PipPipPip
  • 578 posts
Hello ep3w :) Alright lets get started :)


Next
You have a CoolWebSearch infection.

Download CWShredder Here to its own folder.

Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close CWShredder

Boot into Safe Mode:
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Reboot your computer into normal windows.




Next
You have the latest version of VX2. Download L2mfix from one of these two locations:

http://www.atribune....oads/l2mfix.exe
http://www.downloads....org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing enter. This will scan your computer and it may appear nothing is happening, then, after a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 OR any other files in the l2mfix folder until you are asked to do so!

if you receive, while running option #1, an error similar like: ''C:\windows\system32\cmd.exe
C:\windows\system32\autoexec.nt the system file is not suitable for running ms-dos and microsoft windows applications. choose close to terminate the application.."...then please use option 5 or the web page link in the l2mfix folder to solve this error condition. do not run the fix portion without fixing this first.


Please do not reboot your computer until asked to do so from here on out.



retrac :tazz:
  • 0

#4
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
CWShredder found nothing, but i can not remember if i ran this before when i was trying to solve the problem. Here is what L2mfix came up with:
L2MFIX find log 1.04a
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
"Asynchronous"=dword:00000000
"DllName"=hex(2):4c,00,4d,00,49,00,69,00,6e,00,69,00,74,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Impersonate"=dword:00000000
"Lock"="WLEventLock"
"Logoff"="WLEventLogoff"
"Logon"="WLEventLogon"
"Shutdown"="WLEventShutdown"
"StartScreenSaver"="WLEventStartScreenSaver"
"StartShell"="WLEventStartShell"
"Startup"="WLEventStartup"
"StopScreenSaver"="WLEventStopScreenSaver"
"Unlock"="WLEventUnlock"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\k208lcdu1f08.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{7C26763D-9345-FE62-F509-5E08A9F6915E}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{D1FB6C78-10FD-45cd-8FF4-8267D62992FB}"="CompuServe"
"{F802F260-519B-11D1-BB5D-0060974C6013}"="ICQ Shell Extension"
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{20082881-FC36-4E47-9A7A-644C95FF749F}"="IntelliPoint Wireless Control Panel Property Page"
"{AF90F543-6A3A-4C1B-8B16-ECEC073E69BE}"="IntelliPoint Wheel Control Panel Property Page"
"{653DCCC2-13DB-45B2-A389-427885776CFE}"="IntelliPoint Activities Control Panel Property Page"
"{124597D8-850A-41AE-849C-017A4FA99CA2}"="IntelliPoint Buttons Control Panel Property Page"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{19F500E0-9964-11cf-B63D-08002B317C03}"="Desktop Icon Layout"
"{EBDF1F20-C829-11D1-8233-FF20AF3E97A9}"="TrojanHunter Menu Shell Extension"
"{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
"{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
"{9C8DEC29-B27E-4677-8974-2BFB65174009}"=""
"{4BBCA4B3-10C1-4694-AC86-6E3728D74C80}"=""
"{B327765E-D724-4347-8B16-78AE18552FC3}"="NeroDigitalIconHandler"
"{7F1CF152-04F8-453A-B34C-E609530A9DC8}"="NeroDigitalPropSheetHandler"

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9C8DEC29-B27E-4677-8974-2BFB65174009}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C8DEC29-B27E-4677-8974-2BFB65174009}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C8DEC29-B27E-4677-8974-2BFB65174009}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9C8DEC29-B27E-4677-8974-2BFB65174009}\InprocServer32]
@="C:\\WINDOWS\\system32\\tlflog.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
browseui.dll Fri Sep 2 2005 6:52:04p A.... 1,019,904 996.00 K
cdfview.dll Fri Sep 2 2005 6:52:04p A.... 151,040 147.50 K
cdosys.dll Fri Sep 9 2005 8:53:42p A.... 2,067,968 1.97 M
cmdlin~1.dll Thu Aug 18 2005 1:19:54p A.... 43,520 42.50 K
danim.dll Fri Sep 2 2005 6:52:04p A.... 1,053,696 1.00 M
dpl100.dll Thu Oct 27 2005 2:37:46p A.... 86,016 84.00 K
dpu10.dll Thu Oct 27 2005 2:37:44p A.... 294,912 288.00 K
dpu11.dll Thu Oct 27 2005 2:37:44p A.... 294,912 288.00 K
dpugui10.dll Thu Oct 27 2005 2:37:48p A.... 53,248 52.00 K
dpugui11.dll Thu Oct 27 2005 2:37:46p A.... 593,920 580.00 K
dpus11.dll Thu Oct 27 2005 2:37:44p A.... 339,968 332.00 K
dpv11.dll Thu Oct 27 2005 2:37:44p A.... 57,344 56.00 K
dtu100.dll Thu Oct 27 2005 2:37:44p A.... 200,704 196.00 K
dxtrans.dll Fri Sep 2 2005 6:52:04p A.... 205,312 200.50 K
extmgr.dll Fri Sep 2 2005 6:52:04p ..... 55,808 54.50 K
gdi32.dll Wed Oct 5 2005 10:09:36p A.... 280,064 273.50 K
iepeers.dll Fri Sep 2 2005 6:52:04p A.... 251,392 245.50 K
inseng.dll Fri Sep 2 2005 6:52:04p A.... 96,256 94.00 K
layout.dll Tue Aug 16 2005 1:07:48a A.... 13,824 13.50 K
libdivx.dll Wed Sep 28 2005 1:50:06p A.... 1,044,480 1020.00 K
linkinfo.dll Wed Aug 31 2005 8:41:54p A.... 19,968 19.50 K
mshtml.dll Tue Oct 4 2005 4:26:00p A.... 3,015,168 2.88 M
mshtmled.dll Fri Sep 2 2005 6:52:06p A.... 448,512 438.00 K
msrating.dll Fri Sep 2 2005 6:52:06p A.... 146,432 143.00 K
mstime.dll Fri Sep 2 2005 6:52:06p A.... 530,432 518.00 K
netman.dll Mon Aug 22 2005 1:29:46p A.... 197,632 193.00 K
nv4_disp.dll Mon Oct 10 2005 8:49:00p A.... 3,921,024 3.74 M
nvapi.dll Mon Oct 10 2005 8:49:00p A.... 45,056 44.00 K
nvcod.dll Mon Oct 10 2005 8:49:00p A.... 34,304 33.50 K
nvcodins.dll Mon Oct 10 2005 8:49:00p A.... 34,304 33.50 K
nvcpl.dll Mon Oct 10 2005 8:49:00p A.... 7,286,784 6.95 M
nvhwvid.dll Mon Oct 10 2005 8:49:00p A.... 573,440 560.00 K
nview.dll Mon Oct 10 2005 8:49:00p A.... 1,466,368 1.40 M
nvmccs.dll Mon Oct 10 2005 8:49:00p A.... 229,376 224.00 K
nvmccsrs.dll Mon Oct 10 2005 8:49:00p A.... 45,056 44.00 K
nvmctray.dll Mon Oct 10 2005 8:49:00p A.... 86,016 84.00 K
nvnt4cpl.dll Mon Oct 10 2005 8:49:00p A.... 286,720 280.00 K
nvoglnt.dll Mon Oct 10 2005 8:49:00p A.... 5,378,048 5.13 M
nvshell.dll Mon Oct 10 2005 8:49:00p A.... 466,944 456.00 K
nvwddi.dll Mon Oct 10 2005 8:49:00p A.... 81,920 80.00 K
nvwdmcpl.dll Mon Oct 10 2005 8:49:00p A.... 1,662,976 1.59 M
nvwimg.dll Mon Oct 10 2005 8:49:00p A.... 1,019,904 996.00 K
pngfilt.dll Fri Sep 2 2005 6:52:06p A.... 39,424 38.50 K
quartz.dll Mon Aug 29 2005 10:54:26p A.... 1,287,168 1.23 M
shdocvw.dll Fri Sep 2 2005 6:52:06p A.... 1,483,776 1.41 M
shell32.dll Thu Sep 22 2005 10:05:30p A.... 8,450,560 8.06 M
shlwapi.dll Fri Sep 2 2005 6:52:06p A.... 473,600 462.50 K
ssldivx.dll Wed Sep 28 2005 1:50:04p A.... 200,704 196.00 K
tlflog.dll Mon Nov 14 2005 9:44:48p ..S.R 235,933 230.40 K
umpnpmgr.dll Mon Aug 22 2005 10:35:42p A.... 123,392 120.50 K
urlmon.dll Fri Sep 2 2005 6:52:06p A.... 608,768 594.50 K
wininet.dll Fri Sep 2 2005 6:52:06p A.... 658,432 643.00 K
winsrv.dll Wed Aug 31 2005 8:41:54p A.... 291,840 285.00 K

53 items found: 53 files (1 H/S), 0 directories.
Total of file sizes: 49,034,269 bytes 46.76 M
Locate .tmp files:

No matches found.
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is D837-D4FC

Directory of C:\WINDOWS\System32

11/14/2005 09:44 PM 235,933 tlflog.dll
11/14/2005 09:44 PM 237,147 f4j2le1o1h.dll
11/14/2005 09:39 PM 235,933 k208lcdu1f08.dll
11/12/2005 03:51 PM 235,422 lt2027fmg.dll
11/11/2005 09:05 PM 236,683 en62l1jo1.dll
11/10/2005 12:19 AM <DIR> dllcache
12/27/2004 01:12 AM 848 KGyGaAvL.sys
04/24/2003 07:10 PM <DIR> Microsoft
6 File(s) 1,181,966 bytes
2 Dir(s) 30,073,073,664 bytes free


I appreciate you taking the time to help! :tazz: I am still having the same problems though... I did not get an error when i rebooted windows though after running CWShredder.

Edited by ep3w, 14 November 2005 - 08:58 PM.

  • 0

#5
retrac

retrac

    Visiting Staff

  • Member
  • PipPipPip
  • 578 posts
Welcome Back ep3w :)



Next
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a NEW hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
If after the reboot the desktop icons dont dissappear or the log does not pop up then in the l2mfix folder double click the second.bat file to continue with the fix.


Post those logs tonight and ill be back tommorow with a fix. :tazz:

Edited by retrac, 14 November 2005 - 09:28 PM.

  • 0

#6
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
When i chose option 2 and tried to run it, it rebooted my computer then no log came up and the icons only dissapeared for half a second maybe. I then ran second.bat and the dos window came up and killed explorer and it ran the first pass for a minute or so. Then it came up with 2 files and it looked like this:

Killing Processes!
1 file(s) copied.
Scanning First Pass. Please Wait!
First Pass Completed
Second Pass Scanning
C:\WINDOWS\system32\mtdemui.dll: WinLogoff
C:\WINDOWS\system32\guard.tmp: WinLogoff
Second Pass Completed!
C:\WINDOWS\system32\guard.tmp
Access is denied.

After that it sat for a second then it closed.(thats still in dos). Then i gave it a minute and nothing happened. So i did contrl+alt+delete and ran explorer.exe and everything was back to normal. I still get the pop ups and stuff though and i never got a notepad log. I dont know if this is normal or not.

Here is a new Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:54:00 PM, on 11/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ryan Maas\Desktop\ \Security\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...603/mcfscan.cab
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\lvl8093ue.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

EDIT: Tried second.bat again and got the same results but C:\WINDOWS\system32\mtdemui.dll: did not show up. I did not get a notepad log again or anything though. After it said acces denied, then closed after a minute, i gave it about 5 minutes and nothing happened.

Edited by ep3w, 14 November 2005 - 10:10 PM.

  • 0

#7
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello there. Looks like we have a problem here, which is NOT something you did wrong, nor did retrac. :) I'm going to pm the creator of the l2m tool now, and ask him to take a look. If any other staff member gives you instructions here, please DO follow them. It would be one of our tool creators, and I guarantee you they know their stuff. :tazz:

Sit tight for me.
  • 0

#8
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
CCleaner just found this if it helps...I had it fix them.
ActiveX/COM Issue NMUIEngine.NMUIResourceLoaderHarddisk - {number/letters}
ActiveX/COM Issue InProcServer32\C:\WINDOWS\system32\gaurd.tmp

Sorry i am just posting this quick before i go to class.

Edited by ep3w, 15 November 2005 - 10:47 AM.

  • 0

#9
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello again! Retrac won't be online again for several hours. I'm going to jump in here and post some instructions for you. I don't think retrac will mind! :tazz:

Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it. Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Options on the left side.
  • Click the Sweep Options tab.
  • Under What to Sweep please put a check next to the following:
    • Sweep Memory
    • Sweep Registry
    • Sweep Cookies
    • Sweep All User Accounts
    • Enable Direct Disk Sweeping
    • Sweep Contents of Compressed Files
    • Sweep for Rootkits
    • Please UNCHECK Do not Sweep System Restore Folder.
  • Click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply, along with a new HijackThis log

  • 0

#10
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
First time I ran it I got a bunch of stuff but when i when to remove it, it said some was in use of memory so i closed everything then clicked continue, It closed explorer.exe and continued but then the progress bar froze after about 8% then nothing happened. I could move the mouse but could not do anything else or click on anything or acces the task manager. I gave it 10 minutes and nothing happened so i restarted it. Here is the log it gave me after i restarted. I am going to run it again now and I will post up the new log and a new hijackthis log.

********
9:36 AM: | Start of Session, Wednesday, November 16, 2005 |
9:36 AM: Spy Sweeper started
9:36 AM: Sweep initiated using definitions version 573
9:36 AM: Found Adware: look2me
9:36 AM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\installer\ || dllname (ID = 129982)
9:36 AM: dnjq0115e.dll (ID = 129982)
9:36 AM: Starting Memory Sweep
9:37 AM: Found Adware: icannnews
9:37 AM: Detected running threat: C:\WINDOWS\system32\dnjq0115e.dll (ID = 83)
9:38 AM: Detected running threat: C:\WINDOWS\system32\ozedlg.dll (ID = 83)
9:38 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:38 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:38 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:38 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:38 AM: Memory Sweep Complete, Elapsed Time: 00:02:14
9:38 AM: Starting Registry Sweep
9:38 AM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\installer\ (6 subtraces) (ID = 129940)
9:39 AM: Registry Sweep Complete, Elapsed Time:00:00:11
9:39 AM: Starting Cookie Sweep
9:39 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:39 AM: Starting File Sweep
9:40 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:40 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:40 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:40 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:44 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:44 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:44 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:44 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:51 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
9:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:00 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:01 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:01 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:01 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:01 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:02 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:03 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:04 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:05 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:06 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:07 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:08 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:09 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:10 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:10 AM: Found System Monitor: potentially rootkit-masked files
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtkdrawingarea.h (ID = 0)
10:10 AM: iconv.exe (ID = 0)
10:10 AM: gtkdebug.h (ID = 0)
10:10 AM: gtkcurve.h (ID = 0)
10:10 AM: gtkenums.h (ID = 0)
10:10 AM: gtkentrycompletion.h (ID = 0)
10:10 AM: gtkeditable.h (ID = 0)
10:10 AM: gtkentry.h (ID = 0)
10:10 AM: gtkdnd.h (ID = 0)
10:10 AM: glib-mkenums (ID = 0)
10:10 AM: gtkdialog.h (ID = 0)
10:10 AM: fttimer.exe (ID = 0)
10:10 AM: gtkcomboboxentry.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtkcolorseldialog.h (ID = 0)
10:10 AM: gtkcolorbutton.h (ID = 0)
10:10 AM: ftmemchk.exe (ID = 0)
10:10 AM: gtkcombobox.h (ID = 0)
10:10 AM: ftdump.exe (ID = 0)
10:10 AM: gtkcheckmenuitem.h (ID = 0)
10:10 AM: gtkcheckbutton.h (ID = 0)
10:10 AM: gtkcellview.h (ID = 0)
10:10 AM: gtkcellrenderertoggle.h (ID = 0)
10:10 AM: gtkcellrenderertext.h (ID = 0)
10:10 AM: gtkcombo.h (ID = 0)
10:10 AM: gtkcellrendererprogress.h (ID = 0)
10:10 AM: gtkcolorsel.h (ID = 0)
10:10 AM: gtkcellrendererpixbuf.h (ID = 0)
10:10 AM: gtkcellrenderercombo.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: pcftypes.h (ID = 0)
10:10 AM: internal.h (ID = 0)
10:10 AM: gtkcelleditable.h (ID = 0)
10:10 AM: ftxf86.h (ID = 0)
10:10 AM: msgcmp.exe (ID = 0)
10:10 AM: gtkclipboard.h (ID = 0)
10:10 AM: ftsynth.h (ID = 0)
10:10 AM: gtkbox.h (ID = 0)
10:10 AM: gtkbin.h (ID = 0)
10:10 AM: gtkbbox.h (ID = 0)
10:10 AM: gtkaspectframe.h (ID = 0)
10:10 AM: gtkarrow.h (ID = 0)
10:10 AM: gtkalignment.h (ID = 0)
10:10 AM: gtkadjustment.h (ID = 0)
10:10 AM: gtkcellrenderer.h (ID = 0)
10:10 AM: gtkaccessible.h (ID = 0)
10:10 AM: gtkaccelmap.h (ID = 0)
10:10 AM: gtkaccellabel.h (ID = 0)
10:10 AM: gdk-pixbuf.h (ID = 0)
10:10 AM: gtkcontainer.h (ID = 0)
10:10 AM: gtkcelllayout.h (ID = 0)
10:10 AM: ftgloadr.h (ID = 0)
10:10 AM: ftserv.h (ID = 0)
10:10 AM: ftrfork.h (ID = 0)
10:10 AM: ftsysmem.h (ID = 0)
10:10 AM: ftsysio.h (ID = 0)
10:10 AM: ftpfr.h (ID = 0)
10:10 AM: gtkcalendar.h (ID = 0)
10:10 AM: gtkbutton.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtkbindings.h (ID = 0)
10:10 AM: gtkactiongroup.h (ID = 0)
10:10 AM: ftdebug.h (ID = 0)
10:10 AM: ftwinfnt.h (ID = 0)
10:10 AM: gtkaccelgroup.h (ID = 0)
10:10 AM: gtkaboutdialog.h (ID = 0)
10:10 AM: gtk.h (ID = 0)
10:10 AM: gdk-pixdata.h (ID = 0)
10:10 AM: ftmoderr.h (ID = 0)
10:10 AM: ftlzw.h (ID = 0)
10:10 AM: msgconv.exe (ID = 0)
10:10 AM: ftsnames.h (ID = 0)
10:10 AM: ftmemory.h (ID = 0)
10:10 AM: ftsizes.h (ID = 0)
10:10 AM: ftrender.h (ID = 0)
10:10 AM: msgen.exe (ID = 0)
10:10 AM: msgexec.exe (ID = 0)
10:10 AM: ftmm.h (ID = 0)
10:10 AM: ftmac.h (ID = 0)
10:10 AM: ftincrem.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: msgfilter.exe (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: msguniq.exe (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: libpixbufloader-wbmp.dll (ID = 0)
10:10 AM: libpixbufloader-ras.dll (ID = 0)
10:10 AM: im-inuktitut.dll (ID = 0)
10:10 AM: pango-basic-fc.dll (ID = 0)
10:10 AM: gtkclist.h (ID = 0)
10:10 AM: gtk-win32-2.0.def (ID = 0)
10:10 AM: libtiff-bcc.lib (ID = 0)
10:10 AM: libpangowin32-1.0.dll.a (ID = 0)
10:10 AM: tiffio.h (ID = 0)
10:10 AM: gtkwindow.h (ID = 0)
10:10 AM: gtktextview.h (ID = 0)
10:10 AM: libwimp.dll (ID = 0)
10:10 AM: gtktextlayout.h (ID = 0)
10:10 AM: gtkmarshal.h (ID = 0)
10:10 AM: gtkctree.h (ID = 0)
10:10 AM: fttrigon.h (ID = 0)
10:10 AM: ftsystem.h (ID = 0)
10:10 AM: ftgzip.h (ID = 0)
10:10 AM: ftstream.h (ID = 0)
10:10 AM: ftstroke.h (ID = 0)
10:10 AM: ftchapters.h (ID = 0)
10:10 AM: atk.h (ID = 0)
10:10 AM: ftbdf.h (ID = 0)
10:10 AM: libatk-1.0.dll.a (ID = 0)
10:10 AM: ftbbox.h (ID = 0)
10:10 AM: ftstdlib.h (ID = 0)
10:10 AM: fterrors.h (ID = 0)
10:10 AM: fterrdef.h (ID = 0)
10:10 AM: libgdk_pixbuf-2.0.dll.a (ID = 0)
10:10 AM: ftcsbits.h (ID = 0)
10:10 AM: atk-enum-types.h (ID = 0)
10:10 AM: libjpeg.dll.a (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gdk-pixbuf-transform.h (ID = 0)
10:10 AM: ftcmru.h (ID = 0)
10:10 AM: gdk-pixbuf-marshal.h (ID = 0)
10:10 AM: ftcmanag.h (ID = 0)
10:10 AM: gdk-pixbuf-loader.h (ID = 0)
10:10 AM: ftcglyph.h (ID = 0)
10:10 AM: ftccmap.h (ID = 0)
10:10 AM: gdk-pixbuf-features.h (ID = 0)
10:10 AM: ftccache.h (ID = 0)
10:10 AM: gdk-pixbuf-enum-types.h (ID = 0)
10:10 AM: gdk-pixbuf-io.h (ID = 0)
10:10 AM: gdkwin32.h (ID = 0)
10:10 AM: gdkvisual.h (ID = 0)
10:10 AM: gdk-pixbuf-core.h (ID = 0)
10:10 AM: gdk-pixbuf-animation.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gdktypes.h (ID = 0)
10:10 AM: pango-thai-fc.dll (ID = 0)
10:10 AM: pango-basic-win32.dll (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: libgthread-2.0-0.dll (ID = 0)
10:10 AM: gdkspawn.h (ID = 0)
10:10 AM: gdkselection.h (ID = 0)
10:10 AM: gdkscreen.h (ID = 0)
10:10 AM: gdkrgb.h (ID = 0)
10:10 AM: ftmodapi.h (ID = 0)
10:10 AM: gdkregion.h (ID = 0)
10:10 AM: gdkproperty.h (ID = 0)
10:10 AM: sfnt.h (ID = 0)
10:10 AM: fttypes.h (ID = 0)
10:10 AM: xgettext.exe (ID = 0)
10:10 AM: ftglyph.h (ID = 0)
10:10 AM: ftoption.h (ID = 0)
10:10 AM: ftheader.h (ID = 0)
10:10 AM: autohint.h (ID = 0)
10:10 AM: ftmulti.exe (ID = 0)
10:10 AM: giochannel.h (ID = 0)
10:10 AM: ftlist.h (ID = 0)
10:10 AM: gthread.h (ID = 0)
10:10 AM: fontconfig.h (ID = 0)
10:10 AM: msgunfmt.exe (ID = 0)
10:10 AM: gparamspecs.h (ID = 0)
10:10 AM: jerror.h (ID = 0)
10:10 AM: jmorecfg.h (ID = 0)
10:10 AM: gdk-win32-2.0.def (ID = 0)
10:10 AM: zlib.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: msgcomm.exe (ID = 0)
10:10 AM: gdkprivate.h (ID = 0)
10:10 AM: msgcat.exe (ID = 0)
10:10 AM: gdkpixmap.h (ID = 0)
10:10 AM: gdkpixbuf.h (ID = 0)
10:10 AM: msgattrib.exe (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gobject-query.exe (ID = 0)
10:10 AM: gdkinput.h (ID = 0)
10:10 AM: gdkimage.h (ID = 0)
10:10 AM: gdki18n.h (ID = 0)
10:10 AM: ftbench.exe (ID = 0)
10:10 AM: libz.a (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gdkpango.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gdkfont.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: libiconv.a (ID = 0)
10:10 AM: libjpeg-bcc.lib (ID = 0)
10:10 AM: gdkdisplaymanager.h (ID = 0)
10:10 AM: gdkcursor.h (ID = 0)
10:10 AM: gvaluearray.h (ID = 0)
10:10 AM: gvalue.h (ID = 0)
10:10 AM: gtypeplugin.h (ID = 0)
10:10 AM: gtypemodule.h (ID = 0)
10:10 AM: libpangowin32-1.0-0.dll (ID = 0)
10:10 AM: gsourceclosure.h (ID = 0)
10:10 AM: gdkkeys.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: iconv.lib (ID = 0)
10:10 AM: gboxed.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gdkgc.h (ID = 0)
10:10 AM: gmodule.h (ID = 0)
10:10 AM: glib.h (ID = 0)
10:10 AM: glib-object.h (ID = 0)
10:10 AM: gwin32.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gdkdnd.h (ID = 0)
10:10 AM: gdkdrawable.h (ID = 0)
10:10 AM: gdkdisplay.h (ID = 0)
10:10 AM: gdkcolor.h (ID = 0)
10:10 AM: gvaluetypes.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtree.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gvaluecollector.h (ID = 0)
10:10 AM: gtimer.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gsignal.h (ID = 0)
10:10 AM: gobjectnotifyqueue.c (ID = 0)
10:10 AM: gparam.h (ID = 0)
10:10 AM: gobject.h (ID = 0)
10:10 AM: genums.h (ID = 0)
10:10 AM: gmarshal.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gclosure.h (ID = 0)
10:10 AM: freetype.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: freetype6.dll (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gutils.h (ID = 0)
10:10 AM: gunicode.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: libfreetype.lib (ID = 0)
10:10 AM: gthreadpool.h (ID = 0)
10:10 AM: gtypes.h (ID = 0)
10:10 AM: gstring.h (ID = 0)
10:10 AM: gtkeventbox.h (ID = 0)
10:10 AM: gtkexpander.h (ID = 0)
10:10 AM: gtkfilechooser.h (ID = 0)
10:10 AM: gtkfilechooserbutton.h (ID = 0)
10:10 AM: gtkfilechooserdialog.h (ID = 0)
10:10 AM: gtkfilechooserwidget.h (ID = 0)
10:10 AM: gtkfilefilter.h (ID = 0)
10:10 AM: gstdio.h (ID = 0)
10:10 AM: gtkfilesel.h (ID = 0)
10:10 AM: gtkfilesystem.h (ID = 0)
10:10 AM: gspawn.h (ID = 0)
10:10 AM: gslist.h (ID = 0)
10:10 AM: gshell.h (ID = 0)
10:10 AM: grel.h (ID = 0)
10:10 AM: grand.h (ID = 0)
10:10 AM: gscanner.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtkfixed.h (ID = 0)
10:10 AM: gtkfontbutton.h (ID = 0)
10:10 AM: gtkfontsel.h (ID = 0)
10:10 AM: gtkframe.h (ID = 0)
10:10 AM: gtkgamma.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gstrfuncs.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gquark.h (ID = 0)
10:10 AM: gqsort.h (ID = 0)
10:10 AM: gprintf.h (ID = 0)
10:10 AM: gprimes.h (ID = 0)
10:10 AM: gtkgc.h (ID = 0)
10:10 AM: gtkhandlebox.h (ID = 0)
10:10 AM: gtkhbbox.h (ID = 0)
10:10 AM: gtkhbox.h (ID = 0)
10:10 AM: gtkhpaned.h (ID = 0)
10:10 AM: gtkhruler.h (ID = 0)
10:10 AM: gtkhscale.h (ID = 0)
10:10 AM: gtkhscrollbar.h (ID = 0)
10:10 AM: gtkhseparator.h (ID = 0)
10:10 AM: gtkiconfactory.h (ID = 0)
10:10 AM: gtkicontheme.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gpattern.h (ID = 0)
10:10 AM: gqueue.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atknoopobjectfactory.h (ID = 0)
10:10 AM: atknoopobject.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gdk_pixbuf-2.0.def (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gettextlib.dll (ID = 0)
10:10 AM: gtkiconview.h (ID = 0)
10:10 AM: gtkimagemenuitem.h (ID = 0)
10:10 AM: gtkimcontext.h (ID = 0)
10:10 AM: gtkimcontextsimple.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: jpeg62.def (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: ftcimage.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: goption.h (ID = 0)
10:10 AM: gnode.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gthread-2.0.lib (ID = 0)
10:10 AM: fcprivate.h (ID = 0)
10:10 AM: fcfreetype.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtkimmodule.h (ID = 0)
10:10 AM: gtkimmulticontext.h (ID = 0)
10:10 AM: gtkinputdialog.h (ID = 0)
10:10 AM: gtkinvisible.h (ID = 0)
10:10 AM: gtkitem.h (ID = 0)
10:10 AM: gtkitemfactory.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: jpeglib.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gmem.h (ID = 0)
10:10 AM: gmarkup.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: libfreetype.dll.a (ID = 0)
10:10 AM: gmain.h (ID = 0)
10:10 AM: gobject-2.0.def (ID = 0)
10:10 AM: gtklabel.h (ID = 0)
10:10 AM: gtklayout.h (ID = 0)
10:10 AM: gtklist.h (ID = 0)
10:10 AM: gtklistitem.h (ID = 0)
10:10 AM: gtkliststore.h (ID = 0)
10:10 AM: gtkmain.h (ID = 0)
10:10 AM: gmessages.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glist.h (ID = 0)
10:10 AM: gi18n.h (ID = 0)
10:10 AM: gi18n-lib.h (ID = 0)
10:10 AM: ghook.h (ID = 0)
10:10 AM: ghash.h (ID = 0)
10:10 AM: gfileutils.h (ID = 0)
10:10 AM: gerror.h (ID = 0)
10:10 AM: gdir.h (ID = 0)
10:10 AM: gdataset.h (ID = 0)
10:10 AM: gconvert.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gcompletion.h (ID = 0)
10:10 AM: gcache.h (ID = 0)
10:10 AM: gbacktrace.h (ID = 0)
10:10 AM: gatomic.h (ID = 0)
10:10 AM: gasyncqueue.h (ID = 0)
10:10 AM: gdate.h (ID = 0)
10:10 AM: galloca.h (ID = 0)
10:10 AM: ft2build.h (ID = 0)
10:10 AM: ttunpat.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gmodule-2.0.lib (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: garray.h (ID = 0)
10:10 AM: gettext-po.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glibconfig.h (ID = 0)
10:10 AM: gettextpo.lib (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: freetype.def (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: fontconfig.def (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: charset.lib (ID = 0)
10:10 AM: asprintf.lib (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib-2.0.def (ID = 0)
10:10 AM: libpixbufloader-xbm.dll (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: libpixbufloader-pcx.dll (ID = 0)
10:10 AM: zconf.h (ID = 0)
10:10 AM: tiffconf.h (ID = 0)
10:10 AM: tttags.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: libintl.a (ID = 0)
10:10 AM: gdkwindow.h (ID = 0)
10:10 AM: gtype.h (ID = 0)
10:10 AM: msgmerge.exe (ID = 0)
10:10 AM: pangowin32.h (ID = 0)
10:10 AM: pangoft2.h (ID = 0)
10:10 AM: pangofc-decoder.h (ID = 0)
10:10 AM: pango.h (ID = 0)
10:10 AM: pango-utils.h (ID = 0)
10:10 AM: pango-tabs.h (ID = 0)
10:10 AM: pango-modules.h (ID = 0)
10:10 AM: msggrep.exe (ID = 0)
10:10 AM: gettextpo.dll (ID = 0)
10:10 AM: gdk-pixbuf-query-loaders.exe (ID = 0)
10:10 AM: pangofc-fontmap.h (ID = 0)
10:10 AM: pangofc-font.h (ID = 0)
10:10 AM: pango-types.h (ID = 0)
10:10 AM: pango-script.h (ID = 0)
10:10 AM: pango-renderer.h (ID = 0)
10:10 AM: pango-ot.h (ID = 0)
10:10 AM: gdk-pixbuf-csource.exe (ID = 0)
10:10 AM: fc-list.exe (ID = 0)
10:10 AM: charset.dll (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: pango-item.h (ID = 0)
10:10 AM: pango-glyph.h (ID = 0)
10:10 AM: pango-layout.h (ID = 0)
10:10 AM: pango-glyph-item.h (ID = 0)
10:10 AM: gtkmenu.h (ID = 0)
10:10 AM: pango-fontmap.h (ID = 0)
10:10 AM: pango-enum-types.h (ID = 0)
10:10 AM: pango-fontset.h (ID = 0)
10:10 AM: pango-coverage.h (ID = 0)
10:10 AM: pango-font.h (ID = 0)
10:10 AM: libpng12.dll (ID = 0)
10:10 AM: gtkmenubar.h (ID = 0)
10:10 AM: gtkmenuitem.h (ID = 0)
10:10 AM: gtkmenushell.h (ID = 0)
10:10 AM: gtkmenutoolbutton.h (ID = 0)
10:10 AM: gtkmisc.h (ID = 0)
10:10 AM: pango-engine.h (ID = 0)
10:10 AM: pango-context.h (ID = 0)
10:10 AM: pango-break.h (ID = 0)
10:10 AM: localcharset.h (ID = 0)
10:10 AM: atkdocument.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: libpixbufloader-gif.dll (ID = 0)
10:10 AM: im-ipa.dll (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: im-viqr.dll (ID = 0)
10:10 AM: t1tables.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: im-thai-broken.dll (ID = 0)
10:10 AM: t1types.h (ID = 0)
10:10 AM: svxf86nm.h (ID = 0)
10:10 AM: svwinfnt.h (ID = 0)
10:10 AM: svttcmap.h (ID = 0)
10:10 AM: svsfnt.h (ID = 0)
10:10 AM: svpsinfo.h (ID = 0)
10:10 AM: svpscmap.h (ID = 0)
10:10 AM: svpostnm.h (ID = 0)
10:10 AM: im-cyrillic-translit.dll (ID = 0)
10:10 AM: pango.modules (ID = 0)
10:10 AM: gtk.immodules (ID = 0)
10:10 AM: gdk-pixbuf.loaders (ID = 0)
10:10 AM: gtkmessagedialog.h (ID = 0)
10:10 AM: gtkmodules.h (ID = 0)
10:10 AM: gtknotebook.h (ID = 0)
10:10 AM: gtkoptionmenu.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: im-cedilla.dll (ID = 0)
10:10 AM: fonts.conf (ID = 0)
10:10 AM: im-ime.dll (ID = 0)
10:10 AM: libgthread-2.0.dll.a (ID = 0)
10:10 AM: libgmodule-2.0.dll.a (ID = 0)
10:10 AM: gtkobject.h (ID = 0)
10:10 AM: gtkoldeditable.h (ID = 0)
10:10 AM: gtkpaned.h (ID = 0)
10:10 AM: gtkpixmap.h (ID = 0)
10:10 AM: gtkplug.h (ID = 0)
10:10 AM: libcharset.h (ID = 0)
10:10 AM: svpfr.h (ID = 0)
10:10 AM: svmm.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: svgldict.h (ID = 0)
10:10 AM: libintl.h (ID = 0)
10:10 AM: svbdf.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: pango-querymodules.exe (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: jconfig.h (ID = 0)
10:10 AM: iconv.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: ftchkwd.exe (ID = 0)
10:10 AM: ftlint.exe (ID = 0)
10:10 AM: testname.exe (ID = 0)
10:10 AM: atkcomponent.h (ID = 0)
10:10 AM: ftconfig.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: ftdriver.h (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: gkeyfile.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gmacros.h (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: libpixbufloader-xpm.dll (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atkimage.h (ID = 0)
10:10 AM: atkhypertext.h (ID = 0)
10:10 AM: gdkevents.h (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: atkhyperlink.h (ID = 0)
10:10 AM: atkgobjectaccessible.h (ID = 0)
10:10 AM: gtktypeutils.h (ID = 0)
10:10 AM: pango-attributes.h (ID = 0)
10:10 AM: pangowin32-1.0.lib (ID = 0)
10:10 AM: gtk20.mo (ID = 0)
10:10 AM: atk10.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: glib20.mo (ID = 0)
10:10 AM: libz.dll.a (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtkvseparator.h (ID = 0)
10:11 AM: gtkvscrollbar.h (ID = 0)
10:11 AM: gtkvscale.h (ID = 0)
10:11 AM: gtkvruler.h (ID = 0)
10:11 AM: gtkvpaned.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: pngconf.h (ID = 0)
10:11 AM: atkeditabletext.h (ID = 0)
10:11 AM: glib-gettextize (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: ftcalc.h (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: fttrace.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:11 AM: gdk.h (ID = 0)
10:11 AM: gdkenumtypes.h (ID = 0)
10:11 AM: gtkaction.h (ID = 0)
10:11 AM: gtkimage.h (ID = 0)
10:11 AM: gtkprivate.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtkscrolledwindow.h (ID = 0)
10:11 AM: gtktexttag.h (ID = 0)
10:11 AM: intl.lib (ID = 0)
10:11 AM: zlib.def (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtkpreview.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtkprogress.h (ID = 0)
10:11 AM: gtkprogressbar.h (ID = 0)
10:11 AM: atkaction.h (ID = 0)
10:11 AM: zlib-bcc.lib (ID = 0)
10:11 AM: gtkviewport.h (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtkversion.h (ID = 0)
10:11 AM: gtkvbox.h (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtkvbbox.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtkuimanager.h (ID = 0)
10:11 AM: pngconf.h (ID = 0)
10:11 AM: zlib.lib (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: pangowin32-1.0.def (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: ftobjs.h (ID = 0)
10:11 AM: pangoft2-1.0.def (ID = 0)
10:11 AM: gtktypebuiltins.h (ID = 0)
10:11 AM: gtktreeviewcolumn.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: intl.dll (ID = 0)
10:11 AM: pangoft2-1.0.lib (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: trad-chinese.nsh (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: pango-1.0.def (ID = 0)
10:11 AM: libz.lib (ID = 0)
10:11 AM: swedish.nsh (ID = 0)
10:11 AM: spanish.nsh (ID = 0)
10:11 AM: slovenian.nsh (ID = 0)
10:11 AM: slovak.nsh (ID = 0)
10:11 AM: simp-chinese.nsh (ID = 0)
10:11 AM: serbian-latin.nsh (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: romanian.nsh (ID = 0)
10:11 AM: portuguese.nsh (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: portuguese-br.nsh (ID = 0)
10:11 AM: polish.nsh (ID = 0)
10:11 AM: norwegian.nsh (ID = 0)
10:11 AM: korean.nsh (ID = 0)
10:11 AM: japanese.nsh (ID = 0)
10:11 AM: gtktreeview.h (ID = 0)
10:11 AM: italian.nsh (ID = 0)
10:11 AM: hungarian.nsh (ID = 0)
10:11 AM: hebrew.nsh (ID = 0)
10:11 AM: german.nsh (ID = 0)
10:11 AM: libz-bcc.lib (ID = 0)
10:11 AM: libtiff3.def (ID = 0)
10:11 AM: french.nsh (ID = 0)
10:11 AM: finnish.nsh (ID = 0)
10:11 AM: english.nsh (ID = 0)
10:11 AM: dutch.nsh (ID = 0)
10:11 AM: danish.nsh (ID = 0)
10:11 AM: czech.nsh (ID = 0)
10:11 AM: catalan.nsh (ID = 0)
10:11 AM: bulgarian.nsh (ID = 0)
10:11 AM: albanian.nsh (ID = 0)
10:11 AM: gtkrc.lighthouseblue (ID = 0)
10:11 AM: gtkrc.gtkwimp (ID = 0)
10:11 AM: gtkrc.bluecurve (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtkradioaction.h (ID = 0)
10:11 AM: gtkradiobutton.h (ID = 0)
10:11 AM: gtkradiomenuitem.h (ID = 0)
10:11 AM: gtkradiotoolbutton.h (ID = 0)
10:11 AM: gtkrange.h (ID = 0)
10:11 AM: gtktreestore.h (ID = 0)
10:11 AM: gtktreesortable.h (ID = 0)
10:11 AM: gtktreeselection.h (ID = 0)
10:11 AM: gtktreemodelsort.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtktreemodelfilter.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtkrc (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gspawn-win32-helper.exe (ID = 0)
10:11 AM: autosprintf.h (ID = 0)
10:11 AM: freetype-config (ID = 0)
10:11 AM: atkvalue.h (ID = 0)
10:11 AM: libpixbufloader-tiff.dll (ID = 0)
10:11 AM: atkutil.h (ID = 0)
10:11 AM: gtktreeitem.h (ID = 0)
10:11 AM: gtktreemodel.h (ID = 0)
10:11 AM: charset.dll (ID = 0)
10:11 AM: gtktreednd.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: libpixbufloader-tga.dll (ID = 0)
10:11 AM: pango-tibetan-fc.dll (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtktooltips.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: gtktoolbutton.h (ID = 0)
10:11 AM: pango-hangul-fc.dll (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: fttry.exe (ID = 0)
10:11 AM: libpixbufloader-bmp.dll (ID = 0)
10:11 AM: gtktexttagtable.h (ID = 0)
10:11 AM: gtktoggletoolbutton.h (ID = 0)
10:11 AM: gtktogglebutton.h (ID = 0)
10:11 AM: gtktoggleaction.h (ID = 0)
10:11 AM: gtktipsquery.h (ID = 0)
10:11 AM: atk10.mo (ID = 0)
10:11 AM: atkstreamablecontent.h (ID = 0)
10:11 AM: gtktextchild.h (ID = 0)
10:11 AM: gtktearoffmenuitem.h (ID = 0)
10:11 AM: gtkstatusbar.h (ID = 0)
10:11 AM: gtktree.h (ID = 0)
10:11 AM: gtktoolitem.h (ID = 0)
10:11 AM: gtksocket.h (ID = 0)
10:11 AM: gtksizegroup.h (ID = 0)
10:11 AM: gtkseparatortoolitem.h (ID = 0)
10:11 AM: gtkseparatormenuitem.h (ID = 0)
10:11 AM: gtkseparator.h (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: atkstateset.h (ID = 0)
10:11 AM: gtktextmark.h (ID = 0)
10:11 AM: gtktoolbar.h (ID = 0)
10:11 AM: atktext.h (ID = 0)
10:11 AM: atkselection.h (ID = 0)
10:11 AM: atkrelationtype.h (ID = 0)
10:11 AM: atkrelationset.h (ID = 0)
10:11 AM: atkrelation.h (ID = 0)
10:11 AM: atkregistry.h (ID = 0)
10:11 AM: atkobjectfactory.h (ID = 0)
10:11 AM: gettext.sh (ID = 0)
10:11 AM: gtkstock.h (ID = 0)
10:11 AM: gtktextdisplay.h (ID = 0)
10:11 AM: atkstate.h (ID = 0)
10:11 AM: gtktext.h (ID = 0)
10:11 AM: gtkspinbutton.h (ID = 0)
10:11 AM: gtksignal.h (ID = 0)
10:11 AM: gtksettings.h (ID = 0)
10:11 AM: gtkselection.h (ID = 0)
10:11 AM: gtktable.h (ID = 0)
10:11 AM: gtktextiter.h (ID = 0)
10:11 AM: atktable.h (ID = 0)
10:11 AM: gtkscrollbar.h (ID = 0)
10:11 AM: gtkscale.h (ID = 0)
10:11 AM: gtktextbuffer.h (ID = 0)
10:11 AM: gtkrc.h (ID = 0)
10:11 AM: gtkruler.h (ID = 0)
10:11 AM: libtiff.lib (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libfreetype-bcc.lib (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: pango-hebrew-fc.dll (ID = 0)
10:11 AM: pango-indic-fc.dll (ID = 0)
10:11 AM: zlib1.dll (ID = 0)
10:11 AM: intl.dll (ID = 0)
10:11 AM: atk-1.0.lib (ID = 0)
10:11 AM: libpixbufloader-ani.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: fontconfig.lib (ID = 0)
10:11 AM: libfontconfig-1.dll (ID = 0)
10:11 AM: gettextsrc.dll (ID = 0)
10:11 AM: libjpeg.a (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: glib-2.0.lib (ID = 0)
10:11 AM: gdkalias.h (ID = 0)
10:11 AM: pango-syriac-fc.dll (ID = 0)
10:11 AM: pango-khmer-fc.dll (ID = 0)
10:11 AM: pango-arabic-fc.dll (ID = 0)
10:11 AM: libpixbufloader-png.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libpixbufloader-pnm.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libtiff.dll.a (ID = 0)
10:11 AM: xmlparse.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: png.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: png.h (ID = 0)
10:11 AM: libpixbufloader-ico.dll (ID = 0)
10:11 AM: ttnameid.h (ID = 0)
10:11 AM: ftcache.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: copying.lib-2 (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: asprintf.dll (ID = 0)
10:11 AM: gtk.ico (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libgmodule-2.0-0.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libpangoft2-1.0.dll.a (ID = 0)
10:11 AM: gdkkeysyms.h (ID = 0)
10:11 AM: tttables.h (ID = 0)
10:11 AM: pshints.h (ID = 0)
10:11 AM: msgfmt.exe (ID = 0)
10:11 AM: gtk-installer.nsi (ID = 0)
10:11 AM: glib-genmarshal.exe (ID = 0)
10:11 AM: ftview.exe (ID = 0)
10:11 AM: ftstring.exe (ID = 0)
10:11 AM: gdk-win32-2.0.lib (ID = 0)
10:11 AM: libjpeg.lib (ID = 0)
10:11 AM: gdk_pixbuf-2.0.lib (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libgdk-win32-2.0-0.dll (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: tiff.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: libpixbufloader-jpeg.dll (ID = 0)
10:11 AM: ftoutln.h (ID = 0)
10:11 AM: im-ti-et.dll (ID = 0)
10:11 AM: im-ti-er.dll (ID = 0)
10:11 AM: atkobject.h (ID = 0)
10:11 AM: gtk-query-immodules-2.0.exe (ID = 0)
10:11 AM: im-am-et.dll (ID = 0)
10:11 AM: libpango-1.0.dll.a (ID = 0)
10:11 AM: libbluecurve.dll (ID = 0)
10:11 AM: asprintf.dll (ID = 0)
10:11 AM: libpango-1.0-0.dll (ID = 0)
10:11 AM: liblighthouseblue.dll (ID = 0)
10:11 AM: gtkwidget.h (ID = 0)
10:11 AM: msginit.exe (ID = 0)
10:11 AM: gtkstyle.h (ID = 0)
10:11 AM: psaux.h (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: fc-cache.exe (ID = 0)
10:11 AM: freetype6.dll (ID = 0)
10:11 AM: libtiff.a (ID = 0)
10:11 AM: libfontconfig.dll.a (ID = 0)
10:11 AM: libgdk_pixbuf-2.0-0.dll (ID = 0)
10:11 AM: libpangoft2-1.0-0.dll (ID = 0)
10:11 AM: libglib-2.0-0.dll (ID = 0)
10:11 AM: libtiff3.dll (ID = 0)
10:11 AM: gtk-win32-2.0.lib (ID = 0)
10:11 AM: jpeg62.dll (ID = 0)
10:11 AM: libatk-1.0-0.dll (ID = 0)
10:11 AM: ftimage.h (ID = 0)
10:11 AM: tttypes.h (ID = 0)
10:11 AM: gobject-2.0.lib (ID = 0)
10:11 AM: libglib-2.0.dll.a (ID = 0)
10:11 AM: libgobject-2.0-0.dll (ID = 0)
10:11 AM: libpng.lib (ID = 0)
10:11 AM: xmltok.dll (ID = 0)
10:11 AM: libgdk-win32-2.0.dll.a (ID = 0)
10:11 AM: libfreetype.a (ID = 0)
10:11 AM: libpng13.a (ID = 0)
10:11 AM: libgobject-2.0.dll.a (ID = 0)
10:11 AM: gtk-demo.exe (ID = 0)
10:11 AM: iconv.dll (ID = 0)
10:11 AM: iconv.dll (ID = 0)
10:11 AM: gtk-runtime-2.6.9-rev-a.exe (ID = 0)
10:11 AM: libfontconfig-1.dll (ID = 0)
10:11 AM: libpng13.dll (ID = 0)
10:11 AM: gtk-2.6.9-rev-a-installer.tar.gz (ID = 0)
10:11 AM: libpng.dll.a (ID = 0)
10:11 AM: libpng.a (ID = 0)
10:11 AM: pango-1.0.lib (ID = 0)
10:11 AM: libpng13.dll.a (ID = 0)
10:11 AM: libgtk-win32-2.0.dll.a (ID = 0)
10:11 AM: libgtk-win32-2.0-0.dll (ID = 0)
10:11 AM: build.sh (ID = 0)
10:11 AM: ftmodule.h (ID = 0)
10:11 AM: tiffvers.h (ID = 0)
10:11 AM: gmodule-2.0.def (ID = 0)
10:11 AM: gthread-2.0.def (ID = 0)
10:11 AM: gdkconfig.h (ID = 0)
10:11 AM: atk.pc (ID = 0)
10:11 AM: fontconfig.pc (ID = 0)
10:11 AM: gdk-2.0.pc (ID = 0)
10:11 AM: gdk-pixbuf-2.0.pc (ID = 0)
10:11 AM: gdk-win32-2.0.pc (ID = 0)
10:11 AM: glib-2.0.pc (ID = 0)
10:11 AM: gmodule-2.0.pc (ID = 0)
10:11 AM: gmodule-no-export-2.0.pc (ID = 0)
10:11 AM: gobject-2.0.pc (ID = 0)
10:11 AM: gthread-2.0.pc (ID = 0)
10:11 AM: gtk+-2.0.pc (ID = 0)
10:11 AM: gtk+-win32-2.0.pc (ID = 0)
10:11 AM: pango.pc (ID = 0)
10:11 AM: pangoft2.pc (ID = 0)
10:11 AM: pangowin32.pc (ID = 0)
10:11 AM: version.sh (ID = 0)
10:11 AM: .wgbef-rev (ID = 0)
10:11 AM: build.sh (ID = 0)
10:11 AM: gtkrc (ID = 0)
10:11 AM: pango.aliases (ID = 0)
10:11 AM: gtk20.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: glib20.mo (ID = 0)
10:11 AM: gtkrc (ID = 0)
10:11 AM: gtkrc.plain (ID = 0)
10:11 AM: gtkrc (ID = 0)
10:11 AM: version.sh (ID = 0)
10:11 AM: .wgbef-rev (ID = 0)
10:11 AM: Warning: Unhandled Archive Type
10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:11 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:11 AM: Warning: Unhandled Archive Type
10:11 AM: Warning: Unhandled Archive Type
10:11 AM: Warning: Unhandled Archive Type
10:11 AM: Warning: Unhandled Archive Type
10:11 AM: Warning: Unhandled Archive Type
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:12 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:13 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:13 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:13 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:13 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:14 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:15 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:16 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:17 AM: File Sweep Complete, Elapsed Time: 00:38:26
10:17 AM: Full Sweep has completed. Elapsed time 00:40:56
10:17 AM: Traces Found: 927
10:17 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:17 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:17 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:17 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:18 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:19 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:19 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
10:19 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:19 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
10:19 AM: Removal process initiated
10:19 AM: Quarantining All Traces: icannnews
10:19 AM: icannnews is in use. It will be removed on reboot.
10:19 AM: C:\WINDOWS\system32\dnjq0115e.dll is in use. It will be removed on reboot.
10:19 AM: C:\WINDOWS\system32\ozedlg.dll is in use. It will be removed on reboot.
10:19 AM: Quarantining All Traces: look2me
10:19 AM: look2me is in use. It will be removed on reboot.
10:19 AM: dnjq0115e.dll is in use. It will be removed on reboot.
10:19 AM: Quarantining All Traces: potentially rootkit-masked files
10:38 AM: Updating spyware definitions
10:38 AM: Your definitions are up to date.
********
  • 0

Advertisements


#11
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
I scanned again and it only found the potential rootkit files but there was about 916 i think of them. I told it to fix them but it froze again so i shut it down. Then when i rebooted, on the XP screen a big list came up saying remove failed...then a file name for a bunch of files, then booted up normally.

Here is my Hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 11:30:19 AM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Ryan Maas\Desktop\ \Security\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...603/mcfscan.cab
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Here is my spy sweeper log:

********
10:43 AM: | Start of Session, Wednesday, November 16, 2005 |
10:43 AM: Spy Sweeper started
10:43 AM: Sweep initiated using definitions version 573
10:44 AM: Starting Memory Sweep
10:45 AM: Memory Sweep Complete, Elapsed Time: 00:01:36
10:45 AM: Starting Registry Sweep
10:45 AM: Registry Sweep Complete, Elapsed Time:00:00:11
10:45 AM: Starting Cookie Sweep
10:45 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
10:45 AM: Starting File Sweep
11:11 AM: Found System Monitor: potentially rootkit-masked files
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkdrawingarea.h (ID = 0)
11:11 AM: iconv.exe (ID = 0)
11:11 AM: gtkdebug.h (ID = 0)
11:11 AM: gtkcurve.h (ID = 0)
11:11 AM: gtkenums.h (ID = 0)
11:11 AM: gtkentrycompletion.h (ID = 0)
11:11 AM: gtkeditable.h (ID = 0)
11:11 AM: gtkentry.h (ID = 0)
11:11 AM: gtkdnd.h (ID = 0)
11:11 AM: glib-mkenums (ID = 0)
11:11 AM: gtkdialog.h (ID = 0)
11:11 AM: fttimer.exe (ID = 0)
11:11 AM: gtkcomboboxentry.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkcolorseldialog.h (ID = 0)
11:11 AM: gtkcolorbutton.h (ID = 0)
11:11 AM: ftmemchk.exe (ID = 0)
11:11 AM: gtkcombobox.h (ID = 0)
11:11 AM: ftdump.exe (ID = 0)
11:11 AM: gtkcheckmenuitem.h (ID = 0)
11:11 AM: gtkcheckbutton.h (ID = 0)
11:11 AM: gtkcellview.h (ID = 0)
11:11 AM: gtkcellrenderertoggle.h (ID = 0)
11:11 AM: gtkcellrenderertext.h (ID = 0)
11:11 AM: gtkcombo.h (ID = 0)
11:11 AM: gtkcellrendererprogress.h (ID = 0)
11:11 AM: gtkcolorsel.h (ID = 0)
11:11 AM: gtkcellrendererpixbuf.h (ID = 0)
11:11 AM: gtkcellrenderercombo.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: pcftypes.h (ID = 0)
11:11 AM: internal.h (ID = 0)
11:11 AM: gtkcelleditable.h (ID = 0)
11:11 AM: ftxf86.h (ID = 0)
11:11 AM: msgcmp.exe (ID = 0)
11:11 AM: gtkclipboard.h (ID = 0)
11:11 AM: ftsynth.h (ID = 0)
11:11 AM: gtkbox.h (ID = 0)
11:11 AM: gtkbin.h (ID = 0)
11:11 AM: gtkbbox.h (ID = 0)
11:11 AM: gtkaspectframe.h (ID = 0)
11:11 AM: gtkarrow.h (ID = 0)
11:11 AM: gtkalignment.h (ID = 0)
11:11 AM: gtkadjustment.h (ID = 0)
11:11 AM: gtkcellrenderer.h (ID = 0)
11:11 AM: gtkaccessible.h (ID = 0)
11:11 AM: gtkaccelmap.h (ID = 0)
11:11 AM: gtkaccellabel.h (ID = 0)
11:11 AM: gdk-pixbuf.h (ID = 0)
11:11 AM: gtkcontainer.h (ID = 0)
11:11 AM: gtkcelllayout.h (ID = 0)
11:11 AM: ftgloadr.h (ID = 0)
11:11 AM: ftserv.h (ID = 0)
11:11 AM: ftrfork.h (ID = 0)
11:11 AM: ftsysmem.h (ID = 0)
11:11 AM: ftsysio.h (ID = 0)
11:11 AM: ftpfr.h (ID = 0)
11:11 AM: gtkcalendar.h (ID = 0)
11:11 AM: gtkbutton.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkbindings.h (ID = 0)
11:11 AM: gtkactiongroup.h (ID = 0)
11:11 AM: ftdebug.h (ID = 0)
11:11 AM: ftwinfnt.h (ID = 0)
11:11 AM: gtkaccelgroup.h (ID = 0)
11:11 AM: gtkaboutdialog.h (ID = 0)
11:11 AM: gtk.h (ID = 0)
11:11 AM: gdk-pixdata.h (ID = 0)
11:11 AM: ftmoderr.h (ID = 0)
11:11 AM: ftlzw.h (ID = 0)
11:11 AM: msgconv.exe (ID = 0)
11:11 AM: ftsnames.h (ID = 0)
11:11 AM: ftmemory.h (ID = 0)
11:11 AM: ftsizes.h (ID = 0)
11:11 AM: ftrender.h (ID = 0)
11:11 AM: msgen.exe (ID = 0)
11:11 AM: msgexec.exe (ID = 0)
11:11 AM: ftmm.h (ID = 0)
11:11 AM: ftmac.h (ID = 0)
11:11 AM: ftincrem.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: msgfilter.exe (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: msguniq.exe (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: libpixbufloader-wbmp.dll (ID = 0)
11:11 AM: libpixbufloader-ras.dll (ID = 0)
11:11 AM: im-inuktitut.dll (ID = 0)
11:11 AM: pango-basic-fc.dll (ID = 0)
11:11 AM: gtkclist.h (ID = 0)
11:11 AM: gtk-win32-2.0.def (ID = 0)
11:11 AM: libtiff-bcc.lib (ID = 0)
11:11 AM: libpangowin32-1.0.dll.a (ID = 0)
11:11 AM: tiffio.h (ID = 0)
11:11 AM: gtkwindow.h (ID = 0)
11:11 AM: gtktextview.h (ID = 0)
11:11 AM: libwimp.dll (ID = 0)
11:11 AM: gtktextlayout.h (ID = 0)
11:11 AM: gtkmarshal.h (ID = 0)
11:11 AM: gtkctree.h (ID = 0)
11:11 AM: fttrigon.h (ID = 0)
11:11 AM: ftsystem.h (ID = 0)
11:11 AM: ftgzip.h (ID = 0)
11:11 AM: ftstream.h (ID = 0)
11:11 AM: ftstroke.h (ID = 0)
11:11 AM: ftchapters.h (ID = 0)
11:11 AM: atk.h (ID = 0)
11:11 AM: ftbdf.h (ID = 0)
11:11 AM: libatk-1.0.dll.a (ID = 0)
11:11 AM: ftbbox.h (ID = 0)
11:11 AM: ftstdlib.h (ID = 0)
11:11 AM: fterrors.h (ID = 0)
11:11 AM: fterrdef.h (ID = 0)
11:11 AM: libgdk_pixbuf-2.0.dll.a (ID = 0)
11:11 AM: ftcsbits.h (ID = 0)
11:11 AM: atk-enum-types.h (ID = 0)
11:11 AM: libjpeg.dll.a (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gdk-pixbuf-transform.h (ID = 0)
11:11 AM: ftcmru.h (ID = 0)
11:11 AM: gdk-pixbuf-marshal.h (ID = 0)
11:11 AM: ftcmanag.h (ID = 0)
11:11 AM: gdk-pixbuf-loader.h (ID = 0)
11:11 AM: ftcglyph.h (ID = 0)
11:11 AM: ftccmap.h (ID = 0)
11:11 AM: gdk-pixbuf-features.h (ID = 0)
11:11 AM: ftccache.h (ID = 0)
11:11 AM: gdk-pixbuf-enum-types.h (ID = 0)
11:11 AM: gdk-pixbuf-io.h (ID = 0)
11:11 AM: gdkwin32.h (ID = 0)
11:11 AM: gdkvisual.h (ID = 0)
11:11 AM: gdk-pixbuf-core.h (ID = 0)
11:11 AM: gdk-pixbuf-animation.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gdktypes.h (ID = 0)
11:11 AM: pango-thai-fc.dll (ID = 0)
11:11 AM: pango-basic-win32.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libgthread-2.0-0.dll (ID = 0)
11:11 AM: gdkspawn.h (ID = 0)
11:11 AM: gdkselection.h (ID = 0)
11:11 AM: gdkscreen.h (ID = 0)
11:11 AM: gdkrgb.h (ID = 0)
11:11 AM: ftmodapi.h (ID = 0)
11:11 AM: gdkregion.h (ID = 0)
11:11 AM: gdkproperty.h (ID = 0)
11:11 AM: sfnt.h (ID = 0)
11:11 AM: fttypes.h (ID = 0)
11:11 AM: xgettext.exe (ID = 0)
11:11 AM: ftglyph.h (ID = 0)
11:11 AM: ftoption.h (ID = 0)
11:11 AM: ftheader.h (ID = 0)
11:11 AM: autohint.h (ID = 0)
11:11 AM: ftmulti.exe (ID = 0)
11:11 AM: giochannel.h (ID = 0)
11:11 AM: ftlist.h (ID = 0)
11:11 AM: gthread.h (ID = 0)
11:11 AM: fontconfig.h (ID = 0)
11:11 AM: msgunfmt.exe (ID = 0)
11:11 AM: gparamspecs.h (ID = 0)
11:11 AM: jerror.h (ID = 0)
11:11 AM: jmorecfg.h (ID = 0)
11:11 AM: gdk-win32-2.0.def (ID = 0)
11:11 AM: zlib.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: msgcomm.exe (ID = 0)
11:11 AM: gdkprivate.h (ID = 0)
11:11 AM: msgcat.exe (ID = 0)
11:11 AM: gdkpixmap.h (ID = 0)
11:11 AM: gdkpixbuf.h (ID = 0)
11:11 AM: msgattrib.exe (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gobject-query.exe (ID = 0)
11:11 AM: gdkinput.h (ID = 0)
11:11 AM: gdkimage.h (ID = 0)
11:11 AM: gdki18n.h (ID = 0)
11:11 AM: ftbench.exe (ID = 0)
11:11 AM: libz.a (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gdkpango.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gdkfont.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: libiconv.a (ID = 0)
11:11 AM: libjpeg-bcc.lib (ID = 0)
11:11 AM: gdkdisplaymanager.h (ID = 0)
11:11 AM: gdkcursor.h (ID = 0)
11:11 AM: gvaluearray.h (ID = 0)
11:11 AM: gvalue.h (ID = 0)
11:11 AM: gtypeplugin.h (ID = 0)
11:11 AM: gtypemodule.h (ID = 0)
11:11 AM: libpangowin32-1.0-0.dll (ID = 0)
11:11 AM: gsourceclosure.h (ID = 0)
11:11 AM: gdkkeys.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: iconv.lib (ID = 0)
11:11 AM: gboxed.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gdkgc.h (ID = 0)
11:11 AM: gmodule.h (ID = 0)
11:11 AM: glib.h (ID = 0)
11:11 AM: glib-object.h (ID = 0)
11:11 AM: gwin32.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gdkdnd.h (ID = 0)
11:11 AM: gdkdrawable.h (ID = 0)
11:11 AM: gdkdisplay.h (ID = 0)
11:11 AM: gdkcolor.h (ID = 0)
11:11 AM: gvaluetypes.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtree.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gvaluecollector.h (ID = 0)
11:11 AM: gtimer.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gsignal.h (ID = 0)
11:11 AM: gobjectnotifyqueue.c (ID = 0)
11:11 AM: gparam.h (ID = 0)
11:11 AM: gobject.h (ID = 0)
11:11 AM: genums.h (ID = 0)
11:11 AM: gmarshal.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gclosure.h (ID = 0)
11:11 AM: freetype.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: freetype6.dll (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gutils.h (ID = 0)
11:11 AM: gunicode.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: libfreetype.lib (ID = 0)
11:11 AM: gthreadpool.h (ID = 0)
11:11 AM: gtypes.h (ID = 0)
11:11 AM: gstring.h (ID = 0)
11:11 AM: gtkeventbox.h (ID = 0)
11:11 AM: gtkexpander.h (ID = 0)
11:11 AM: gtkfilechooser.h (ID = 0)
11:11 AM: gtkfilechooserbutton.h (ID = 0)
11:11 AM: gtkfilechooserdialog.h (ID = 0)
11:11 AM: gtkfilechooserwidget.h (ID = 0)
11:11 AM: gtkfilefilter.h (ID = 0)
11:11 AM: gstdio.h (ID = 0)
11:11 AM: gtkfilesel.h (ID = 0)
11:11 AM: gtkfilesystem.h (ID = 0)
11:11 AM: gspawn.h (ID = 0)
11:11 AM: gslist.h (ID = 0)
11:11 AM: gshell.h (ID = 0)
11:11 AM: grel.h (ID = 0)
11:11 AM: grand.h (ID = 0)
11:11 AM: gscanner.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkfixed.h (ID = 0)
11:11 AM: gtkfontbutton.h (ID = 0)
11:11 AM: gtkfontsel.h (ID = 0)
11:11 AM: gtkframe.h (ID = 0)
11:11 AM: gtkgamma.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gstrfuncs.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gquark.h (ID = 0)
11:11 AM: gqsort.h (ID = 0)
11:11 AM: gprintf.h (ID = 0)
11:11 AM: gprimes.h (ID = 0)
11:11 AM: gtkgc.h (ID = 0)
11:11 AM: gtkhandlebox.h (ID = 0)
11:11 AM: gtkhbbox.h (ID = 0)
11:11 AM: gtkhbox.h (ID = 0)
11:11 AM: gtkhpaned.h (ID = 0)
11:11 AM: gtkhruler.h (ID = 0)
11:11 AM: gtkhscale.h (ID = 0)
11:11 AM: gtkhscrollbar.h (ID = 0)
11:11 AM: gtkhseparator.h (ID = 0)
11:11 AM: gtkiconfactory.h (ID = 0)
11:11 AM: gtkicontheme.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gpattern.h (ID = 0)
11:11 AM: gqueue.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atknoopobjectfactory.h (ID = 0)
11:11 AM: atknoopobject.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gdk_pixbuf-2.0.def (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gettextlib.dll (ID = 0)
11:11 AM: gtkiconview.h (ID = 0)
11:11 AM: gtkimagemenuitem.h (ID = 0)
11:11 AM: gtkimcontext.h (ID = 0)
11:11 AM: gtkimcontextsimple.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: jpeg62.def (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: ftcimage.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: goption.h (ID = 0)
11:11 AM: gnode.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gthread-2.0.lib (ID = 0)
11:11 AM: fcprivate.h (ID = 0)
11:11 AM: fcfreetype.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtkimmodule.h (ID = 0)
11:11 AM: gtkimmulticontext.h (ID = 0)
11:11 AM: gtkinputdialog.h (ID = 0)
11:11 AM: gtkinvisible.h (ID = 0)
11:11 AM: gtkitem.h (ID = 0)
11:11 AM: gtkitemfactory.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: jpeglib.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gmem.h (ID = 0)
11:11 AM: gmarkup.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: libfreetype.dll.a (ID = 0)
11:11 AM: gmain.h (ID = 0)
11:11 AM: gobject-2.0.def (ID = 0)
11:11 AM: gtklabel.h (ID = 0)
11:11 AM: gtklayout.h (ID = 0)
11:11 AM: gtklist.h (ID = 0)
11:11 AM: gtklistitem.h (ID = 0)
11:11 AM: gtkliststore.h (ID = 0)
11:11 AM: gtkmain.h (ID = 0)
11:11 AM: gmessages.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glist.h (ID = 0)
11:11 AM: gi18n.h (ID = 0)
11:11 AM: gi18n-lib.h (ID = 0)
11:11 AM: ghook.h (ID = 0)
11:11 AM: ghash.h (ID = 0)
11:11 AM: gfileutils.h (ID = 0)
11:11 AM: gerror.h (ID = 0)
11:11 AM: gdir.h (ID = 0)
11:11 AM: gdataset.h (ID = 0)
11:11 AM: gconvert.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gcompletion.h (ID = 0)
11:11 AM: gcache.h (ID = 0)
11:11 AM: gbacktrace.h (ID = 0)
11:11 AM: gatomic.h (ID = 0)
11:11 AM: gasyncqueue.h (ID = 0)
11:11 AM: gdate.h (ID = 0)
11:11 AM: galloca.h (ID = 0)
11:11 AM: ft2build.h (ID = 0)
11:11 AM: ttunpat.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gmodule-2.0.lib (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: garray.h (ID = 0)
11:11 AM: gettext-po.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glibconfig.h (ID = 0)
11:11 AM: gettextpo.lib (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: freetype.def (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: fontconfig.def (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: charset.lib (ID = 0)
11:11 AM: asprintf.lib (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib-2.0.def (ID = 0)
11:11 AM: libpixbufloader-xbm.dll (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: libpixbufloader-pcx.dll (ID = 0)
11:11 AM: zconf.h (ID = 0)
11:11 AM: tiffconf.h (ID = 0)
11:11 AM: tttags.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libintl.a (ID = 0)
11:11 AM: gdkwindow.h (ID = 0)
11:11 AM: gtype.h (ID = 0)
11:11 AM: msgmerge.exe (ID = 0)
11:11 AM: pangowin32.h (ID = 0)
11:11 AM: pangoft2.h (ID = 0)
11:11 AM: pangofc-decoder.h (ID = 0)
11:11 AM: pango.h (ID = 0)
11:11 AM: pango-utils.h (ID = 0)
11:11 AM: pango-tabs.h (ID = 0)
11:11 AM: pango-modules.h (ID = 0)
11:11 AM: msggrep.exe (ID = 0)
11:11 AM: gettextpo.dll (ID = 0)
11:11 AM: gdk-pixbuf-query-loaders.exe (ID = 0)
11:11 AM: pangofc-fontmap.h (ID = 0)
11:11 AM: pangofc-font.h (ID = 0)
11:11 AM: pango-types.h (ID = 0)
11:11 AM: pango-script.h (ID = 0)
11:11 AM: pango-renderer.h (ID = 0)
11:11 AM: pango-ot.h (ID = 0)
11:11 AM: gdk-pixbuf-csource.exe (ID = 0)
11:11 AM: fc-list.exe (ID = 0)
11:11 AM: charset.dll (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: pango-item.h (ID = 0)
11:11 AM: pango-glyph.h (ID = 0)
11:11 AM: pango-layout.h (ID = 0)
11:11 AM: pango-glyph-item.h (ID = 0)
11:11 AM: gtkmenu.h (ID = 0)
11:11 AM: pango-fontmap.h (ID = 0)
11:11 AM: pango-enum-types.h (ID = 0)
11:11 AM: pango-fontset.h (ID = 0)
11:11 AM: pango-coverage.h (ID = 0)
11:11 AM: pango-font.h (ID = 0)
11:11 AM: libpng12.dll (ID = 0)
11:11 AM: gtkmenubar.h (ID = 0)
11:11 AM: gtkmenuitem.h (ID = 0)
11:11 AM: gtkmenushell.h (ID = 0)
11:11 AM: gtkmenutoolbutton.h (ID = 0)
11:11 AM: gtkmisc.h (ID = 0)
11:11 AM: pango-engine.h (ID = 0)
11:11 AM: pango-context.h (ID = 0)
11:11 AM: pango-break.h (ID = 0)
11:11 AM: localcharset.h (ID = 0)
11:11 AM: atkdocument.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: libpixbufloader-gif.dll (ID = 0)
11:11 AM: im-ipa.dll (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: im-viqr.dll (ID = 0)
11:11 AM: t1tables.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: im-thai-broken.dll (ID = 0)
11:11 AM: t1types.h (ID = 0)
11:11 AM: svxf86nm.h (ID = 0)
11:11 AM: svwinfnt.h (ID = 0)
11:11 AM: svttcmap.h (ID = 0)
11:11 AM: svsfnt.h (ID = 0)
11:11 AM: svpsinfo.h (ID = 0)
11:11 AM: svpscmap.h (ID = 0)
11:11 AM: svpostnm.h (ID = 0)
11:11 AM: im-cyrillic-translit.dll (ID = 0)
11:11 AM: pango.modules (ID = 0)
11:11 AM: gtk.immodules (ID = 0)
11:11 AM: gdk-pixbuf.loaders (ID = 0)
11:11 AM: gtkmessagedialog.h (ID = 0)
11:11 AM: gtkmodules.h (ID = 0)
11:11 AM: gtknotebook.h (ID = 0)
11:11 AM: gtkoptionmenu.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: im-cedilla.dll (ID = 0)
11:11 AM: fonts.conf (ID = 0)
11:11 AM: im-ime.dll (ID = 0)
11:11 AM: libgthread-2.0.dll.a (ID = 0)
11:11 AM: libgmodule-2.0.dll.a (ID = 0)
11:11 AM: gtkobject.h (ID = 0)
11:11 AM: gtkoldeditable.h (ID = 0)
11:11 AM: gtkpaned.h (ID = 0)
11:11 AM: gtkpixmap.h (ID = 0)
11:11 AM: gtkplug.h (ID = 0)
11:11 AM: libcharset.h (ID = 0)
11:11 AM: svpfr.h (ID = 0)
11:11 AM: svmm.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: svgldict.h (ID = 0)
11:11 AM: libintl.h (ID = 0)
11:11 AM: svbdf.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: pango-querymodules.exe (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: jconfig.h (ID = 0)
11:11 AM: iconv.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: ftchkwd.exe (ID = 0)
11:11 AM: ftlint.exe (ID = 0)
11:11 AM: testname.exe (ID = 0)
11:11 AM: atkcomponent.h (ID = 0)
11:11 AM: ftconfig.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: ftdriver.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gkeyfile.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gmacros.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libpixbufloader-xpm.dll (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atkimage.h (ID = 0)
11:11 AM: atkhypertext.h (ID = 0)
11:11 AM: gdkevents.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atkhyperlink.h (ID = 0)
11:11 AM: atkgobjectaccessible.h (ID = 0)
11:11 AM: gtktypeutils.h (ID = 0)
11:11 AM: pango-attributes.h (ID = 0)
11:11 AM: pangowin32-1.0.lib (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: libz.dll.a (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtkvseparator.h (ID = 0)
11:11 AM: gtkvscrollbar.h (ID = 0)
11:11 AM: gtkvscale.h (ID = 0)
11:11 AM: gtkvruler.h (ID = 0)
11:11 AM: gtkvpaned.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: pngconf.h (ID = 0)
11:11 AM: atkeditabletext.h (ID = 0)
11:11 AM: glib-gettextize (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: ftcalc.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: fttrace.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gdk.h (ID = 0)
11:11 AM: gdkenumtypes.h (ID = 0)
11:11 AM: gtkaction.h (ID = 0)
11:11 AM: gtkimage.h (ID = 0)
11:11 AM: gtkprivate.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtkscrolledwindow.h (ID = 0)
11:11 AM: gtktexttag.h (ID = 0)
11:11 AM: intl.lib (ID = 0)
11:11 AM: zlib.def (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtkpreview.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtkprogress.h (ID = 0)
11:11 AM: gtkprogressbar.h (ID = 0)
11:11 AM: atkaction.h (ID = 0)
11:11 AM: zlib-bcc.lib (ID = 0)
11:11 AM: gtkviewport.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkversion.h (ID = 0)
11:11 AM: gtkvbox.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkvbbox.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtkuimanager.h (ID = 0)
11:11 AM: pngconf.h (ID = 0)
11:11 AM: zlib.lib (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: pangowin32-1.0.def (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: ftobjs.h (ID = 0)
11:11 AM: pangoft2-1.0.def (ID = 0)
11:11 AM: gtktypebuiltins.h (ID = 0)
11:11 AM: gtktreeviewcolumn.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: intl.dll (ID = 0)
11:11 AM: pangoft2-1.0.lib (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: trad-chinese.nsh (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: pango-1.0.def (ID = 0)
11:11 AM: libz.lib (ID = 0)
11:11 AM: swedish.nsh (ID = 0)
11:11 AM: spanish.nsh (ID = 0)
11:11 AM: slovenian.nsh (ID = 0)
11:11 AM: slovak.nsh (ID = 0)
11:11 AM: simp-chinese.nsh (ID = 0)
11:11 AM: serbian-latin.nsh (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: romanian.nsh (ID = 0)
11:11 AM: portuguese.nsh (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: portuguese-br.nsh (ID = 0)
11:11 AM: polish.nsh (ID = 0)
11:11 AM: norwegian.nsh (ID = 0)
11:11 AM: korean.nsh (ID = 0)
11:11 AM: japanese.nsh (ID = 0)
11:11 AM: gtktreeview.h (ID = 0)
11:11 AM: italian.nsh (ID = 0)
11:11 AM: hungarian.nsh (ID = 0)
11:11 AM: hebrew.nsh (ID = 0)
11:11 AM: german.nsh (ID = 0)
11:11 AM: libz-bcc.lib (ID = 0)
11:11 AM: libtiff3.def (ID = 0)
11:11 AM: french.nsh (ID = 0)
11:11 AM: finnish.nsh (ID = 0)
11:11 AM: english.nsh (ID = 0)
11:11 AM: dutch.nsh (ID = 0)
11:11 AM: danish.nsh (ID = 0)
11:11 AM: czech.nsh (ID = 0)
11:11 AM: catalan.nsh (ID = 0)
11:11 AM: bulgarian.nsh (ID = 0)
11:11 AM: albanian.nsh (ID = 0)
11:11 AM: gtkrc.lighthouseblue (ID = 0)
11:11 AM: gtkrc.gtkwimp (ID = 0)
11:11 AM: gtkrc.bluecurve (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtkradioaction.h (ID = 0)
11:11 AM: gtkradiobutton.h (ID = 0)
11:11 AM: gtkradiomenuitem.h (ID = 0)
11:11 AM: gtkradiotoolbutton.h (ID = 0)
11:11 AM: gtkrange.h (ID = 0)
11:11 AM: gtktreestore.h (ID = 0)
11:11 AM: gtktreesortable.h (ID = 0)
11:11 AM: gtktreeselection.h (ID = 0)
11:11 AM: gtktreemodelsort.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtktreemodelfilter.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtkrc (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gspawn-win32-helper.exe (ID = 0)
11:11 AM: autosprintf.h (ID = 0)
11:11 AM: freetype-config (ID = 0)
11:11 AM: atkvalue.h (ID = 0)
11:11 AM: libpixbufloader-tiff.dll (ID = 0)
11:11 AM: atkutil.h (ID = 0)
11:11 AM: gtktreeitem.h (ID = 0)
11:11 AM: gtktreemodel.h (ID = 0)
11:11 AM: charset.dll (ID = 0)
11:11 AM: gtktreednd.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: libpixbufloader-tga.dll (ID = 0)
11:11 AM: pango-tibetan-fc.dll (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtktooltips.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: gtktoolbutton.h (ID = 0)
11:11 AM: pango-hangul-fc.dll (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: fttry.exe (ID = 0)
11:11 AM: libpixbufloader-bmp.dll (ID = 0)
11:11 AM: gtktexttagtable.h (ID = 0)
11:11 AM: gtktoggletoolbutton.h (ID = 0)
11:11 AM: gtktogglebutton.h (ID = 0)
11:11 AM: gtktoggleaction.h (ID = 0)
11:11 AM: gtktipsquery.h (ID = 0)
11:11 AM: atk10.mo (ID = 0)
11:11 AM: atkstreamablecontent.h (ID = 0)
11:11 AM: gtktextchild.h (ID = 0)
11:11 AM: gtktearoffmenuitem.h (ID = 0)
11:11 AM: gtkstatusbar.h (ID = 0)
11:11 AM: gtktree.h (ID = 0)
11:11 AM: gtktoolitem.h (ID = 0)
11:11 AM: gtksocket.h (ID = 0)
11:11 AM: gtksizegroup.h (ID = 0)
11:11 AM: gtkseparatortoolitem.h (ID = 0)
11:11 AM: gtkseparatormenuitem.h (ID = 0)
11:11 AM: gtkseparator.h (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: atkstateset.h (ID = 0)
11:11 AM: gtktextmark.h (ID = 0)
11:11 AM: gtktoolbar.h (ID = 0)
11:11 AM: atktext.h (ID = 0)
11:11 AM: atkselection.h (ID = 0)
11:11 AM: atkrelationtype.h (ID = 0)
11:11 AM: atkrelationset.h (ID = 0)
11:11 AM: atkrelation.h (ID = 0)
11:11 AM: atkregistry.h (ID = 0)
11:11 AM: atkobjectfactory.h (ID = 0)
11:11 AM: gettext.sh (ID = 0)
11:11 AM: gtkstock.h (ID = 0)
11:11 AM: gtktextdisplay.h (ID = 0)
11:11 AM: atkstate.h (ID = 0)
11:11 AM: gtktext.h (ID = 0)
11:11 AM: gtkspinbutton.h (ID = 0)
11:11 AM: gtksignal.h (ID = 0)
11:11 AM: gtksettings.h (ID = 0)
11:11 AM: gtkselection.h (ID = 0)
11:11 AM: gtktable.h (ID = 0)
11:11 AM: gtktextiter.h (ID = 0)
11:11 AM: atktable.h (ID = 0)
11:11 AM: gtkscrollbar.h (ID = 0)
11:11 AM: gtkscale.h (ID = 0)
11:11 AM: gtktextbuffer.h (ID = 0)
11:11 AM: gtkrc.h (ID = 0)
11:11 AM: gtkruler.h (ID = 0)
11:11 AM: libtiff.lib (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libfreetype-bcc.lib (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: pango-hebrew-fc.dll (ID = 0)
11:11 AM: pango-indic-fc.dll (ID = 0)
11:11 AM: zlib1.dll (ID = 0)
11:11 AM: intl.dll (ID = 0)
11:11 AM: atk-1.0.lib (ID = 0)
11:11 AM: libpixbufloader-ani.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: fontconfig.lib (ID = 0)
11:11 AM: libfontconfig-1.dll (ID = 0)
11:11 AM: gettextsrc.dll (ID = 0)
11:11 AM: libjpeg.a (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: glib-2.0.lib (ID = 0)
11:11 AM: gdkalias.h (ID = 0)
11:11 AM: pango-syriac-fc.dll (ID = 0)
11:11 AM: pango-khmer-fc.dll (ID = 0)
11:11 AM: pango-arabic-fc.dll (ID = 0)
11:11 AM: libpixbufloader-png.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libpixbufloader-pnm.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libtiff.dll.a (ID = 0)
11:11 AM: xmlparse.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: png.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: png.h (ID = 0)
11:11 AM: libpixbufloader-ico.dll (ID = 0)
11:11 AM: ttnameid.h (ID = 0)
11:11 AM: ftcache.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: copying.lib-2 (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: asprintf.dll (ID = 0)
11:11 AM: gtk.ico (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libgmodule-2.0-0.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libpangoft2-1.0.dll.a (ID = 0)
11:11 AM: gdkkeysyms.h (ID = 0)
11:11 AM: tttables.h (ID = 0)
11:11 AM: pshints.h (ID = 0)
11:11 AM: msgfmt.exe (ID = 0)
11:11 AM: gtk-installer.nsi (ID = 0)
11:11 AM: glib-genmarshal.exe (ID = 0)
11:11 AM: ftview.exe (ID = 0)
11:11 AM: ftstring.exe (ID = 0)
11:11 AM: gdk-win32-2.0.lib (ID = 0)
11:11 AM: libjpeg.lib (ID = 0)
11:11 AM: gdk_pixbuf-2.0.lib (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libgdk-win32-2.0-0.dll (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: tiff.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: libpixbufloader-jpeg.dll (ID = 0)
11:11 AM: ftoutln.h (ID = 0)
11:11 AM: im-ti-et.dll (ID = 0)
11:11 AM: im-ti-er.dll (ID = 0)
11:11 AM: atkobject.h (ID = 0)
11:11 AM: gtk-query-immodules-2.0.exe (ID = 0)
11:11 AM: im-am-et.dll (ID = 0)
11:11 AM: libpango-1.0.dll.a (ID = 0)
11:11 AM: libbluecurve.dll (ID = 0)
11:11 AM: asprintf.dll (ID = 0)
11:11 AM: libpango-1.0-0.dll (ID = 0)
11:11 AM: liblighthouseblue.dll (ID = 0)
11:11 AM: gtkwidget.h (ID = 0)
11:11 AM: msginit.exe (ID = 0)
11:11 AM: gtkstyle.h (ID = 0)
11:11 AM: psaux.h (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: fc-cache.exe (ID = 0)
11:11 AM: freetype6.dll (ID = 0)
11:11 AM: libtiff.a (ID = 0)
11:11 AM: libfontconfig.dll.a (ID = 0)
11:11 AM: libgdk_pixbuf-2.0-0.dll (ID = 0)
11:11 AM: libpangoft2-1.0-0.dll (ID = 0)
11:11 AM: libglib-2.0-0.dll (ID = 0)
11:11 AM: libtiff3.dll (ID = 0)
11:11 AM: gtk-win32-2.0.lib (ID = 0)
11:11 AM: jpeg62.dll (ID = 0)
11:11 AM: libatk-1.0-0.dll (ID = 0)
11:11 AM: ftimage.h (ID = 0)
11:11 AM: tttypes.h (ID = 0)
11:11 AM: gobject-2.0.lib (ID = 0)
11:11 AM: libglib-2.0.dll.a (ID = 0)
11:11 AM: libgobject-2.0-0.dll (ID = 0)
11:11 AM: libpng.lib (ID = 0)
11:11 AM: xmltok.dll (ID = 0)
11:11 AM: libgdk-win32-2.0.dll.a (ID = 0)
11:11 AM: libfreetype.a (ID = 0)
11:11 AM: libpng13.a (ID = 0)
11:11 AM: libgobject-2.0.dll.a (ID = 0)
11:11 AM: gtk-demo.exe (ID = 0)
11:11 AM: iconv.dll (ID = 0)
11:11 AM: iconv.dll (ID = 0)
11:11 AM: gtk-runtime-2.6.9-rev-a.exe (ID = 0)
11:11 AM: libfontconfig-1.dll (ID = 0)
11:11 AM: libpng13.dll (ID = 0)
11:11 AM: gtk-2.6.9-rev-a-installer.tar.gz (ID = 0)
11:11 AM: libpng.dll.a (ID = 0)
11:11 AM: libpng.a (ID = 0)
11:11 AM: pango-1.0.lib (ID = 0)
11:11 AM: libpng13.dll.a (ID = 0)
11:11 AM: libgtk-win32-2.0.dll.a (ID = 0)
11:11 AM: libgtk-win32-2.0-0.dll (ID = 0)
11:11 AM: build.sh (ID = 0)
11:11 AM: ftmodule.h (ID = 0)
11:11 AM: tiffvers.h (ID = 0)
11:11 AM: gmodule-2.0.def (ID = 0)
11:11 AM: gthread-2.0.def (ID = 0)
11:11 AM: gdkconfig.h (ID = 0)
11:11 AM: atk.pc (ID = 0)
11:11 AM: fontconfig.pc (ID = 0)
11:11 AM: gdk-2.0.pc (ID = 0)
11:11 AM: gdk-pixbuf-2.0.pc (ID = 0)
11:11 AM: gdk-win32-2.0.pc (ID = 0)
11:11 AM: glib-2.0.pc (ID = 0)
11:11 AM: gmodule-2.0.pc (ID = 0)
11:11 AM: gmodule-no-export-2.0.pc (ID = 0)
11:11 AM: gobject-2.0.pc (ID = 0)
11:11 AM: gthread-2.0.pc (ID = 0)
11:11 AM: gtk+-2.0.pc (ID = 0)
11:11 AM: gtk+-win32-2.0.pc (ID = 0)
11:11 AM: pango.pc (ID = 0)
11:11 AM: pangoft2.pc (ID = 0)
11:11 AM: pangowin32.pc (ID = 0)
11:11 AM: version.sh (ID = 0)
11:11 AM: .wgbef-rev (ID = 0)
11:11 AM: build.sh (ID = 0)
11:11 AM: gtkrc (ID = 0)
11:11 AM: pango.aliases (ID = 0)
11:11 AM: gtk20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: glib20.mo (ID = 0)
11:11 AM: gtkrc (ID = 0)
11:11 AM: gtkrc.plain (ID = 0)
11:11 AM: gtkrc (ID = 0)
11:11 AM: version.sh (ID = 0)
11:11 AM: .wgbef-rev (ID = 0)
11:13 AM: File Sweep Complete, Elapsed Time: 00:27:16
11:13 AM: Full Sweep has completed. Elapsed time 00:29:09
11:13 AM: Traces Found: 916
11:18 AM: Removal process initiated
11:18 AM: Quarantining All Traces: potentially rootkit-masked files
********


Thanks for all the help! My popups have seemed to stop for now. I have only been using it for an hour now though so I will see tonight.
  • 0

#12
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello again! I'm GLAD the popups have gone, but I am concerned about something, and I hope you'll indulge me!?

We are lucky to have one of the Malware research teams members from Webroot on Staff here. I talked with him, and he took a look at this log for me. He'd like you to do something for us, if you would please. :tazz:

Go into SpySweepers' quarantine and place a check next to all of those potentially rootkit masked files..and then restore them. None of them appear malicious, and we're pretty sure they are false positives.

After you restore them, I want you to follow my above instructions to run another SpySweeper scan. However...I want you to UNcheck the "Sweep for rootkits" option. IF we think there could be a rootkit after I see the next scan results, I can have you run RootkitRevealer. I'm confident you do NOT have one, though. :)

After you run the new scan, post me a log from SS as well as another HijackThis log.
  • 0

#13
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
Alright here is my spy sweeper log after i restored the items. I clicked restore then it went a long for a while and the progress bar was full and it was finished, but the items are still under quarentine. I just want to make sure this is normal. The restore went like I think it was supposed to, nothing weird happened. Here is the SS log:


********
7:49 PM: | Start of Session, Wednesday, November 16, 2005 |
7:49 PM: Spy Sweeper started
7:49 PM: Sweep initiated using definitions version 573
7:49 PM: Starting Memory Sweep
7:51 PM: Memory Sweep Complete, Elapsed Time: 00:01:46
7:51 PM: Starting Registry Sweep
7:51 PM: Registry Sweep Complete, Elapsed Time:00:00:13
7:51 PM: Starting Cookie Sweep
7:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
7:51 PM: Starting File Sweep
8:11 PM: File Sweep Complete, Elapsed Time: 00:19:46
8:11 PM: Full Sweep has completed. Elapsed time 00:21:50
8:11 PM: Traces Found: 0
********

Here is the Hijackthis log:


Logfile of HijackThis v1.99.1
Scan saved at 9:40:06 PM, on 11/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ryan Maas\Desktop\ \Security\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Color Calibration.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...603/mcfscan.cab
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


So far still no pop ups or anything. Let me know if there is anything else i need to do. Thanks again :tazz:
  • 0

#14
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello again! :tazz:

I talked with our Webroot person. He went in and re-created what you did. The only thing that he can find is that there were so many items found that the UNquarantine didn't finish. Go ahead and try removing them from quarantine again. I'm confident you do NOT have a rootkit hiding. But just to be on the safe side, let's run this, ok?

Please download Rootkit Revealer (link is at the very bottom of the page)
  • Unzip it to your desktop.
  • Open the rootkitrevealer folder and double-click rootkitrevealer.exe
  • Click the Scan button (bottom right)
  • It may take a while to scan (don't do anything while it's running)
  • When it's done, go up to File > Save. Choose to save it to your desktop.
  • Open rootkitrevealer.txt on your desktop and copy the entire contents and paste them here

  • 0

#15
ep3w

ep3w

    Member

  • Topic Starter
  • Member
  • PipPip
  • 34 posts
I restored the files then ran the scan. The scan said there were no descrepencies found and when i saved the text file, it was empty.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP