Thanks again and let me know if there is anything else.
********
3:50 PM: | Start of Session, Sunday, December 04, 2005 |
3:50 PM: Spy Sweeper started
3:50 PM: Sweep initiated using definitions version 577
3:50 PM: Starting Memory Sweep
3:53 PM: Memory Sweep Complete, Elapsed Time: 00:02:26
3:53 PM: Starting Registry Sweep
3:53 PM: Found Adware: findthewebsiteyouneed hijacker
3:53 PM: HKU\.default\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555438)
3:53 PM: Found Adware: delfin
3:53 PM: HKLM\software\vidmon\ (3 subtraces) (ID = 890155)
3:53 PM: Found Adware: dollarrevenue
3:53 PM: HKLM\software\microsoft\drsmartload\ (1 subtraces) (ID = 916795)
3:53 PM: Found Adware: command
3:53 PM: HKLM\system\currentcontrolset\services\cmdservice\ (12 subtraces) (ID = 958670)
3:53 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (6 subtraces) (ID = 1016064)
3:53 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (8 subtraces) (ID = 1016072)
3:53 PM: Found Adware: maxifiles
3:53 PM: HKCR\typelib\{5279231e-fabe-4abf-83a8-7c7e17e3ce1a}\ (9 subtraces) (ID = 1020940)
3:53 PM: HKLM\software\classes\typelib\{5279231e-fabe-4abf-83a8-7c7e17e3ce1a}\ (9 subtraces) (ID = 1021009)
3:53 PM: HKU\WRSS_Profile_S-1-5-21-329068152-926492609-725345543-1006\software\xbtb07618\ (61 subtraces) (ID = 134858)
3:53 PM: Found Adware: cydoor
3:53 PM: HKU\WRSS_Profile_S-1-5-21-329068152-926492609-725345543-1006\software\cydoor\ (1162 subtraces) (ID = 639126)
3:53 PM: HKU\WRSS_Profile_S-1-5-21-329068152-926492609-725345543-1006\software\cydoor services\ (204 subtraces) (ID = 639128)
3:53 PM: HKU\WRSS_Profile_S-1-5-21-329068152-926492609-725345543-1006\software\microsoft\internet explorer\extensions\cmdmapping\ || {77fbf9b8-1d37-4ff2-9ced-192d8e3aba6f} (ID = 1021025)
3:53 PM: HKU\S-1-5-21-329068152-926492609-725345543-1004\software\director\ || baseurl (ID = 980277)
3:53 PM: HKU\S-1-5-21-329068152-926492609-725345543-1004\software\microsoft\internet explorer\extensions\cmdmapping\ || {77fbf9b8-1d37-4ff2-9ced-192d8e3aba6f} (ID = 1021025)
3:54 PM: HKU\S-1-5-18\software\xbtb07618\ (61 subtraces) (ID = 134858)
3:54 PM: HKU\S-1-5-18\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555437)
3:54 PM: HKU\S-1-5-18\software\vidmon\ (1 subtraces) (ID = 890125)
3:54 PM: HKU\S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping\ || {77fbf9b8-1d37-4ff2-9ced-192d8e3aba6f} (ID = 1021025)
3:54 PM: Registry Sweep Complete, Elapsed Time:00:00:47
3:54 PM: Starting Cookie Sweep
3:54 PM: Found Spy Cookie: 2o7.net cookie
3:54 PM:
[email protected][1].txt (ID = 1958)
3:54 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
3:54 PM: Starting File Sweep
3:54 PM: Warning: Failed to open file "c:\hiberfil.sys". Access is denied
3:54 PM: Warning: Failed to open file "c:\pagefile.sys". Access is denied
3:54 PM: drsmartload.dat (ID = 198788)
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\system.log". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\software.log". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\default.log". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\security". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\sam". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\sam.log". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\security.log". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\system". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\software". The process cannot access the file because it is being used by another process
3:56 PM: Warning: Failed to open file "c:\windows\system32\config\default". The process cannot access the file because it is being used by another process
3:57 PM: c:\windows\system32\nfomon (1 subtraces) (ID = -2147468684)
3:57 PM: c:\windows\system32\vidmon (ID = -2147468683)
4:06 PM: c:\documents and settings\all users\application data\nfo (16 subtraces) (ID = -2147468687)
4:06 PM: mon1204.ddx (ID = 57680)
4:06 PM: mon0315.ddx (ID = 57680)
4:06 PM: mon0204.ddx (ID = 57680)
4:06 PM: mon0504.ddx (ID = 57680)
4:06 PM: c:\documents and settings\all users\application data\vidmon (1 subtraces) (ID = -2147468685)
4:06 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\networkservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\networkservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\ntuser.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc87caff8-b83a-4cfe-846f-9314ac123807.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8ba06737-9867-41ec-9290-c60499b6bf1d.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs224b39cb-cbf5-45d2-8fcb-78c7816e798b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8e543053-3296-446b-b463-8aeeb8da3857.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7ab3f7b0-6a7d-4066-b13e-da50b1c82416.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd90681e8-223c-4424-9cf6-e6c6173a8f4b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3c301c62-aba3-4f9e-a4f5-a9753503d95d.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9c11b185-ce6a-48c2-9251-ff219aa635ac.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5af04734-f653-43f4-85c9-c2927396c91a.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdfce1930-724b-4df1-9341-1c0b110a1677.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs20112a3f-c6e5-4836-9854-bff48deae564.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2b7807bf-2c01-4e81-abd2-bb040b1dd2dd.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa3054bc8-2522-41cb-a806-81e2a2fc9073.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb80f749d-00f6-4282-abde-8d2bf03012a9.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbaa2f9b5-f7ee-4bc3-a518-a16001241fe0.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs14a5cdc0-5ea0-4129-a8fb-78f267585836.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9e83bdd2-a0b9-41c6-911d-0fec6e2523fb.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb57bc4f8-8535-4201-a1b1-42b637e2eaee.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2b2a22ba-3f57-4106-a944-426d62a00cb1.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbd25617f-dd53-4639-a250-18181c8eaa56.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb829d5ec-8463-4eb2-94a6-b401cf0e59e5.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse28e0940-cfe1-4aa5-bffe-a8ee0262b688.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsab62aee3-6e9e-4f3e-b3ed-b67fced30d67.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa442cbb8-45a2-4456-afac-b2517f3d2212.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsefb23ea3-34c5-4912-befe-345ebbf13d34.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs73710fa6-9e93-445b-ada8-c5618748f2e6.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8e7b2a4e-e5c9-4162-ab19-1e8066687dc8.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc5c18010-c81e-4500-8ad4-84c33e50f771.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsae7c900c-eb49-4797-b050-22bbd2bdf308.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs71504aa4-4570-4238-9a5b-556ba02f9b29.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8fe5f581-d3d0-4092-b1d8-505c17c17f2d.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs89ef477a-9fbd-41a1-a73c-a3cd3d652096.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs37080901-d25e-491b-a986-30a384fbd99c.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7e09e368-2229-4103-887f-3286516f8f6b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4667f319-4362-418d-a8c7-8c93d7cc11ba.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse243c62e-0f1a-4019-9480-be152e43c392.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5f4cb7b2-40c2-458d-b14a-ca9727e08e36.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8d4c78b9-cad2-4ff7-91d7-6194e2ed1aea.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5d07fd32-97bc-4457-808b-d93f7a712e23.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs190a52fb-9d3c-4e54-8b95-c4a4fd3f3dee.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsefbff5c0-b789-4c67-8936-478602934a80.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7317d9dc-1332-43fe-9c12-7401cd6c5a41.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf60242da-4489-49a8-a3aa-a635ad6fcd8a.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs038d78bc-789d-4b92-9fa5-e98a835e883b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9f82f102-cbfe-40f4-b654-1357d40e2fc3.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf16aed75-5dee-4424-8b23-d3578ad96d76.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa7d7b8a6-9b6d-4490-a2f3-21a022e9cc14.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsa66c3619-6124-472f-8bb6-999dd4a07183.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsad4f7593-88b9-40fb-9158-cd6953fd559c.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdfdcfdc4-9c19-49e8-8f83-3576d6288ed2.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs85de43bf-5a5f-43de-a459-5604b57904b7.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscscb822816-3a6c-4e68-bb37-535f4df1e050.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs4f3a7e3a-dc50-4465-89b2-de7d73a94fd2.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsce5d8e8a-958e-4c7e-8dc5-98c74353e423.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse7f8c10c-efce-4105-9d57-50a522e200be.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbd3b3852-b787-46b8-9e7d-6cd406b24b7e.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbcae9892-9d3f-45b1-858f-0d8dbf69e158.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf0bf84e7-4c64-41f8-ba1e-fde19803de4d.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd91ba39c-f5de-4326-8f1c-06508fd26a47.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs16990403-c420-4981-930f-d69af2ac8ae2.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs8495ffe8-a58d-419a-8f1d-a7b85af6e224.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsecb718de-8797-42d4-b5bb-9d712d0900d0.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb792ac93-7397-4970-b8ce-b28131096851.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs362e7eea-52e3-4452-9b52-a0b3d2b86a61.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc63aec92-697c-419d-af7a-b90d10311ca0.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb6f209d0-adae-4ad4-932f-4a43b3fc1506.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsd2c5dd14-e01b-4685-9023-53cb40cb4af0.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs25e44036-f4a7-4828-9a1e-217b8345e3e5.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbaac0d87-9fb7-479e-91d7-d4de4c5d1977.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsda67680d-5583-405a-a5a1-e93c3f4ee5c9.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6d69e958-9681-4447-837b-bf0b3fca54bd.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf184bbb5-e514-40c3-8af7-c131dedde849.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsee9317c3-c267-456d-a049-1780b06c5f72.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsda6e0470-5bc6-42d9-a21e-f7815a34275b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf084d576-2418-43e3-bef2-473257f7f731.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs88cfa3d2-1bf7-455a-b38a-39e1bfab54de.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs955993db-a61c-412d-8df6-9b869cb5a904.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs451e18da-308c-4ae4-81c3-82869cd8d5d4.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs99ba9cc9-1544-43f7-bd8f-cc5bea331e27.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsbf767228-f1b6-4620-940f-8be861102cfc.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2e64f202-fe14-431d-8172-d60b9d6fce51.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs80a512af-7b22-444e-8646-9cb913ef8fc7.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs6c8a119f-eddd-4238-b441-d63b887c1823.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsf8fd16ff-af6e-4f15-af4a-cb14185db596.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2eaa737b-b3a3-4ed6-8ac7-7eb3d8acddcf.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2020223c-ffc8-4ba6-adb9-96e0115db3cc.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs213cd78c-e098-4106-a72c-9f027e482d23.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs16d3d5da-9f72-40b5-b6a0-fa7a70b2723d.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3fb021b4-197f-4f68-b923-7a878aea68ea.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs85a2d319-d0d3-43d7-9278-813f322ed601.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsc1f0c942-8d87-4e0f-8b69-586438d84786.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs3e4fcc0a-c740-4dc4-9b06-65929897e5d3.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs34be65de-0d94-4908-a481-94f45acd96b1.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2bf75fd9-99d5-4903-9c41-a2220e5acfa1.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs7b46bc1d-1710-44e5-be09-a9be81be2abf.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs5fec763e-c55e-4434-aea3-e16ae2f857d9.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscse29e9e4c-e4a9-40e9-ab52-7d1d5142d491.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsdfca94a6-8ec2-49b3-b2ba-660e8d935e39.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsae2ec339-a5b9-4a7b-a417-9ed1225a3952.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs33c96273-b67f-4db8-bcad-56e2c145a95c.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscsb106450d-7c6b-460c-8eab-4b2c5677fd6b.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs0a975618-825f-4605-8964-594f3cab10b7.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs9f9a20c2-14b7-4565-a7dd-f173411539df.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\localservice\application data\webroot\spy sweeper\temp\sscs2c60b004-3673-4237-9e37-7756ed7856db.tmp". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\kirsten\ntuser.dat". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\kirsten\ntuser.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\kirsten\local settings\application data\microsoft\windows\usrclass.dat.log". The process cannot access the file because it is being used by another process
4:06 PM: Warning: Failed to open file "c:\documents and settings\kirsten\local settings\application data\microsoft\windows\usrclass.dat". The process cannot access the file because it is being used by another process
4:06 PM: mon0904.ddx (ID = 57684)
4:06 PM: mon0412.ddx (ID = 57680)
4:06 PM: mon0106.ddx (ID = 57679)
4:06 PM: mon1125.ddx (ID = 57685)
4:06 PM: mon2007.dbd (ID = 57693)
4:06 PM: mon1909.ddx (ID = 57684)
4:06 PM: mon1920.dbd (ID = 57692)
4:06 PM: mon1215.dbd (ID = 57687)
4:06 PM: 538.dfn (ID = 133429)
4:07 PM: Found Adware: look2me
4:07 PM: __delete_on_reboot__guard.tmp (ID = 159)
4:07 PM: crrtmgr.dll (ID = 159)
4:07 PM: hhzlnt07.dll (ID = 159)
4:07 PM: irlol5331.dll (ID = 159)
4:07 PM: k8440ihqe84e0.dll (ID = 159)
4:08 PM: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcsys.dll". The process cannot access the file because it is being used by another process
4:08 PM: Warning: Failed to open file "c:\program files\common files\symantec shared\ccpd-lc\symlcrst.dll". The process cannot access the file because it is being used by another process
4:08 PM: Found Trojan Horse: trojan downloader matcash
4:08 PM: c:\program files\common files\inetget (ID = -2147477182)
4:08 PM: c:\program files\common files\inetget2 (ID = -2147471395)
4:08 PM: autoit3.exe (ID = 119348)
4:08 PM: Found Adware: targetsaver
4:08 PM: class-barrel (ID = 78229)
4:08 PM: vocabulary (ID = 78283)
4:15 PM: c:\program files\freeprod toolbar (8 subtraces) (ID = -2147463651)
4:15 PM: Found Trojan Horse: trojan-backdoor-surila
4:15 PM: webhost2.exe (ID = 184175)
4:17 PM: a0075677.dll (ID = 159)
4:17 PM: a0075678.dll (ID = 159)
4:17 PM: a0075679.dll (ID = 159)
4:17 PM: a0075680.dll (ID = 159)
4:17 PM: a0075681.dll (ID = 159)
4:17 PM: a0075682.dll (ID = 159)
4:17 PM: a0075685.exe (ID = 166181)
4:17 PM: Found Adware: adtech2005
4:17 PM: a0075686.exe (ID = 194580)
4:17 PM: a0075687.exe (ID = 65722)
4:17 PM: a0075689.dll (ID = 195129)
4:17 PM: a0075684.ocx.tcf (ID = 194608)
4:17 PM: a0075701.dll (ID = 159)
4:17 PM: a0075709.dll (ID = 159)
4:17 PM: a0075710.dll (ID = 159)
4:21 PM: Found Adware: effective-i toolbar
4:21 PM: ucmore tour.lnk (ID = 59855)
4:21 PM: how to uninstall.lnk (ID = 59838)
4:21 PM: File Sweep Complete, Elapsed Time: 00:27:44
4:21 PM: Full Sweep has completed. Elapsed time 00:31:13
4:21 PM: Traces Found: 1628
4:26 PM: Removal process initiated
4:26 PM: Quarantining All Traces: look2me
4:26 PM: Quarantining All Traces: trojan downloader matcash
4:26 PM: Quarantining All Traces: trojan-backdoor-surila
4:26 PM: Quarantining All Traces: maxifiles
4:26 PM: Quarantining All Traces: adtech2005
4:26 PM: Quarantining All Traces: command
4:26 PM: Quarantining All Traces: cydoor
4:26 PM: Quarantining All Traces: delfin
4:26 PM: Quarantining All Traces: dollarrevenue
4:26 PM: Quarantining All Traces: effective-i toolbar
4:26 PM: Quarantining All Traces: findthewebsiteyouneed hijacker
4:26 PM: Quarantining All Traces: targetsaver
4:27 PM: Quarantining All Traces: 2o7.net cookie
4:28 PM: Removal process completed. Elapsed time 00:02:03
********
3:49 PM: | Start of Session, Sunday, December 04, 2005 |
3:49 PM: Spy Sweeper started
3:49 PM: Your spyware definitions have been updated.
3:49 PM: Updating spyware definitions
3:49 PM: Your definitions are up to date.
3:50 PM: | End of Session, Sunday, December 04, 2005 |
Logfile of HijackThis v1.99.1
Scan saved at 4:29:05 PM, on 12/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kirsten\Desktop\Spyware Removal\HijackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [Microsoft Windows DLL Services Configuration] windir32.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support.com SmartIssue) -
http://support.chart...oad/tgctlsi.cabO16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) -
http://support.chart...ad/tgctlins.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) -
http://thesims.ea.co...cationTeleX.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1133393680968O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} -
http://download.spys...rcabinstall.cabO16 - DPF: {FF054BED-D972-4215-897E-726C3488DDBB} (sonyctl.sonycm) -
http://supportcentra...oad/sonyctl.CABO20 - Winlogon Notify: BITS - C:\WINDOWS\system32\o0480ahued480.dll
O20 - Winlogon Notify: Unimodem - C:\WINDOWS\system32\irlol5331.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: GBPoll - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe