Ok ... I've done everything there and here are the logs.
********
11:43 AM: | Start of Session, Tuesday, November 22, 2005 |
11:43 AM: Spy Sweeper started
11:43 AM: Sweep initiated using definitions version 574
11:43 AM: Starting Memory Sweep
11:43 AM: Found Adware: icannnews
11:43 AM: Detected running threat: F:\WINDOWS\system32\mhiole32.dll (ID = 83)
11:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:44 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:44 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:44 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:44 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:44 AM: Detected running threat: F:\WINDOWS\system32\lvr4099qe.dll (ID = 83)
11:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:45 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:46 AM: Memory Sweep Complete, Elapsed Time: 00:02:53
11:46 AM: Starting Registry Sweep
11:46 AM: Found Trojan Horse: spamrelayer_alpiok
11:46 AM: HKCR\clsid\{7368d5fc-6f5c-4f5b-b964-e67214f67852}\ (3 subtraces) (ID = 913291)
11:46 AM: HKLM\software\classes\clsid\{7368d5fc-6f5c-4f5b-b964-e67214f67852}\ (3 subtraces) (ID = 913513)
11:46 AM: Found Adware: dollarrevenue
11:46 AM: HKLM\software\microsoft\drsmartload\ (1 subtraces) (ID = 916795)
11:46 AM: Found Adware: websearch.com hijacker
11:46 AM: HKU\S-1-5-21-1229272821-515967899-682003330-1004\software\microsoft\internet explorer\main\ || search bar (ID = 146561)
11:46 AM: Found Adware: wildmedia
11:46 AM: HKU\S-1-5-21-1229272821-515967899-682003330-1004\software\microsoft\internet explorer\main\ || updater2 (ID = 146720)
11:46 AM: HKU\S-1-5-21-1229272821-515967899-682003330-1004\software\microsoft\internet explorer\main\ || updater (ID = 146721)
11:46 AM: Registry Sweep Complete, Elapsed Time:00:00:12
11:46 AM: Starting Cookie Sweep
11:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:46 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:46 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:46 AM: Found Spy Cookie: about cookie
11:46 AM: patrick@about[2].txt (ID = 2037)
11:46 AM: Found Spy Cookie: yieldmanager cookie
11:46 AM: patrick@ad.yieldmanager[1].txt (ID = 3751)
11:46 AM: Found Spy Cookie: adultfriendfinder cookie
11:46 AM: patrick@adultfriendfinder[1].txt (ID = 2165)
11:46 AM: Found Spy Cookie: ask cookie
11:46 AM: patrick@ask[1].txt (ID = 2245)
11:46 AM: Found Spy Cookie: dl cookie
11:46 AM: patrick@dl[1].txt (ID = 2529)
11:46 AM: Found Spy Cookie: kinghost cookie
11:46 AM: patrick@kinghost[1].txt (ID = 2903)
11:46 AM: Found Spy Cookie: nextag cookie
11:46 AM: patrick@nextag[1].txt (ID = 5014)
11:46 AM: patrick@nintendo.about[1].txt (ID = 2038)
11:46 AM: Found Spy Cookie: promaxtraffic cookie
11:46 AM: patrick@tds.promaxtraffic[1].txt (ID = 3200)
11:46 AM: patrick@yieldmanager[1].txt (ID = 3749)
11:46 AM: Cookie Sweep Complete, Elapsed Time: 00:00:03
11:46 AM: Starting File Sweep
11:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:47 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:48 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:49 AM: Found Adware: look2me
11:49 AM: gplsl3371.dll (ID = 159)
11:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:49 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:50 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:52 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:53 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:53 AM: lacmgr10.dll (ID = 159)
11:53 AM: n8l80i3ue8.dll (ID = 159)
11:53 AM: Found Adware: apropos
11:53 AM: contextplus[1].exe (ID = 185940)
11:53 AM: dlvclnt.dll (ID = 159)
11:54 AM: lvrm0991e.dll (ID = 159)
11:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:54 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:55 AM: Found Adware: targetsaver
11:55 AM: stub_113_4_0_4_0[1].exe (ID = 193995)
11:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:55 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:56 AM: lvr4099qe.dll (ID = 159)
11:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:56 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:56 AM: Found Adware: purityscan
11:56 AM: w?wexec.exe (ID = 72918)
11:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:57 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:57 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:57 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:58 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:58 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:58 AM: o084lalq1dqe.dll (ID = 159)
11:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:59 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:00 PM: Warning: Failed to open file "f:\documents and settings\all users\application data\mcafee\spamkiller\logs\filtering.log". The process cannot access the file because it is being used by another process
12:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:00 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:01 PM: Warning: Failed to read file "f:\documents and settings\patrick\my documents\journal.rtf". Data error (cyclic redundancy check)
12:01 PM: l4l60e3seh.dll (ID = 159)
12:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:01 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:01 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:02 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:02 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:02 PM: timessquare[1].exe (ID = 194150)
12:02 PM: lrdis12n.dll (ID = 159)
12:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:03 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:04 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:05 PM: Warning: Failed to open file "f:\documents and settings\patrick\local settings\temp\temporary internet files\content.ie5\6j6vet2n\1_0%26idx%3d0%26yy%3d95029%26inc%3d25%26order%3ddown%26sort%3ddate%26pos%3d0%26view%3da%26head%3db%26box%3dinbox&u_h=768&u_w=1024&u_ah=768&u_aw=1024&u_cd=32&u_tz=-360&u_java=true". The system cannot find the path specified
12:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:05 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:06 PM: i024lafq1d2e.dll (ID = 159)
12:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:06 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:07 PM: Found Adware: command
12:07 PM: mte3ndi6odoxng[1].exe (ID = 185985)
12:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:08 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:08 PM: lxavi80n.dll (ID = 159)
12:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:09 PM: mhiole32.dll (ID = 159)
12:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:09 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:10 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:10 PM: Found Trojan Horse: trojan-backdoor-us15info
12:10 PM: tool5[1].txt (ID = 183857)
12:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:11 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:12 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:12 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:13 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:14 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:14 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:14 PM: Warning: Failed to open file "f:\videos\blah\". The system cannot find the path specified
12:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:15 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:16 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:16 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:17 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:18 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:19 PM: Found Adware: spysheriff
12:19 PM: secure32.html (ID = 184319)
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:19 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:20 PM: Warning: Failed to open file "f:\windows\softwaredistribution\eventcache\{66297667-d81b-473d-b7be-95dbc8c807a6}.bin". The process cannot access the file because it is being used by another process
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:21 PM: n (ID = 88414)
12:21 PM: nwq (ID = 88019)
12:21 PM: File Sweep Complete, Elapsed Time: 00:35:18
12:21 PM: Full Sweep has completed. Elapsed time 00:38:35
12:21 PM: Traces Found: 46
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:22 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:23 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:23 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:24 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:25 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:26 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:26 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:27 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:28 PM: Removal process initiated
12:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:28 PM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
12:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:28 PM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
12:28 PM: Quarantining All Traces: icannnews
12:28 PM: icannnews is in use. It will be removed on reboot.
12:28 PM: F:\WINDOWS\system32\mhiole32.dll is in use. It will be removed on reboot.
12:28 PM: F:\WINDOWS\system32\lvr4099qe.dll is in use. It will be removed on reboot.
12:28 PM: Quarantining All Traces: look2me
12:28 PM: look2me is in use. It will be removed on reboot.
12:28 PM: lvr4099qe.dll is in use. It will be removed on reboot.
12:28 PM: i024lafq1d2e.dll is in use. It will be removed on reboot.
12:28 PM: mhiole32.dll is in use. It will be removed on reboot.
12:28 PM: Quarantining All Traces: purityscan
12:28 PM: Quarantining All Traces: spamrelayer_alpiok
12:28 PM: Quarantining All Traces: spysheriff
12:28 PM: Quarantining All Traces: trojan-backdoor-us15info
12:28 PM: Quarantining All Traces: wildmedia
12:28 PM: Quarantining All Traces: apropos
12:28 PM: Quarantining All Traces: command
12:28 PM: Quarantining All Traces: dollarrevenue
12:28 PM: Quarantining All Traces: targetsaver
12:28 PM: Quarantining All Traces: websearch.com hijacker
12:28 PM: Quarantining All Traces: about cookie
12:28 PM: Quarantining All Traces: adultfriendfinder cookie
12:28 PM: Quarantining All Traces: ask cookie
12:28 PM: Quarantining All Traces: dl cookie
12:28 PM: Quarantining All Traces: kinghost cookie
12:28 PM: Quarantining All Traces: nextag cookie
12:28 PM: Quarantining All Traces: promaxtraffic cookie
12:28 PM: Quarantining All Traces: yieldmanager cookie
12:28 PM: Warning: Could not read current IE Hijack Setting value: HKCU\S-1-5-21-1229272821-515967899-682003330-1004\Software\Microsoft\Internet Explorer\Main\Search Bar\
12:28 PM: Warning: Could not store new IE Hijack Setting value: HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar\
http://ie.search.msn...st/srchasst.htm
12:29 PM: Preparing to restart your computer. Please wait...
12:29 PM: Removal process completed. Elapsed time 00:01:26
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:32 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:39 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:39 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:39 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:39 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:40 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
12:41 PM: The Spy Communication shield has blocked access to: fullbizzone.com
********
11:40 AM: | Start of Session, Tuesday, November 22, 2005 |
11:40 AM: Spy Sweeper started
11:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:41 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:41 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:41 AM: Your spyware definitions have been updated.
11:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:42 AM: Updating spyware definitions
11:42 AM: Your definitions are up to date.
11:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:42 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:42 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:43 AM: Processing Hosts File Alerts
11:43 AM: Fixed Hosts File entry: www.kazaagold.com
11:43 AM: Fixed Hosts File entry: kazaagold.com
11:43 AM: Fixed Hosts File entry: www.k-lite.com
11:43 AM: Fixed Hosts File entry: www.kazaa-download.de
11:43 AM: Fixed Hosts File entry: www.mp3downloadhq.com
11:43 AM: Fixed Hosts File entry: www.easymusicdownload.com
11:43 AM: Fixed Hosts File entry: easymusicdownload.com
11:43 AM: Fixed Hosts File entry: www.mp3madeeasy.com
11:43 AM: Fixed Hosts File entry: www.monstershare.com
11:43 AM: Fixed Hosts File entry: www.kazaa-plus.net
11:43 AM: Fixed Hosts File entry: kazaa-plus.net
11:43 AM: Fixed Hosts File entry: www.kazaa-plus.com
11:43 AM: Fixed Hosts File entry: www.edonkey.com
11:43 AM: Fixed Hosts File entry: www.kazaa-file-sharing-downloads.com
11:43 AM: Fixed Hosts File entry: www.kazaaplatinum.com
11:43 AM: Fixed Hosts File entry: www.madeformusic.com
11:43 AM: Fixed Hosts File entry: ikazaa.net
11:43 AM: Fixed Hosts File entry: www.mp3specialty.com
11:43 AM: Fixed Hosts File entry: music-download-world.com
11:43 AM: Fixed Hosts File entry: song-download-world.com
11:43 AM: Fixed Hosts File entry: www.flixs.net
11:43 AM: Fixed Hosts File entry: www.ishareit.net
11:43 AM: Fixed Hosts File entry: www.ishareit.com
11:43 AM: Fixed Hosts File entry: www.download-doctor.com
11:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.ad-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:43 AM: The Spy Communication shield has blocked access to: www.a-d-w-a-r-e.com
11:43 AM: | End of Session, Tuesday, November 22, 2005 |
And the HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 12:54:30 PM, on 11/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft IntelliType Pro\type32.exe
F:\Program Files\Microsoft IntelliPoint\point32.exe
F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\Messenger\msmsgs.exe
F:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
F:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
F:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
F:\WINDOWS\System32\Ati2evxx.exe
F:\WINDOWS\System32\cisvc.exe
f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
F:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
F:\WINDOWS\system32\hpoipm07.exe
f:\progra~1\mcafee.com\vso\mcvsftsn.exe
F:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
F:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
F:\Program Files\Spyware Doctor\sdhelp.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\cidaemon.exe
F:\WINDOWS\explorer.exe
F:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.websearch...spx?tb_id=50141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - f:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NeroCheck] F:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "F:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "F:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [VirusScan Online] f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATIPTA] F:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] F:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - Startup: Stardock ObjectDock.lnk = F:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Trillian.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://f:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://f:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://f:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://f:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://f:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://f:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - F:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O12 - Plugin for .spop: F:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
http://download.mcaf...90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by18fd.bay18....es/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitd...can8/oscan8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cab
O20 - Winlogon Notify: WRNotifier - F:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - F:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - F:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - F:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe