This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

KEEP GETTING POPUP Advertisements that actually intertervenes with any

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

KEEP GETTING POPUP Advertisements that actually intertervenes with any browser window i am in. This happened because of some program i installed that posed as a hoax or a diversion for spyware installation into my computer. Here is my hijack log after i scanned with Adaware, Spybot and microsoft Antispyware and it deleted all that it could find.

__________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 9:18:29 PM, on 10/31/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\spm\spmd.exe
C:\Program Files\Plextor2000\AFSSVC.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\svchost.exe
C:\Justin's CPU\programs\security suite\ewidoctrl.exe
C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\nvsvc32.exe
C:\Justin's CPU\applications\Maya6.5\docs\jre\bin\java.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\Tablet.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Justin's CPU\programs\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\justin's cpu\programs\Quicktime 6\qttask.exe
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Justin's CPU\applications\Microsoft Antispyware\gcasDtServ.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINNT\system32\WTablet\TabUserW.exe
C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Justin's CPU\applications\Microsoft Antispyware\gcasServ.exe
C:\WINNT\explorer.exe
C:\Justin's CPU\programs\Winamp\winamp.exe
C:\Justin's CPU\applications\Internet protection\HijackThis.exe

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] C:\Justin's CPU\programs\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\justin's cpu\programs\Quicktime 6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PLXSTART] C:\PROGRA~1\PLEXTO~1\PLXSTART.EXE
O4 - HKLM\..\Run: [PLXTASK] C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] C:\Prograam Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Justin's CPU\applications\Microsoft Antispyware\gcasServ.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\WTablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download with &DAP - C:\JUSTIN~1\programs\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {18CD2FD8-81CE-44C3-99E1-0822E1C7116C} (EARTPatch8X Class) - http://files.ea.com/downloads/rtpatch/v4/EARTP8X.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123325882312
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: StillImage - C:\WINNT\system32\hr2805fue.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: afssvc - Plextor Corp. - C:\Program Files\Plextor2000\AFSSVC.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Justin's CPU\programs\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe" -s "C:\Justin's CPU\applications\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: RaySatxsi4_0 Server (RaySatxsi4_0Server) - Unknown owner - C:\Softimage\XSI_4.0\Application\bin\raysatxsi4_0server.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH & Co. KG - C:\WINNT\system32\spm\spmd.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINNT\system32\Tablet.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

_______________________________________

thanks.
By the way. does Hijack this! save a backup off all things that were checked and fixed? If not, what's a safe way to back up incase Hijack this screws something up?
Hello Jinian, welcome to the TC.

By the way. does Hijack this! save a backup off all things that were checked and fixed?

Yes it does. Look in your HJT folder and there should be a folder called Backup.

Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Thanks a lot for your help. I've lost the annoying popups now. Just like to know if Spy Sweeper makes a backup after it removes the files, and where is it located? Also, just like to confirm that after the reboot Spy sweeper prompted after the scan, Spy sweeper removed a file while Windows 2000 was still loading and hadn't start up yet. Just like to know if this was normal?

Here are my logs:

Logfile of HijackThis v1.99.1
Scan saved at 12:35:47 AM, on 11/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\spm\spmd.exe
C:\Program Files\Plextor2000\AFSSVC.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\svchost.exe
C:\Justin's CPU\programs\security suite\ewidoctrl.exe
C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Justin's CPU\applications\Maya6.5\docs\jre\bin\java.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\Tablet.exe
C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\Justin's CPU\programs\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\justin's cpu\programs\Quicktime 6\qttask.exe
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Justin's CPU\applications\Microsoft Antispyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINNT\system32\WTablet\TabUserW.exe
C:\WINNT\system32\svchost.exe
C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Justin's CPU\applications\Internet protection\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Justin's CPU\programs\Winamp\winamp.exe

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] C:\Justin's CPU\programs\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\justin's cpu\programs\Quicktime 6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PLXSTART] C:\PROGRA~1\PLEXTO~1\PLXSTART.EXE
O4 - HKLM\..\Run: [PLXTASK] C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Justin's CPU\applications\Microsoft Antispyware\gcasServ.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\WTablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download with &DAP - C:\JUSTIN~1\programs\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {18CD2FD8-81CE-44C3-99E1-0822E1C7116C} (EARTPatch8X Class) - http://files.ea.com/downloads/rtpatch/v4/EARTP8X.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123325882312
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: afssvc - Plextor Corp. - C:\Program Files\Plextor2000\AFSSVC.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Justin's CPU\programs\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe" -s "C:\Justin's CPU\applications\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: RaySatxsi4_0 Server (RaySatxsi4_0Server) - Unknown owner - C:\Softimage\XSI_4.0\Application\bin\raysatxsi4_0server.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH & Co. KG - C:\WINNT\system32\spm\spmd.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINNT\system32\Tablet.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

____________________________________________________________________________

SPY SWEEPER LOG




********
11:35 PM: | Start of Session, Sunday, November 06, 2005 |
11:35 PM: Spy Sweeper started
11:35 PM: Sweep initiated using definitions version 567
11:35 PM: Starting Memory Sweep
11:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:35 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:35 PM: Found Adware: icannnews
11:35 PM: Detected running threat: C:\WINNT\system32\l44qleh51h4.dll (ID = 83)
11:35 PM: Detected running threat: C:\WINNT\system32\aumeter.dll (ID = 83)
11:36 PM: Detected running threat: C:\WINNT\system32\guard.tmp (ID = 83)
11:36 PM: Memory Sweep Complete, Elapsed Time: 00:01:15
11:36 PM: Starting Registry Sweep
11:36 PM: Found Adware: hotbar
11:36 PM: HKCR\interface\{9dd19d39-2cdc-465b-bb21-1d433590ba3d}\ (8 subtraces) (ID = 127331)
11:36 PM: HKCR\interface\{8578d35e-c6c0-4808-9a80-0f6c29a2c423}\ (8 subtraces) (ID = 127339)
11:36 PM: HKCR\interface\{bc190da5-0187-4d99-b3ac-6c45ea1b9324}\ (8 subtraces) (ID = 127353)
11:36 PM: HKLM\software\classes\interface\{9dd19d39-2cdc-465b-bb21-1d433590ba3d}\ (8 subtraces) (ID = 127496)
11:36 PM: HKLM\software\classes\interface\{8578d35e-c6c0-4808-9a80-0f6c29a2c423}\ (8 subtraces) (ID = 127503)
11:36 PM: HKLM\software\classes\interface\{bc190da5-0187-4d99-b3ac-6c45ea1b9324}\ (8 subtraces) (ID = 127514)
11:36 PM: Found Adware: navexcel navhelper
11:36 PM: HKCR\interface\{20f36af3-3486-4bb6-8bcb-f1f8abe74d07}\ (8 subtraces) (ID = 135518)
11:36 PM: HKLM\software\classes\interface\{20f36af3-3486-4bb6-8bcb-f1f8abe74d07}\ (8 subtraces) (ID = 135531)
11:36 PM: Found Adware: adware delete
11:36 PM: HKCR\clsid\{d4519056-e895-f0fe-d9b5-b83903b8df79}\ (5 subtraces) (ID = 359282)
11:36 PM: HKLM\software\classes\clsid\{d4519056-e895-f0fe-d9b5-b83903b8df79}\ (5 subtraces) (ID = 359283)
11:36 PM: Found Trojan Horse: trojan-downloader-zlob
11:36 PM: HKCR\nvideocodek.chl\ (2 subtraces) (ID = 820294)
11:36 PM: HKLM\software\classes\nvideocodek.chl\ (2 subtraces) (ID = 820324)
11:36 PM: HKU\S-1-5-21-515967899-362288127-839522115-1000\software\microsoft\internet explorer\extensions\cmdmapping\ || {e77eda01-3c56-4a96-8d08-02b42891c169} (ID = 127576)
11:36 PM: HKU\S-1-5-21-515967899-362288127-839522115-1000\software\microsoft\internet explorer\toolbar\shellbrowser\ || {b195b3b3-8a05-11d3-97a4-0004aca6948e} (ID = 127585)
11:36 PM: HKU\S-1-5-21-515967899-362288127-839522115-1000\software\microsoft\internet explorer\toolbar\webbrowser\ || {b195b3b3-8a05-11d3-97a4-0004aca6948e} (ID = 127587)
11:36 PM: Registry Sweep Complete, Elapsed Time:00:00:05
11:36 PM: Starting Cookie Sweep
11:36 PM: Found Spy Cookie: yieldmanager cookie
11:36 PM: justin yu [removed][2].txt (ID = 3751)
11:36 PM: Found Spy Cookie: azjmp cookie
11:36 PM: justin yu villa@azjmp[2].txt (ID = 2270)
11:36 PM: Found Spy Cookie: belnk cookie
11:36 PM: justin yu villa@belnk[1].txt (ID = 2292)
11:36 PM: justin yu [removed][2].txt (ID = 2293)
11:36 PM: Found Spy Cookie: starware.com cookie
11:36 PM: justin yu [removed][2].txt (ID = 3442)
11:36 PM: justin yu [removed][1].txt (ID = 3442)
11:36 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
11:36 PM: Starting File Sweep
11:36 PM: Found Adware: ignkeys
11:36 PM: 8709f4ad-cdb1-4fe2-8a30-373282 (ID = 63484)
11:42 PM: Found Adware: look2me
11:42 PM: installer[1].exe (ID = 168558)
11:43 PM: Found Adware: exact cashback/bargain buddy
11:43 PM: 3d7181db-01a9-45b0-9f48-7088d6 (ID = 50531)
11:43 PM: 68b256d7-295a-40a4-abb2-5fcd13 (ID = 78317)
11:44 PM: Found Adware: effective-i toolbar
11:44 PM: e9d48e22-041c-445d-a2a5-21fb3e (ID = 59853)
11:44 PM: Found Adware: sp2ms
11:44 PM: drsmartload[1].exe (ID = 178567)
11:44 PM: Found Adware: crackspider
11:44 PM: ! crackspider.net - cracks search engine.url (ID = 54755)
11:44 PM: File Sweep Complete, Elapsed Time: 00:08:04
11:44 PM: Full Sweep has completed. Elapsed time 00:09:27
11:44 PM: Traces Found: 109
12:05 AM: Removal process initiated
12:06 AM: Quarantining All Traces: icannnews
12:06 AM: icannnews is in use. It will be removed on reboot.
12:06 AM: C:\WINNT\system32\l44qleh51h4.dll is in use. It will be removed on reboot.
12:06 AM: C:\WINNT\system32\aumeter.dll is in use. It will be removed on reboot.
12:06 AM: C:\WINNT\system32\guard.tmp is in use. It will be removed on reboot.
12:06 AM: Quarantining All Traces: look2me
12:06 AM: Quarantining All Traces: trojan-downloader-zlob
12:06 AM: Quarantining All Traces: hotbar
12:06 AM: Quarantining All Traces: sp2ms
12:06 AM: Quarantining All Traces: adware delete
12:06 AM: Quarantining All Traces: crackspider
12:06 AM: Quarantining All Traces: effective-i toolbar
12:06 AM: Quarantining All Traces: exact cashback/bargain buddy
12:06 AM: Quarantining All Traces: ignkeys
12:06 AM: Quarantining All Traces: navexcel navhelper
12:06 AM: Quarantining All Traces: azjmp cookie
12:06 AM: Quarantining All Traces: belnk cookie
12:06 AM: Quarantining All Traces: starware.com cookie
12:06 AM: Quarantining All Traces: yieldmanager cookie
12:07 AM: Preparing to restart your computer. Please wait…
12:07 AM: Removal process completed. Elapsed time 00:01:55
********
11:23 PM: | Start of Session, Sunday, November 06, 2005 |
11:23 PM: Spy Sweeper started
11:23 PM: Sweep initiated using definitions version 567
11:23 PM: Starting Memory Sweep
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: Sweep Canceled
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:23 PM: Memory Sweep Complete, Elapsed Time: 00:00:16
11:23 PM: Traces Found: 0
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:29 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:30 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:31 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:32 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:33 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:34 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:35 PM: | End of Session, Sunday, November 06, 2005 |
********
11:18 PM: | Start of Session, Sunday, November 06, 2005 |
11:18 PM: Spy Sweeper started
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:22 PM: Your spyware definitions have been updated.
11:23 PM: | End of Session, Sunday, November 06, 2005 |

Just like to know if Spy Sweeper makes a backup after it removes the files, and where is it located?

That I don't know.

Also, just like to confirm that after the reboot Spy sweeper prompted after the scan, Spy sweeper removed a file while Windows 2000 was still loading and hadn't start up yet. Just like to know if this was normal

Yes, that is normal.


Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL



I recommend you download RegSeeker. Extract it to it's own folder, open and double click RegSeeker.exe to start the program. Maximize the window and click clean registry. Check all sections and click OK. When the scan is complete, verify the backup box in lower left corner is checked and click the select all button, then select all again. Then right click within the search results and select delete. Run it again and again, deleting everything it finds until it finds nothing. Reboot and make sure your programs are working properly, control panel and add/remove programs windows open, etc (basically just do a quick check of everything). In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done.
You said: "In the event anything was 'broken', you can open RegSeeker, click backups and double click any/all files to put the information back. A reboot may be required for the effects to be seen. Reboot When done. " I opened up the backups folder and all i saw was one registry backup file. I didn't see a list of keys that i could check and it would just revert those keys. After running RegSeeker and having it remove all the keys it found, i ran into a couple of problems but don't know whiich keys that were deleted that caused them. Anyways, i'd really prefer to revert to my old registry before RegSeeker tampered with it. Will this be fine, or do i really need to run RegSeeker to have my computer back into the shape it was before the spyware infected it ? I really do prefer not to run this Regseeker after seing the quirkiness of the behavior of my computer after i had run it. I have backed up what you have told me to. However, when i try to import the backup registry file using regedit, it imports it, but after its done it prompts me that not all have been imported successfully. I did however saved my own backup of the registry and that is through the Accessories/ System tools/ Backup Wizard– clicked backup only system data(for Win2k). Is it alright if i use this type of backup instead? If you are familiar with this type of backup, how does it differ from using regedit and exporting all the registry keys there?

do i really need to run RegSeeker to have my computer back into the shape it was before the spyware infected it ?

It just removes old entries as far as I know.

Is it alright if i use this type of backup instead?

I'm sure tahat's OK.

How's it running?

Post a new HJT log.
Because of these complications, i really did wish you never told me about using Regseeker. I also would like to say that the registry that you instructed me to back up, i could never import back into the registry using regedit, because at the very end of the restoration, it would say "unable to copy successfully, some keys are missing". However, i did back up my registry another way, and that is what symantec would suggest and that is using the system's very own "Backup wizard" which does it all for you. This was a successful restoration. It may have fixed some of the problems Regseeker did to my computer, but it brought new ones of its own. One is my computer every now and then, just reboots itself out of nowhere(like when i'm surfing the net, listening to music). Luckily, once it reboots once, it never really does this again as long as i don't shut down my computer and turn it back on again. I also noticed it only does this behavior after a few minutes of using my computer right after i had just turn it on for the day.

Another is(although a minor one), while i am browsing through pictures in my computer using a picture viewing program(like Slowview), every now and then some of the pictures appear chopped and have static lines running across some of them. But after i quit the picture viewing program and restart it again, the lines are gone. However, this is only short-lived, since if i keep on viewing the pictures, a minute later or two, the static lines come back again on some of the pictures. Although you may say, it is just my program, but this never happened to me before, not until after restoring the registry backup to replace the one regseeker tampered with.

Anyways, here is my current hijack log, i hope you could help.


______________________________________________________________________

Logfile of HijackThis v1.99.1
Scan saved at 9:08:31 PM, on 11/14/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\spm\spmd.exe
C:\Program Files\Plextor2000\AFSSVC.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\svchost.exe
C:\Justin's CPU\programs\security suite\ewidoctrl.exe
C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Justin's CPU\applications\Maya6.5\docs\jre\bin\java.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\Tablet.exe
C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\Justin's CPU\programs\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\justin's cpu\programs\Quicktime 6\qttask.exe
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
C:\Justin's CPU\applications\Microsoft Antispyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\WINNT\system32\WTablet\TabUserW.exe
C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\svchost.exe
C:\Justin's CPU\programs\Winamp\winamp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Justin's CPU\programs\Kazaa Lite K++\KazaaLite.kpp
C:\Program Files\KaZaA Download Accelerator\kda.exe
C:\Justin's CPU\applications\Internet protection\HijackThis.exe

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] C:\Justin's CPU\programs\Winamp\winampa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\justin's cpu\programs\Quicktime 6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PLXSTART] C:\PROGRA~1\PLEXTO~1\PLXSTART.EXE
O4 - HKLM\..\Run: [PLXTASK] C:\PROGRA~1\PLEXTO~1\PLXTASK.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Justin's CPU\applications\Microsoft Antispyware\gcasServ.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Anti-Blaxx Manager] C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINNT\system32\WTablet\TabUserW.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Justin's CPU\programs\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download with &DAP - C:\JUSTIN~1\programs\DAP\dapextie.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {18CD2FD8-81CE-44C3-99E1-0822E1C7116C} (EARTPatch8X Class) - http://files.ea.com/downloads/rtpatch/v4/EARTP8X.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1123325882312
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: afssvc - Plextor Corp. - C:\Program Files\Plextor2000\AFSSVC.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Justin's CPU\programs\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Justin's CPU\applications\Maya6.5\docs\wrapper.exe" -s "C:\Justin's CPU\applications\Maya6.5\docs\Wrapper.conf (file missing)
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: RaySatxsi4_0 Server (RaySatxsi4_0Server) - Unknown owner - C:\Softimage\XSI_4.0\Application\bin\raysatxsi4_0server.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH & Co. KG - C:\WINNT\system32\spm\spmd.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINNT\system32\Tablet.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Because of these complications, i really did wish you never told me about using Regseeker. I also would like to say that the registry that you instructed me to back up, i could never import back into the registry using regedit, because at the very end of the restoration,

I've never had any problems with running Regseeker. As for the Backup, do you do this?

Backup your Registry…
- Press "CTRL - ALT - DEL" keys all at the same time to start "Task Manager"
- In the Task Manager window click on "File", then from the drop-down menu select "New Task (Run…)"
- In the "Create New Task" window enter\type "regedit" (without quotes)
- Once Regedit opens click on the FILE menu and select Export
- Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL


If you did this, all you have to do is Double Click the "backup" file and it will restore the registry as it was before running Regseeker.
I did that and it said "Do you want to add the information in C:/documents/……regbackup.bkf to the registry", and then i clicked yes and it tried to restore the files but to no avail. A window pops up and says it could copy some keys into the registry, backup failed. So i did it the other way, i opened up regedit, and imported the registry file, but in the end it said it could not copy it completely. But anyways, based on my hijack log now, is there anything you know i could do to fix the computer self-reboot problem. Also, forget about my problem with the static lines showing up in my picture viewer, i fixed that yesterday. Turns out, it was just a display resolution setting.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI