No known serious problems, pop-ups and general computer slowdown experienced.
Thanks for all the help, I'm not very knowledgable about this stuff. I read the newbies file and ran Ad-aware, Spybot and also Microsoft Antispyware. This is the file HJT came up with after running those programs.
Logfile of HijackThis v1.99.1
Scan saved at 10:35:47 AM, on 11/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\Jason.POKER-731DD4C3C\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra 'Tools' menuitem: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Bet Hold'em Poker - {1BB3B2DD-30A2-4231-9547-B61760F0BF86} - C:\Program Files\betholdemMPP\MPPoker.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Program Files\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
Hello BlackandGold, welcome to the TC.
Go here and run this scan. Let me know what it finds.
Microsoft - Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx
Download this one and let me know if it finds anything.
RootkitRevealer
http://www.sysinternals.com/Utilities/RootkitRevealer.html
First off, thanks for the welcome and the help LDTate.
I ran the Microsoft program and it came up with nothing.
I ran the RootkitRevealer program and the only thing it came up with was the following: F: error mounting device (0 bytes). That is just my external harddrive that I only have used to back up a couple files for work, there is nothing important on there.
Thanks,
BlackandGold
Download the trial version of
Spy Sweeper from
Here
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)
You will be prompted to check for updated definitions, please do so.
(This may take several minutes)
Click on
Options > Sweep Options and check
Sweep all Folders on Selected drives. Check
Local Disc C . Under
What to Sweep , check every box.
Click on
Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately.
This is a necessary step to kill the infection!
When the sweep has finished, click
Remove . Click
Select All and then
Next
From
'Results' , select the
Session Log tab. Click
Save to File and save the log somewhere convenient.
Exit
Spy Sweeper.
Empty Recycle Bin
Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
HJT:
Logfile of HijackThis v1.99.1
Scan saved at 10:18:01 AM, on 12/5/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\Air Utility\AirCFG.exe
C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Jason.POKER-731DD4C3C\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [D-Link Air Utility] C:\Program Files\D-Link\Air Utility\AirCFG.exe
O4 - HKLM\..\Run: [ANIWZCSService] C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: UltraMon.lnk = C:\Program Files\UltraMon\UltraMon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra 'Tools' menuitem: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Bet Hold'em Poker - {1BB3B2DD-30A2-4231-9547-B61760F0BF86} - C:\Program Files\betholdemMPP\MPPoker.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Program Files\PokermMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Spy Sweeper:
********
2:25 PM: | Start of Session, Sunday, December 04, 2005 |
2:25 PM: Spy Sweeper started
2:25 PM: Sweep initiated using definitions version 577
2:25 PM: Starting Memory Sweep
2:33 PM: Memory Sweep Complete, Elapsed Time: 00:08:18
2:33 PM: Starting Registry Sweep
2:34 PM: Registry Sweep Complete, Elapsed Time:00:00:39
2:34 PM: Starting Cookie Sweep
2:34 PM: Found Spy Cookie: 64.62.232 cookie
2:34 PM: jason@64.62.232[1].txt (ID = 1987)
2:34 PM: jason@64.62.232[2].txt (ID = 1987)
2:34 PM: jason@64.62.232[3].txt (ID = 1987)
2:34 PM: jason@64.62.232[4].txt (ID = 1987)
2:34 PM: jason@64.62.232[5].txt (ID = 1987)
2:34 PM: Found Spy Cookie: websponsors cookie
2:34 PM: [removed][1].txt (ID = 3665)
2:34 PM: Found Spy Cookie: about cookie
2:34 PM: jason@about[1].txt (ID = 2037)
2:34 PM: Found Spy Cookie: reunion cookie
2:34 PM: [removed][1].txt (ID = 3256)
2:34 PM: Found Spy Cookie: yieldmanager cookie
2:34 PM: [removed][2].txt (ID = 3751)
2:34 PM: Found Spy Cookie: adecn cookie
2:34 PM: jason@adecn[2].txt (ID = 2063)
2:34 PM: Found Spy Cookie: adknowledge cookie
2:34 PM: jason@adknowledge[2].txt (ID = 2072)
2:34 PM: Found Spy Cookie: adlegend cookie
2:34 PM: jason@adlegend[1].txt (ID = 2074)
2:34 PM: Found Spy Cookie: specificclick.com cookie
2:34 PM: [removed][2].txt (ID = 3400)
2:34 PM: Found Spy Cookie: nextag cookie
2:34 PM: [removed][2].txt (ID = 5015)
2:34 PM: Found Spy Cookie: adrevolver cookie
2:34 PM: jason@adrevolver[2].txt (ID = 2088)
2:34 PM: jason@adrevolver[3].txt (ID = 2088)
2:34 PM: Found Spy Cookie: cc214142 cookie
2:34 PM: jason@ads.cc214142[2].txt (ID = 2367)
2:34 PM: Found Spy Cookie: adultfriendfinder cookie
2:34 PM: jason@adultfriendfinder[1].txt (ID = 2165)
2:34 PM: Found Spy Cookie: advertising cookie
2:34 PM: jason@advertising[2].txt (ID = 2175)
2:34 PM: Found Spy Cookie: askmen cookie
2:34 PM: jason@askmen[2].txt (ID = 2247)
2:34 PM: Found Spy Cookie: ask cookie
2:34 PM: jason@ask[1].txt (ID = 2245)
2:34 PM: Found Spy Cookie: atlas dmt cookie
2:34 PM: jason@atdmt[2].txt (ID = 2253)
2:34 PM: Found Spy Cookie: belnk cookie
2:34 PM: [removed][2].txt (ID = 2293)
2:34 PM: Found Spy Cookie: atwola cookie
2:34 PM: jason@atwola[2].txt (ID = 2255)
2:34 PM: Found Spy Cookie: a cookie
2:34 PM: jason@a[1].txt (ID = 2027)
2:34 PM: Found Spy Cookie: banner cookie
2:34 PM: jason@banner[2].txt (ID = 2276)
2:34 PM: jason@belnk[2].txt (ID = 2292)
2:34 PM: Found Spy Cookie: burstnet cookie
2:34 PM: jason@burstnet[2].txt (ID = 2336)
2:34 PM: Found Spy Cookie: cardomain cookie
2:34 PM: jason@cardomain[1].txt (ID = 2350)
2:34 PM: Found Spy Cookie: ccbill cookie
2:34 PM: jason@ccbill[1].txt (ID = 2369)
2:34 PM: Found Spy Cookie: classmates cookie
2:34 PM: jason@classmates[1].txt (ID = 2384)
2:34 PM: Found Spy Cookie: 2o7.net cookie
2:34 PM: jason@cnn.122.2o7[1].txt (ID = 1958)
2:34 PM: Found Spy Cookie: 360i cookie
2:34 PM: jason@ct.360i[1].txt (ID = 1962)
2:34 PM: Found Spy Cookie: clickzs cookie
2:34 PM: [removed][2].txt (ID = 2413)
2:34 PM: [removed][2].txt (ID = 2413)
2:34 PM: [removed][2].txt (ID = 2413)
2:34 PM: [removed][2].txt (ID = 2413)
2:34 PM: Found Spy Cookie: danni cookie
2:34 PM: jason@danni[2].txt (ID = 2493)
2:34 PM: [removed][1].txt (ID = 2038)
2:34 PM: [removed][1].txt (ID = 2293)
2:34 PM: Found Spy Cookie: go.com cookie
2:34 PM: [removed][2].txt (ID = 2729)
2:34 PM: Found Spy Cookie: fe.lea.lycos.com cookie
2:34 PM: [removed][1].txt (ID = 2660)
2:34 PM: jason@go[2].txt (ID = 2728)
2:34 PM: Found Spy Cookie: clickandtrack cookie
2:34 PM: [removed][2].txt (ID = 2397)
2:34 PM: [removed][1].txt (ID = 2038)
2:34 PM: Found Spy Cookie: howstuffworks cookie
2:34 PM: jason@howstuffworks[1].txt (ID = 2805)
2:34 PM: jason@msnportal.112.2o7[1].txt (ID = 1958)
2:34 PM: jason@nextag[1].txt (ID = 5014)
2:34 PM: Found Spy Cookie: offeroptimizer cookie
2:34 PM: jason@offeroptimizer[2].txt (ID = 3087)
2:34 PM: Found Spy Cookie: touchclarity cookie
2:34 PM: [removed][1].txt (ID = 3567)
2:34 PM: Found Spy Cookie: partypoker cookie
2:34 PM: jason@partypoker[1].txt (ID = 3111)
2:34 PM: Found Spy Cookie: paypopup cookie
2:34 PM: jason@paypopup[2].txt (ID = 3119)
2:34 PM: [removed][1].txt (ID = 3120)
2:34 PM: [removed][1].txt (ID = 2729)
2:34 PM: Found Spy Cookie: pub cookie
2:34 PM: jason@pub[2].txt (ID = 3205)
2:34 PM: Found Spy Cookie: questionmarket cookie
2:34 PM: jason@questionmarket[1].txt (ID = 3217)
2:34 PM: jason@reunion[2].txt (ID = 3255)
2:34 PM: Found Spy Cookie: rn11 cookie
2:34 PM: jason@rn11[2].txt (ID = 3261)
2:34 PM: Found Spy Cookie: adjuggler cookie
2:34 PM: [removed][1].txt (ID = 2071)
2:34 PM: [removed][1].txt (ID = 2729)
2:34 PM: [removed][1].txt (ID = 2806)
2:34 PM: [removed][1].txt (ID = 2729)
2:34 PM: Found Spy Cookie: trb.com cookie
2:34 PM: jason@trb[1].txt (ID = 3587)
2:34 PM: [removed][1].txt (ID = 2413)
2:34 PM: Found Spy Cookie: adminder cookie
2:34 PM: [removed][1].txt (ID = 2079)
2:34 PM: Found Spy Cookie: burstbeacon cookie
2:34 PM: [removed][1].txt (ID = 2335)
2:34 PM: Found Spy Cookie: myaffiliateprogram.com cookie
2:34 PM: [removed][2].txt (ID = 3032)
2:34 PM: jason@yieldmanager[2].txt (ID = 3749)
2:34 PM: Found Spy Cookie: zedo cookie
2:34 PM: jason@zedo[1].txt (ID = 3762)
2:34 PM: Cookie Sweep Complete, Elapsed Time: 00:00:05
2:34 PM: Starting File Sweep
2:34 PM: Found Adware: keenvalue/perfectnav
2:34 PM: c:\program files\cursonzone (3 subtraces) (ID = -2147480786)
2:34 PM: Found Adware: bullguard popup ad
2:34 PM: c:\windows\temp\bullguard (ID = -2147476409)
2:34 PM: Found Adware: 180search assistant/zango
2:34 PM: c:\windows\system32\fleok (ID = -2147480556)
2:35 PM: Found Adware: gain - common components
2:35 PM: gstartup.lnk (ID = 61450)
2:41 PM: Found Adware: navexcel navhelper
2:41 PM: f95b285a-b29a-4426-8efd-44ebc7 (ID = 70376)
2:41 PM: f422e697-5f60-4c7b-a7a3-7323fb (ID = 70373)
2:41 PM: fa004d31-f981-4ac2-b94e-11fe2f (ID = 70377)
2:41 PM: db6245d5-847b-4c11-84e2-a3fe21 (ID = 70373)
2:42 PM: 11333389-974a-49bc-a9f7-33524c (ID = 70373)
2:42 PM: about gain publishing.lnk (ID = 61270)
2:43 PM: e1b81cf9-0884-4005-afc3-e6206a (ID = 93779)
2:43 PM: 0b366572-5763-4d6a-917e-f72e97 (ID = 70374)
2:43 PM: 75d6771b-d6a1-4509-882f-354c75 (ID = 70377)
2:43 PM: 290c5ae4-2723-4e09-98a2-e404af (ID = 70376)
2:46 PM: Found Adware: ezsearchbar
2:46 PM: a0415290.cpy (ID = 60351)
2:46 PM: a0397600.cpy (ID = 60351)
2:46 PM: a0405936.cpy (ID = 60351)
2:47 PM: setup_incredifind_czone_p2.exe (ID = 64967)
2:47 PM: powersearch_cursorzone_p2.exe (ID = 64948)
2:48 PM: Found Adware: lopdotcom
2:48 PM: comver.dll (ID = 111424)
2:48 PM: a0392720.cpy (ID = 60351)
2:48 PM: uninstall.ico (ID = 65001)
2:49 PM: 6f32bd61-0a48-4188-80ee-6f6a91 (ID = 70376)
2:51 PM: 07f5879e-8710-41b1-b5ed-7d557a (ID = 70377)
2:55 PM: a0388807.cpy (ID = 60351)
2:55 PM: Found Adware: altnet
2:55 PM: __unin__.exe (ID = 49795)
2:59 PM: 249da8fb-4170-4695-a383-d09d51 (ID = 93779)
3:00 PM: a0388803.cpy (ID = 60329)
3:00 PM: a0388804.cpy (ID = 60332)
3:00 PM: a0388805.cpy (ID = 60333)
3:00 PM: a0388806.cpy (ID = 60352)
3:00 PM: a0388808.cpy (ID = 60360)
3:00 PM: a0388809.cpy (ID = 60362)
3:00 PM: a0388810.cpy (ID = 60353)
3:00 PM: a0388811.cpy (ID = 60353)
3:00 PM: a0392716.cpy (ID = 60329)
3:00 PM: a0392717.cpy (ID = 60332)
3:00 PM: a0392718.cpy (ID = 60333)
3:00 PM: a0392719.cpy (ID = 60352)
3:00 PM: a0392721.cpy (ID = 60360)
3:00 PM: a0392722.cpy (ID = 60362)
3:00 PM: a0392723.cpy (ID = 60353)
3:00 PM: a0392724.cpy (ID = 60353)
3:00 PM: a0397596.cpy (ID = 60329)
3:00 PM: a0397597.cpy (ID = 60332)
3:00 PM: a0397598.cpy (ID = 60333)
3:00 PM: a0397599.cpy (ID = 60352)
3:00 PM: a0397601.cpy (ID = 60360)
3:00 PM: a0397602.cpy (ID = 60362)
3:00 PM: a0397603.cpy (ID = 60353)
3:00 PM: a0397604.cpy (ID = 60353)
3:00 PM: a0405932.cpy (ID = 60329)
3:00 PM: a0405933.cpy (ID = 60332)
3:00 PM: a0405934.cpy (ID = 60333)
3:00 PM: a0405935.cpy (ID = 60352)
3:00 PM: a0405937.cpy (ID = 60360)
3:00 PM: a0405938.cpy (ID = 60362)
3:00 PM: a0405939.cpy (ID = 60353)
3:00 PM: a0405940.cpy (ID = 60353)
3:00 PM: a0415286.cpy (ID = 60329)
3:00 PM: a0415287.cpy (ID = 60332)
3:00 PM: a0415288.cpy (ID = 60333)
3:00 PM: a0415289.cpy (ID = 60352)
3:00 PM: a0415291.cpy (ID = 60360)
3:00 PM: a0415292.cpy (ID = 60362)
3:00 PM: a0415293.cpy (ID = 60353)
3:00 PM: a0415294.cpy (ID = 60353)
3:01 PM: gain publishing web site.url (ID = 61372)
3:03 PM: File Sweep Complete, Elapsed Time: 00:28:49
3:03 PM: Full Sweep has completed. Elapsed time 00:38:01
3:03 PM: Traces Found: 140
3:11 PM: Removal process initiated
3:11 PM: Quarantining All Traces: 180search assistant/zango
3:11 PM: Quarantining All Traces: lopdotcom
3:11 PM: Quarantining All Traces: gain - common components
3:11 PM: Quarantining All Traces: altnet
3:11 PM: Quarantining All Traces: bullguard popup ad
3:11 PM: Quarantining All Traces: ezsearchbar
3:11 PM: Quarantining All Traces: keenvalue/perfectnav
3:11 PM: Quarantining All Traces: navexcel navhelper
3:12 PM: Quarantining All Traces: 2o7.net cookie
3:12 PM: Quarantining All Traces: 360i cookie
3:12 PM: Quarantining All Traces: 64.62.232 cookie
3:12 PM: Quarantining All Traces: a cookie
3:12 PM: Quarantining All Traces: about cookie
3:12 PM: Quarantining All Traces: adecn cookie
3:12 PM: Quarantining All Traces: adjuggler cookie
3:12 PM: Quarantining All Traces: adknowledge cookie
3:12 PM: Quarantining All Traces: adlegend cookie
3:12 PM: Quarantining All Traces: adminder cookie
3:12 PM: Quarantining All Traces: adrevolver cookie
3:12 PM: Quarantining All Traces: adultfriendfinder cookie
3:12 PM: Quarantining All Traces: advertising cookie
3:12 PM: Quarantining All Traces: ask cookie
3:12 PM: Quarantining All Traces: askmen cookie
3:12 PM: Quarantining All Traces: atlas dmt cookie
3:12 PM: Quarantining All Traces: atwola cookie
3:12 PM: Quarantining All Traces: banner cookie
3:12 PM: Quarantining All Traces: belnk cookie
3:12 PM: Quarantining All Traces: burstbeacon cookie
3:12 PM: Quarantining All Traces: burstnet cookie
3:12 PM: Quarantining All Traces: cardomain cookie
3:12 PM: Quarantining All Traces: cc214142 cookie
3:12 PM: Quarantining All Traces: ccbill cookie
3:12 PM: Quarantining All Traces: classmates cookie
3:12 PM: Quarantining All Traces: clickandtrack cookie
3:12 PM: Quarantining All Traces: clickzs cookie
3:12 PM: Quarantining All Traces: danni cookie
3:12 PM: Quarantining All Traces: fe.lea.lycos.com cookie
3:12 PM: Quarantining All Traces: go.com cookie
3:12 PM: Quarantining All Traces: howstuffworks cookie
3:12 PM: Quarantining All Traces: myaffiliateprogram.com cookie
3:12 PM: Quarantining All Traces: nextag cookie
3:12 PM: Quarantining All Traces: offeroptimizer cookie
3:12 PM: Quarantining All Traces: partypoker cookie
3:12 PM: Quarantining All Traces: paypopup cookie
3:12 PM: Quarantining All Traces: pub cookie
3:12 PM: Quarantining All Traces: questionmarket cookie
3:12 PM: Quarantining All Traces: reunion cookie
3:12 PM: Quarantining All Traces: rn11 cookie
3:12 PM: Quarantining All Traces: specificclick.com cookie
3:12 PM: Quarantining All Traces: touchclarity cookie
3:12 PM: Quarantining All Traces: trb.com cookie
3:12 PM: Quarantining All Traces: websponsors cookie
3:12 PM: Quarantining All Traces: yieldmanager cookie
3:12 PM: Quarantining All Traces: zedo cookie
3:12 PM: Removal process completed. Elapsed time 00:00:43
********
9:11 PM: | Start of Session, Saturday, December 03, 2005 |
9:11 PM: Spy Sweeper started
9:11 PM: Sweep initiated using definitions version 577
9:11 PM: Starting Memory Sweep
9:17 PM: Memory Sweep Complete, Elapsed Time: 00:06:08
9:17 PM: Starting Registry Sweep
9:18 PM: Registry Sweep Complete, Elapsed Time:00:00:26
9:18 PM: Starting Cookie Sweep
9:18 PM: Found Spy Cookie: 64.62.232 cookie
9:18 PM: jason@64.62.232[1].txt (ID = 1987)
9:18 PM: jason@64.62.232[2].txt (ID = 1987)
9:18 PM: jason@64.62.232[3].txt (ID = 1987)
9:18 PM: jason@64.62.232[4].txt (ID = 1987)
9:18 PM: jason@64.62.232[5].txt (ID = 1987)
9:18 PM: Found Spy Cookie: websponsors cookie
9:18 PM: [removed][1].txt (ID = 3665)
9:18 PM: Found Spy Cookie: about cookie
9:18 PM: jason@about[1].txt (ID = 2037)
9:18 PM: Found Spy Cookie: reunion cookie
9:18 PM: [removed][1].txt (ID = 3256)
9:18 PM: Found Spy Cookie: yieldmanager cookie
9:18 PM: [removed][2].txt (ID = 3751)
9:18 PM: Found Spy Cookie: adecn cookie
9:18 PM: jason@adecn[2].txt (ID = 2063)
9:18 PM: Found Spy Cookie: adknowledge cookie
9:18 PM: jason@adknowledge[2].txt (ID = 2072)
9:18 PM: Found Spy Cookie: adlegend cookie
9:18 PM: jason@adlegend[1].txt (ID = 2074)
9:18 PM: Found Spy Cookie: specificclick.com cookie
9:18 PM: [removed][2].txt (ID = 3400)
9:18 PM: Found Spy Cookie: nextag cookie
9:18 PM: [removed][2].txt (ID = 5015)
9:18 PM: Found Spy Cookie: adrevolver cookie
9:18 PM: jason@adrevolver[2].txt (ID = 2088)
9:18 PM: jason@adrevolver[3].txt (ID = 2088)
9:18 PM: Found Spy Cookie: cc214142 cookie
9:18 PM: jason@ads.cc214142[2].txt (ID = 2367)
9:18 PM: Found Spy Cookie: adultfriendfinder cookie
9:18 PM: jason@adultfriendfinder[1].txt (ID = 2165)
9:18 PM: Found Spy Cookie: advertising cookie
9:18 PM: jason@advertising[2].txt (ID = 2175)
9:18 PM: Found Spy Cookie: askmen cookie
9:18 PM: jason@askmen[2].txt (ID = 2247)
9:18 PM: Found Spy Cookie: ask cookie
9:18 PM: jason@ask[1].txt (ID = 2245)
9:18 PM: Found Spy Cookie: atlas dmt cookie
9:18 PM: jason@atdmt[2].txt (ID = 2253)
9:18 PM: Found Spy Cookie: belnk cookie
9:18 PM: [removed][2].txt (ID = 2293)
9:18 PM: Found Spy Cookie: atwola cookie
9:18 PM: jason@atwola[2].txt (ID = 2255)
9:18 PM: Found Spy Cookie: a cookie
9:18 PM: jason@a[1].txt (ID = 2027)
9:18 PM: Found Spy Cookie: banner cookie
9:18 PM: jason@banner[2].txt (ID = 2276)
9:18 PM: jason@belnk[2].txt (ID = 2292)
9:18 PM: Found Spy Cookie: burstnet cookie
9:18 PM: jason@burstnet[2].txt (ID = 2336)
9:18 PM: Found Spy Cookie: cardomain cookie
9:18 PM: jason@cardomain[1].txt (ID = 2350)
9:18 PM: Found Spy Cookie: ccbill cookie
9:18 PM: jason@ccbill[1].txt (ID = 2369)
9:18 PM: Found Spy Cookie: classmates cookie
9:18 PM: jason@classmates[1].txt (ID = 2384)
9:18 PM: Found Spy Cookie: 2o7.net cookie
9:18 PM: jason@cnn.122.2o7[1].txt (ID = 1958)
9:18 PM: Found Spy Cookie: 360i cookie
9:18 PM: jason@ct.360i[1].txt (ID = 1962)
9:18 PM: Found Spy Cookie: clickzs cookie
9:18 PM: [removed][2].txt (ID = 2413)
9:18 PM: [removed][2].txt (ID = 2413)
9:18 PM: [removed][2].txt (ID = 2413)
9:18 PM: [removed][2].txt (ID = 2413)
9:18 PM: Found Spy Cookie: danni cookie
9:18 PM: jason@danni[2].txt (ID = 2493)
9:18 PM: [removed][1].txt (ID = 2038)
9:18 PM: [removed][1].txt (ID = 2293)
9:18 PM: Found Spy Cookie: go.com cookie
9:18 PM: [removed][2].txt (ID = 2729)
9:18 PM: Found Spy Cookie: fe.lea.lycos.com cookie
9:18 PM: [removed][1].txt (ID = 2660)
9:18 PM: jason@go[2].txt (ID = 2728)
9:18 PM: Found Spy Cookie: clickandtrack cookie
9:18 PM: [removed][2].txt (ID = 2397)
9:18 PM: [removed][1].txt (ID = 2038)
9:18 PM: Found Spy Cookie: howstuffworks cookie
9:18 PM: jason@howstuffworks[1].txt (ID = 2805)
9:18 PM: jason@msnportal.112.2o7[1].txt (ID = 1958)
9:18 PM: jason@nextag[1].txt (ID = 5014)
9:18 PM: Found Spy Cookie: offeroptimizer cookie
9:18 PM: jason@offeroptimizer[2].txt (ID = 3087)
9:18 PM: Found Spy Cookie: touchclarity cookie
9:18 PM: [removed][1].txt (ID = 3567)
9:18 PM: Found Spy Cookie: partypoker cookie
9:18 PM: jason@partypoker[1].txt (ID = 3111)
9:18 PM: Found Spy Cookie: paypopup cookie
9:18 PM: jason@paypopup[2].txt (ID = 3119)
9:18 PM: [removed][1].txt (ID = 3120)
9:18 PM: [removed][1].txt (ID = 2729)
9:18 PM: Found Spy Cookie: pub cookie
9:18 PM: jason@pub[2].txt (ID = 3205)
9:18 PM: Found Spy Cookie: questionmarket cookie
9:18 PM: jason@questionmarket[1].txt (ID = 3217)
9:18 PM: jason@reunion[2].txt (ID = 3255)
9:18 PM: Found Spy Cookie: rn11 cookie
9:18 PM: jason@rn11[2].txt (ID = 3261)
9:18 PM: Found Spy Cookie: adjuggler cookie
9:18 PM: [removed][1].txt (ID = 2071)
9:18 PM: [removed][1].txt (ID = 2729)
9:18 PM: [removed][1].txt (ID = 2806)
9:18 PM: [removed][1].txt (ID = 2729)
9:18 PM: Found Spy Cookie: trb.com cookie
9:18 PM: jason@trb[1].txt (ID = 3587)
9:18 PM: [removed][1].txt (ID = 2413)
9:18 PM: Found Spy Cookie: adminder cookie
9:18 PM: [removed][1].txt (ID = 2079)
9:18 PM: Found Spy Cookie: burstbeacon cookie
9:18 PM: [removed][1].txt (ID = 2335)
9:18 PM: Found Spy Cookie: myaffiliateprogram.com cookie
9:18 PM: [removed][2].txt (ID = 3032)
9:18 PM: jason@yieldmanager[2].txt (ID = 3749)
9:18 PM: Found Spy Cookie: zedo cookie
9:18 PM: jason@zedo[1].txt (ID = 3762)
9:18 PM: Cookie Sweep Complete, Elapsed Time: 00:00:06
9:18 PM: Starting File Sweep
9:18 PM: Found Adware: keenvalue/perfectnav
9:18 PM: c:\program files\cursonzone (3 subtraces) (ID = -2147480786)
9:18 PM: Found Adware: 180search assistant/zango
9:18 PM: c:\windows\system32\fleok (ID = -2147480556)
9:18 PM: Found Adware: bullguard popup ad
9:18 PM: c:\windows\temp\bullguard (ID = -2147476409)
9:19 PM: Found Adware: gain - common components
9:19 PM: gstartup.lnk (ID = 61450)
9:22 PM: Found Adware: navexcel navhelper
9:22 PM: f95b285a-b29a-4426-8efd-44ebc7 (ID = 70376)
9:22 PM: f422e697-5f60-4c7b-a7a3-7323fb (ID = 70373)
9:22 PM: fa004d31-f981-4ac2-b94e-11fe2f (ID = 70377)
9:23 PM: db6245d5-847b-4c11-84e2-a3fe21 (ID = 70373)
9:23 PM: 11333389-974a-49bc-a9f7-33524c (ID = 70373)
9:23 PM: about gain publishing.lnk (ID = 61270)
9:24 PM: e1b81cf9-0884-4005-afc3-e6206a (ID = 93779)
9:24 PM: 0b366572-5763-4d6a-917e-f72e97 (ID = 70374)
9:24 PM: 75d6771b-d6a1-4509-882f-354c75 (ID = 70377)
9:24 PM: 290c5ae4-2723-4e09-98a2-e404af (ID = 70376)
9:26 PM: Found Adware: ezsearchbar
9:26 PM: a0415290.cpy (ID = 60351)
9:27 PM: a0397600.cpy (ID = 60351)
9:27 PM: a0405936.cpy (ID = 60351)
9:28 PM: setup_incredifind_czone_p2.exe (ID = 64967)
9:28 PM: powersearch_cursorzone_p2.exe (ID = 64948)
9:28 PM: Found Adware: lopdotcom
9:28 PM: comver.dll (ID = 111424)
9:29 PM: a0392720.cpy (ID = 60351)
9:29 PM: uninstall.ico (ID = 65001)
9:31 PM: 6f32bd61-0a48-4188-80ee-6f6a91 (ID = 70376)
9:32 PM: 07f5879e-8710-41b1-b5ed-7d557a (ID = 70377)
9:35 PM: a0388807.cpy (ID = 60351)
9:35 PM: Found Adware: altnet
9:35 PM: __unin__.exe (ID = 49795)
9:38 PM: 249da8fb-4170-4695-a383-d09d51 (ID = 93779)
9:39 PM: a0388803.cpy (ID = 60329)
9:39 PM: a0388804.cpy (ID = 60332)
9:39 PM: a0388805.cpy (ID = 60333)
9:39 PM: a0388806.cpy (ID = 60352)
9:39 PM: a0388808.cpy (ID = 60360)
9:39 PM: a0388809.cpy (ID = 60362)
9:39 PM: a0388810.cpy (ID = 60353)
9:39 PM: a0388811.cpy (ID = 60353)
9:39 PM: a0392716.cpy (ID = 60329)
9:39 PM: a0392717.cpy (ID = 60332)
9:39 PM: a0392718.cpy (ID = 60333)
9:39 PM: a0392719.cpy (ID = 60352)
9:39 PM: a0392721.cpy (ID = 60360)
9:39 PM: a0392722.cpy (ID = 60362)
9:39 PM: a0392723.cpy (ID = 60353)
9:39 PM: a0392724.cpy (ID = 60353)
9:39 PM: a0397596.cpy (ID = 60329)
9:39 PM: a0397597.cpy (ID = 60332)
9:39 PM: a0397598.cpy (ID = 60333)
9:39 PM: a0397599.cpy (ID = 60352)
9:39 PM: a0397601.cpy (ID = 60360)
9:39 PM: a0397602.cpy (ID = 60362)
9:39 PM: a0397603.cpy (ID = 60353)
9:39 PM: a0397604.cpy (ID = 60353)
9:39 PM: a0405932.cpy (ID = 60329)
9:39 PM: a0405933.cpy (ID = 60332)
9:39 PM: a0405934.cpy (ID = 60333)
9:39 PM: a0405935.cpy (ID = 60352)
9:39 PM: a0405937.cpy (ID = 60360)
9:39 PM: a0405938.cpy (ID = 60362)
9:39 PM: a0405939.cpy (ID = 60353)
9:39 PM: a0405940.cpy (ID = 60353)
9:39 PM: a0415286.cpy (ID = 60329)
9:39 PM: a0415287.cpy (ID = 60332)
9:39 PM: a0415288.cpy (ID = 60333)
9:39 PM: gain publishing web site.url (ID = 61372)
9:40 PM: a0415289.cpy (ID = 60352)
9:40 PM: a0415291.cpy (ID = 60360)
9:40 PM: a0415292.cpy (ID = 60362)
9:40 PM: a0415293.cpy (ID = 60353)
9:40 PM: a0415294.cpy (ID = 60353)
9:41 PM: Warning: Unhandled Archive Type
9:42 PM: File Sweep Complete, Elapsed Time: 00:23:49
9:42 PM: Full Sweep has completed. Elapsed time 00:30:33
9:42 PM: Traces Found: 140
********
9:08 PM: | Start of Session, Saturday, December 03, 2005 |
9:08 PM: Spy Sweeper started
9:08 PM: Sweep initiated using definitions version 556
9:08 PM: Starting Memory Sweep
9:10 PM: Sweep Canceled
9:10 PM: Memory Sweep Complete, Elapsed Time: 00:02:24
9:10 PM: Traces Found: 0
9:10 PM: Updating spyware definitions
9:11 PM: Your spyware definitions have been updated.
9:11 PM: | End of Session, Saturday, December 03, 2005 |
********
9:07 PM: | Start of Session, Saturday, December 03, 2005 |
9:07 PM: Spy Sweeper started
9:08 PM: | End of Session, Saturday, December 03, 2005 |
Computer is running fine, no current problems.
BlackandGold
Be sure to keep SunJava, updated
In Add/Remove programs click on these and press *remove* if listed:
J2SE Runtime Environment 5.0 - 97.99Mb
J2SE Runtime Environment 5.0 Update 2 - 143.00Mb
J2SE Runtime Environment 5.0 Update 4 - 144.00Mb
J2SE Runtime Environment 5.0 Update 5- 151.00Mb
Java 2 Runtime Environment, SE v1.4.2_04 - 130.00Mb
Or any other outdated J2SE
It is important to remove older versions as these are the ones with the holes in them. You will be surprised when you go to add/remove to see all of the versions sitting there.
Download Newest >>>>
http://www.java.com/en/download/index.jsp
Once installed you can test to see that it is in fact installed >>>>
Sun Java Test
Sun Microsystems has fixed five security bugs in Java that expose computers running Linux, Solaris and Windows to hacker attack.
These are Optional fixes:
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a
Check in the box on the left side on these:
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O9 - Extra button: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra 'Tools' menuitem: Coral Eurobet Poker - {050AC5CD-E1E1-41ab-8CE0-61B56EFA7FA1} - C:\Program Files\CoralEurobetPoker\coraleurobetpoker.exe
O9 - Extra button: Bet Hold'em Poker - {1BB3B2DD-30A2-4231-9547-B61760F0BF86} - C:\Program Files\betholdemMPP\MPPoker.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: POKER - {FB389F33-303A-4490-9E18-B301A493FBF2} - C:\Program Files\PokermMPP\MPPoker.exe
Close
ALL windows and browsers
except HijackThis and click
"Fix checked"
1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.
Restart your computer.
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Due to inactivity this topic will be closed.
If you need help please start a new thread and post a new HJT log