LDTate,
NKTRAP.DLL was a little difficult to find in the registry, but I ended up doing a search for it and found it in the Extensions folder (the file wasn't named NKTRAP.DLL, but it contained it)
But, I did everything you said and below are the updated HJT log and SpySweeper log.
Still getting McAfee warnings for VeryLince.
Thanks,
-Anna
********
12:05 PM: | Start of Session, Thursday, October 27, 2005 |
12:05 PM: Spy Sweeper started
12:05 PM: Sweep initiated using definitions version 563
12:05 PM: Starting Memory Sweep
12:06 PM: Found Adware: icannnews
12:06 PM: Detected running threat: C:\WINDOWS\SYSTEM32\NKTRAP.DLL (ID = 156955)
12:07 PM: Detected running threat: C:\WINDOWS\SYSTEM32\ARWAV.DLL (ID = 156955)
12:08 PM: Memory Sweep Complete, Elapsed Time: 00:03:03
12:08 PM: Starting Registry Sweep
12:08 PM: Found Adware: apropos
12:08 PM: HKLM\software\aprps\ (ID = 103741)
12:08 PM: Found Adware: media-motor
12:08 PM: HKLM\software\mm\ (1 subtraces) (ID = 140211)
12:08 PM: Found Adware: search fast communicator toolbar
12:08 PM: HKCR\communicator.communicator\ (3 subtraces) (ID = 140680)
12:08 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb428}\ (6 subtraces) (ID = 140681)
12:08 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140682)
12:08 PM: HKCR\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140683)
12:08 PM: HKCR\communicator.communicatormenu button\ (3 subtraces) (ID = 140684)
12:08 PM: HKCR\communicator.communicatortoggle button\ (3 subtraces) (ID = 140685)
12:08 PM: HKLM\software\classes\communicator.communicatormenu button\ (3 subtraces) (ID = 140686)
12:08 PM: HKLM\software\classes\communicator.communicatortoggle button\ (3 subtraces) (ID = 140687)
12:08 PM: HKLM\software\classes\communicator.communicator\ (3 subtraces) (ID = 140691)
12:08 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb428}\ (6 subtraces) (ID = 140692)
12:08 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb429}\ (6 subtraces) (ID = 140693)
12:08 PM: HKLM\software\classes\clsid\{4e7bd74f-2b8d-469e-8dbc-a42eb79cb42a}\ (6 subtraces) (ID = 140694)
12:08 PM: HKU\.default\software\communicator toolbar\ (9 subtraces) (ID = 140696)
12:08 PM: HKU\.default\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140697)
12:08 PM: Found Adware: surfsidekick
12:08 PM: HKLM\software\microsoft\internet explorer\urlsearchhooks\ || {02ee5b04-f144-47bb-83fb-a60bd91b74a9} (ID = 143400)
12:08 PM: Found Adware: drsnsrch hijacker
12:08 PM: HKCR\dsrch.band\ (5 subtraces) (ID = 509134)
12:08 PM: HKCR\dsrch.bottomframe\ (5 subtraces) (ID = 509135)
12:08 PM: HKCR\dsrch.leftframe\ (5 subtraces) (ID = 509136)
12:08 PM: HKCR\dsrch.popupbrowser\ (5 subtraces) (ID = 509137)
12:08 PM: HKCR\dsrch.popupwindow\ (5 subtraces) (ID = 509138)
12:08 PM: HKCR\clsid\{8b51fc2f-c687-40a3-b54a-bb9ebf8d407f}\ (11 subtraces) (ID = 509139)
12:08 PM: HKCR\clsid\{ce27d4df-714b-4427-95eb-923fe53adf8e}\ (13 subtraces) (ID = 509140)
12:08 PM: HKCR\clsid\{e2d2fe40-5674-4b77-802b-ec86b6c2c41d}\ (13 subtraces) (ID = 509141)
12:08 PM: HKCR\clsid\{e311d3a5-4a3b-4e49-9e0a-b40fae1f0b28}\ (11 subtraces) (ID = 509142)
12:08 PM: HKCR\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 509153)
12:08 PM: HKLM\software\classes\dsrch.band\ (5 subtraces) (ID = 509171)
12:08 PM: HKLM\software\classes\dsrch.leftframe\ (5 subtraces) (ID = 509179)
12:08 PM: HKLM\software\classes\dsrch.popupbrowser\ (5 subtraces) (ID = 509185)
12:08 PM: HKLM\software\classes\dsrch.popupwindow\ (5 subtraces) (ID = 509191)
12:08 PM: HKLM\software\classes\clsid\{8b51fc2f-c687-40a3-b54a-bb9ebf8d407f}\ (11 subtraces) (ID = 509198)
12:08 PM: HKLM\software\classes\clsid\{ce27d4df-714b-4427-95eb-923fe53adf8e}\ (13 subtraces) (ID = 509210)
12:08 PM: HKLM\software\classes\clsid\{e2d2fe40-5674-4b77-802b-ec86b6c2c41d}\ (13 subtraces) (ID = 509224)
12:08 PM: HKLM\software\classes\clsid\{e311d3a5-4a3b-4e49-9e0a-b40fae1f0b28}\ (11 subtraces) (ID = 509238)
12:08 PM: HKCR\dsrch.band\clsid\ (1 subtraces) (ID = 509361)
12:08 PM: HKCR\dsrch.band\curver\ (1 subtraces) (ID = 509362)
12:08 PM: HKCR\dsrch.bottomframe\clsid\ (1 subtraces) (ID = 509363)
12:08 PM: HKCR\dsrch.bottomframe\curver\ (1 subtraces) (ID = 509364)
12:08 PM: HKCR\dsrch.leftframe\clsid\ (1 subtraces) (ID = 509365)
12:08 PM: HKCR\dsrch.leftframe\curver\ (1 subtraces) (ID = 509366)
12:08 PM: HKCR\dsrch.popupbrowser\clsid\ (1 subtraces) (ID = 509367)
12:08 PM: HKCR\dsrch.popupbrowser\curver\ (1 subtraces) (ID = 509368)
12:08 PM: HKCR\dsrch.popupwindow\clsid\ (1 subtraces) (ID = 509369)
12:08 PM: HKCR\dsrch.popupwindow\curver\ (1 subtraces) (ID = 509370)
12:08 PM: HKCR\dsrch.band.1\ (3 subtraces) (ID = 512692)
12:08 PM: HKCR\dsrch.bottomframe.1\ (3 subtraces) (ID = 512699)
12:08 PM: HKCR\dsrch.leftframe.1\ (3 subtraces) (ID = 512706)
12:08 PM: HKCR\dsrch.popupbrowser.1\ (3 subtraces) (ID = 512713)
12:08 PM: HKCR\dsrch.popupwindow.1\ (3 subtraces) (ID = 512720)
12:08 PM: HKCR\clsid\{00f1d395-4744-40f0-a611-980f61ae2c59}\ (11 subtraces) (ID = 512747)
12:08 PM: HKLM\software\classes\dsrch.band.1\ (3 subtraces) (ID = 513072)
12:08 PM: HKLM\software\classes\dsrch.bottomframe.1\ (3 subtraces) (ID = 513076)
12:08 PM: HKLM\software\classes\dsrch.leftframe.1\ (3 subtraces) (ID = 513080)
12:08 PM: HKLM\software\classes\dsrch.popupbrowser.1\ (3 subtraces) (ID = 513084)
12:08 PM: HKLM\software\classes\dsrch.popupwindow.1\ (3 subtraces) (ID = 513088)
12:08 PM: HKLM\software\classes\clsid\{00f1d395-4744-40f0-a611-980f61ae2c59}\ (11 subtraces) (ID = 513114)
12:08 PM: HKLM\software\classes\dsrch.bottomframe\ (5 subtraces) (ID = 646382)
12:08 PM: HKLM\software\classes\typelib\{8f73ac0f-5769-4282-8762-b396a3bff377}\ (9 subtraces) (ID = 646384)
12:08 PM: Found Adware: abetterinternet
12:08 PM: HKLM\software\microsoft\windows\currentversion\uninstall\bsto-1\ (7 subtraces) (ID = 746835)
12:08 PM: Found Adware: clkoptimizer
12:08 PM: HKLM\software\qstat\ (5 subtraces) (ID = 769771)
12:08 PM: Found Adware: maxifiles
12:08 PM: HKCR\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829231)
12:08 PM: HKCR\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829237)
12:08 PM: HKCR\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829241)
12:08 PM: HKCR\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829253)
12:08 PM: HKLM\software\classes\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829282)
12:08 PM: HKLM\software\classes\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829292)
12:08 PM: HKLM\software\classes\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829298)
12:08 PM: HKLM\software\classes\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829302)
12:08 PM: HKLM\software\qstat\ || brr (ID = 877670)
12:08 PM: Found Adware: one2one viewer
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\livesvc\ (ID = 136368)
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\communicator toolbar\ (10 subtraces) (ID = 140688)
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140689)
12:08 PM: Found Adware: targetsaver
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\tsl2\ (1 subtraces) (ID = 143616)
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\dsrch\ (4 subtraces) (ID = 509156)
12:08 PM: Found Adware: enbrowser
12:08 PM: HKU\S-1-5-21-2796314089-2078633152-111728159-1006\software\system\sysuid\ (1 subtraces) (ID = 731748)
12:08 PM: Found Adware: drsnsrch.com hijack
12:08 PM: HKU\S-1-5-18\software\microsoft\search assistant\ || defaultsearchurl (ID = 128205)
12:08 PM: Found Adware: purityscan
12:08 PM: HKU\S-1-5-18\software\microsoft\windows\currentversion\run\ || ncao (ID = 138536)
12:08 PM: HKU\S-1-5-18\software\communicator toolbar\ (9 subtraces) (ID = 140688)
12:08 PM: HKU\S-1-5-18\software\microsoft\internet explorer\toolbar\webbrowser\ || {4e7bd74f-2b8d-469e-8dbc-a42eb79cb428} (ID = 140689)
12:08 PM: HKU\S-1-5-18\software\dsrch\ (7 subtraces) (ID = 509156)
12:08 PM: Registry Sweep Complete, Elapsed Time:00:00:15
12:09 PM: Starting Cookie Sweep
12:09 PM: Found Spy Cookie: yieldmanager cookie
12:09 PM: anna [removed][1].txt (ID = 3751)
12:09 PM: Found Spy Cookie: hbmediapro cookie
12:09 PM: anna [removed][2].txt (ID = 2768)
12:09 PM: Found Spy Cookie: hotbar cookie
12:09 PM: anna [removed][2].txt (ID = 4207)
12:09 PM: Found Spy Cookie: ask cookie
12:09 PM: anna pavel@ask[1].txt (ID = 2245)
12:09 PM: Found Spy Cookie: belnk cookie
12:09 PM: anna [removed][1].txt (ID = 2293)
12:09 PM: anna pavel@belnk[2].txt (ID = 2292)
12:09 PM: anna [removed][1].txt (ID = 2293)
12:09 PM: Found Spy Cookie: exitexchange cookie
12:09 PM: anna pavel@exitexchange[1].txt (ID = 2633)
12:09 PM: Found Spy Cookie: kmpads cookie
12:09 PM: anna pavel@kmpads[1].txt (ID = 2909)
12:09 PM: Found Spy Cookie: top-banners cookie
12:09 PM: anna [removed]-banners[1].txt (ID = 3548)
12:09 PM: Found Spy Cookie: 2o7.net cookie
12:09 PM: anna pavel@microsoftwga.112.2o7[1].txt (ID = 1958)
12:09 PM: Found Spy Cookie: mygeek cookie
12:09 PM: anna pavel@mygeek[2].txt (ID = 3041)
12:09 PM: Found Spy Cookie: paypopup cookie
12:09 PM: anna pavel@paypopup[1].txt (ID = 3119)
12:09 PM: Found Spy Cookie: questionmarket cookie
12:09 PM: anna pavel@questionmarket[1].txt (ID = 3217)
12:09 PM: Found Spy Cookie: rn11 cookie
12:09 PM: anna pavel@rn11[2].txt (ID = 3261)
12:09 PM: Found Spy Cookie: servedby advertising cookie
12:09 PM: anna [removed][1].txt (ID = 3335)
12:09 PM: Found Spy Cookie: reliablestats cookie
12:09 PM: anna [removed][1].txt (ID = 3254)
12:09 PM: Found Spy Cookie: adserver cookie
12:09 PM: anna [removed][1].txt (ID = 2142)
12:09 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
12:09 PM: Starting File Sweep
12:09 PM: Found Adware: shopathomeselect
12:09 PM: c:\windows\system32\sahimages (6 subtraces) (ID = -2147480329)
12:09 PM: Found Adware: winad
12:09 PM: gpw_32.dll (ID = 180542)
12:09 PM: arwav.dll (ID = 156955)
12:09 PM: m?iexec.exe (ID = 154286)
12:09 PM: HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run || Megli (ID = 0)
12:10 PM: Found Adware: bookedspace
12:10 PM: towesxhe.xcg (ID = 159010)
12:11 PM: xlxqdwu.xtz (ID = 159018)
12:11 PM: eqcfobzylt.sbm (ID = 158994)
12:12 PM: kahyfee.bar (ID = 159031)
12:12 PM: atmtd.dll._ (ID = 166754)
12:13 PM: ryaxuuas.xbt (ID = 159052)
12:13 PM: ydrwfhionku.eha (ID = 159038)
12:14 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:14 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:14 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:14 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:14 PM: unstall.exe (ID = 133210)
12:15 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:15 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:15 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:15 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:15 PM: znrqnegndmc.ssu (ID = 159015)
12:16 PM: nktrap.dll (ID = 156955)
12:16 PM: linun.exe (ID = 60121)
12:16 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:16 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:16 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:16 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:16 PM: uninstall_wh.exe (ID = 60133)
12:17 PM: igvgimtf.ryf (ID = 158997)
12:18 PM: elnqmyovnw.bfm (ID = 159023)
12:18 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:18 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:18 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:18 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:18 PM: dajxekhldp.kcy (ID = 164416)
12:18 PM: juzrdysqc.fpj (ID = 159040)
12:18 PM: wfosdsp.spy (ID = 159013)
12:18 PM: fzadlhwcz.asl (ID = 159017)
12:18 PM: eziapqzd.fvo (ID = 159027)
12:18 PM: zxpdfwzrcpb.wvv (ID = 158991)
12:18 PM: unfrdrcvho.hbj (ID = 159005)
12:18 PM: xkpaqty.ycb (ID = 159030)
12:18 PM: xwevdicpa.djc (ID = 158995)
12:18 PM: ctjidrmq.adl (ID = 159020)
12:18 PM: eqwjfdqaif.cdx (ID = 159016)
12:18 PM: tklhrgiuvnd.ulx (ID = 158988)
12:18 PM: dfcrodlswqt.mvt (ID = 159047)
12:18 PM: hmpjlmmjv.mqm (ID = 159060)
12:18 PM: rieiafp.lhh (ID = 158986)
12:18 PM: uptjvuip.yqq (ID = 164361)
12:18 PM: jzlmdegbmy.rub (ID = 159024)
12:18 PM: gtjwgzjkkhu.ldp (ID = 159019)
12:18 PM: dmbynkb.zwh (ID = 159056)
12:18 PM: axhwjqvf.dff (ID = 159014)
12:18 PM: vnehidbpei.hrb (ID = 159058)
12:18 PM: dqskpkwblm.wwq (ID = 159028)
12:18 PM: zljleyfwzm.bns (ID = 159061)
12:18 PM: widdauriwyk.hdw (ID = 159012)
12:18 PM: jsnsfvqt.ije (ID = 164390)
12:18 PM: vimlirlsfeg.rhx (ID = 159026)
12:18 PM: rwmdcghxo.bsr (ID = 159018)
12:18 PM: zdwgxopsqht.wlj (ID = 158994)
12:18 PM: sbqquizqgn.slc (ID = 159031)
12:18 PM: hcvggoa.fdt (ID = 159035)
12:18 PM: fxhwbwsn.puw (ID = 159052)
12:18 PM: ubaywruxz.crj (ID = 159038)
12:18 PM: bgrwtekhuff.pkt (ID = 159001)
12:18 PM: sugwbku.igj (ID = 159051)
12:18 PM: vogivxx.cmc (ID = 158990)
12:18 PM: iehoataopi.rqx (ID = 159029)
12:18 PM: ymjfzkd.tpr (ID = 159010)
12:18 PM: coeonmiza.aaz (ID = 159015)
12:18 PM: hcmcmulz.iov (ID = 159046)
12:18 PM: alraujgcd.avo (ID = 159023)
12:18 PM: uieksarb.tne (ID = 159059)
12:18 PM: h23kkch8.dat (ID = 159521)
12:18 PM: mc-58-12-0000106.exe (ID = 156275)
12:18 PM: Found Adware: mirar webband
12:18 PM: 876056.exe (ID = 158984)
12:18 PM: preuninstallcom.exe (ID = 161421)
12:19 PM: atmtd.dll (ID = 166754)
12:19 PM: txzxqheb.ujj (ID = 164416)
12:19 PM: wzovmrei.aiw (ID = 159013)
12:19 PM: ifabylkwz.aex (ID = 159017)
12:19 PM: xgfzowcwjv.tdi (ID = 159027)
12:19 PM: smbolfqt.hpz (ID = 158991)
12:19 PM: gbffegcqtr.tar (ID = 159005)
12:19 PM: ezxaseao.yrs (ID = 159030)
12:19 PM: wnbbswx.ebx (ID = 159003)
12:19 PM: tmndwoi.bnm (ID = 158995)
12:19 PM: iisitwzvhga.xip (ID = 159037)
12:19 PM: igxdxai.tqd (ID = 159016)
12:19 PM: calotmc.ynq (ID = 158988)
12:19 PM: rpnlctzba.wgb (ID = 159047)
12:19 PM: jrkeyhls.srx (ID = 159045)
12:19 PM: xgrllzhr.syr (ID = 159060)
12:19 PM: thiwhqggs.zpe (ID = 158986)
12:19 PM: yechyfx.auk (ID = 159024)
12:19 PM: evqryjrapc.scg (ID = 159019)
12:19 PM: ukefjdo.ahh (ID = 159056)
12:19 PM: donazcgat.nac (ID = 159061)
12:19 PM: sojndfrv.cdm (ID = 159012)
12:19 PM: Found Trojan Horse: trojan downloader matcash
12:19 PM: autoit3.exe (ID = 119348)
12:19 PM: mc-58-12-0000106.exe (ID = 156275)
12:19 PM: ukemnhkafg.bia (ID = 159003)
12:19 PM: ms059148320241.exe (ID = 180425)
12:19 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:19 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:19 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:19 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:19 PM: klyyhllrz.ctx (ID = 159001)
12:19 PM: lcfbghpx.uak (ID = 158998)
12:19 PM: lhjobsotby.rjo (ID = 159004)
12:19 PM: lqipvukki.wrq (ID = 159020)
12:19 PM: mddiawkhmoe.tav (ID = 159028)
12:19 PM: mfjiyceo.uzu (ID = 159059)
12:19 PM: moreemc.cfv (ID = 159025)
12:19 PM: mpdfyzlsqns.qup (ID = 158987)
12:19 PM: mzlxddusdrg.edg (ID = 159025)
12:19 PM: nebhhviw.jxw (ID = 159053)
12:19 PM: nrbsyoveuae.utt (ID = 159026)
12:19 PM: nxumwmm.sfg (ID = 159029)
12:19 PM: oalonugrfa.vpp (ID = 158998)
12:19 PM: ocwfoayjzvt.wgv (ID = 159046)
12:19 PM: oiollunu.xvi (ID = 159053)
12:19 PM: okpkveafl.tup (ID = 159051)
12:19 PM: ooxespr.qop (ID = 158987)
12:19 PM: orfmagxcf.yje (ID = 159045)
12:19 PM: pagplsz.hjq (ID = 159014)
12:19 PM: pfjneql.elr (ID = 159037)
12:19 PM: pzzmkfpxw.pey (ID = 159004)
12:19 PM: winnb57.dll (ID = 159067)
12:19 PM: Found Trojan Horse: lzio
12:19 PM: adwaylbk.dll (ID = 155404)
12:19 PM: pesapop.dbe (ID = 164416)
12:19 PM: fghmoddw.nxv (ID = 158998)
12:19 PM: bntnwtiux.tqp (ID = 159040)
12:19 PM: csevdjnhue.phv (ID = 159017)
12:19 PM: oovwrujhqr.btz (ID = 159027)
12:19 PM: qcefmpptze.fgx (ID = 159035)
12:19 PM: qiylnqhes.jtw (ID = 158990)
12:19 PM: qpbguxwf.kzz (ID = 158997)
12:19 PM: qtkkmboixcg.hcr (ID = 159058)
12:19 PM: qwrlimscis.cxt (ID = 159040)
12:19 PM: Found Adware: instant access
12:19 PM: msclock32.dll (ID = 158351)
12:20 PM: Found Adware: adlogix
12:20 PM: ekfpxb.xml (ID = 49280)
12:20 PM: File Sweep Complete, Elapsed Time: 00:11:09
12:20 PM: Full Sweep has completed. Elapsed time 00:14:33
12:20 PM: Traces Found: 622
12:20 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:20 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:20 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:20 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:22 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:22 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:22 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:22 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:23 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:23 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:23 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:23 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:24 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:24 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:24 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:24 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:25 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:25 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:25 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:25 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:26 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:26 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:26 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:26 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:28 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:28 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:28 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:28 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:29 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:29 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:29 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:29 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:30 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:30 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:30 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:30 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:31 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:31 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:31 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:31 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:33 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:33 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:33 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:33 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:33 PM: Removal process initiated
12:34 PM: Quarantining All Traces: abetterinternet
12:34 PM: Quarantining All Traces: clkoptimizer
12:34 PM: Quarantining All Traces: lzio
12:34 PM: Quarantining All Traces: trojan downloader matcash
12:34 PM: Quarantining All Traces: adlogix
12:34 PM: Quarantining All Traces: apropos
12:34 PM: Quarantining All Traces: bookedspace
12:34 PM: Quarantining All Traces: drsnsrch hijacker
12:34 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:34 PM: The Spy Communication shield has blocked access to: www.icannnews.com
12:34 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:34 PM: The Spy Communication shield has blocked access to: www.licenseverify.com
12:34 PM: Quarantining All Traces: drsnsrch.com hijack
12:34 PM: Quarantining All Traces: enbrowser
12:34 PM: Quarantining All Traces: icannnews
12:34 PM: icannnews is in use. It will be removed on reboot.
12:34 PM: arwav.dll is in use. It will be removed on reboot.
12:34 PM: nktrap.dll is in use. It will be removed on reboot.
12:34 PM: C:\WINDOWS\SYSTEM32\NKTRAP.DLL is in use. It will be removed on reboot.
12:34 PM: C:\WINDOWS\SYSTEM32\ARWAV.DLL is in use. It will be removed on reboot.
12:34 PM: Quarantining All Traces: instant access
12:34 PM: Quarantining All Traces: maxifiles
12:34 PM: Quarantining All Traces: media-motor
12:34 PM: Quarantining All Traces: mirar webband
12:34 PM: Quarantining All Traces: one2one viewer
12:34 PM: Quarantining All Traces: purityscan
12:34 PM: Quarantining All Traces: search fast communicator toolbar
12:34 PM: Quarantining All Traces: shopathomeselect
12:34 PM: Quarantining All Traces: surfsidekick
12:34 PM: Quarantining All Traces: targetsaver
12:34 PM: Quarantining All Traces: winad
12:34 PM: Quarantining All Traces: 2o7.net cookie
12:34 PM: Quarantining All Traces: adserver cookie
12:34 PM: Quarantining All Traces: ask cookie
12:34 PM: Quarantining All Traces: belnk cookie
12:34 PM: Quarantining All Traces: exitexchange cookie
12:34 PM: Quarantining All Traces: hbmediapro cookie
12:34 PM: Quarantining All Traces: hotbar cookie
12:34 PM: Quarantining All Traces: kmpads cookie
12:34 PM: Quarantining All Traces: mygeek cookie
12:34 PM: Quarantining All Traces: paypopup cookie
12:34 PM: Quarantining All Traces: questionmarket cookie
12:34 PM: Quarantining All Traces: reliablestats cookie
12:34 PM: Quarantining All Traces: rn11 cookie
12:34 PM: Quarantining All Traces: servedby advertising cookie
12:34 PM: Quarantining All Traces: top-banners cookie
12:34 PM: Quarantining All Traces: yieldmanager cookie
12:34 PM: Warning: Launched explorer.exe
12:34 PM: Warning: Quarantine process could not restart Explorer.
12:35 PM: Removal process completed. Elapsed time 00:01:10
********
12:03 PM: | Start of Session, Thursday, October 27, 2005 |
12:03 PM: Spy Sweeper started
12:04 PM: Your spyware definitions have been updated.
12:05 PM: | End of Session, Thursday, October 27, 2005 |
Logfile of HijackThis v1.99.1
Scan saved at 1:18:37 PM, on 10/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\AIM95\aim.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Common Files\AOL\1127935427\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1127935427\ee\AOLServiceHost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1127935427\ee\AOLServiceHost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\DESKTOP\VIRUS TOOLS\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\HiJack This\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.webcoins.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127935427\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
https://objects.aol.com/mcafee/molbin/share…83/mcinsctl.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
https://objects.aol.com/mcafee/molbin/share…,20/McGDMgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\aolserv.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\DESKTOP\VIRUS TOOLS\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe