This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

really stubborn spyware

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

during a daily spy sweeper scan this morning, i discovered i have a little computer mess. problem is, spy sweeper will not remove the "system monitor" that is imbedded in my system; spysweeper locks down while trying to remove this particularly tough spy, and being unfamiliar with HJT code, i am unable to locate it in the HJT logfile. here's my log file from HJT. thanks in advance for any assistance with this problem.

Logfile of HijackThis v1.99.1
Scan saved at 5:02:43 PM, on 12/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\DOCUME~1\Scott\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\SpywareDetector\SDMonitor.exe
C:\WINDOWS\system32\SDSystemTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Scott\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/news?sourceid=navclient&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SystemTraySD] C:\WINDOWS\system32\SDSystemTray.exe
O4 - HKLM\..\Run: [MonitorSD] C:\Program Files\SpywareDetector\SDMonitor.exe
O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\WINDOWS\system32\LiveUpdateSD.exe -AUTO
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131478506968
O20 - Winlogon Notify: SDNotify - C:\WINDOWS\SYSTEM32\SDNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SpyDetectSVC - Max Secure Software Technologies - C:\WINDOWS\system32\SpywareDetectorSVC.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
You are running HJT from a temporary file and desktop we will be cleaning out all of you temp. files latter you will need to make a new folder for HijackThis. Instructions can be found here.


C:\DOCUME~1\Scott\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

C:\Documents and Settings\Scott\Desktop\HijackThis.exe


Remove this in add and remove programs. http://www.spywarewarrior.com/rogue_anti-spyware.htm
C:\Program Files\SpywareDetector


Then post another log.
first of all, thanks for your time and prompt response. i saved the file to the C: drive and ran HJT from that location. prior to running the HJT scan, i also deleted spyware detector using A/R programs, then went into C: and deleted the folder.



Logfile of HijackThis v1.99.1
Scan saved at 7:48:20 PM, on 12/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\DOCUME~1\Scott\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Scott\Desktop\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/news?sourceid=navclient&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131478506968
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
little eagle: i never did any spyware removal other than what i posted previously (moved HJT in C:, and removed Spyware Detector). when i scan with spy sweeper this morning, I still get the following infestations: 6:17 AM: | Start of Session, Wednesday, December 21, 2005 | 6:17 AM: Spy Sweeper started 6:17 AM: Sweep initiated using definitions version 587 6:17 AM: Starting Memory Sweep 6:18 AM: Memory Sweep Complete, Elapsed Time: 00:01:42 6:18 AM: Starting Registry Sweep 6:18 AM: Found Trojan Horse: infected mushrooms 6:18 AM: HKCR (ID = 1059498) 6:18 AM: Found Adware: e2g 6:18 AM: HKCR (ID = 1059519) 6:18 AM: HKCR (ID = 1059521) 6:18 AM: HKLM (ID = 1059523) 6:18 AM: HKLM (ID = 1059525) 6:18 AM: HKCR (ID = 1059562) 6:18 AM: Found Trojan Horse: trojan-downloader-hochladen 6:18 AM: HKLM (ID = 1059579) 6:18 AM: HKU\S-1-5-21-789336058-1677128483-725345543-1003 (18961 subtraces) (ID = 1059502) 6:18 AM: Found Adware: ezula ilookup 6:18 AM: HKU\S-1-5-21-789336058-1677128483-725345543-1003 (18961 subtraces) (ID = 1059530) 6:18 AM: HKU\S-1-5-21-789336058-1677128483-725345543-1003 (18961 subtraces) (ID = 1059566) 6:18 AM: HKU\S-1-5-20 (245 subtraces) (ID = 1059502) 6:18 AM: HKU\S-1-5-20 (245 subtraces) (ID = 1059530) 6:18 AM: HKU\S-1-5-20 (245 subtraces) (ID = 1059566) 6:18 AM: HKU\S-1-5-19 (262 subtraces) (ID = 1059502) 6:18 AM: HKU\S-1-5-19 (262 subtraces) (ID = 1059530) 6:18 AM: HKU\S-1-5-19 (262 subtraces) (ID = 1059566) 6:19 AM: HKU\S-1-5-18 (5887 subtraces) (ID = 1059502) 6:19 AM: HKU\S-1-5-18 (5887 subtraces) (ID = 1059530) 6:19 AM: HKU\S-1-5-18 (5887 subtraces) (ID = 1059566) 6:19 AM: Registry Sweep Complete, Elapsed Time:00:00:12 6:19 AM: Starting Cookie Sweep 6:19 AM: Found Spy Cookie: specificclick.com cookie 6:19 AM: [removed][1].txt (ID = 3400) 6:19 AM: Found Spy Cookie: about cookie 6:19 AM: [removed][1].txt (ID = 2038) 6:19 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00 6:19 AM: Starting File Sweep 6:19 AM: Found System Monitor: ????????????????????? ??????? ??????????????? ???????????????? ????????????????? ?????????????? ???????????? ??????????????????????? ???????????????????????????????? ????????? ??????????????????????? ???????????????????????????? ???????????? ??????????????????? ?????????????? ???????????????????????????????? ??????????????? ????????????????????????? ??????????????? ???????????????? ??????????????? ???????????????? ???????????????? ????????????????? ??????????????????? ????????????? ???????????? ???????????????? ??????????????????????? ??????????????????????? ??????????????????????? ???????????????? ??????????????????????? ?????????? ??????? ??????????????????? ??????????????????????????????????? ??????????????????? ???????????????????????? ??????????????????????? ????????????????????? ??????????????????????????? ??????????????????????????? ???????????????? ????????????? ????????????????????????? ??????????????? ????????????????????????????? ?????????????????????????? ??????????????????? ???????????????? ??????????????????????????? ????????????????? ????????????? ??????????????????????????? ??????????????????????? ????????????????? ?????????????????????????????????? ??????????????????????????????? ???????????????????????????? ????????????? ???????????????????????? ????????????????????? ??????????????? ??????? ???????????????? ??????????????????????????? ?????????????????? ??????????????????? ????????????????????????? ??????????? ? ???????????????? ???????????????????????? ????????????? ?????????????????? ???????????? ?????????????????????????????????????????? ????????????????? ???????????? ???????????????? ????????????????????????????????????????? ???????????????????????? ?????????????? ????????????????????????? ???????????????? ???????????????????????????????? ???????????????? ???????????????? ??????????????? ??????????????????????????????????? ??????????????????????????????????????? ????????????????????????? ?????????????????????????????????????? ???????????????? ?????????????? ?????????????????????? ??????????? ???????????????? ?????????????????????????? ?????????????????? ????????????? ?????????????????????????????????????????????????? ?????????????????????? ?????????????????????????? ??????????????? ?????????????? ???????????????????? ???????????????????????????????????? ????????????????? ?????????? ???????????????? ???????????????? ?????????????????? ??? ????? ??????????????????? ??? ???????????? ?????????????????????????????? ?????????? ??????????????????????????? ????????????????????????? ????????????????????? ??????`????????? ??????????????? ???????????????????????????????????????????????????????????? ????????? ??????????????????????????????????? ?????????????? ??????????????????????????? ?????????????????????? ????????????????? ?????????????? ?????????????????? ?????????????????? ?????????????? ???????????????????????????? ?????????? ??????????????????????????????????????????????????????????? ???????? ??????????????????? ???????????????????????? ?? ????????? ?????????????????????? ????????????? ????????????? ??????????????????? ????????????????????????? ????????????????? ????????? ??????????????? ????????????????????????? ??????????????? ??????????????? ???????????????????? ??? ???????????????????????????? ?????????????? ??????? ?????????????????????????? ?????????????????????????? ?????????????????? ?????????????????????????????? ???????????? ???????????????????????????????? ???????????????? ??????????????????????????????????????????????????????????????? ????????????????????????? ?????????????????????? ????????????????????? ????????????????? ??????????? ??????????? ????????????????????? ?????????????????????? ??????????????????????????? ??????????????? ???????????????????????? ????????????????????????? ???????????????? ???????????????????????? ?????????????????????????? ??????????????????? ?????????????????????????? ????????????????????? ????????????????????????????????????????????????? ?????????????????????? ????????????? ??????????????????????????????? ???????????????????????? ????? ???????????????????????????????? ?????????????????? ??????????????? ???????????? ???????????????? ???????????????? ?????????????????????????????????? ??????????????????? ??????????????????? ???????????????????????????????? ????????????????? ??????????????????????????????????? ????????????? ??????????????????????? ?????????????????? ??????????????????????????????????????? ??????????????????????????????? ????????????? ?????????????????? ????????????????????????????????????? ???????????????????????????? ??????????????????? ???????????????? ?????????????????? ??????????????? ????????????? ????????? ?????? ????????????????????????????? ???????????????? ??? ??????????????????? ??????????? ????? ????????????????????????? ??????????????????????????????? ? ????????????????????????????????????????????????????????? ??????????????? ?????????????????????? ????????????????????????????????? ???????????????? ?????????????????? ???????????????????? ???????????????? ???????????????? ??????????????????? ??????????????? ?????????????? ???????????????? ??????????????????????????????????????????????? ??????????????????? ?????? ????????????????????? ????????????? ?????????????? ?????????????????????? ??????????????????????????? ??????????????????? ???????????????????????????????????????? ??????????????????????? ????????????????????? ?????????????????????? ???????????????????? ?????????????? ??????????????? ?????????????????????????? ?????????????????????? ???????????????? ?????????????????? ???????? ????????????????? ???????????????????????????????? ????????????????? ?????????????????????????????????????????????? ?????????????????????????????????????? ?????????????????? ????????????????????????????? ????????????????? ????????????????????????????????? ???????????????????? ????????????????? ?????????????????????? ??????????????? ?????????????? ?????????????????????????????????????????????`?????????????????????????????????????????????????? ????????????????????????? ????????????????? ??????????????? ?????????? ???????????????? ??????????????? ????????????? ?????? ?????????????????????? ???????????? ?????????????????? ???????????? ?????????????????????????? ????????????????????? ?????????? ?????????? ???? ????????????????????????? ?????????? ??? ?????????? ????????????????????? ?????????????????????????????? ???????????????????? ????????????????????? ??????????????????????? ?????????????????????? ??????????????????????????-????????????? ???????????? ? ?????????????????????? ???????????? ??????????????????????????????????? ???????????? ???????????? ?????????????????????? ????????????????????????????? ??????????????????????? ??????????????????????????????????????? ?????????????????????? ????????????? ????????????????????????????????? ???????????????????????????????? ???????????????? ?????????????????????? ?????????????????? ???????????? ???????????? ????????????????????? ?????????????????????? ???????????? ? ????????????????????? ???????????? ??????????? ?????????????????????????? ????????????????????????????? ?????????????? ???????????? ???????????? ???????????????? ?????????????????????? ?????????????????????????????????? ?????????????????????? ??????????????????? ??????????????? ???????????? ??????????? ???????????????????? ?????????????????? ??????????????????????????????? ???????????????????????? ?????????????????? ???????????? ???????????? ?????????????? ?????????????????? ????????????????????????????????? ??????????????????? ??????????? ?????????????????????????????????? ?????????????????? ????????????????????????? ???????????? ???????????? ????????????????? ???????????????????????? ???????????? ?????????? ?????????????????? ???????????????? ???????????? ???????????? ???????????????????????????????????????? ???????????? ??????????? ???????????? ??????????? ???????????????????????????? ????????????? ???????????????????????? ????????????????????? ?????????????????? ??????????????????????? ??????????????????????????????????? ?????????????????? ????????????????????? ?????????????????????? ???????????????? ???????????????????????? ???????????????????????? ???????????? ??????????????? ??????????????????? ?????????????? ????????????????? ??????????????????? ??????????????????????????????? ????????????????????? ???????????????????? ???????????? ??????? ?????????????????? ????????????????????????? ????????????????????? ???????????????? ??????????????????????????????? ?????????????????? ????????????????????? ???????????????????? ????????????????? ???????? ??????????????????? ???????????? ??????????? ??????????????????? ??????????????????? ?????????????? ???????????????????? ?????????????????????? ??????????????????? ???????????????????????? ??????????????? ??????????????????????????????????????????????? ??????????????????? ???????????????????????? ???????????????????? ???????????????????? ?????????????????????? ???????????????????????????? ????????????????????????? ?????????????????????? ?????????????? ????????????????? ???????????????????????????????????????????????????? ????????????? ????????????? ???????????? ?????????????????`??????????????????????????????????????? ??????????????????? ???????????????????? ???????????? ?????? ???????????? ??????????????????????????? ??????????????????????? ??????????? ??????????? ??????????????? ???????????????????????? ??????????????-?????????????????????????????? ????????????????????????? ?????????????????????????? ????????????????????????? ??????????????????????????????? ?????????????????????? ?????????????????????????? ????????????????????????? ????????????????????? ????????????????? ???????????????? ????? ?????????????? ??????????? ??????????????????????????????????????????????????????????????????????????? ??????????????? ???????????????????????????????????? ??????????????????????????????? ???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ???? ???????????????? ???????????????? ???????????????? ?????????? ????????????? ?????????????? ???????????? ?????????????????? ??????????? ?????????????? ????????? ???????????? ???????????????? ?????????????????? ??????? ????????????? ???????? ??????????????????????????????? ???????????????????? ??????????????? ????????????????????? ????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ???????????????????????? ?????????????????????????????? ????????????????????????????????`?????? ? ???????????????????? ????????????????????????????????? ??????????????????? ??????`??????????????????? ????????????????????????????????????????? ????????????? ????? ?????????? ??????????? ??????????? ??????????? ??????????? ???????????????????? ??????????? ??????????? ??????????????????? ????????????????? ??????????? ??????????? ??????????? ??????????? ??????????? ?????????????????????? ????????????????? ????????????????????? ?????????????? ????????? ???????????? ?????????????? ??????????????????????????? ????????????? ?????????????? ?????????????? ???????? ???????????? ???????? ????????????????????????????? ??????????????? ??????????????????????????? ?????????????? ?????????????? ????????????? ???????????????????????????????? ???????????????????????????????? ????????????????? ??????????????? ??????????????????? ???????????????????????????????????????? ?????????????????????????????? ??????????????? ????????????? ?????????????????????????????????????????????????? ?????????????? ???????`????????????????????????? ????????????? ???????????????????????? ????????????????????? ?????????????????????????????????????????? ???????????????? ??????????? ?????????????????? ???????????????????????? ???????????????? ??? ???????????????????????????????? ??????????????? ??????????????? ?????????????????????? ???????????? ?????????????????? ??????????????????????????? ??????????????? ??? ?????????????????????????????? ??????????? ????????????????????? ??????????????????? ???????????????????????????? ??????????????? ?????????????????????? ??????????????????????????????????????? ????????????????????? ??????????????????????????????????????????????? ?????????????? ??????????????????????? ?????????????????? ?????????? ??????? ??????????????????????????? ?????????????????????? ??????????????????????????????????????????????? ??????????????????? ??????????? ???????????????????????????? ?????????????????????? ???????????????????? ??????????????????????????????????? ?????????????????????? ???????????????? ??????????????????????????? ???????????????????????????? ??????????????? ????????????????? ??????????????? ????????????? ????????? ??? ????? ??????????? ????????????????? ?????????????? ???????????????????? ??????????? ???????????????????????? ???????????? ????????????????????????? ??????????????????????? ???????????????????????????????? ???????????? ?????????????????????????????????????????????? ?????????????????????? ????????????? ??????????????????????? ?????????????????????????????? ????????????????????????? ???????????????????? ????????????????????? ????????????????????????? ?????????????? ???????????????? ????????????????????? ?? ????????????? ????????????????? ?????????????? ??????`?????????? ?????????? ???????????????? ?????? ????????????? ???? ??????????????????? ???????????????????? ????????????????? ????????????? ???????????????????? ?????????????? ???????????????? ?????????????? ?????????????????????? ?????????????????????????????? ??????????????????????? ??????? ???????? ??????????? ???????????????? ??????????????? ??????????????? ?????????????????? ?????????????????????????? ??????????????????????? ??????????????? ?????????????????????????????? ?????????????? ????????????????? ????????????????? ??????????????????????? ???????????????? ????????????????? ??????????????????? ?????? ??????????? ?????????????????????? ?????????????????????? ????????????????????????? ???????????????????? ????????????? ????????????????? ???????? ????? ???????????????????????? ??????????????????? ?????????????????? ?????????????????? ????????????? ???????????????????????? ????????????? ??????????????? ??????????????????? ????????????????????????????? ??????????? ??????????????????????????????????? ?????????????????????????? ?? ???????????????????????? ????????????? ???????????????????? ?????????????????????????????????????????? ???????????????????????????? ???????????????????????????????????????????????? ???????????????????? ????????????????????????????? ???????????????????? ???????????? ??????????????????????????? ?????????????????????????? ?????????????????? ??????????????????????? ????????????????????????????????? ????????????? ??????????? ?????????? ?????????????? ?????????? ?????? ??????? ????????? ?????????????????? ??????????? ??????????? ?????????? ????????????? ????????? ???????????????????????? ?????????? ????????????????????????????????????????? ????????????????? ???????????????????????????????????????? ??????????????????????? ????????? ??????????? ???????????????????????? ??????????????????????????? ??????????????? ???????????????????????????? ????????????????? ????????????????????????? ???????????? ??????????????? ????????????????????? ????????????????? ??????????????????????? ?????????????????? ?????????????????? ?????????????????? ??????????? ????????????????????????? ???????????????????????????????????????? ???????????????????????????????????????????? ???????????????? ????????????? ??????????????? ????????????? ??? ???????????????????????????? ??????????????????????????????? ???????????????????????? ???????????????????????? ??????????????????? ??????????????????????????????????????????????? ????????????????????????????????? ???????? ????????????? ???????????????? ??????????????? ??????????? ?????????????????? ???????????????????????? ????????????????????????????? ??????????????????? ??????? ?????????????? ?????????????????????????????? ???????? ?????????????????????????????????????????????????????? ????????????? ???????????????? ??????????????? ??????????????????????? ?????????????? ???????????????????????? ??????????? ????????????????????????????? ????????????????? ?????????????????????????? ??????????????????????????????????? ?????????? ???????? ???????????????????? ?????????????????? ????????????????? ??????? ?????????????????????????????????????????????????? ???????? ? ???????????? ? ???????? ???????????? ????????????????????????????????????????????????????????? ???? ??? ???????????????????????? ?????????? ???????????????????????????? ???????????? ???????????????????? ??????? ??????????????? ??????????????? ??????????????????????? ??????????? ???????????? ????????????????????? ???? ?????????????????????????????? ?????????????? ?????????? ???????????? ? ????????????? ???????????????????? ???????????????????????????? ?????????????????????????? ?????????????????? ?????????????????? ???????????????????????????????? ???????????????? ???????????????? ??????????????? ??????????? ???????? ??????????????? ??????????????? ???????????????????? ??????????????????????????????????????? ???????????????? ??????????????????????????? ???????????????????????? ???????????? ????????????????????????????????? ??????????????????? ???????????? ?????????????? ??? ??????????????????? ????????????????????? ????????????? ???????????????? ???? ?????????????????? ??????????????????????? ?????????????? ????????????? ?????????????? ??????????????? ?????????????? ??????????????????????????? ??????????????????????????????????? ???????????????????????????????????????? ??????????????? ????????????????????????? ?????????????????????????????????????? ????????????????????????? ?????????????????????????????????????????????? ??????????????????? ????????????????? ??????????????? ????????????????? ?????? ?????????????????? ???????????????????????????????????? ??????????????????? ????????????????????????? ??????????????????? ????????????? ??????????????? ?????????????????????????????? ?????????????? ????????????????????? ???? ??????????????????????????????????????????????????? ????????????????? ????????????????????????????? ?????????????????? ???????????????? ???????????????????????????????????? ?????????????? ??????????? ? ?????????????????????????????? ??????????????????? ???????????????????????????????????? ?????????????????????? ????????????????????????????????????????????? ???????`????????????????????? ???????? ??????????????????? ????????????????????????? ??????????????????????? ???????????????????????????????????????? ???????????????? ???????????????????? ????????????????????? ??????????? ???? ?????????? ?????????????? ??????????????????????????????????????????? ????????????????? ???? ??????????? ?????? ?????????? ????????? ??????????? ??????`??????????????????????????????????? ????????? ????? ???????????? ???? ???????? ????????? ???? ??? ????????? ??????????????? ????????????????????????????? ??????????????????? ??????????????????????? ???????????????????????????????????????????? ???????????????? ????????????????? ????????????????? ????????????? ???????????????????????????????????????????????????? ????????????????? ?????????????????? ??????????????????? ???????????????????????????????????????? ??????????????????? ???????????????????? ??????????????? ??????????????????????????????????? ?????? ?????????????????????? ????????? ?????? ???????????????????????????????? ????????????????????????? ?????????????? ????????? ??????????????? ???? ??????????? ???????? ??????????????????????????????????? ?????????????????????????????????????????????????????????????? ???????????????????????????????????????????????????? ??????????????????????? ???????????????????? ??????????????????????? ?????????????? ?????????????????????????? ???????????????????????????????????????? ?????????????????????? ????????????????????? ?????????????????????? ???? ??????? ???????????????????? ????????????????? ?????????? ???????????????????? ???????????????????????????? ????????????????? ????????????????????????????????????????????? ???????????? ?????????????????????????????????????? ???????????????????????? ????????????????????? ????????????????? ???????????????????? ??????????????? ???????????????????????? ?????????????? ?????????????????? ????????????????????????????????????????????????????????????????? ????????????????????? ?????????????????????????? ??????????????????????? ????????????? ?????????????????????????????????? ?????????????? ???????????????????????? ?? ??????????? ?????????????????? ????? ??? ??????????????? ???????????????????? ????????????????? ?????????????????????????????????? ??????????????? ???????????????????????????????????? ??????????????? ????????? ???????? ?????????? ?????????? ????????? ??????? ????????? ????????? ?????????????????????????????????? ??????????????????????? ?????????????????? ????????? ??????????????????????? ??????? ???????????????????? ???????????? ?????????????? ????????????????? ????? ??????????????? ?????????`??????????? ?? ??? ???????????????????????????????????????????????????????????????????????????? ??????????????????????????? ?????????????????????? ???????????? ??????????? ?????????????? ?????????????? ????????????????????? ???????????????????? ?????????????????????????????????????? ???????????????? ?????????????????????? ????????????? ??????????????????? ?????????????????? ??????????????????????????? ???????????? ???????????????? ??????????????????????? ???????????????????? ??????????????????? ????????????????????????????? ??????????? ?????? ?????????????????????? ??????????????????? ????????????????????????? ??????????????? ?????????????????? ?????????????????????????????????? ?????????????? ????????????????????? ?????????????????????????????????????????????????? ?????????????????????????????????? ???????????????????? ???????????????????????????? ????????????????? ???????????????????? ????????????????????? ?????????????????????????? ??? ? ???????????????????????? ????????????????????? ???????????????????? ??????????????????? ???????????????????????`?????????????? ?????????????????????? ??????????????????? ?????????? ??????????????????????? ???????????????????????????? ?????????????????? ??????????????? ????????????????????????? ???????????????????????????? ?????????? ????????????????? ????????????? ???????????? ????????????????????? ??????????????????????????????????? ???????????? ??????????? ???????????? ??????????????? ???? ????????????????????????????????????`?????????? ?????????????????? ?????????????????????? ???????????????? ??????????? ??? ????????????????? ????????????????? ???????????????????????????????? ????????????????? ??????????????????????????????? ?????????????????????????? ???????? ?????????????? ??????????????????????????????????? ????????????????? ?????????????????????????????????? ?????????????????????????? ?????????????????????? ????? ???????????????????? ????????????????? ????????????? ???????? ??????? ???????????????????????? ????????????????? ?????????????????? ???????????????????????? ??????????????????? ?????????????? ???? ?????????? ???????????????????? ????????????? ?????? ????????????????????? ????????? ??????????????????????? ??????? ????????????????? ??????`?????????????????? ?????????????? ????????????? ????????????????????????????????????????????? ???????? ???????????????? ??????????? ??????????????????????? ? ???????????? ? ??????????? ??????????? ??????????? ???????????????????????????????????????????? ??????????????????????????? ????????????? ????????????????????????????????? ????????????? ????????????????????????????????? ????????????????????????? ??????????? ?????????????????????????????? ????????????????????? ??????????????????????? ??????????????????? ????????????? ???????? ????????????????????????????????? ??????????????????? ????????????????? ??????????????????????? ???????????????????????????????????????????????? ???????????????????????? ?????????????????? ?????????????? ?????????????? ??????????????????????? ?????????????????????????? ?????????????????? ???????????????????????????????????? ?????????????????????????????????????????????????????????????? ?????????????????????? ????????????????????????????????????????????? ??????????????????????????? ???????????????????????????????????????? ??????????? ??????????? ?????????????????? ????????????????? ??????????????????????? ??????????????????????????? ?????????????????? ????????????????????? ??????????????????? ?????????????? ?????????????????????? ?????????????????????? ????????????????? ??????????????? ?????? ??????? ???????????????? ??????????????? ?????? ??????????????????????????????????? ??????????????????????? ???????????????????????? 6:19 AM: c:\documents and settings\all users\start menu (181 subtraces) (ID = -2147461784) 6:22 AM: File Sweep Complete, Elapsed Time: 00:03:46 6:22 AM: Full Sweep has completed. Elapsed time 00:05:43 6:22 AM: Traces Found: 76268 ********
Just to give you an update, SpySweeper support sent me a fix, which was: go into Safe Mode, run a SpySweep scan three times back to back, then reboot into normal mode and then run a scan. Believe it or not, when i ran a scan in normal mode, it came back clean as a whistle… seems like hocus-pocus to me, but the last scan was clean! Below is a HJT file taken after the above SpySweeper fix:

Logfile of HijackThis v1.99.1
Scan saved at 5:00:23 PM, on 12/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/news?sourceid=navclient&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131478506968
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")


Post the report here in this thread.
Here's the ewido report: ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 11:01:38 PM, 12/21/2005 + Report-Checksum: 6AA6AAB3 + Scan result: HKU\S-1-5-21-789336058-1677128483-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup HKU\S-1-5-21-789336058-1677128483-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7C559105-9ECF-42B8-B3F7-832E75EDD959} -> Spyware.ISTBar : Cleaned with backup HKU\S-1-5-21-789336058-1677128483-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup HKU\S-1-5-21-789336058-1677128483-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup ::Report End
here's another HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 8:13:36 AM, on 12/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/news?sourceid=navclient&ie=UTF-8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1131478506968
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI