Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Winfixer Adware


  • This topic is locked This topic is locked
12 replies to this topic

#1 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 25 November 2005 - 03:49 AM

I am running Windows 98 SE - Please help me remove Winfixer... I was infected a few days ago.
Here is my HJT log...

Logfile of HijackThis v1.99.1
Scan saved at 1:53:15 AM, on 11/25/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CG16EH.EXE
C:\UTIL\OPENOFFICE.ORG1.1.4\PROGRAM\SOFFICE.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.library.ubc.ca:8000
F1 - win.ini: load=ptsnoop.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\SYSTEM\HGGEB.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunOnce: [*HGGEB] rundll32.exe C:\WINDOWS\SYSTEM\HGGEB.DLL,CreateProtectProc rerun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O4 - User Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A5DF5E1-6EA9-494C-98A8-8A0534C5D03F} (TMSCTL.SSDLoad) - http://broadcast.mic...a/tmsct2000.CAB
O16 - DPF: {F7A42F5D-C82A-4680-B2C1-4E530BC72C23} (PostalCodePicker Control) - http://broadcast.mic...ata/tbpcctl.cab
O16 - DPF: {0FAB1B8C-5AEA-4A46-A4A8-06611412D675} (tsettask Class) - http://broadcast.mic...ta/TSetTask.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcaf...ed/MGBrwFld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {F0E42D60-368C-11D0-AD81-00A0C90DC8D9} (Snapshot Viewer Control 8.0) - http://activex.micro...ss/Snapview.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://gisweb7.city....ad/mgaxctrl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by99fd.bay99....ex/HMAtchmt.ocx
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} - http://www.easypix.ca/en/ulcontrol.cab
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = lynx.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.18.70.248,216.18.70.233

Thanks!

    Advertisements

Register to Remove


#2 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 25 November 2005 - 08:22 AM

Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
Click the Free Trial link under to "SpySweeper" to download the program.
Install it. Once the program is installed, it will open.
It will prompt you to update to the latest definitions, click Yes.
Once the definitions are installed, click Options on the left side.
Click the Sweep Options tab.
Under What to Sweep please put a check next to the following:
Sweep Memory
Sweep Registry
Sweep Cookies
Sweep All User Accounts
Enable Direct Disk Sweeping
Sweep Contents of Compressed Files
Sweep for Rootkits
Please UNCHECK Do not Sweep System Restore Folder.
Click Sweep Now on the left side.
Click the Start button.
When it's done scanning, click the Next button.
Make sure everything has a check next to it, then click the Next button.
It will remove all of the items found.
Click Session Log in the upper right corner, copy everything in that window.
Click the Summary tab and click Finish.
Paste the contents of the session log you copied into your next reply.

#3 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 25 November 2005 - 11:39 AM

*edit* Thought I fixed it but Winfixer just popped up again. I will use spysweeper and post a reply here. Thanks.

Edited by KaY-o-Ree, 25 November 2005 - 11:41 AM.


#4 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 26 November 2005 - 03:09 AM

Here is the Session Log from Spy Sweeper: ******** 11:36 PM: | Start of Session, Friday, November 25, 2005 | 11:36 PM: Spy Sweeper started 11:36 PM: Sweep initiated using definitions version 575 11:36 PM: Starting Memory Sweep 11:42 PM: Found Adware: virtumonde 11:42 PM: Detected running threat: C:\WINDOWS\SYSTEM\hggeb.dll (ID = 77) 11:43 PM: Memory Sweep Complete, Elapsed Time: 00:07:01 11:43 PM: Starting Registry Sweep 11:45 PM: Found Adware: morpheus adware 11:45 PM: HKCR\windowsie\ (ID = 135220) 11:45 PM: HKLM\software\classes\windowsie\ (ID = 135221) 11:46 PM: HKCR\msevents.msevents\ (5 subtraces) (ID = 749130) 11:46 PM: HKCR\msevents.msevents.1\ (3 subtraces) (ID = 749136) 11:46 PM: HKLM\software\classes\msevents.msevents\ (5 subtraces) (ID = 749153) 11:46 PM: HKLM\software\classes\msevents.msevents.1\ (3 subtraces) (ID = 749157) 11:46 PM: Registry Sweep Complete, Elapsed Time:00:03:25 11:46 PM: Starting Cookie Sweep 11:46 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00 11:46 PM: Starting File Sweep 11:47 PM: Found Adware: ezsearchbar 11:47 PM: addr_var.ini (ID = 60329) 11:47 PM: birth_var.ini (ID = 60332) 11:47 PM: city_var.ini (ID = 60333) 11:47 PM: name_var.ini (ID = 60352) 11:47 PM: states.ini (ID = 60360) 11:47 PM: name_gender.ini (ID = 60351) 11:47 PM: zip_var.ini (ID = 60362) 11:47 PM: phone_var.ini (ID = 60353) 11:47 PM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because it is being used by another process 11:48 PM: Found Adware: vcatch 11:48 PM: vcwebinstall.exe (ID = 82196) 11:49 PM: rulesdata3.xml (ID = 82178) 11:49 PM: rulesdata2.xml (ID = 82177) 11:49 PM: rulesdata1.xml (ID = 82176) 11:49 PM: rulesdata.xml (ID = 82175) 11:49 PM: rulesfactors.xml (ID = 82179) 11:49 PM: anticipator.dll (ID = 82162) 11:49 PM: snd.mgf (ID = 82180) 11:49 PM: sub.mgf (ID = 82181) 11:49 PM: ath.mgf (ID = 82164) 11:49 PM: frb.mgf (ID = 82168) 11:49 PM: sze.mgf (ID = 82182) 11:49 PM: mcact.dll (ID = 82172) 11:49 PM: prm.mgf (ID = 82173) 11:49 PM: bnr.mgf (ID = 82167) 11:51 PM: Found Adware: netpal 11:51 PM: gamehouse games.url (ID = 70891) 11:51 PM: big fish games.url (ID = 70885) 11:51 PM: flyordie games.url (ID = 70890) 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d364-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d365-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d366-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d367-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d368-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d369-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36a-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36b-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36c-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36d-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36e-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d36f-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d370-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d371-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d372-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d373-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d374-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d375-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d376-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d377-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d378-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d379-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37a-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37b-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37c-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37d-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37e-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d37f-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d380-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d381-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d382-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d383-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d384-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d385-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d386-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d387-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d388-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d389-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38a-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38b-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38c-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38d-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38e-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d38f-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d390-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d391-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d392-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d393-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d394-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d395-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d396-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d397-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d398-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d399-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39a-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39b-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39c-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39d-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39e-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d39f-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a0-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a1-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a2-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a3-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a4-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a5-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a6-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a7-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a8-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3a9-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3aa-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ab-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ac-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ad-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ae-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3af-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b0-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b1-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b2-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b3-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b4-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b5-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b6-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b7-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b8-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3b9-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ba-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3bb-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3bc-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3bd-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3be-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3bf-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c0-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c1-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c2-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c3-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c4-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c5-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c6-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c7-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c8-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3c9-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3ca-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:52 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs3882d3cb-5e0b-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because it is being used by another process 11:54 PM: windowsie.dll (ID = 70102) 12:05 AM: Found Adware: bullguard popup ad 12:05 AM: bulldownload.exe (ID = 52017) 12:18 AM: upgrade.ico (ID = 82189) 12:18 AM: rulesdata.xml (ID = 82174) 12:18 AM: snd.mgf (ID = 82180) 12:18 AM: rulesdata3.xml (ID = 82178) 12:18 AM: rulesdata2.xml (ID = 82177) 12:18 AM: rulesdata1.xml (ID = 82176) 12:18 AM: rulesfactors.xml (ID = 82179) 12:18 AM: anticipator.dll (ID = 82163) 12:18 AM: vcwebinstall.exe (ID = 82196) 12:18 AM: sub.mgf (ID = 82181) 12:18 AM: sze.mgf (ID = 82182) 12:18 AM: ath.mgf (ID = 82164) 12:18 AM: bnr.mgf (ID = 82167) 12:18 AM: frb.mgf (ID = 82168) 12:18 AM: mcact.dll (ID = 82172) 12:18 AM: prm.mgf (ID = 82173) 12:36 AM: Warning: Unhandled Archive Type 12:37 AM: Found Adware: keenvalue/perfectnav 12:37 AM: updater-040517-1005p.zip (ID = 64871) 12:37 AM: Warning: Unhandled Archive Type 12:39 AM: File Sweep Complete, Elapsed Time: 00:53:07 12:39 AM: Full Sweep has completed. Elapsed time 01:03:37 12:39 AM: Traces Found: 68 1:03 AM: Removal process initiated 1:03 AM: Quarantining All Traces: virtumonde 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine virtumonde 1:03 AM: Failed to quarantine msevents.msevents\ 1:03 AM: Failed to quarantine msevents.msevents.1\ 1:03 AM: Failed to quarantine HKLM: software\classes\msevents.msevents\ 1:03 AM: Failed to quarantine HKLM: software\classes\msevents.msevents.1\ 1:03 AM: Failed to quarantine C:\WINDOWS\SYSTEM\hggeb.dll 1:03 AM: Quarantining All Traces: bullguard popup ad 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine bullguard popup ad 1:03 AM: Failed to quarantine bulldownload.exe 1:03 AM: Quarantining All Traces: ezsearchbar 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine ezsearchbar 1:03 AM: Failed to quarantine addr_var.ini 1:03 AM: Failed to quarantine birth_var.ini 1:03 AM: Failed to quarantine city_var.ini 1:03 AM: Failed to quarantine name_var.ini 1:03 AM: Failed to quarantine states.ini 1:03 AM: Failed to quarantine name_gender.ini 1:03 AM: Failed to quarantine zip_var.ini 1:03 AM: Failed to quarantine phone_var.ini 1:03 AM: Quarantining All Traces: keenvalue/perfectnav 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine keenvalue/perfectnav 1:03 AM: Failed to quarantine updater-040517-1005p.zip 1:03 AM: Quarantining All Traces: morpheus adware 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine morpheus adware 1:03 AM: Failed to quarantine windowsie.dll 1:03 AM: Failed to quarantine windowsie\ 1:03 AM: Failed to quarantine HKLM: software\classes\windowsie\ 1:03 AM: Quarantining All Traces: netpal 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Failed to quarantine netpal 1:03 AM: Failed to quarantine gamehouse games.url 1:03 AM: Failed to quarantine big fish games.url 1:03 AM: Failed to quarantine flyordie games.url 1:03 AM: Quarantining All Traces: vcatch 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:03 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory 1:04 AM: Warning: Out of memory ******** I'm guess it didn't work very well? Also when I restarted Windows after the sweep, a warning said something like "could not locate C:\WINDOWS\SYSTEM\hggeb.dll" which I noticed is one the infected registry files.

#5 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 26 November 2005 - 07:09 AM

Can you post another log from hijackthis. :)

#6 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 26 November 2005 - 06:03 PM

Logfile of HijackThis v1.99.1
Scan saved at 4:06:45 PM, on 11/26/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CG16EH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.library.ubc.ca:8000
F1 - win.ini: load=ptsnoop.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\SYSTEM\HGGEB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O4 - User Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A5DF5E1-6EA9-494C-98A8-8A0534C5D03F} (TMSCTL.SSDLoad) - http://broadcast.mic...a/tmsct2000.CAB
O16 - DPF: {F7A42F5D-C82A-4680-B2C1-4E530BC72C23} (PostalCodePicker Control) - http://broadcast.mic...ata/tbpcctl.cab
O16 - DPF: {0FAB1B8C-5AEA-4A46-A4A8-06611412D675} (tsettask Class) - http://broadcast.mic...ta/TSetTask.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcaf...ed/MGBrwFld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {F0E42D60-368C-11D0-AD81-00A0C90DC8D9} (Snapshot Viewer Control 8.0) - http://activex.micro...ss/Snapview.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://gisweb7.city....ad/mgaxctrl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by99fd.bay99....ex/HMAtchmt.ocx
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} - http://www.easypix.ca/en/ulcontrol.cab
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = lynx.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.18.70.248,216.18.70.233

#7 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 26 November 2005 - 06:51 PM

Reboot in to safe mode and try to run spysweeper again.

#8 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 27 November 2005 - 11:53 PM

OK so I ran SpySweeper in Safe Mode and it quarantined morpheus adware from HKLM\software\classes\windowsie\ (a registry item I think)
For some reason the log never saved so I had to run it again to get another log. This time it found nothing. Here it is:
I've also included another HijackThis log after the SpySweeper log.

********
8:57 PM: | Start of Session, Sunday, November 27, 2005 |
8:57 PM: Spy Sweeper started
8:57 PM: Sweep initiated using definitions version 575
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anyusr
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: ShorTees
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anyuer
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: KaY-o-Ree
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anuyser
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anyuse4r
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anyone
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: anyuse
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: amyuser
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: ShorTe
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: An I/O operation initiated by the Registry failed unrecoverably.
The Registry could not read in, or write out, or flush, one of the files
that contain the system's image of the Registry
8:57 PM: Warning: TIdentify2700Obj.Identify: Unable to map user: ShorTeee
8:57 PM: Starting Memory Sweep
9:02 PM: Memory Sweep Complete, Elapsed Time: 00:05:32
9:02 PM: Starting Registry Sweep
9:08 PM: Registry Sweep Complete, Elapsed Time:00:05:05
9:08 PM: Starting Cookie Sweep
9:08 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:08 PM: Starting File Sweep
9:08 PM: Warning: Failed to open file "c:\windows\win386.swp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1001-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1002-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1003-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1004-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1005-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1006-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1007-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1008-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1009-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd100f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1010-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1011-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1012-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1013-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1014-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1015-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1016-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1017-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1018-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1019-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd101f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1020-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1021-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1022-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1023-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1024-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1025-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1026-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1027-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1028-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1029-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd102f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1030-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1031-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1032-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1033-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1034-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1035-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1036-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1037-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1038-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1039-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd103f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1040-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1041-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1042-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1043-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1044-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1045-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1046-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1047-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1048-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1049-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd104f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1050-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1051-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1052-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1053-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1054-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1055-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1056-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1057-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1058-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1059-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105a-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105b-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105c-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105d-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105e-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd105f-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1060-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1061-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1062-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1063-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1064-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1065-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1066-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1067-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:13 PM: Warning: Failed to open file "c:\windows\profiles\shortee\application data\webroot\spy sweeper\temp\sscs46dd1068-5f86-11da-bc4b-00d0097e3c34.tmp". The process cannot access the file because
it is being used by another process
9:50 PM: File Sweep Complete, Elapsed Time: 00:42:38
9:50 PM: Full Sweep has completed. Elapsed time 00:53:27
9:50 PM: Traces Found: 0
********

Logfile of HijackThis v1.99.1
Scan saved at 9:57:14 PM, on 11/27/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CG16EH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.library.ubc.ca:8000
F1 - win.ini: load=ptsnoop.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\SYSTEM\HGGEB.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O4 - User Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A5DF5E1-6EA9-494C-98A8-8A0534C5D03F} (TMSCTL.SSDLoad) - http://broadcast.mic...a/tmsct2000.CAB
O16 - DPF: {F7A42F5D-C82A-4680-B2C1-4E530BC72C23} (PostalCodePicker Control) - http://broadcast.mic...ata/tbpcctl.cab
O16 - DPF: {0FAB1B8C-5AEA-4A46-A4A8-06611412D675} (tsettask Class) - http://broadcast.mic...ta/TSetTask.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcaf...ed/MGBrwFld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {F0E42D60-368C-11D0-AD81-00A0C90DC8D9} (Snapshot Viewer Control 8.0) - http://activex.micro...ss/Snapview.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://gisweb7.city....ad/mgaxctrl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by99fd.bay99....ex/HMAtchmt.ocx
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} - http://www.easypix.ca/en/ulcontrol.cab
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = lynx.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.18.70.248,216.18.70.233

#9 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 28 November 2005 - 04:34 AM

Close all programs leaving only HijackThis running. Place a check against each of the following, making sure you get them all and not any others by mistake:

O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\SYSTEM\HGGEB.DLL (file missing)
O9 - Extra button: Browser Adjustment - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL


Not sure if these are bad but they will reinstall if you go back to the site you can delete these.
O16 - DPF: {D57262F5-9637-4E67-BC59-88C53EA76FC3} - http://www.easypix.ca/en/ulcontrol.cab
O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/d...SISTransfer.cab


Click on Fix Checked when finished and exit HijackThis.
Post back a fresh HijackThis log and we will take another look.

Also there is a new version of open office out :)

#10 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 28 November 2005 - 07:41 PM

Here is the new HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 5:45:04 PM, on 11/28/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\PTSNOOP.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
C:\PROGRAM FILES\NORTON CRASHGUARD\CG16EH.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\WRSSSDK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.library.ubc.ca:8000
F1 - win.ini: load=ptsnoop.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Norton CrashGuard Monitor] C:\PROGRAM FILES\NORTON CRASHGUARD\CGMENU.EXE
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE" /startintray
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O4 - User Startup: OpenOffice.org 1.1.4.lnk = C:\Util\OpenOffice.org1.1.4\program\quickstart.exe
O8 - Extra context menu item: Open Frame in &New Window - C:\WINDOWS\WEB\frm2new.htm
O8 - Extra context menu item: &Highlight - C:\WINDOWS\WEB\highlight.htm
O8 - Extra context menu item: &Web Search - C:\WINDOWS\WEB\selsearch.htm
O8 - Extra context menu item: &Links List - C:\WINDOWS\WEB\urllist.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O8 - Extra context menu item: I&mages List - C:\WINDOWS\Web\imglist.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQ\ICQLite.exe (file missing)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {9A5DF5E1-6EA9-494C-98A8-8A0534C5D03F} (TMSCTL.SSDLoad) - http://broadcast.mic...a/tmsct2000.CAB
O16 - DPF: {F7A42F5D-C82A-4680-B2C1-4E530BC72C23} (PostalCodePicker Control) - http://broadcast.mic...ata/tbpcctl.cab
O16 - DPF: {0FAB1B8C-5AEA-4A46-A4A8-06611412D675} (tsettask Class) - http://broadcast.mic...ta/TSetTask.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcaf...ed/MGBrwFld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {F0E42D60-368C-11D0-AD81-00A0C90DC8D9} (Snapshot Viewer Control 8.0) - http://activex.micro...ss/Snapview.ocx
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://gisweb7.city....ad/mgaxctrl.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.s.../ActiveData.cab
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_01) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...StatsClient.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...MineSweeper.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by99fd.bay99....ex/HMAtchmt.ocx
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan....r/axscanner.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = lynx.net
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 216.18.70.248,216.18.70.233

Is this one bad? ---
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab

Thanks for the info on OpenOffice! :D

#11 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 28 November 2005 - 08:02 PM

Is this one bad? ---
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://msevents.web...bex/ieatgpc.cab


You would think had to check it twice but it looks ok,
You can remove it it will reinstall if you go back to the site
How is it running looks clean.


Please follow a few tips to remain malware free:

Make sure you keep your Windows OS current by visiting Windows update
occasionaly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

Also download, install and keep updated- Antivirus Software (and use only one):
Free for home users:
avast! 4 Home Edition Download
AVG free version 7.0 AVG free version v6.0 updates ended 12/31/04
AntiVir Personal Edition

Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more:
Internet Explorer Privacy & Security Settings
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser:
Like Firefox,
And Thunderbird for controling spam in your e-mail.

Install a firewall. A firewall will control what comes in from the internet and what leaves your computer to the internet. A firewall will also alert you when a application trys to connect to the internet from your computer, this is a good way to catch crapware or trojans, trying to connect out bound from your computer- whats that and why does it need a internet connection? You can deny it access it until more investigation is done. Zone Alarm is a free and easy to use firewall, that will provide in and outbound protection. Microsoft XP firewall only provides inbound protection, but is not as robust as third party firewalls, Be sure to run only >one< firewall.If you use another, be sure to disable XP's built in firewall.A inexpensive NAT hardware router with SPI (firewall)would be even better,along with a software firewall.
Zone Alarm
Kerio Personal Firewall
Outpost Firewall

Download, install and update before using:(if these are constantly finding malware, then you need to make some changes)
Ad-Aware SE Personal edition
Spybot Search and destroy
Becarful with spyware "removers and scanners"-- there are many "rogue/suspect" programs that "claim to remove" spyware.

Other programs to consider:
SpywareBlaster
IE-SPYAD
AntiTrojan software to fill in the gap:
a2 free
Ewido Security Suite
Trojan Hunter (30 day trial version)

Learn More:
Tony's article So how did I get infected in the first place?
How to Secure (and Keep Secure) My (New) Computer(s)
Home Computer Security
Wilders Security Advisors

Watch what you download, and where you download it from.
Many programs come bundled with "extra" crapware you may not want. Make sure you know what it is you will be downloading and installing. Visit the makers website, learn more about the program, Does the program you want come bundled with other "3rd party" programs? What do the 3rd party programs do? Will they deliver ads? Track your surfing habits?.You may be installing more than you think, Read the EULA agreement, you know that paragraph of stuff you "agree to" before the software installs? Stay away from warez and crack sites. Becarful what you download from file sharing networks.If you are not sure, scan it with your Antivirus app. A small file (in KB) is probably not what you think it is. Some p2p clients also install 3rd party stuff you probably dont want.

Edited by little eagle, 28 November 2005 - 08:02 PM.


#12 KaY-o-Ree

KaY-o-Ree

    New Member

  • New Member
  • Pip
  • 7 posts

Posted 28 November 2005 - 08:05 PM

It seems to be running fine. Thank you very much for your help. :)

#13 little eagle

little eagle

    spyware hawk

  • Visiting Fellow
  • PipPipPipPipPipPip
  • 8,968 posts
  • Interests:spyware

Posted 28 November 2005 - 08:09 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users